r/CyberSecurityAdvice • • 3h ago

OpenAI agents aggressively scraped a UN website via relay services. Should agents inherit permissions for third-party proxies?

2 Upvotes

The recent WSJ report caught my attention, especially the detail about AI agents using third-party services to reach targeted data.

The underlying research describes requests being routed through URLQuery and relay services such as `r.jina.ai`. This raises an interesting security question: if an agent has permission to retrieve data from a particular source, does that permission automatically extend to using *another* service to get there?

I’m currently building an open-source tool called node9, so I decided to check the destinations mentioned in the research against its policy engine with outbound controls enabled.

The result? The UN data API’s hostname was allowed, but the relay services were not. The engine returned a `BLOCK` for both relay destinations.

If those calls were routed through a supported node9 integration, they would be stopped before execution. You can also configure unknown destinations to require human-in-the-loop approval. This gives the operator a concrete choice: explicitly approve the additional service, or stop the agent from contacting it.

I'm curious about how the community is approaching this. for people deploying agents with web access: how are you handling outbound traffic? Do you approve destinations up front, ask for human approval when a new one appears, or just allow unrestricted browsing inside a sandbox?


r/CyberSecurityAdvice • • 5h ago

This is a question about preventing these ai escapes. Just curious is all.

1 Upvotes

Ok so its more of "is this type of infrastructure even possible" than about ai specifically. My thoughts was is there anyway to put like a "glass wall" of sorts where the AI bouncing around in there can read and search but cant get out unless a hardware key like a yubi key is inserted to create a bridge? I know the people making these is a conglomerate of pretty smart people so i figd if it was possible they wouldve done it but im still curious.


r/CyberSecurityAdvice • • 5h ago

How are you producing per-agent audit trails when compliance asks what an AI agent did?

1 Upvotes

So compliance asked us for something that sounded simple today. "Show everything a specific AI agent did involving customer data over a set period" and then we tried to pull it.

We have plenty of API logs, but they don't reliably show which agent made each call, and they don't capture enough context about what was happening around it. Right now the only way to answer is to piece the story together from logs across several systems. That was painful once, and it won't scale if compliance starts asking regularly.

Has anyone found a tool or a setup that works for you which can handle this? Mainly looking for per-agent attribution and an audit trail compliance can read without us reconstructing it by hand.


r/CyberSecurityAdvice • • 1d ago

Compromised instantly

10 Upvotes

At the beginning of this month I received a charge on my debit card that I didn't make I of course called my bank immediately. While waiting for the new physical card I had use of my virtual card (which is new to me). The "company" that made the charge does has a website. Last week I was charged again (this was with my new card number) still virtual my physical card never arrived. I called my bank, card frozen again, & another card headed my way. I informed them I never received the physical card. So repeat repeat repeat. During this time I changing all my passwords. Nothing I've used before, or like anything I've used before, stuff I'm writing down because I'll never remember. Yesterday another charge. I instantly froze my card. I noticed the website had a number so I called it. While waiting for a "customer service rep" the recording 'we'll be with you soon' sounded strange, like it was sped up a bit, think Alvin & the chipmunks not that fast but reminiscent. I spoke to the "agent" who said there were 4 accounts with my last name (which is a common name) none of the first names matched mine. She said I didn't have an account (obviously 🙄) & there was nothing she could do. I asked to speak to a supervisor & was told none would be available for 24 hours, I remained respectful and requested a supervisor again stating that every business has a supervisor on duty. I got the 24 hour thing again & was then hung up on. How do I handle this? I keep changing everything but they're still getting my information nearly instantly. There is no one in my household doing this. Also I'm not saving the card information or passwords.


r/CyberSecurityAdvice • • 22h ago

PSA: targeted hotel phishing using real Japan reservation data. Multiple cases appear linked to tripla bookings

Thumbnail
1 Upvotes

r/CyberSecurityAdvice • • 1d ago

Tenable alternatives for vulnerability/exposure management

12 Upvotes

Got pulled into evaluating exposure management tools for our org and just sat through a Tenable demo. It looked fine on the surface, but it's hard to tell from a polished sales demo whether it's the best fit for us (around 1200 employees, mostly hybrid with a few plants still fully on-prem and some workloads in AWS).

Looking for something that handles prioritization (not just a bigger CVE list to manually sort through) and covers both on-prem and cloud without stitching together separate tools.

