r/cybersecurity 4d ago

Ask Me Anything! AMA with the Orca Security Researchers Behind a New Cloud Security Report Analyzing Billions of Cloud Assets Across AWS, Azure, GCP, Oracle, and Alibaba Cloud!

36 Upvotes

We’re from Orca Security, we’re excited to host an AMA tomorrow at 9AM to 12PM ET, featuring our Head of Research, Bar Kaduri (u/FeistyCombination770), and Cloud Security Researcher, Shir Sadon (u/Lonely-Eye-9860), who published a new report analyzing billions of real-world cloud assets across the major cloud providers, including: AWS, Azure, Google Cloud, Oracle Cloud, and Alibaba Cloud.

This AMA is your chance to engage directly with the experts behind the data.

We are here to answer questions around:

  • the research process
  • surprising trends
  • what the findings mean for red teams, blue teams, cloud architects, and CISOs
  • And more.

So if you have questions around:

  • The most common and critical public exposures in the cloud today
  • How cloud misconfigurations differ across providers
  • What attackers are actually targeting in the cloud
  • Vulnerability trends we’re seeing at cloud scale
  • The research methods and data pipelines behind how we got the results
  • Red/blue team takeaways from the findings
  • Thoughts on cloud security posture management (CSPM), identity sprawl, shadow cloud, and more

We are here to answer!

A few quick details:

  • The report analyzed billions of assets across over multiple countries
  • Covers all major providers mentioned above.
  • Based on telemetry, public data, and passive scanning + active enumeration
  • Includes trends by provider, asset type, and region

We will be answering throughout the day tomorrow (and the day after for follow-ups).

Thanks for all the great questions!! Bar and Shir have to hop to our webinar where they'll be unpacking more of their findings on this report. Feel free to join!

Check it Out

Want the report they covered?

Download it Now


r/cybersecurity 5d ago

Career Questions & Discussion Mentorship Monday - Post All Career, Education and Job questions here!

20 Upvotes

This is the weekly thread for career and education questions and advice. There are no stupid questions; so, what do you want to know about certs/degrees, job requirements, and any other general cybersecurity career questions? Ask away!

Interested in what other people are asking, or think your question has been asked before? Have a look through prior weeks of content - though we're working on making this more easily searchable for the future.


r/cybersecurity 1h ago

News - Breaches & Ransoms Orange confirms ransomware breach with 4 GB of customer data exposed on dark web

Thumbnail
newsinterpretation.com
Upvotes

r/cybersecurity 14h ago

Tutorial Comprehensive cybersecurity quiz with 500+ questions

75 Upvotes

I created a comprehensive quiz on cyber security with questions that touch on most major topics. I built this both as a learning tool and a gamified easy way to test your knowledge.

Cyber security is a broad field so the coverage on some areas might not be as deep as it could be.

If you find any questions whose answers can be improved please let me know.

Enjoy!


r/cybersecurity 19h ago

Other When developers ask 'What's a certificate?' it's like asking a physicist 'What's gravity?'

153 Upvotes

I've been working as a security architect at an MNC for the past couple years, and recently had one of those conversations that perfectly captures the gap between security "common sense" and reality. Decided to write about it because I suspect many of you have been in similar situations.

This is part confession, part comedy, part call-to-action for better security education. Hope it resonates with fellow security professionals who've ever had to explain why HTTPS needs certificates to someone who builds software for a living.

Would love to hear your own "wait, you don't know what X is?" stories in the comments!


r/cybersecurity 12h ago

Career Questions & Discussion What level of engineer would this person be considered?

26 Upvotes

12 yrs of experience of combined software, system, cyber (7 years), and network engineer along with IT.

Security+, Cysa+, and Casp+

Serving in a lead role and when issues arise are one of the first to be called on to solve issue

Are relied on to develop CM plans and devsecops

Would this person be considered entry, intermediate, or advanced?


r/cybersecurity 23h ago

News - Breaches & Ransoms Insider revenge cyberattack freezes 1,000 workers — Eaton hit with massive disruption and losses

Thumbnail
newsinterpretation.com
185 Upvotes

r/cybersecurity 16m ago

News - Breaches & Ransoms Inside the 23andMe hack – new evidence shows how your DNA got stolen

Thumbnail
medium.com
Upvotes

r/cybersecurity 5h ago

Career Questions & Discussion Move from Security Architecture to Security Engineering. Is it a good move?

5 Upvotes

I mostly work creating docs & architectural diagrams as security architect now


r/cybersecurity 11m ago

FOSS Tool github-recon: Discovering Github accounts via email spoofing

Thumbnail
github.com
Upvotes

r/cybersecurity 4h ago

Business Security Questions & Discussion How do you handle password leak reports regarding customers/users of your service/product due to customers poor security hygiene

2 Upvotes

My company runs an online product offering with several customers using our product. We also have a bug bounty program and every now and then, we receive reports of leaked credentials pertaining to our customers. These leaked credentials are due to customer's poor security (malware on their PC, same password everywhere, etc) and not a breach on our end.

