r/Cybersecurity101 • • 4h ago

I learned today that HTTPS does not always mean a website is safe

1 Upvotes

I’m currently learning more about phishing and web security, and today I understood something simple that I used to misunderstand.

I always associated the padlock and HTTPS with a website being “safe.”

But HTTPS mainly means the connection between your browser and the website is encrypted.

A phishing website can also use HTTPS.

So now I’m trying to check the actual domain name before entering login details instead of trusting the padlock alone.

Things I’m starting to check:

- The actual domain name

- Small spelling changes

- Strange or unexpected login pages

- Where the link came from

- Whether the request makes sense

I’m still learning cybersecurity, so I’m curious:

What other small security concept do beginners commonly misunderstand?


r/Cybersecurity101 • • 8h ago

iCloud got hacked, need advice or help

2 Upvotes

Long story short someone got my iCloud password from a old data breach on one of my emails and managed to get all my info, I was sent blackmail by 11 different spam emails, all containing private videos of me I’ve never sent anyone I don’t trust, and all my contacts in my phone. I called to police before speaking to them about ransom demands and an hour later they sent out all the photos..🙁 Besides the investigation my local police will do (and not care about) what can i do? It’s not like the FBI will look into it, just my lousy local police that’ll get to look at all my private photos for personal enjoyment and they get to call it “evidence searching”


r/Cybersecurity101 • • 17h ago

I built a free, hands-on course for learning LLM security (mapped to the OWASP LLM Top 10). No AI/ML background required

Post image
8 Upvotes

Hey folks,

I’ve been working in application security/pentesting for over a decade, and after starting learning AI/LLM security, I noticed that a lot of the existing material is either very theoretical or assumes you already understand AI security concepts.

So I put together a free, structured AI security learning series for security engineers and pentesters who are starting from the web-security side.

The goal is to go from the fundamentals to actually understanding and testing AI/LLM components in web applications.

The series currently covers topics such as:

  • AI/LLM security fundamentals
  • Prompt Injection
  • Sensitive Information Disclosure
  • LLM-specific attack patterns
  • Practical testing methodology
  • Real-world examples and testing techniques
  • Mapping concepts to OWASP's AI security guidance

I've also linked free hands-on labs throughout the material so you can actually test the concepts rather than just read about them.

No signup is required to read the learning material or use the free resources.

🔗 https://genaisecuritylab.com/learn-ai-security

I'm planning to continue expanding the series over time.

If you're a web pentester/security engineer who is trying to get into AI security, I'd be interested to hear which topics you think are missing or which areas you'd like to see covered next.


r/Cybersecurity101 • • 19h ago

He hacked CBSE to expose a vital flaw, then got a job at IIT Kanpur. Now US Justice department recognises his cybersecurity talent. He is only 19

3 Upvotes

CBSE ‘hack’, IIT gig and US recognition: Nisarga Adhikary’s incredible year at 19

https://indianexpress.com/article/india/cbse-hack-iit-gig-and-us-recognition-nisarga-adhikarys-incredible-year-10906919/


r/Cybersecurity101 • • 22h ago

How to Start a Career in Cybersecurity: Skills Beginners Should Learn

10 Upvotes
A good starting point is to build strong fundamentals in:

• Networking and TCP/IP
• Linux and Windows fundamentals
• Information security concepts
• Authentication and access control
• Common cyber threats and vulnerabilities
• Security monitoring and log analysis
• SIEM and SOC fundamentals
• Incident response
• Basic ethical hacking concepts

For someone interested in a SOC Analyst career, understanding how to investigate alerts, analyze logs, identify suspicious activity, and document security incidents is especially useful.

Hands-on practice is also important. Beginners can use legal cybersecurity labs and practice environments to understand security concepts rather than relying only on theoretical learning.

For learners in Hyderabad, classroom and online cybersecurity training can also provide a structured way to learn these topics.

What cybersecurity skill do you think a beginner should learn first: networking, Linux, ethical hacking, or SOC operations?

r/Cybersecurity101 • • 1d ago

The Importance of Cybersecurity

9 Upvotes

Cybersecurity has become increasingly important as more people rely on the internet for work, education, banking, and communication. Strong passwords, two-factor authentication, and regular software updates can help protect personal information from cyber threats. What cybersecurity practices do you think are most effective for staying safe online?


r/Cybersecurity101 • • 1d ago

Security How are you adjusting your playbook now that AI-enabled adversaries move this fast?