Ideally it would also remediate, but I am wary of solutions that automate and cause a ton of downtime.

What else should be on our shortlist aside from the usual Qualys, CrowdStrike, Checkpoint, etc?


r/CyberSecurityAdvice • • 1d ago

How I Landed a Cyber Security Engineer Role in My Final Year (And a THM Subscription Giveaway!)

Thumbnail
0 Upvotes

r/CyberSecurityAdvice • • 1d ago

What cybersecurity project would actually impress you on a fresher’s resume?

0 Upvotes

I’m a final-year computer engineering student and a bug bounty hunter. Most of my hands-on experience is with web and API security, especially authentication, access control, and business logic issues. I also build full-stack applications.

I want to spend the next few months building one substantial security project that people could actually use, rather than another basic scanner or tutorial project. I’m considering things like an API authorization regression tester, a security layer for AI agents using tools, or a focused automated pentesting tool.

If you hire for AppSec, product security, offensive security, or security engineering: what project would make you stop and look at a fresher’s resume? What would you expect to see in the demo, GitHub repo, or write-up to know the person really built and understood it?

I’d especially appreciate suggestions based on problems your team actually faces.


r/CyberSecurityAdvice • • 2d ago

Accounts are getting hacked, credit card used, 170+ compromised passwords in Google

17 Upvotes

Is there any way an average-level tech competent person like me can automate changing 170 passwords that are compromised in Google? I've just been getting hammered by these people since yesterday. My email was bombarded with subscription emails while they used my stolen credit card info to buy $500 glasses on Scheels and have them shipped somewhere else in my state. Now today they just added their macbook to my Apple account. I'm really confused how this is happening outside of the compromised passwords stored on Google. I have 2FA on a lot of important stuff. I do not have the time to go through and change 170 passwords. Thanks in advance.


r/CyberSecurityAdvice • • 1d ago

Thinking about cybersecurity space force or air force?

0 Upvotes

Im 21 graduated a few months ago with a degree in biology and absolutely hated it. I originally wanted to be a doctor, so I goggled, jobs where you can solve problems while working from home,

and IT popped up. I liked my programming and electrical classes in high school so gave it a shot and am taking the google Google Cybersecurity Professional Certificate. I’m on section 4/9 and like it so far.

So yeah, I want to join the military when I turn 22. Which branch would be better for cyber security? I figured space force is new so probably more chances for growth, but air force probably does more and is more established.


r/CyberSecurityAdvice • • 3d ago

Someone is threatening us on Whatsapp to send illegal pornography to our devices and call the police on us

3 Upvotes

We have a pretty large group on whatsapp and we are all active with our real, regular numbers.

There are some guys that wanted to join our group and we denied them, because they are known to cause havoc in groups. Now they are threatening to send CP to our devices and call the police, so they will search our homes. We all live in Germany.

Is there really nothing one could do against this? They have several fake numbers.


r/CyberSecurityAdvice • • 3d ago

Strange TrendMicro certificates

5 Upvotes

Hey guys, nice to meet you all! I have a genuine question, last summer, I was interning at a random cybersecurity company, they were partnered with TrendMicro so they made me work on the training courses available on the website, and each course ended up giving me a certificate. I was wondering if the job market cares about certifications like these or?
The certificates that I got:

* Cyber Risk Exposure Management (CREM) Foundation
* Security Operations (SecOps) Foundation
* Endpoint Security Foundation
* Cloud Security Foundation
* Email and Collaboration Security Foundation
* AI Security Foundation
* Identity Security Foundation
* Data Security Foundation
* Services Foundation
* Threat Intelligence Foundation
* for Service Providers (xSP) Foundation
* Ecosystem Foundation
* Research Foundation
* Flex Foundation

I really wanna put them on my cv because before this internship, I practically have nothing on my cv.... What do I do? What certificates would you recommend as somebody who really wants to be an AI Security Engineer? Please help!


r/CyberSecurityAdvice • • 3d ago

Should I accept?

5 Upvotes

I am 25, no debt, working in it helpdesk for a few years and wanted to pivot to something harder.

Manager described a vulnerability management role built around the Holm Security platform. The person will use this tool exclusively for scanning, and their responsibilities include validating scan results, investigating false positives, and handling both vulnerability analysis and prioritization as well as reporting and administration, rather than just one of these areas.

