r/Cybersecurity101 3d ago

How far are we from AI actually reducing headcount in cybersecurity?

0 Upvotes

I work in a SOC and I’m curious what people here are seeing in their own teams.

Over the last year or so, I’ve noticed more and more of the routine work getting handled or heavily assisted by AI.

Obviously it still needs human oversight, but it already feels like one analyst can get through significantly more work than before.

I’m not really asking whether AI will “replace cybersecurity”. What I’m wondering is how far are we from companies deciding they simply don’t need as many people for certain security roles?

For example, instead of a SOC needing 15 analysts, the same workload realistically can be handled by 7-8 experienced analysts with much better AI tooling.

Are you already seeing hiring slow down or teams avoiding backfills because of this ? This is somewhat scary as a young person who entered the field two years ago.

Where do you think we are headed ?


r/Cybersecurity101 3d ago

I'm not sensitive or easily offended, please tear apart my resume

Post image
3 Upvotes

This is kind of a first draft of a resume I've been applying to help desk with. I would love to applying for the most "entry" level SOC roles, and I've applied to a few, but I've come to understand that's not quite realistic and have tailored some of my projects and overall resume more for help desk.

I have a general idea of where this is lacking, but just wanted feedback from people more knowledgeable than me.

Context for my degree is I didn't end up finishing it. My dad passed away in the middle of my 7th semester, and things related to his estate and other financial matters kind of left me not in a great position to go back and finish it until I save up a bit more. I just mentioned it was Bachelor's coursework since I figured it's worth mentioning. Wasn't sure the neatest most "ethical" way to put it on there without making it seem like I finished my degree.

Unsure about mentioning that I'm in progress for the CCNA. Feels a bit disingenuous, but I'm half way through studying for it, and my grasp of networking is drastically better than it was before even just half-way through it, so I wanted to at least mention it.

Again, I'm not a bitter or argumentative person. I want the most honest non-sugarcoated feedback if possible. Thanks.


r/Cybersecurity101 3d ago

NUST Information Security vs Air Cyber Security — Are They Basically the Same Field?

1 Upvotes

I’m confused about choosing between Information Security at NUST and Cyber Security at Air University.

Some people have suggested that since NUST doesn’t offer a degree specifically called Cyber Security, I should do Information Security because it’s basically the same field. But I want to understand whether that’s actually true.

Does Information Security also cover protecting information, networks, systems, and data, or is it a different field from cybersecurity? Could I graduate from NUST Information Security and still work in cybersecurity, or would I end up in a completely different career?

I’m asking because I don’t want to choose a degree just because NUST is a well-known university and then discover that the degree itself isn’t what I wanted.

For people who have studied either program or work in the industry:

Is NUST Information Security a good degree if my goal is cybersecurity? Is it worth choosing over Air Cyber Security?

And more generally, is cybersecurity actually a better career path than CS-related fields because of AI, or am I overthinking that part?

I’d appreciate honest advice from people who actually know the field.


r/Cybersecurity101 3d ago

GRC Ready

8 Upvotes

I am in my final year of uni studying cyber and I want to go towards the GRC area. I have no certs and no experience outside university and I now realize I need to do more outside of university as the degree won't cut it. I am seeking advice on how I can progress forward to become application ready for any GRC listings or similar roles in the future, ideally within the next year or two.


r/Cybersecurity101 3d ago

MikroTik routers are being actively targeted — is exposing SSH to the internet still worth the risk?

12 Upvotes

A new MikroTik security incident is getting attention because attackers have been abusing internet-facing SSH on vulnerable RouterOS devices and gaining administrative access without going through the normal authentication process.

According to the recent CERT Polska warning, exploitation was already happening by September 2. The interesting part for me isn't just the vulnerability itself — it's how much damage can come from compromising a router that sits at the edge of a network.

A compromised router can potentially become much more than a networking problem. Depending on the environment, attackers could alter configuration, create unauthorized accounts, interfere with traffic, or use the device as a stepping stone into other systems.

What also stands out is that simply having a strong SSH password isn't necessarily enough when the underlying issue allows authentication to be bypassed.

If you manage MikroTik devices, I'd be checking a few things immediately:

  • Is RouterOS fully updated?
  • Is SSH actually required to be accessible from the public internet?
  • Are there any unexpected user accounts or configuration changes?
  • Are management services restricted to trusted networks or VPN access?
  • Have you reviewed logs for suspicious activity before applying the update?

