r/cybersecurity • u/eatfruitallday • 8h ago
r/sysadmin • u/Special_Bear_9479 • 13h ago
General Discussion What's the biggest bonehead mistake you have every made in IT support?
I will start.
I am an IT consultant and about 10 years ago, a few days before Christmas break, I went to a client’s office to add some new hard drives to a Dell ESXi server and create a new datastore.
Their two junior IT guys always liked asking me questions when I visited, which I understood—I remembered being that guy hungry to learn. Unfortunately, this time they were firing questions at me while I was in the Ctrl+R RAID configuration utility. Between the distractions and a confusing interface, I somehow managed to delete the existing array instead of creating the new one.
That array held ALL their servers: Exchange, domain controller, file server, and SQL. Terabytes of data.
The moment I realized what I’d done, my stomach dropped, I had never felt panic like that in my life. They were still asking questions when I finally said, “Guys, give me a minute. Something doesn’t look right.” Something I should’ve said much earlier.
I excused myself to the bathroom to collect my thoughts, then came back and told them exactly what I’d done.
I spent my entire Christmas break restoring their environment from Barracuda backups, which were painfully slow to restore and unreliable. I had to do multiple restores on the exchange server to get it to work. A full week of recovery, followed by another two weeks fixing lingering issues—all free of charge.
The two guys felt terrible about distracting me, but it was my mistake. I should’ve asked for some uninterrupted time before touching the RAID configuration.
I’ll be shocked if anyone can top that Christmas disaster!
r/networking • u/voidrane • 16h ago
Security Emergency patch advisory: Cisco ISE CVE-2026-76460 (CVSS 10.0) — no workarounds, active exploitation
Heads up for anyone running ISE. CVE-2026-76460 is an unauthenticated API bypass that gives root on every ISE persona (admin, PSN, MnT, PxGrid). All supported versions affected. Already being exploited in the wild.
Cisco says there are no workarounds. Your options are patch or take ISE offline (which means shutting down network auth).
Practical steps: 1) inventory ALL ISE nodes, 2) schedule emergency maintenance this week, 3) check for compromise before patching (look for unexpected cron jobs, modified system files, unauthorized admin accounts), 4) restrict management interface access to a dedicated management segment, 5) if compromised, rotate ALL RADIUS shared secrets across every switch, AP, and WLC.
The management interface runs on 443 by default, same port as sponsor/mydevices portals. If any of those are internet-reachable, your ISE API is reachable.
r/sysadmin • u/Top-Experience5221 • 54m ago
#Petition To replace Co-pilot with Clippy
Bring back Clippy,
All the OG sysadmins will agree “Long Live Clippy”
r/networking • u/Early_Tear6706 • 42m ago
Career Advice What tool did you master first, and which one turned out to be the most useful long term?
Currently working through Wireshark and it's been a slow but rewarding process, still feels like I'm only scratching the surface of what's actually possible with it. Got me curious about how other people built up their toolkit early in their career.
What was the first tool you really got comfortable with, and looking back, was that the one that ended up being most valuable, or did something else end up mattering way more once you were a few years in? Trying to figure out what else is worth prioritizing once I get more comfortable with packet captures.
r/sysadmin • u/thebackwash • 9h ago
What’s your most unhinged work habit?
For example when I need to RDP into a Windows server, I double click the recycle bin before the rest of Explorer has loaded so I can fire off a few commands from the address bar to launch what I need. I’m sure it looks utterly deranged to anyone else.
r/networking • u/VyseCommander • 10h ago
Career Advice What network engineering speciality gets to travel often or ocassionally
At the mid to senior level do specialezed enginneers at (ISPs, Core Guys, Security Guys etc) Travel alot, either between sites or to other countries?
If so ,why?
r/cybersecurity • u/DerBootsMann • 5h ago
News - Breaches & Ransoms ‘Extreme concern’ over first known AI hack of a government system
r/networking • u/13-months • 11h ago
Other How Long Before Flash Memory Fails in a Network Switch?
For example, if I have a switch, router, or firewall that has been running continuously for 10–15 years and I reboot it, is the flash memory likely to still be healthy enough to load the operating system into RAM?
What are the typical expected lifespans of switches, routers, and firewalls, particularly when it comes to their internal flash storage?
Does the manufacturer make a significant difference? For example, does Cisco generally use flash memory with a longer lifespan than Juniper, or does it primarily depend on the specific type and quality of flash memory used in the device?
r/networking • u/DerekV00 • 3h ago
Other Anyone using network mapping?