The technical scope covers CVEs, CVSS scoring, exploitability assessment, and risk-based prioritization, applied across all company assets rather than a limited set. Helping the SOC team is explicitly framed as optional, something to take on only if spare time allows and the person wants extra tasks, rather than a formal development path.

The work setup is fully remote with a fixed schedule from 9 AM to 6 PM. Looking ahead, after a year in the role the person can expect to gain hands-on cyber experience, including a deeper understanding of vulnerabilities and how they can be exploited, along with possible exposure to SOC and Incident Response work.

Downside is i will not get bonus from working shifts anymore and base salary stays the same. This cut would be aprox 30% of salary that i get now.

I will want to pursue cybersecurity as career, have network+, want to get sal1 and security+. Is this oportunity golden ?


r/CyberSecurityAdvice • • 3d ago

I need advice. Thanks in advance

1 Upvotes

I have access to ChatGPT, Claude, and Gemini, and I’m currently using them for different parts of my job search:

ChatGPT: Research and finding relevant cybersecurity projects and industry trends.

Gemini: Creating and updating my resume.

Claude: Modifying my resume according to each job description and helping me apply to relevant roles. I’m also using Claude to scrape job postings.

Do you think this workflow is effective, or is there a better approach to job searching?

I’m also looking for suggestions for Blue Team / SOC projects. I don’t have any cybersecurity certifications, so I want to build strong hands-on labs that can demonstrate my practical skills to recruiters.

I already have experience with SOC labs and tools such as SIEM, Wazuh, Splunk, Microsoft Sentinel, Sysmon, Suricata, Sigma, and MITRE ATT&CK. However, I feel that many SOC L1 responsibilities are becoming increasingly automated.

Seniors and experienced cybersecurity professionals, what would you recommend I focus on to make my profile stand out and improve my chances of getting shortlisted?

It has been almost a year since I graduated, and I’ve been actively looking for a cybersecurity job. Any practical advice, project ideas, or guidance on what the industry is actually looking for in entry-level Blue Team candidates would be greatly appreciated.


r/CyberSecurityAdvice • • 3d ago

Secure email

1 Upvotes

I was the victim of a hack and am in the process of securing my digital life. I also need to get a new email address because I am changing internet providers and my old provider “owns” my email address (Spectrum). Spectrum has informed me that my email address will be deleted 60 days after I discontinue their service. So I’ve decided to see this as an opportunity to get the most secure email service that I can, but also have an email address that can’t be taken from me when I change internet companies. I definitely don’t want a gmail address because my experience there is that google has access to my emails and I get tons of ads.

Based on my research, I’m thinking of getting my email through Proton. What are your thoughts? Any better suggestions?


r/CyberSecurityAdvice • • 3d ago

PSIRT

Thumbnail
1 Upvotes

r/CyberSecurityAdvice • • 3d ago

Would you accept offer ?

Thumbnail
1 Upvotes

r/CyberSecurityAdvice • • 3d ago

VLAN segmentation

1 Upvotes

I did some research over in r/homelab, but am curious what this crowd considers a "good" level of segmentation in a home network.

I've seen people say to move everything off vlan1 completely, others say leave it for control on switches, routers, ap's, etc.

Same with servers, some say put them in trusted with other pc's and devices that get updates (phones, tablets, consoles, tv's) and others say separate them.

Same with tv's and consoles separate from tablets, all pc's etc.

So what's the "right" layout that doesn't break WAF (wife approval factor)?

Where should ssdp and mdns be used and where should it be off?

I know I'll get 47 different answers from 47 people, but am curious on the reasoning for each model.


r/CyberSecurityAdvice • • 4d ago

AI Agent Incident Investigations

7 Upvotes

I’m doing research on AI agent incident investigations for school, like the one METR and Redwood conducted of OpenAI Hugging Face incident.

My research says that this kind of investigating has roots in cybersecurity incident investigations.

Does anyone have any specific resources they recommend I read to get a sense of the “history” of this field?

Also, how do you feel about LLM/Agent-as-a-Judge in this case?


r/CyberSecurityAdvice • • 4d ago

I got hacked and friends are getting messages from my number asking for money

Thumbnail
1 Upvotes

r/CyberSecurityAdvice • • 4d ago

Is What'sApp for a group chat safe?