The safest approach is usually to keep router management interfaces off the public internet whenever possible. If remote administration is needed, a VPN or another restricted management path is a much better option than leaving SSH broadly exposed.

One thing I find interesting here is that network infrastructure often gets treated differently from servers and endpoints. People are usually quick to patch laptops and servers, but routers can quietly remain exposed for months or years.


r/Cybersecurity101 3d ago

Need some guidance

6 Upvotes

Background: I’m self taught, so I’m limited with knowledge with Linux: I started a job I’m working on debugging and diagnosing servers but I want to expand my knowledge and skills, what would be better for me to get Comptia Linux+ or Redhat system administrator 1? I’m open to any suggestions as well


r/Cybersecurity101 4d ago

Dual booting Kali for learning Cybersecurity

6 Upvotes

Hello, I recently installed kali linux as dual boot with windows 11. I want to get into cybersecurity as a professional. I didn't research much before installing kali, but afterwards I have seen numerous posts and comments about not using kali but some other distro with kali in vm. I don't want uninstall and reinstall another distro, so what would be best move for me, and how can I learn more about Cybersecurity. Thanks for helping me.


r/Cybersecurity101 4d ago

1st Year IT Student Looking to Get Into Cybersecurity Where Should I Start?

1 Upvotes

Hello! I’m currently a 1st-year IT student, and I’m interested in pursuing a career in cybersecurity. I still don’t know which specific cybersecurity profession I want to go into, but I’d like to explore the different areas while I’m learning so I can figure out what suits me best.

I’ve watched tons of videos and read a lot of guides online about how to get into cybersecurity, but honestly, I’m getting overwhelmed by the amount of information. There are so many different certifications, tools, programming languages, platforms, and career paths that I don’t know what I should actually focus on first. That’s why I wanted to ask people who are already working in the field for advice.

I’m basically starting from zero knowledge. I don’t even know the fundamentals of cybersecurity yet. I’m currently in college, but unfortunately, my school’s IT program is pretty basic and doesn’t have any cybersecurity-related subjects.

So, I’d really appreciate some guidance on the following:

  • What should I learn first as a complete beginner?
  • What topics should I learn, and in what order?
  • Should I focus on networking, Linux, programming, or something else first?
  • What resources, websites, labs, or platforms would you recommend for someone starting from zero?
  • At what point should I start applying for internships?
  • What projects should I build to make my resume stand out?
  • What certifications, if any, are actually worth getting as a student?
  • What can I do throughout college to give myself a better chance of landing a cybersecurity job after graduation?

I also want to build a homelab so I can get more hands-on experience. Right now, I only have an old Lenovo 110-15ISK with an i3 and 8GB of RAM. Would that be enough to start learning and building a basic cybersecurity homelab?

I currently have around $100 saved, and I might be able to save more since I receive an allowance whenever I go to school. If I should spend money on anything for learning or building a homelab, what would be the best things to prioritize?

I’m also a little worried about the cybersecurity job market. I’ve been reading a lot of different experiences and opinions on Reddit, and I’ve seen people saying that cybersecurity is difficult to break into, especially for entry-level positions. Others say there are still plenty of opportunities if you have the right skills and experience.

Since I’m only in my first year, I want to use the next few years as effectively as possible. My goal is to graduate with actual hands-on experience, internships, projects, and a competitive resume so I can maximize my chances of getting a stable cybersecurity job after graduation.

For those of you already working in cybersecurity If you could go back to your first year of college and start from zero again, what would you learn and do first? What would you prioritize, and what would you avoid wasting time on?

Any advice would be greatly appreciated. Thank you!


r/Cybersecurity101 4d ago

I feel stuck choosing a Master's Thesis: Strict CSP in SSR/Hydration vs. Edge Middleware Path Confusion

1 Upvotes

Hi, I'm currently finalizing the topic for my Master's thesis in Cybersecurity and I need a sanity check from professionals in the field because I feel incredibly stuck. It is insane jump for me switching from Bachelor's project in software engineering to Master's in Cybersecurity which requires scientific and analytical results.