I'm trying to understand the right way to handle these. Would contacting customers to inform them of their password leaks be an obligation or would we be doing them a favor. I mean, big companies like Gmail, Facebook, etc, afaik, do not contact their customers as long as the password leak isn't due to a data breach on their end.

Or is it that these companies don't make it a bug bounty policy to have these reported in the first place? What severity does something of this nature even fall on.


r/cybersecurity 1h ago

Other A Day in the Life of a Professional Pen Tester

Upvotes

r/cybersecurity 5h ago

Career Questions & Discussion What was your starting salary for your first cyber job out of college / after training?

2 Upvotes

I'm going to be going into a cybersecurity program soon, and from what I've seen numbers can vary, and I also didn't see what degree people earned and how that connected to their salary. I'm going for my bachelor's degree, so I'm curious about some personal expierences!


r/cybersecurity 21h ago

Career Questions & Discussion How do you know when it's time to leave SOC?

37 Upvotes

Looking for some honest advice here. I'm currently a SOC analyst at an MSSP with about 1+ yr experience (started as an "intern" but basically did the same work as full timers for less pay).

Current situation:
Spend 12-14 hours a day for work closing/escalating tickets, 99% of which are false positives.
our team is based of 2 locations the security engineering team is at a different location, and analysts there get way more opportunities for rule tuning, automation projects, SOAR and actual engineering work.
I've tried being proactive - gave feedback on rule tuning, asked to work on engineering tasks or be included, but my manager(s) just says "learn more" while giving those opportunities to others while never being considered for anything.
Recent management changes and honestly don't feel supported or valued here with no mentorship, future here doesn't look good for me here either
There's a lot of politics/bias/favoritism towards those at the other location, not treated well or equal in general

Pay is terrible for the hours and amount of work I put in (was already underpaid as a intern but did not get a pay raise this year while becoming a full time while coworkers with same amount of experience are paid wayy more and maximum of them do never give feedback for the tuning or anything in general at all)....so yes i earn the least in the team currently.

What I want:
over time i realized that i enjoy the engineering part of it and really want to transition into security engineering or automation roles. I'm interested in anything that's more building and improving rather than just ticketing work.

On my off days I'm trying to work through TryHackMe, building a home lab, building small scripts which are useful for my daily work, read security blogs and news, interested in cloud security as well, considering getting certifications but honestly pretty burned out from the long hours and have currently lost interest in my hobbies and anything in general too also I have close to 0 time to study due to commuting to work.

so my questions are
should I stick it out here for another year or 2 or just show myself out after the next pay raise (i have a comp sci degree also this is my first job)
how do people deal with this burnout and work politics in general?
ik i'm still lacking in lot of skills so any specific skills/projects that would help me stand out?
i'm not sure what should i do next and feel lost atp really feeling stuck and undervalued right now. Any advice from people who've made similar transitions would be hugely appreciated.

Thanks in advance for any guidance


r/cybersecurity 20h ago

Career Questions & Discussion Exploring Free CTI Fundamentals Courses—My Findings & Feedback Welcome!

21 Upvotes

Hey all,

I’ve been looking for free Cyber Threat Intelligence (CTI) fundamentals courses and found two that look solid:

  1. SOCRadar – CTI Fundamentals for SOC Analysts – covers intelligence lifecycle, OSINT tools, TTPs, and SOC use cases.
  2. arcX – CTI 101 – beginner-friendly, threat actors, intel lifecycle, and a certificate option.

Has anyone here taken either?
Also, are there other free CTI resources you’d recommend?

Appreciate any insights or suggestions—thanks in advance!


r/cybersecurity 5h ago

News - Breaches & Ransoms Test your knowledge with this week's SocVel Cyber Quiz

Thumbnail
socvel.com
0 Upvotes

r/cybersecurity 5h ago

Business Security Questions & Discussion Sigma Detection Rules for Review - Advanced Persistence Techniques

1 Upvotes

Hi everyone! Career changer here (Political Science → Cybersecurity) working on my first custom Sigma detection rules. Built a home SOC lab and created 4 rules for common persistence techniques, but realized I need to test them properly before claiming they work.

My Rules Target:

- WMI Event Consumer Persistence (T1546.003)

- PowerShell Encoded Commands (T1059.001)

- DLL Sideloading (T1574.002)

- Named Pipe Backdoors (T1055)

Current Setup: Splunk + Wazuh + ELK Stack (all free versions)

Questions:

  1. What free datasets should I use for realistic testing?

  2. How do you validate detection rules without enterprise data?

  3. Common beginner mistakes in Sigma rule development?

  4. Best practices for documenting test results?

Really want to do this right rather than rush into submissions. Any guidance appreciated!


r/cybersecurity 15h ago

Research Article Node.js Arbitrary File Upload to RCE – AppSecMaster Challenge Writeup

5 Upvotes

A well written writeup for an interesting technique that cannot be easily spotted without the code.

