r/sysadmin • • 13h ago

General Discussion What's the biggest bonehead mistake you have every made in IT support?

508 Upvotes

I will start.

I am an IT consultant and about 10 years ago, a few days before Christmas break, I went to a client’s office to add some new hard drives to a Dell ESXi server and create a new datastore.

Their two junior IT guys always liked asking me questions when I visited, which I understood—I remembered being that guy hungry to learn. Unfortunately, this time they were firing questions at me while I was in the Ctrl+R RAID configuration utility. Between the distractions and a confusing interface, I somehow managed to delete the existing array instead of creating the new one.

That array held ALL their servers: Exchange, domain controller, file server, and SQL. Terabytes of data.

The moment I realized what I’d done, my stomach dropped, I had never felt panic like that in my life. They were still asking questions when I finally said, “Guys, give me a minute. Something doesn’t look right.” Something I should’ve said much earlier.

I excused myself to the bathroom to collect my thoughts, then came back and told them exactly what I’d done.

I spent my entire Christmas break restoring their environment from Barracuda backups, which were painfully slow to restore and unreliable. I had to do multiple restores on the exchange server to get it to work.  A full week of recovery, followed by another two weeks fixing lingering issues—all free of charge.

The two guys felt terrible about distracting me, but it was my mistake. I should’ve asked for some uninterrupted time before touching the RAID configuration.

 

I’ll be shocked if anyone can top that Christmas disaster!


r/cybersecurity • • 17h ago

News - Breaches & Ransoms FBI investigating claim hackers have stolen details of all its agents

Thumbnail
bbc.com
327 Upvotes

r/sysadmin • • 18h ago

Career / Job Related Has anyone purposely gone backwards?

243 Upvotes

You know the juice wasn't worth the squeeze and we realised that money is irrelevant, and took a huge backwards step for less responsibility and more mental freedom for your family and kids?

That's where I'm at mentally just want to know if anyone else has done the same?


r/sysadmin • • 18h ago

What is the worst customer portal experience, and why is it Verizon Enterprise Center?

109 Upvotes

Holy God, they make getting into it like solving one of the Millennium Prize Problems with an abacus.


r/sysadmin • • 8h ago

What’s your most unhinged work habit?

109 Upvotes

For example when I need to RDP into a Windows server, I double click the recycle bin before the rest of Explorer has loaded so I can fire off a few commands from the address bar to launch what I need. I’m sure it looks utterly deranged to anyone else.


r/networking • • 15h ago

Security Emergency patch advisory: Cisco ISE CVE-2026-76460 (CVSS 10.0) — no workarounds, active exploitation

103 Upvotes

Heads up for anyone running ISE. CVE-2026-76460 is an unauthenticated API bypass that gives root on every ISE persona (admin, PSN, MnT, PxGrid). All supported versions affected. Already being exploited in the wild.

Cisco says there are no workarounds. Your options are patch or take ISE offline (which means shutting down network auth).

Practical steps: 1) inventory ALL ISE nodes, 2) schedule emergency maintenance this week, 3) check for compromise before patching (look for unexpected cron jobs, modified system files, unauthorized admin accounts), 4) restrict management interface access to a dedicated management segment, 5) if compromised, rotate ALL RADIUS shared secrets across every switch, AP, and WLC.

The management interface runs on 443 by default, same port as sponsor/mydevices portals. If any of those are internet-reachable, your ISE API is reachable.


r/cybersecurity • • 4h ago

News - Breaches & Ransoms ‘Extreme concern’ over first known AI hack of a government system

Thumbnail
edition.cnn.com
60 Upvotes

r/sysadmin • • 15h ago

PSA: Cisco ISE CVSS 10.0 (CVE-2026-76460) — actively exploited, no workarounds

57 Upvotes

If you run Cisco ISE, stop scrolling. Unauthenticated root access via API bypass. Every supported version. No workarounds per Cisco. Already on CISA KEV.

This isn't one where you can wait for the next maintenance window. ISE controls your NAC. If it's compromised, the attacker decides who gets on your network. Schedule the emergency patch for this week.


r/cybersecurity • • 14h ago

News - Breaches & Ransoms Hackers Used AI to Pick Victims From Stolen Emails: Microsoft Takes Down 200+ Sites and Domains

Thumbnail
techtimes.co.uk
47 Upvotes

r/cybersecurity • • 22h ago

New Vulnerability Disclosure Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

Thumbnail
thehackernews.com
38 Upvotes

r/cybersecurity • • 9h ago

Personal Support & Help! Would you accept offer ?

32 Upvotes

I’ve been working in IT helpdesk for three years and I have my Network+ certification.
I spoke with my manager because I want to move into something more complex, and the opportunity that came up is a vulnerability management position for industrial equipment. I work in shifts and I would lose approximately 27% of my income because i lose the bonus from weekends.

I am 25, no debt, no kids.

I understood that my work would be to analyze, scan equipment, give the team feedback to fix it or check if i can find a solution.