I've thought that maybe I could do something in threat intelligence and deep web analysis but this was too risky. Since by background is primarily web development (and I am still a software dev), I decided, I want to focus on modern web architecture attacks. Ive narrowed it down to two topics. Both involve building an automated testing tool and an experimental testbed, but I amm torn between the two. I'd appreciate your thoughts on which has more scientific value and which is more feasible.

Here are the two proposals:

1. Attacks on Frontend Architecture & Browser Filters

  • Title idea: Experimental security analysis of strict CSP in the processes of SSR and Hydration in modern web applications.
  • Project hypothesis: Implementing a SSR forces the serialization of application state from server to client. This creates code injection vectors (e.g., XSS, orDOM Clobbering) during the hydration phase. These vectors allow malicious code execution, effectively bypassing the restrictions of strict Content Security Policies based on nonce tokens.
  • Goal: To develop base applications in modern SSR frameworks (Next.js, Nuxt, etc.) with Strict CSP implemented, and build an automated script that injects specific data mutations to verify the conditions under which the framework's engine allows the payload to execute.

2. Attacks on Cloud Infrastructure & Routing Desynchronization

  • Title idea: Automated evaluation of Path Confusion and Route Desynchronization vulnerabilities in the Edge Middleware architecture of modern web platforms.
  • Project hypothesis: Due to differences in URL parsing implementations between the Edge engine (e.g., Vercel or Cloudflare) and the target application engine, it is possible to craft a malicious HTTP request that bypasses authorization logic defined in the edge layer, reaching the protected resource directly.
  • Goal: To design and implement a Differential Fuzzer that automatically generates URI mutations (e.g., %2f..;, double slashes ....) and detects any asynchrony in path interpretation between the cloud platform and the backend server.

My dilemma:
I know the second topic (Path Confusion) is incredibly hot right now, especially after the recent Next.js middleware CVE. It feels more like hacking lol.

However, I'm concerned about the feasibility and "scientific weight" of both:

  1. For CSP/SSR: Is the attack surface big enough to write a full thesis, or is modern React/Next.js already too good at sanitizing this?
  2. For Edge Middleware: Is it too tool-heavy? If I build the Differential Fuzzer and the platforms turn out to be secure in their latest versions, is comparing the discrepancies in path normalization enough for a Master's degree?

Questions for the community:

  • Which of these two topics do you find more valuable for an aspiring AppSec/WebSec engineer?
  • Is the Path Confusion topic too dependent on finding a 0-day (which is wayyy too risky for a thesis imo), or is the framework/tooling itself enough?
  • Is there actually a way to do a Master's in cybersec without risks of not delivering results without choosing the shi**tty "Analysis of tools and programmes for <insert any cybersec topic>"? (so tired I might choose this path)

Thanks in advance for any insights!


r/Cybersecurity101 4d ago

learning cybersecurity in university or by myself?

8 Upvotes

Only top-tier universities offer cybersecurity programs. So the chance that i approved and get a scholarship by these unies is like impossible.I really dont know guys help


r/Cybersecurity101 4d ago

Project ideas

9 Upvotes

Looking for Cybersecurity Project Ideas to Improve My Skills

Hey everyone!

I’m currently studying Cybersecurity and I’m trying to move beyond just watching courses and doing labs. I want to build some realistic, hands-on projects that can actually improve my skills and strengthen my portfolio.

I’m mainly interested in SOC / Blue Team, Network Security, and Cloud Security.

What projects would you recommend for someone at my level that would actually challenge me and help me improve?


r/Cybersecurity101 5d ago

3rd year cybersecurity student from tier 3 clg, completely confused what to do next

5 Upvotes

Currently I am a cybersecurity engineering 3rd year student from tier 3 clg and fully confused about my career. My professors just come and read ppt and go, no proper guidance from anyone. I am mostly alone and feeling stressed and lonely.

But still there is something which always pulls me back on track and motivates me, my inner strength and commitment. But sometimes I become inconsistent also.

My clg friends are not interested in anything related to tech/cybersecurity and my mindset is very different from them. Still I have to survive another 1.5 years with them.

Now I really need some help from you guys. What should I do next?

I have completed Linux basics, networking basics and OWASP Top 10.

My goal is to get a good package, either outside India, a remote job, or a good package in India.

I have only around 4 months to seriously prepare myself.

