More posts — page 2

40 posts total
D
dotjobs
@dotjobs
2.3K

🚀 Your next career move starts HERE!

📍 Location: Baghdad – Onsite 🏢 Company: Horizon Scope technologies 🕘 Employment Type: Full-time

We’re hiring a SOC Engineer to join the growing team at Horizon Scope technologies in Baghdad 🇮🇶

🔐 Key Responsibilities:

✔️ SIEM Engineering & management ✔️ Monitoring and responding to security incidents ✔️ SOAR automation & playbook development ✔️ Threat detection & security monitoring ✔️ Incident analysis and response handling ✔️ Improving SOC processes and efficiency

🧠 Requirements:

✔️ Experience with SIEM tools (e.g., Splunk) ✔️ Strong understanding of cybersecurity fundamentals ✔️ Knowledge of TCP/IP, DNS, VPNs, and endpoint security ✔️ Experience with scripting (Python / PowerShell / Bash) is a plus ✔️ Familiarity with SOAR and threat intelligence ✔️ Relevant certifications (CEH, Security+, CISSP, etc.) are a plus

💬 Think you’re a fit? Let’s talk — apply now: https://horizonscope.com/job/soc-engineer-3/

Or you can send your CV to [email protected] with the subject line "SOC Engineer"

#DotJobs #DotJobsIQ #وظائف_العراق #بغداد #SOC #CyberSecurity #SIEM #SOAR #SecurityEngineer #ITJobs #TechJobs #IraqJobs #Hiring #وظائف

C
cissp
@cissp
1.4K

OWASP ASVS 5.0 is officially out.

Application Security is no longer just about finding vulnerabilities. It’s about standardized security verification, Security by Design, and measurable security maturity.

ASVS 5 brings •Better alignment with cloud-native & API-driven architectures •Stronger Authentication & Access Control requirements •More mature verification and governance approach •Better integration into Secure SDLC & DevSecOps

The real problem in many organizations They have security tools, but no standardized way to verify whether an application is actually secure.

ASVS helps close that gap.

A must review framework for: •AppSec Teams •Security Architects •DevSecOps •Banks & FinTechs •API Platforms

— CISO as a Service — Strategic Cyber Defense & GRC Resilient Through Knowledge 2026.05.19

#OWASP #ASVS #AppSec #DevSecOps #SecureByDesign #CyberSecurity #SecureSDLC #ApplicationSecurity

https://www.linkedin.com/posts/alirezaghahrood_owasp-asvs-v5-ugcPost-7462365974600740864-aKiE

D
DeepWeb
@deepwebita
17.5K

⁣⚠️ Texas accende i riflettori sui dispositivi medici cinesi: cresce l’allarme cyber-spionaggio

Negli Stati Uniti, il Texas ha avviato un’indagine su possibili rischi di cybersecurity e spionaggio digitale legati a dispositivi medici prodotti in Cina, dopo una serie di warning federali su vulnerabilità in apparecchi connessi utilizzati negli ospedali. L’attenzione si concentra soprattutto su sistemi di monitoraggio pazienti e dispositivi IoT sanitari potenzialmente esposti a backdoor software o accessi remoti non autorizzati.

Secondo le autorità statali, alcuni dispositivi potrebbero teoricamente consentire la trasmissione di dati sanitari sensibili verso server esterni o essere sfruttati come punto d’ingresso per attacchi alla rete ospedaliera. Il contesto è quello di una crescente preoccupazione per la supply chain tecnologica e per la sicurezza dei dispositivi medici connessi, sempre più integrati con infrastrutture cloud e sistemi digitali complessi.

Esperti di sicurezza evidenziano che il rischio non riguarda solo la privacy dei pazienti, ma anche la possibilità di manipolazione dei dati clinici, con impatti potenzialmente critici su diagnosi e trattamenti. Le agenzie federali USA hanno già emesso avvisi su specifici modelli di patient monitor con vulnerabilità note, spingendo diversi stati a rivedere procurement e policy di sicurezza.

Il caso si inserisce in una più ampia tensione geopolitica tra Stati Uniti e Cina, dove la cybersecurity è ormai diventata un elemento centrale della strategia di sicurezza nazionale.

🔗 Fonte: MD+DI (MDDI Online)

#cybersecurity #medicaldevices #IoT #spionaggio #infosec #supplychain #China #USA #healthtech

✍🏻 @DeepWebITA 👥 @DeepWebITAGroup

D
DocuPlanet
@documentaryplanet
1.2K

Africa can become an important digital power, but only if it builds strong cybersecurity. To keep people’s money and data safe, African countries need their own technologies, shared rules, and trained experts, instead of relying on Western systems like SWIFT.

The invisible war / 2026 #Africa@documentaryplanet

🍿 en.rtdoc.tv | @documentaryplanet | 🚀boost us

D
dotjobs
@dotjobs
2.1K

🚀 We’re Hiring — Network Engineers | Baghdad, Iraq 🇮🇶

Join our growing infrastructure & security team at Supercell and work on enterprise-grade networking environments.