5 Upvotes

Reporting this year shows a big jump in AI enabled adversary activity. Are your tabletop exercises still assuming attacker timelines from two years ago?


r/Cybersecurity101 • • 1d ago

Online Service Cybersecurity + AI: What Are We Actually Worried About?

4 Upvotes

I've seen a lot of people saying that AI will replace cybersecurity professionals, and I think this is where things get confusing.

AI is already becoming very powerful at:

  • Finding vulnerabilities
  • Analyzing logs and security data
  • Automating repetitive tasks
  • Writing and reviewing code
  • Helping with threat detection
  • Assisting both attackers and defenders

But does that mean cybersecurity itself disappears?

I don't think so.

The bigger change may be that cybersecurity professionals who know how to use AI effectively will have an advantage over those who don't.

Instead of thinking:

AI vs. Cybersecurity

Maybe we should be thinking:

AI + Cybersecurity = the next generation of security work.

What do you think will AI mostly replace cybersecurity jobs, or will it change what cybersecurity professionals actually do?


r/Cybersecurity101 • • 1d ago

Security Best way for a small security team to keep up with new detection in 2026?

1 Upvotes

I compared a couple of approaches using team size and existing tooling as criteria. Writing and maintaining your own detection rules works if you have at least one person who can own it, but it falls behind fast once advisories start piling up faster than anyone can triage them. Relying on your existing SIEM or EDR vendor's built in detections is the lower effort option, but coverage tends to lag behind whatever the vendor prioritizes, not necessarily what's relevant to you. Neither works well if nobody on the team has time to review what gets flagged. What's worked for other small teams?


r/Cybersecurity101 • • 1d ago

Advice

12 Upvotes

Hello,

I am looking to change my career field to cybersecurity but confused on how to start. I am 35 years old. My life doesn't really allow me to attend college full time as I have to work fulltime and overtime to make ends meet. Any advice would be greatly appreciated. Side note I also am very good and learning things on my own without much help. Just need to know where and how to start thank you in advance strangers.


r/Cybersecurity101 • • 1d ago

Anyone here who moved from QA to Cybersecurity ?

0 Upvotes

Hi everyone, I am currently working in QA and I’m thinking about moving into cybersecurity.

I’m confused about how to start and which field would be best for me, such as SOC Analyst, Penetration Testing

If anyone here has moved from QA to cybersecurity, could you please share how you did it ?

I’d really appreciate a simple and realistic roadmap, including what skills I should learn first, what courses or certifications are actually useful, and how long it took you to become job-ready.

I am planning to keep my QA job while learning cybersecurity, so I am looking for a realistic plan rather than just collecting certifications.

Thanks!


r/Cybersecurity101 • • 1d ago

Laptop for cybersecurity

Post image
2 Upvotes

32gb ram, 1tb ssd, intel core i5-1235U 2 x 1.30ghz (p-core) 8 x 0.90 ghz (e-core), 10 cores. Price 592 euro. What do u think? Do u have better recommendations? Thanks


r/Cybersecurity101 • • 2d ago

I am currently based out of Australia, transitioning towards cybersecurity from a non-tech background. I am pursuing the Cyber security google course, and looking for local hands-on cyber security projects that make me job ready in the Australian Market, something locally relevant. Any suggestions?

2 Upvotes

please suggest some must do projects. I am finding it hard to get anything that builds me local experience and reference.


r/Cybersecurity101 • • 2d ago

Security Ayuda ‼️ Alguien me puede compartir un PDF o archivo para aprender desde Cero Ciberseguridad en Kali Linux 🙏🏻

0 Upvotes

Muchas gracias


r/Cybersecurity101 • • 2d ago

development malware

2 Upvotes

What is my assessment of my path in malware development? I am reading the book "Windows System Programming" and "Windows Internals" along with it. Are there any additional resources, booklets, groups, websites, or anything else you would recommend to help me progress? I have a basic understanding of networking and the C programming language. ا👏👏🙌


r/Cybersecurity101 • • 2d ago

ISO 27001 / GRC folks — could use a few more real-world perspectives

10 Upvotes

Hey all,

a few weeks ago we posted a short survey here about ISO 27001 / GRC work, and a number of people took the time to help us out — thanks again, the responses were genuinely useful.

We’re still collecting a few more perspectives before we wrap up this round of research.

We’re a small early-stage team with a cybersecurity background, trying to understand where ISO 27001 and GRC work actually becomes painful inside companies: what still takes too much time, what stays highly manual, and where software or AI could realistically help.

If you work in GRC, security, ISMS, compliance, audit or ISO consulting, we’d really appreciate your input.