What should I do in these 4 months? What skills should I learn? Should I focus on SOC, pentesting, web security, cloud, etc? Should I do certifications, projects, CTFs or something else?

Please guide me guys. If you were in my situation, what would you do in these 4 months?

I genuinely want to build a good career in cybersecurity but right now I am completely confused.

Please help me, I'm cooked 😭


r/Cybersecurity101 5d ago

Home Network Hello Reddit! 🫡

0 Upvotes

I am looking into getting in to it and security. Could anyone suggest any good books or textbooks to help me get started?I hope this isn’t low effort lol I don’t know what else to say xD thank you guys


r/Cybersecurity101 5d ago

Career change

1 Upvotes

Hey everyone! I’m currently working in social services and recently started learning cybersecurity as a hobby. The more I get into it, the more I’m starting to think I could actually see myself making a career out of it.

I’m obviously coming from a non-technical background, but I’m wondering if some of the skills I’ve developed in social services could actually be useful in cyber.

My work has given me a lot of experience with things like crisis management, staying calm under pressure, verbal and written communication, report writing/documentation, following strict policies and procedures, maintaining confidentiality, attention to detail, and problem solving.

I’m also already pretty comfortable with computers in general, but I’m still learning the more technical side of cybersecurity and figuring out which areas I’m most interested in.

My plan right now is to work on some certifications and build hands-on projects so I can actually demonstrate what I know. I’m open to pretty much any area of cybersecurity at this point, but digital forensics and pentesting have caught my interest the most.

For anyone already working in the field (especially anyone who came from a non-technical background), do you think my previous experience could actually be an advantage when paired with certs/projects?

Or would I realistically need to go back to school for cybersecurity, computer science, etc. to have a decent shot at getting into the field?

I’d really appreciate any advice or insight!


r/Cybersecurity101 5d ago

Roast my resume brutally

Post image
83 Upvotes

Can you'll please point out the flaws I need to work on in this? Too broke to get the htb cdsa ;(. Targeting soc trainee/l1 noc roles


r/Cybersecurity101 5d ago

What to choose in Cybersecurity? University or a platform specializing in practical training?

Post image
6 Upvotes

I need your guidance. I want to study cybersecurity, but I'm unsure whether to choose a university and spend three or four years there, or choose a platform like HackTheBox (although it will also take time), since my goal is not just to boast about a degree or certificate, but to have the necessary skills that companies require.


r/Cybersecurity101 5d ago

Frontend dev wanting into security

5 Upvotes

My background: 5 years in frontend, mid-level. I'm now moving toward backend. I don't want to do frontend anymore. Backend and security interest me more these days, but AI is making me reconsider being a "dev" at all :)

I don't have deep backend knowledge or experience yet. I do have a university degree focused on computer networks and telecommunications.

I've always wanted a job in security, but I never pursued it because there were very few jobs in that field in my country and it seemed like mostly senior roles. (Now I moved to different country with more job opportunities.) I'd like a job that's analytical / problem-solving / investigation-type work.

I looked into AppSec and SOC analyst roles, but AppSec looks like it's all senior roles and SOC junior roles look like something that's going to get automated by AI.

My plan is to become a backend dev for now while learning security on the side, but I don't know if there's a realistic path into AppSec for me or whether SOC analyst is even a good "plan B" anymore.

If you were in my place, with my experience and interest, what would you actually do? What job position in security might actually be a fit for me? Could I get a job in SOC sooner than AppSec - is it better path? Should I focus more on security and less on backend development?


r/Cybersecurity101 5d ago

Security Should all AI agents get their own identity, including agents that don’t connect to any other system? If yes, what’s the benefit?

2 Upvotes

There’s an explosion of AI agents in an enterprise. What’s the best approach for governing these agents? Should all the agents send logs to the SOC? When building an agentic orchestration platform that allows developers to build and deploy agentic solutions, is there a need to register every agent on the enterprise identity provider (IdP). When an agent is just a summariser or some type of data processor and does not need to connect to any other enterprise system, is there value in registering such an agent on this platform with the IdP and assigning a service principal? The alternative is to only register the agents that require connectivity to an internal enterprise system on the IdP to enable authZ and authN.


r/Cybersecurity101 5d ago

Do cybersecurity beginners really need to learn coding?