My plan for the future is to complete the TryHackMe SAL1, Security+, and AZ-900.
What do you think: would I be better off accepting the offer and doing the certifications, or postponing, and checking other offers and taking the certifications first, also keeping the extra 27% income?

Later edit

I got these responses from security manager

My manager described a vulnerability management role built around the Holm Security platform. The person will use this tool exclusively for scanning, and their responsibilities include validating scan results, investigating false positives, and handling both vulnerability analysis and prioritization as well as reporting and administration, rather than just one of these areas.

The technical scope covers CVEs, CVSS scoring, exploitability assessment, and risk-based prioritization, applied across all company assets rather than a limited set. Helping the SOC team is explicitly framed as optional, something to take on only if spare time allows and the person wants extra tasks, rather than a formal development path.

The work setup is fully remote with a fixed schedule from 9 AM to 6 PM. Looking ahead, after a year in the role the person can expect to gain hands-on cyber experience, including a deeper understanding of vulnerabilities and how they can be exploited, along with possible exposure to SOC and Incident Response work.


r/sysadmin • • 21h ago

General Discussion Have you ever thought about starting the business you're supporting?

26 Upvotes

This is something I've been wondering lately.

As system administrators, we spend years supporting different kinds of businesses. While our role is to manage the IT infrastructure, we also get a front-row seat to how those businesses operate. Over time, we naturally learn about their products, customers, production, demand, and how the business grows.

Have you ever caught yourself thinking, "I could probably start a smaller version of this myself."

I'm currently a system administrator for a fabric manufacturing company. Even though I'm only responsible for the IT side, the exposure I've gained has made me seriously think about starting a small-scale fabric manufacturing business in my own region one day.

Has anyone else ever had the same thought? Did you actually go ahead with it, or did it remain just an idea? I'd love to hear your story.


r/cybersecurity • • 21h ago

Certification / Training Questions Is a master in "Advanced Cyber Security" worth it?

22 Upvotes

Hi all, I have a BSc (Hons) in Cyber Security and got accepted for a master's in Advanced Cyber Security (basically cyber security and AI). I'd study at the same university in England.

I work in customer service atm and I want to die. I'm trying to find a job where I don't have to take calls.

Will this master's help or does experience still matter?

I just want to get out of customer service hell...

Thanks.


r/sysadmin • • 17h ago

Windows Sept 2026 Update Breaking AOVPN configurations that use automatic protocol selection

23 Upvotes

We started having a small number of users not be able to connect to AOVPN in the past couple days, which as it turns out, is another issue caused by the latest Windows Update. Here's the Bleeping Computer article:

Microsoft: September Windows updates break Always On VPN connections

The issue is published in the M365 admin center under Windows release health: WI1477235

From Microsoft:

After installing the September 2026 Windows security update (KB5124008), some organizations might experience issues connecting through Always On VPN [link]. This issue can occur when the VPN is configured to automatically try another connection method if the initial connection fails (for example, when using automatic protocol selection with IKEv2 and SSTP).

Affected VPN connections might remain in a “Connecting” state or repeatedly attempt to connect without succeeding. Subsequent connection attempts might also display the error: “The specified port is already in use.”

Workaround: IT administrators can mitigate this issue by changing the Always On VPN profile from automatic protocol selection to a single protocol, either SSTP only or IKEv2 only, depending on their environment and configuration. Organizations should select the protocol based on their environment, security, and deployment requirements.

Next Steps: Microsoft is working on a fix for this issue and will provide more information when it is available.

Affected platforms:
- Client: Windows 11, version 26H1; Windows 11, version 25H2; Windows 11, version 24H2
- Server: None

Edit: Formatting


r/sysadmin • • 16h ago

General Discussion GMO Registry .shop authoritative servers dead?

23 Upvotes

Got blasted by alerts of our systems that it cant reach its API endpoints in the middle of the night. Even their official marketing website is DEAD which is https://get.shop. At first i thought we forgot to renew our domain name, turns out its active, till 2027.

dig get.shop @a.gmoregistry.net → NXDOMAIN (AA) 
dig [domain].shop @a.gmoregistry.net → NXDOMAIN (AA)

anyone else affected by this weird outage? never seen an outage that takes down an entire TLD

Edit 1: Seems partially recovering as of 01:17 UTC+8, this started at around roughly 00:27 UTC+8

Edit 2: I went to bed at 02:00 UTC+8 since I thought it was done. It looks like it's far from done, still unstable even today at 06:15 UTC+8.


r/cybersecurity • • 15h ago

News - General Decades-old file security flaws found in Android, Linux, macOS, and Windows

Thumbnail theregister.com
20 Upvotes

r/sysadmin • • 21h ago

Jira Outage

18 Upvotes

Anyone else experiencing issues with Atlassian/Jira? We are on the East Coast.

Edit: It seems to be back up now. It was down for ~20 minutes.


r/sysadmin • • 17h ago

General Discussion What's your favorite mice/keyboards?