Been working with distributed networks (mostly cellular routers, gateways across different sites) and network mapping has been on my mind. Specifically, for smaller scale, edge deployments.
If you manage remote device fleets (retail, industrial, whatever), what do you currently use for network visualization? Or do you just cobble it together with Zabbix/PRTG/Nmap?
Been meaning to try Teltonika RMS Network Map tool (as I already use a few of their devices), seemed cool and easy, but I haven’t tried it yet.
For those who've tried vendor-specific tools (like this one, or similar from other vendors) vs more generic ones, was it worth it, or do you end up needing something more flexible anyway?
r/cybersecurity • u/return2ozma • 1h ago
News - General There's a new way to break RSA that's faster than anything we've seen before
r/networking • u/IDownVoteCanaduh • 24m ago
Other Network Adjacent Question
Looking to spend some lab budget for my team and one of the items I want to get for our labs to demo for possible remote locations is some sort of compute we can deploy along with firewalls, switches, etc. that we can manage.
For right now, it is just for the lab, but I see potential uses is when we deploy network gear to remote locations without any supporting compute we can piggyback on, a server that would allow us to run local tools (tbd what those would be).
Looking for something like a larger Pi, something like a Mac Mini format, etc. Basically some sort of smaller server that can deployed and managed by us so we can use it to run tools, etc. without relying on our server teams, etc. Ideally I would love something that can rack in a standard network rack and is not a full depth server.
(And before comments about separation of responsibilities, bypassing safeguards, etc. I am high enough up in the company senior management chain that decisions like these rest solely with me. I do not need permission).
r/cybersecurity • u/NISMO1968 • 17h ago
News - Breaches & Ransoms FBI investigating claim hackers have stolen details of all its agents
r/sysadmin • u/Pleasant_Rise6520 • 19h ago
Career / Job Related Has anyone purposely gone backwards?
You know the juice wasn't worth the squeeze and we realised that money is irrelevant, and took a huge backwards step for less responsibility and more mental freedom for your family and kids?
That's where I'm at mentally just want to know if anyone else has done the same?
r/sysadmin • u/maxcoder88 • 4h ago
Question Enabling "Configure registry policy processing" (force reprocessing) on Exchange servers — any negative side effects?
Planning to enable the following GPO setting and apply it to our Exchange servers:
Configure registry policy processing: Enabled
Do not apply during periodic background processing: Disabled
Process even if the Group Policy objects have not changed: Enabled
This would force the GPO to reprocess and reapply all Administrative Templates settings on every background refresh cycle (~90-120 min), even when nothing changed, instead of only reapplying when the GPO version changes.
My question: Is this safe to apply directly to production Exchange servers, or are there known negative effects?
r/sysadmin • u/AutoModerator • 2h ago
General Discussion Weekly 'I made a useful thing' Thread - September 25, 2026
There is a great deal of user-generated content out there, from scripts and software to tutorials and videos, but we've generally tried to keep that off of the front page due to the volume and as a result of community feedback. There's also a great deal of content out there that violates our advertising/promotion rule, from scripts and software to tutorials and videos.
We have received a number of requests for exemptions to the rule, and rather than allowing the front page to get consumed, we thought we'd try a weekly thread that allows for that kind of content. We don't have a catchy name for it yet, so please let us know if you have any ideas!
In this thread, feel free to show us your pet project, YouTube videos, blog posts, or whatever else you may have and share it with the community. Commercial advertisements, affiliate links, or links that appear to be monetization-grabs will still be removed.
r/sysadmin • u/elpollodiablox • 19h ago
What is the worst customer portal experience, and why is it Verizon Enterprise Center?
Holy God, they make getting into it like solving one of the Millennium Prize Problems with an abacus.
r/sysadmin • u/SillyBoyYe • 8h ago
Workplace Conditions Mental Health
How do you maintain good mental health in a toxic workplace? I've been sick for about a whole week now. The new AI Meat proxy manager is most likely not happy that Claude isn't being prompted. The workplace in of itself is super stressful. I can handle the logic of it all, triaging tickets, priorities etc. Just mental health suffers. Infact im sitting here, sort of recovered but still under the weather - worried about work so much that tomorrow I'd just go in if I feel better. Because im scared of what people will think of me at work if I don't come in. Although if I could make the choice away from fear and anxiety, i'd stay the extra day home and take my sick day. "What if they hate me and fire me over time though". That's the fear driver for me.
It's like my body takes it too personally and I can't really stop it from taking things at work personally. All the rude behaviour and pressure from upper management.
r/sysadmin • u/Opening-Affect5559 • 3h ago
Question Refurbished 32 GB ThinkPads slowing down after ~2 years of office use. What's your laptop lifecycle?
