This $30 Tool Helps You Spot Scams Before You Click
IsThisSpam helps you check suspicious emails, texts, links, and websites before you click or respond.
The post This $30 Tool Helps You Spot Scams Before You Click appeared first on TechRepublic.
IsThisSpam helps you check suspicious emails, texts, links, and websites before you click or respond.
The post This $30 Tool Helps You Spot Scams Before You Click appeared first on TechRepublic.
Before pasting passwords, medical records, source code, or company data into ChatGPT, use this checklist to decide what should stay private.
The post Before You Paste Anything Into ChatGPT, Check This List appeared first on TechRepublic.
AI could accelerate vulnerability discovery, shrinking the pool of exploits governments rely on while speeding up the race between attackers and defenders.
The post AI Could Shrink the Supply of Exploits Governments Rely On appeared first on TechRepublic.
Hey r/cybersecurity!
I'm Larry Pesce, VP of Services at Finite State. I've spent the last two decades-plus breaking (and then helping fix) the things most people don't think of as computers: medical devices, cars, industrial control systems, IP cameras, routers, and basically anything with a radio or a debug header.
A quick rundown of what I've been up to over the years:
Why am I doing this AMA?
Honestly, because the intersection of IoT, supply chain, and regulation is getting genuinely interesting right now. The CRA is coming, SBOMs are moving from buzzword to requirement, and the gap between "we make a connected product" and "we understand our connected product's security" is still enormous. I think there's a lot worth discussing, and I always learn something from these threads too.
One line on my $DAYJOB since the rules ask for it: Finite State does binary firmware analysis and product security services for connected device manufacturers. I've spent the last 20 years giving back to the community through sharing what I know: That's it, no pitch. I'm here to talk shop.
Ask me anything about:
I'll be answering questions today, September 8th, 2026 roughly during business hours on the East coast of the US - I will keep checking in during the evening, and I would encourage questions over the next few days for those of you all over the planet. Fire away!
Transparency note per the AMA guidelines: I may use generative AI to help polish some longer answers, but the experiences, opinions, and war stories are all mine.
| With 1168 ransomware events recorded in August 2026, it is now the month with the highest amount of ransomware events ever, what are we making of this? [link] [comments] |
I'm the sole cybersecurity person for mid-size local government municipality (around 600 users), came in about 8 months ago. Landscape here is pretty wild west…minimal governance, no real established program but slowly building it out. I’m running EDR/NDR, a firewall/log platform, email security, and phishing awareness training (all different platforms) while also owning policy development, policy gap analysis (establishing NIST CSF 2.0 framework), risk assessments, audits and quarterly reporting to leadership.
It’s a lot of work and something always loses. Policy work in particular keeps getting bumped because incidents/investigations always outrank it in the moment. The problem isn't any one part of the job.. i can do investigations, I can write policy, I can run the security tools, I can build training programs. I actually enjoy those things…The problem is all of it landing on my desk at the same time. I honestly am starting to question if I’m even good at my job because I can’t make it all work.
Questions for anyone who's been here:
-If you've been a solo practitioner..how did you actually prioritize across investigation, GRC, tooling, and training without letting any one of them rot?
-Is this genuinely a "normal growing pain" for a first year solo, or a sign to run..
Not looking for sympathy, just want to know if I'm missing a better way to run this!
Hey guys i need threat intelligence feeds to come up on my email for threat advisories and for free any solution?
What videos are out there of step by step alert handling in a traditional SOC setting? I know there wont be ones with real company data, but I'm having a hard time wrapping my head around everything involved (or not involved) just by reading or listening about it. Recommendations?
I'm participating in a Tech Expo. I need a few suggestions on what to make. The audience are mostly students who are new to the Tech world ( they don't know much about technology and its terms), i'm looking for something that's not too technical and must look cool to the students. Can anyone help?
Hello everyone.
After a few years in the auditing/pentesting world, I identified that I am lacking experience on the code analysis topics.
Unfortunately when pentesting/auditing, I seldom had the time to look at the code of the applications I am auditing due to time constraints as the white-box approach we take does not systematically include an access to the Gitlab of the entities I audit.
I would like to avoid being overwhelmed by an eventual audit of source code of an entreprise-grade application that I might have to do.
Would any of you share you code audit methodology ?
By that, I mean how do you tackle the following topics :
- Secure coding / Best coding practices
- Secure secret management of the app
- For very large codebase, what types of tools do you use to automate some of your work ?
- What specific things in your checklist do you look for systematically ? (Do include the "obvious" one like how authentication is handled)
I know the subject is quite broad and dependent of the tech-stack used for each case.
Thank you for reading. :)
Hope this isn't a dumb question, but I've been seeing more vendors talk about AI DSPM instead of just regular DSPM. Is this a different category, or just new branding for existing data security capabilities? And if they are different, what problem(s) is AI DSPM supposed to solve?
22M, from New Delhi INDIA.
I am studying to be a SOC analyst, but freshers aren't getting jobs as SOC analysts, and in cybersecurity they also say certificates hold value, so I am thinking of pivoting myself to a data analyst role.
Can someone tell me how fresher jobs are in both SOC analyst and data analyst roles, because I am having this doubt that there is a huge crowd in data analyst but freshers manage to get jobs, whereas in SOC analyst the crowd is slightly lower, but getting a job as a fresher is very difficult? Please help.
| Hey everyone, Have you ever followed a lab walkthrough perfectly, word for word, and it still failed? I recently spent 5 hours refusing to accept that "it just doesn't work." What started as a stuck lab turned into a fifteen-hour investigation, a silent bug, and a GitHub issue against the #1 most popular extension (JWT Editor) in the Burp Suite BApp Store as of today. I wrote a full deep-dive into the methodology, how I tracked this silent bug down to its root cause, how to bypass it, and how the investigation ultimately led to the maintainer releasing a new version fixing the problem. And how I reached out to PortSwigger directly to highlight that their official lab solution is broken, pushing them to update their documentation so others don't fall into the same trap. If you enjoy debugging, reverse-engineering, and the mindset of not taking "it happens because it happens" for an answer, I’d love for you to read the full journey here: https://RivenX173.medium.com/when-burp-extension-breaks-lab-b5bce69fc89a Let me know your thoughts! [link] [comments] |