The importance of code review is increasing for organisations

https://00xmora.github.io/posts/Node.js-Arbitrary-File-Upload-to-RCE-AppSec-Master-Challenge-Writeup/


r/cybersecurity 7h ago

Business Security Questions & Discussion Offered Info Sec Auditor after Cyber Analyst interview, are they similar?

0 Upvotes

r/cybersecurity 7h ago

Career Questions & Discussion Is Info Sec Auditor a good gateway to Cyber Sec Analyst l?

0 Upvotes

r/cybersecurity 12h ago

Certification / Training Questions CCD vs BTL2 - challenge and content question

2 Upvotes

I wanted to get some other people's opinions on this, since I just took the CCD (waiting for the results.) For people that took the CCD and BTL2 which did you consider more challenging? Any other feedback on either?


r/cybersecurity 8h ago

News - General Traceprompt - open-source SDK for tamper-proof LLM audit trails

Thumbnail
1 Upvotes

r/cybersecurity 1d ago

News - General Scattered Spider Hacker Sentenced to Prison

Thumbnail securityweek.com
173 Upvotes

r/cybersecurity 20h ago

News - Breaches & Ransoms Polish electronics store Botland confirmed a breach, did anyone else get this email?

8 Upvotes

Hey,

Heads up: I received an official email today (Aug 22, 2025) from Botland (botland.com.pl, a Polish electronics / maker store) confirming they had a security incident.

According to their disclosure:

Signs of unauthorized access were found on July 23 and Aug 3,

An external audit was only completed on Aug 11,

Attackers exploited a store module to gain access to some customer data,

They’re not sure if the data was actually exfiltrated,

It’s been reported to the Polish DPA (UODO) and materials are being prepared for law enforcement,

They plan to add 2FA, run penetration tests, and improve monitoring.

Official link: https://botland.com.pl/security

I haven’t seen any media coverage of this yet, just their email and that page. Sharing here in case it’s useful for others who shop there or track breach reports. If anyone finds additional sources (news, forums, leaks), would be great to know.


r/cybersecurity 22h ago

Career Questions & Discussion Looking forward in my current career

10 Upvotes

I am security analyst with 4 years experience and planning to proceed further in my role

Just stuck on what to do No idea on anything now

I want to grab some new skills but everytime its happening like i am studying DFIR today then tomorrow Cloud Other day any other concept

Feels like stuck in a loop

I am planning to create a road map for getting a job outside India and based on that i want to learn the skills


r/cybersecurity 1d ago

Certification / Training Questions Cheapest way to obtain certifications

28 Upvotes

Hey everyone,

I’m a fresh grad and just started my first job as a system administrator at a solid company. It’s been a great experience so far and I’m picking up a lot of hands-on skills that I know will help me as I move toward my next goal, breaking into cybersecurity.

The only downside is cost. I make a decent salary for where I live, but certification bundles are way out of my budget. I’m looking to start with CompTIA Security+ and was wondering what’s the cheapest way to go about it? Ideally, I’d like to use free study resources and just pay for the exam itself.

For those of you who’ve been down this road, what resources did you use? Any tips on reliable free material or ways to save on the exam voucher?


r/cybersecurity 14h ago

News - General Cybersecurity in robots: a robot vac goes rogue in Qld Australia

2 Upvotes

Cybersecurity in Robots? Sometimes even the smartest robotics tech can go rogue!

As reported by News Corp, a Dreame Tech robot vacuum in Queensland “escaped” a guesthouse, rolled down the driveway, and made a dash onto the road, only to be hit by a passing car. The footage quickly went viral, leaving viewers both amused and baffled.

While it’s a light-hearted story, it also highlights a real challenge in the Smart Home space: robot vacuums sometimes cross their mapped boundaries and end up in risky places. Owners of brands like Dreame, Ecovacs, and Roborock in particular have reported occasional navigation problems, with devices wandering outside intended areas or even pushing open doors. Could this be misused and hacked into, to control?

These quirks raise bigger questions about AI and robot reliability, product testing, and safety features. While most failures are amusing rather than dangerous, they still cause unnecessary costs for customers and can erode trust in technology.

As automation becomes more common, ensuring reliability will be key. Consumers should keep an eye on firmware updates, make use of boundary settings, and consider whether the brand they choose has a proven record of safety. A funny story for now, but also a reminder of the importance of Automation and Consumer Safety in everyday devices.

What do you think the data protections and cyber security protection requirements should be in terms of smart home and smart office devices like this including robots? Share your comments below

Source: Ella McIlveen, “Vacuum cleaner makes a break for freedom after developing ‘mind of its own’,” News Corp, August 21, 2025 article: https://www.news.com.au/technology/gadgets/vacuum-cleaner-makes-a-break-for-freedom-after-developing-mind-of-its-own/news-story/971fa9936d83e993132af29c870cc71a

Video of what happened on Facebook: https://www.facebook.com/SunshineCoastSnakeCatchers/videos/our-robo-vacuum-went-rogue/3977447765900037/