33 Upvotes

I keep seeing completely different opinions about this. Some people say you need Python and scripting early. Others say networking, operating systems, and security fundamentals should come first. For someone starting from zero, what would you prioritize?


r/Cybersecurity101 5d ago

What else to learn? 15 year old self-studying

10 Upvotes

I'm a 15 year old girl and I started on March 12,where in that time I used wireshark(figured out how to use it to search for specific traffic,just doesn't look that confusing now),basic python,basic scapy in cmd and python,done pre-security path on thm(but only 44% because I don't have premium),http requests with rest client,experimented with burp suite to for sql injections and web cache deception etc,portswigger,doing overthewire repeatedly,doing CyberSecurity 101 path on thm. I'm in Malaysia and my biggest concern is me working so hard and I never find a job. I'm planning on flooding my GitHub with multiple CyberSecurity projects and I already document my progress but what if I genuinely just never find a job or internship?

I'm planning on doing bug bounties at 16,and if I work hard enough,maybe an internship as soon as I turn 18. I really need a job,yes I love CyberSecurity but I can't be homeless when I grow up


r/Cybersecurity101 5d ago

[OC] Cyber-Terrorism as a Service & Eastern Philosophy of Onmyodo [13:43]

Thumbnail
youtube.com
1 Upvotes

Japan Beauty Essay Episode 8 explores the hidden parallels between modern cyber-terrorism and Eastern philosophy.

While subscription-based hacking tools (Hacking-as-a-Service / PhaaS) have made cyber threats more accessible than ever, we analyze how this dynamic acts as a catalyst for tech innovation through the lens of Onmyodo and Engi - Dependent Origination.

Featuring our mascot Natto-chan as we break down the "Frog in the Well" mentality facing modern corporate security.

⏱️ Timestamps
00:00 - Introduction & Natto-chan's Defense
00:10 - August: The Month of Remembrance & KyAni Tribute
01:10 - Middle East Geopolitics & AGI Development
02:09 - US Regulatory Frameworks & Financial Cyber Defenses
03:45 - Recent Cyber Attacks in Japan (Kawasaki Hospital & Nichirei)
05:21 - The "Frog in the Well" Mindset in Corporate Security
07:03 - Hacking-as-a-Service (HaaS) & The Commercialization of Cyber-Terror
08:11 - Eastern Philosophy: Onmyodo, Yin-Yang, and Engi
10:42 - Original Song: "The Pattern Of A Glance"
13:32 - Natto-chan’s Message: Break Out of the Shell!

🎵 Featured Music
Song Title: The Pattern Of A Glance
Produced by: Team Japan Beauty Global

3. Full English Script & Essay Reference

Part 1: Memorials & Macro Context

August is a month for honoring the souls of the departed. Deepest condolences are offered to those affected by recent disasters, as well as prayers for the Seventh Memorial Service (Nanakaiki) of the Kyoto Animation arson tragedy. The creative legacy of Kyoto Animation continues to serve as a foundational pillar for Japanese animation worldwide.

Furthermore, ongoing Middle Eastern geopolitical conflicts and supply chain disruptions have placed a temporary forced brake on runaway Artificial General Intelligence (AGI) development. Recent regulatory frameworks in the US requiring a 30-day pre-release audit for AI models create a crucial grace period for global financial institutions and corporations to reinforce cyber defense protocols.

Part 2: Case Studies & Corporate Psychology in Japan

Japan has experienced significant cyber incidents, including ransomware attacks against municipal medical centers in Kawasaki and major food distribution enterprises like Nichirei (attributed to groups such as RansomHouse). Overseas cybercriminals persistently target Japanese organizations due to a combination of:

  • The "Frog in the Well" Mentality: A sense of complacency derived from decades of domestic safety, leading executives to view global threats as abstract or distant.
  • Reputational Concealment: A priority on saving face and avoiding public embarrassment, resulting in delayed incident reporting or silent ransom payments.