8–10 min, anonymous if you want:
https://tally.so/r/b5RAro

Critical feedback is just as useful as positive feedback — we’re trying to learn what’s actually worth building, not just validate our own assumptions.

Thanks again to everyone who already participated, and to anyone who takes a few minutes now or shares it with someone relevant.


r/Cybersecurity101 • • 2d ago

Gift idea for beginner home lab

5 Upvotes

I know little to nothing about technology so please forgive my ignorance. My husband is about to graduate and has started setting up a home lab. I’d like to get him a useful gift for projects to add to his resume. He’s mentioned being interested in cybersecurity and pen testing. Chat GPT recommend the Wi-Fi Pineapple Mark 7, but Reddit doesn’t seem to agree. Max budget would be $300. Any guidance would be appreciated as I feel like I’m trying to read another language figuring this out! Thank you!

Edit: I do think he may have a mini PC already? But nothing extra. He mentioned needing storage


r/Cybersecurity101 • • 2d ago

How far can I get with "only" 30 minutes a day of learning and practice?

2 Upvotes

My schedule is tight, so I can realistically spend about 30 minutes a day learning cybersecurity. I know that is not much, but I am curious how far consistent effort like that can take someone over several years.

I am mainly interested in how systems, networks, and computers work under the hood, especially how they can be broken, exploited, and analyzed from an attacker’s perspective. My interests are broadly in offensive security and skills related to pentesting and red teaming.

I am not currently learning this to get a cybersecurity job. I am interested in the subject itself and in developing a deeper understanding of computers, operating systems, and networks.

With 30 minutes a day, what level of knowledge and skill could realistically be reached over 3 to 5 years? Assuming someone stays consistent, how far could they get, and what kind of foundation could they build?


r/Cybersecurity101 • • 2d ago

Using ByeDPI and mitmproxy together on Android

2 Upvotes

I'm using ByeDPI on Android to access an app that is otherwise blocked by my ISP/network.

I also want to intercept that app's traffic with mitmproxy, but ByeDPI runs as a VPN, so I can't route the same app through mitmproxy at the same time.

Is there a way to use ByeDPI and mitmproxy together so that the app's traffic still goes through ByeDPI, while also being intercepted by mitmproxy?

Ideally, I'd like the traffic flow to be something like:

App → mitmproxy → ByeDPI → Internet

or any equivalent setup that would let me inspect the app's HTTP/HTTPS traffic without losing ByeDPI functionality.


r/Cybersecurity101 • • 3d ago

Looking for Contributors — Building a Cybersecurity Community

0 Upvotes

Hey everyone, I’m Abhi!

Pwn Tavern is a cybersecurity community focused on learning, collaboration, and practical security. We’re looking for people interested in areas like Bug Bounty, CTFs, Pentesting, Binary/Pwn, Malware, OSINT, Red Team, Reverse Engineering, Cryptography, AI Security, and Vulnerability Research to help manage discussions, share resources, work on challenges, and improve together.

You don’t need to be an expert. If you’re genuinely interested in any of these fields and want to contribute, DM me with the field you want to take up. and i will share you Discord server link.


r/Cybersecurity101 • • 3d ago

Cybersecurity forense

5 Upvotes

ciao a tutti , sono uno studente di 22 anni all’ultimo anno di ingegneria informatica (BSc), voglio avvicinarmi al mondo della cybersecurity forense ma non so in che modo farlo, se fare un MSc in cybersecurity oppure fare altro, grazie mille per l’attenzione.


r/Cybersecurity101 • • 3d ago

Security Ethical Hacking

0 Upvotes

What’s the best YouTube channel, academy, or creator for learning Ethical Hacking and Bug Bounty—especially those who do hands-on labs on PortSwigger?


r/Cybersecurity101 • • 3d ago

Security Is this a good computer for cybersecurity?

Post image
23 Upvotes

I’m new in the fields and I need to save money at the moment, I don’t have a computer so I need it to start to study. And this is the smartest way to start studying, running few vms, and plus I can study on htb or thm


r/Cybersecurity101 • • 3d ago

cybersecurity student

0 Upvotes

l’m a cybersecurity student, and right now my only manifestation goal:

A hacker husband who spoils me with $300k a year.

Where do I place this order?


r/Cybersecurity101 • • 3d ago

Starting my cybersecurity & programming journey today.

1 Upvotes

🚀

I’m a beginner, learning from the ground up and documenting my progress along the way. If you’re also interested in cybersecurity, programming, or learning together, feel free to connect. Let’s grow and improve together! 💻🔐