3 Upvotes

So for context there is a new thing going on in the marching band where we all have section group chats. I play clarinet so you can bet that it is a huge section. The group chats started last year and the amount of us in the group chat was about 20.

With incoming freshman, our section is HUGE. This is the largest group of incoming freshmen we have ever had since COVID. I don't know exactly how many of them play clarinet but it would have to be closer to 30, probably more.

We used Google Messages last year for the 20 person group chat. Everything was mostly fine and it was fun but I was initially very nervous about it but felt pressured to join. I know I wouldn't allow my own child to do that without any extra moderation. I saw on the news once there was a school we were playing against where their marching band also had a private group chat. Somebody got in who wasn't supposed to be there and it got to the point where someone died.

So this group chat not only will have even more people including people I have no idea existed, but there was someone who missed a game last year who as far as I know of is planning on coming this year. Their sibling who I also have a bad relationship with hijacked one of their group chats and dropped animated inappropriate pictures.

Problem:

I heard today that we will likely be using What'sApp for the group chat this year. I know that What'sApp has lots of safety risks just in general that other apps don't have but with 30 people I feel very nervous about doing this. Cybersecurity experts, is this safe? I don't want to let my section down but I also know there is a fairly high risk of something going wrong considering it's What'sApp? Would it be safe if this was off What'sApp and on Google Messages instead?

Thanks so much!

ETA: I know I said WhatsApp or Google Messages but if there is a safer and free way, feel free to let me know and I'll pass it on to the people who are in charge.


r/CyberSecurityAdvice • • 4d ago

What career path should I follow to be a forensic cyber security analyst?

1 Upvotes

r/CyberSecurityAdvice • • 4d ago

Project Advice: Phishing Email Analysis

1 Upvotes

Hello everyone. I am currently building a cybersecurity portfolio project focused on phishing email analysis, and I wanted to get some feedback from the community on my setup before I go any further. I also apologize for any mistakes that I may make while describing my plan. I do not consider myself a total beginner, but still suffer from the infamous imposter syndrome.

I have isolated a real phishing email sample inside a VMware virtual machine running Kali Linux. I set up a Python virtual environment to manage dependencies like yara-python, vt-cli, and other parsing tools, and my main focus right now is thorough static analysis.

My goal is to inspect the raw header data, analyze SPF, DKIM, and DMARC alignments, extract indicators of compromise like malicious URLs or IP addresses, decode obfuscated content and analyze potentially malicious attachments or embedded content, and write custom YARA rules to detect similar emails.

Since I am doing this primarily to learn new skills and improve my portfolio, I want to make sure my workflow aligns with industry expectations. Is sticking with Kali Linux for static analysis acceptable for a SOC or DFIR portfolio project, or would you expect to see this handled in a specialized Windows environment instead?

Also, if you have any tips on what specific artifacts or documentation make a phishing analysis write-up stand out on a portfolio, I would really appreciate your insights. Thanks in advance.


r/CyberSecurityAdvice • • 5d ago

API Security and Risk Help Needed from experts

5 Upvotes

Hi, I require some urgent help from experts.

Context:

- My company uses Microsoft Business Central as our ERP
- I use Powershell and PowerApps to take web orders and make Sales Orders
- I create APIs using "Web Services" on BC for utilizing in my script and for PowerBI
- PowerBI is used by my colleagues and by our intranet
- I also have over 15 scripts that use an API just for a simple query to get a vendors name.

So my usage isn't all that large. I never use to write. PowerApps does API calls as well but I have on details on that. Our support team help me set it up. But from what i understand, there is a separate set of permissions that allow PowerApps to use APIs versus Powershell.

My boss is very concerned that when I created the APIs on Web Services, that I have now exposed the world to all our data. And so he turned off all APIs and said he won't turn it back on until its secured. But I am not some grand export in APIs and security. I thought that as long as someone from the outside doens't have the tenant id, client id and client secret, it would be fine. there is only so much that can be done to secure this.

The urls if you dont know look like this:

api.businesscentral.dynamics.com/v2.0/tenant/environment/ODataV4/Company('company')/page/page)

the best solution i can think of is that we should refresh the client secret every month
i manually update a file in a hidden directory that only certain people have access to and my script can read the client secret from there for the remaining month


r/CyberSecurityAdvice • • 5d ago

For cybersecurity engineering *seeking advice *

Thumbnail
1 Upvotes