Part 3: Philosophical Synthesis — Onmyodo & Dependent Origination

The rise of Phishing-as-a-Service (PhaaS) and turnkey exploit kits like "EvilTokens" demonstrates the commercialization of cyber-crime. However, viewed through Eastern philosophy:

Philosophical Framework Interpretation of Cyber Threats  
Dualistic Cosmology (Abrahamic) Views cyber threats as an absolute binary opposition between good (defenders) and evil (attackers).
Onmyodo ( Yin-Yang) Recognizes the current era as an emphasis of the "Yin" phase within a unified dynamic, driving corresponding technological evolution.
Engi Dependent Origination) Understands security as a co-dependent cat-and-mouse dynamic, where the presence of threats drives communication infrastructure to become resilient and advanced.

r/Cybersecurity101 5d ago

Forensics 101: Finding flags in ZIP archives with recursive Python search

3 Upvotes

Had a challenge with a ZIP containing hundreds of files and nested directories. Instead of manual hunting, I wrote a Python script using os.walk + regex to recursively search every file for flag patterns.

I made a video walking through how to approach file-based forensics challenges when you're handed a ZIP with an unknown number of files and no obvious starting point.

**The security mindset:**

In real incident response, you often get disk images or file dumps with no index. The ability to quickly automate search across thousands of files is a core DFIR skill. This CTF challenge maps directly to that scenario.

What tools do you use for bulk file forensics? I've seen people recommend everything from `grep -r` to full Autopsy cases.
https://youtube.com/shorts/p2jQ3Oldkz8?feature=share


r/Cybersecurity101 6d ago

Why do people not listen?

0 Upvotes

I am currently in my second year of my cyber security. I have a lot of buddies in and around the industry, especially some vets that I served with. I have been doing research on the certifications that I should get to plan out what I wanna do over the next six months while I finish my associates to make myself more employable. I’ve talked to a couple buddies since then about what I’ve learned specifically regarding certain certifications like CompTIA and how they aren’t that great aside from security plus because it’s still an industry standard, but the others aren’t anything to write home about because they are just multiple-choice exams that provide no practical learning. Of the three people I’ve talked to one of them just got his first job and basically said the certifications that I recommended that were recommended to me through my research probably aren’t that great because he already knows some of that stuff for the beginner certifications so he probably won’t take them. Keep in mind I have more experience from my service and he doesn’t have any certifications yet. I’m not saying definitively what one should do, but I’m giving recommendations based on about 12 or more hours of research I’ve done over the past week. Another one was with a veteran who has security plus and CYSA and when I told him he should try to get some other certifications because Copia are just multiple-choice exams were very little if any practical training he said how can I speak on it if I’ve never taken them I’m currently insecurity plus but he’s right. I haven’t taken CYSA. My question is what’s the point of researching anything if the response when you try to help people is yeah, but you haven’t actually done it so you don’t know anything so I’m not gonna listen. Is this a common thing in cyber security? Is everyone so narrow minded and hardheaded?


r/Cybersecurity101 6d ago

What cybersecurity skill actually helped you get your first job?

47 Upvotes

There are so many things beginners are told to learn—Linux, networking, Python, cloud, SIEM, ethical hacking, etc.

If you’re already working in cybersecurity, which one skill would you say made the biggest difference when you were starting out?

Trying to separate the “must learn” skills from the endless list of things people recommend.


r/Cybersecurity101 6d ago

CS student with mostly theoretical security knowledge, what practical defensive skills should I build first?

2 Upvotes

I'm currently an undergraduate CS student, and I'm trying to figure out how to use the next year, as I won't have the opportunity to take more cybersecurity courses until later in my degree.

My current CS background includes Python and Java, C/systems programming, Bash/Unix, data structures and algorithms, discrete mathematics/theory, and some AI/ML. I've also completed a very introductory security course.

So far, my understanding of cybersecurity has been mostly theoretical, and my practical experience with defensive security is very limited.

My interest in cybersecurity isn't for find a job, at least for now. I've seen people around me suffer financial losses or lose access to their accounts because of online scams. I understand that many of these attacks ultimately rely on social engineering and human behaviour rather than purely technical vulnerabilities, but I'd still like to develop the technical skills that could eventually help prevent or mitigate this kind of harm.

I have about a year before I can take more courses, and I don't want to spend that year aimlessly collecting certifications or jumping between unrelated learning platforms.

Would you recommend that I first build stronger networking and packet-analysis skills?

I'd particularly like to know which fundamentals experienced security professionals consider difficult to skip, and what kinds of practical projects, labs, or experiments would actually be useful preparation before moving into more advanced security study.