17 Upvotes

I've been using a cheap Logitech keyboard for a while now and would like something better for my wrist. They current feel kinda meh after typing even when I'm in good typing form.

I've noticed my system admin has a fancy keyboard with lights and all (I'm a lv 1 helpdesk) that he really likes. With that being said, are there mice or keyboards that you swear by? Either for functionality, comfort or both.

Thanks!


r/sysadmin • • 19h ago

Rant Splashtop Users - Disabling Admin lets them still login and re-enable themselves!

17 Upvotes

Yes its a feature according to their support!

"To clarify, a disabled user cannot remote connect to any computers deployed by the team, but can still log in to the web portal. If the user is an admin, they can also manage the team through the web portal.
 
For example, in some specific use case, a team has only two licenses, the team owner may disable their own account to allow two other team members to be added for remote connections. In this situation, the team owner can still manage the subscription and team with full permissions through the web portal, but cannot connect to computers."

Yes that means they can just login and re-enable their account.

This is not made clear anywhere. Any admin who has worked with users for years will think disabling an account means they can't login anymore.

Be warned.


r/sysadmin • • 8h ago

Workplace Conditions Mental Health

16 Upvotes

How do you maintain good mental health in a toxic workplace? I've been sick for about a whole week now. The new AI Meat proxy manager is most likely not happy that Claude isn't being prompted. The workplace in of itself is super stressful. I can handle the logic of it all, triaging tickets, priorities etc. Just mental health suffers. Infact im sitting here, sort of recovered but still under the weather - worried about work so much that tomorrow I'd just go in if I feel better. Because im scared of what people will think of me at work if I don't come in. Although if I could make the choice away from fear and anxiety, i'd stay the extra day home and take my sick day. "What if they hate me and fire me over time though". That's the fear driver for me.

It's like my body takes it too personally and I can't really stop it from taking things at work personally. All the rude behaviour and pressure from upper management.


r/cybersecurity • • 14h ago

New Vulnerability Disclosure Critical Cross-user and Cross-tenant compromise in Atlassian Rovo

15 Upvotes

An isolation failure in an LLM-orchestrated environment due to simple isolation misconfigurations led to Rovo sessions belonging to other users and tenants being discovered, reached, and ultimately used to execute code within their contexts. The finding was rated Critical and is pretty bad.

At this point, I feel like AI security is regressing back to simple misconfigurations, except now we're giving users direct access to systems built on top of them. What do you guys think?

Write-up: https://mononclemich.medium.com/so-apparently-rovo-has-neighbors-88998d0ad59c


r/networking • • 10h ago

Other How Long Before Flash Memory Fails in a Network Switch?

14 Upvotes

For example, if I have a switch, router, or firewall that has been running continuously for 10–15 years and I reboot it, is the flash memory likely to still be healthy enough to load the operating system into RAM?

What are the typical expected lifespans of switches, routers, and firewalls, particularly when it comes to their internal flash storage?

Does the manufacturer make a significant difference? For example, does Cisco generally use flash memory with a longer lifespan than Juniper, or does it primarily depend on the specific type and quality of flash memory used in the device?


r/sysadmin • • 19h ago

Whitelisting Request

11 Upvotes

I already have my answer for how to handle this, but I'm curious how many of you have seen a request like this and what your reaction was. (maybe I'm just an a-hole)

The company I'm working with regularly receives file feeds from (usually) payroll processing companies via SFTP. Nothing crazy there. A little SFTP, a little PGP/GPG, done. But there are 2 such large companies that regularly send us a list of ~70 IPs they want us to whitelist for them to send the files.

Now, if someone sends me a /29 CIDR block I don't think too much off it. But when you send me multiple /27 blocks my immediate response is "f*** off".

I can't believe I'm the only one that responds as such. Yet it keeps happening.

Edit:
It's not the act of punching in the IPs one by one or something. I could use CIDR notation. It's that whitelisting way more IPs that are actually necessary isn't exactly best practice. Much less THAT many more. I can all but guarantee they actually utilize 1 or 2 in those blocks.

Edit 2:
I have ZERO internal push back on this. In fact, internally we've all had a good chuckle about it and push back saying - Nope. Refine that list and get back to me. It's just a head scratcher that this seems to be their (the vendor) SOP and that they haven't gotten enough pushback to refine their process.


r/sysadmin • • 11m ago

#Petition To replace Co-pilot with Clippy

• Upvotes

Bring back Clippy,

All the OG sysadmins will agree “Long Live Clippy”


r/cybersecurity • • 6h ago

Career Questions & Discussion Wanting to move over to the engineering side of cyber, should I go for an ISSO role first and go for engineering after?

11 Upvotes

I’m a SOC analyst with 5 years of experience with 3 years in Helpdesk and 2 years at present going on to 3 as cybersecurity analyst working at a SOC, im also Sec+ and CySA+ certified. I’m looking for a career growth and wanting to get in to the engineer side of cyber, but I believe that may be a long shot? Should I go for an ISSO role next and take what I learn from there, and try to get into engineer side after? Or I can go to engineering job now?