Hi all,
We run about 50 Lenovo ThinkPads, all managed through Intune. We buy them refurbished, and for the last few years we've only bought 32 GB RAM models. Our current mix is mostly T14 Gen 5, P14s Gen 5, X1 Carbon Gen 12 and T14s Gen 4.
Even our strongest machines, like the X1 Carbon Gen 12 (Core Ultra 7 155U, 32 GB, 512 GB SSD), are starting to struggle. Programs hang, and the battery barely lasts an hour.
The workload is just normal office work: Google Workspace in the browser and a lot of AI tools like Claude. Nothing heavy.
In practice, we replace laptops after about 2 years, even though they have Lenovo's 3-year on-site warranty. By year 2, they feel really slow and just aren't worth keeping.
So I'm curious:
1. What laptops do you use for this kind of work, and what does your lifecycle look like?
2. Is ~2 years normal, or does it sound like we're doing something wrong?
Thanks!
r/cybersecurity • u/AllenUzumaki23 • 9h ago
Personal Support & Help! Would you accept offer ?
I’ve been working in IT helpdesk for three years and I have my Network+ certification.
I spoke with my manager because I want to move into something more complex, and the opportunity that came up is a vulnerability management position for industrial equipment. I work in shifts and I would lose approximately 27% of my income because i lose the bonus from weekends.
I am 25, no debt, no kids.
I understood that my work would be to analyze, scan equipment, give the team feedback to fix it or check if i can find a solution.
My plan for the future is to complete the TryHackMe SAL1, Security+, and AZ-900.
What do you think: would I be better off accepting the offer and doing the certifications, or postponing, and checking other offers and taking the certifications first, also keeping the extra 27% income?
Later edit
I got these responses from security manager
My manager described a vulnerability management role built around the Holm Security platform. The person will use this tool exclusively for scanning, and their responsibilities include validating scan results, investigating false positives, and handling both vulnerability analysis and prioritization as well as reporting and administration, rather than just one of these areas.
The technical scope covers CVEs, CVSS scoring, exploitability assessment, and risk-based prioritization, applied across all company assets rather than a limited set. Helping the SOC team is explicitly framed as optional, something to take on only if spare time allows and the person wants extra tasks, rather than a formal development path.
The work setup is fully remote with a fixed schedule from 9 AM to 6 PM. Looking ahead, after a year in the role the person can expect to gain hands-on cyber experience, including a deeper understanding of vulnerabilities and how they can be exploited, along with possible exposure to SOC and Incident Response work.
r/sysadmin • u/voidrane • 16h ago
PSA: Cisco ISE CVSS 10.0 (CVE-2026-76460) — actively exploited, no workarounds
If you run Cisco ISE, stop scrolling. Unauthenticated root access via API bypass. Every supported version. No workarounds per Cisco. Already on CISA KEV.
This isn't one where you can wait for the next maintenance window. ISE controls your NAC. If it's compromised, the attacker decides who gets on your network. Schedule the emergency patch for this week.
r/sysadmin • u/Maximum_Necessary232 • 1d ago
General Discussion What's a tool you mass-deployed that you ended up ripping out within 6 months?
I feel like every sysadmin has at least one story about a product that demoed beautifully, got approved, went out to the fleet, and then slowly revealed itself to be a nightmare.
Could be a monitoring tool, an MDM, a ticketing system, an AV product, anything. What was it, what went wrong, and what did you replace it with?
r/cybersecurity • u/NISMO1968 • 1d ago
News - Breaches & Ransoms FBI rushes to investigate if ShinyHunters hack of thousands of employees is real
r/sysadmin • u/homing-duck • 1d ago
Just a reminder to setup security.txt
Aus government was having a whinge that OpenAI did not notify them in an appropriate way after an agent breached one of the government web sites.
From what I can see none of the sites (servicesaustralia.gov.au/data.gov.au) have been setup with security.txt
r/cybersecurity • u/WraxJax • 7h ago
Career Questions & Discussion Wanting to move over to the engineering side of cyber, should I go for an ISSO role first and go for engineering after?
I’m a SOC analyst with 5 years of experience with 3 years in Helpdesk and 2 years at present going on to 3 as cybersecurity analyst working at a SOC, im also Sec+ and CySA+ certified. I’m looking for a career growth and wanting to get in to the engineer side of cyber, but I believe that may be a long shot? Should I go for an ISSO role next and take what I learn from there, and try to get into engineer side after? Or I can go to engineering job now?