🔹 Senior Network Engineer

Responsibilities:

Design, implement, and maintain network infrastructure (LAN / WAN / Wi-Fi) Configure and manage FortiGate firewalls (Policies, VPNs, NAT, Security Profiles) Manage site-to-site & remote-access VPNs Document network configurations and operational procedures Troubleshoot and optimize network performance & security

Required Skills:

Strong knowledge of TCP/IP, DNS, DHCP, VLANs Experience with routing protocols and network architecture Hands-on FortiGate administration experience

🔹 Junior Network Engineer

Responsibilities:

Support daily network operations (LAN/WAN, VLANs, IP addressing) Assist in troubleshooting connectivity & security issues Support SSL/IPSec VPN setup and maintenance Assist with FortiGate firewall configuration & monitoring

✅ Requirements for Both Roles

Fortinet Certifications Cisco Certifications

📍 Location: Baghdad, Iraq 🏢 Employment Type: Full-time — Onsite

📩 Send your CV to: [email protected]

⚠️ Please mention the job title in the email subject line.

#DotJobs #DotJobsIQ #IraqJobs #BaghdadJobs #NetworkEngineer #Fortinet #Cisco #CyberSecurity #ITJobs #Hiring #TechJobs #وظائف_العراق

C
cissp
@cissp
1.5K

CISO as a Service is not just about managing security tools. It is about aligning cybersecurity with business risk, operational resilience, governance, and strategic decision making.

A mature security program is built on • Visibility • Context • Risk prioritization • Continuous improvement • Executive level accountability🤙🏾

Technology alone does not reduce risk. Governance, architecture, process maturity, and informed leadership do.

#vCISO #CyberSecurity #GRC #RiskManagement #SecurityLeadership #CyberResilience

رویکرد CISO as a Service فقط مدیریت ابزارهای امنیتی نیست. هدف اصلی، همراستا کردن امنیت سایبری با ریسک کسب‌وکار، تاب‌آوری عملیاتی، حاکمیت و تصمیم‌گیری راهبردی است. ‌ یک برنامه امنیتی بالغ بر پایه موارد زیر شکل می‌گیرد • دید و شفافیت واقعی • تحلیل مبتنی بر زمینه • اولویت‌بندی ریسک • بهبود مستمر • پاسخگویی در سطح مدیریت

فناوری به‌تنهایی ریسک را کاهش نمی‌دهد. حاکمیت، معماری صحیح، بلوغ فرایندی و رهبری آگاهانه هستند که امنیت واقعی ایجاد می‌کنند.

#vCISO #امنیت_سایبری #مدیریت_ریسک #حاکمیت_امنیت #تاب_آوری_سایبری

— CISO as a Service — Strategic Cyber Defense & GRC Resilient Through Knowledge 2026.05.15

https://www.linkedin.com/posts/alirezaghahrood_incident-vulnerability-response-playbooks-ugcPost-7461141374130708480-4lYV

D
DeepWeb
@deepwebita
17.8K

⁣🎓 ShinyHunters colpisce il settore education: rubati terabyte di dati da piattaforme scolastiche

Il gruppo cybercriminale ShinyHunters avrebbe sottratto oltre 3,6 TB di dati dalla piattaforma educativa Canvas di Instructure, utilizzata da migliaia di scuole e università nel mondo. Secondo le prime analisi, il breach coinvolgerebbe dati di studenti, docenti e staff, inclusi email, ID scolastici e messaggi privati.

L’attacco ha causato anche disservizi e blocchi della piattaforma durante il periodo degli esami in diversi atenei. Gli esperti avvertono che informazioni di questo tipo possono alimentare campagne di phishing mirato, furti d’identità e ulteriori attacchi contro istituzioni educative già spesso nel mirino del cybercrime.

Il caso conferma la crescente pressione dei gruppi di estorsione digitale contro il settore education, sempre più dipendente da infrastrutture cloud e piattaforme SaaS.

🔗 Fonte: TechCrunch

#cybersecurity #ShinyHunters #databreach #education #infosec #ransomware #hacking #privacy

✍🏻 @DeepWebITA 👥 @DeepWebITAGroup

D
DeepWeb
@deepwebita
15.3K

⁣🌍 Cyberwarfare globale: le tensioni geopolitiche stanno ridefinendo Internet

Le crisi internazionali non si combattono più solo sul piano militare: oggi il cyberspazio è diventato un vero fronte strategico. Secondo il recente Global Cybersecurity Outlook 2026 del World Economic Forum, conflitti geopolitici, AI e frammentazione digitale stanno aumentando il numero di attacchi contro infrastrutture critiche, supply chain e sistemi governativi.

Gli esperti parlano ormai di guerra ibrida, dove campagne di disinformazione, attacchi DDoS, ransomware e operazioni cyber sponsorizzate dagli Stati accompagnano le tensioni internazionali in tempo reale. Anche reti Internet, data center e cavi sottomarini sono diventati asset strategici sempre più esposti a sabotaggi e operazioni offensive.

L’accelerazione dell’intelligenza artificiale sta inoltre rendendo gli attacchi più sofisticati e automatizzati, aumentando il rischio di escalation digitali con impatti concreti su economia, energia, trasporti e sicurezza nazionale.

🔗 Fonte: World Economic Forum

#cybersecurity #geopolitica #cyberwarfare #infosec #AI #cyberattack #digitalsecurity #threatintel

✍🏻 @DeepWebITA 👥 @DeepWebITAGroup

C
cissp
@cissp
1.8K

The CERT Wavestone Incident Response Report confirms something many security teams are already experiencing

Attackers are no longer just trying to get in. They are optimizing for operational paralysis, data theft, and destruction of recovery capability.

Some key findings from the report: • 65% of attacks were financially motivated • 90% of ransomware incidents also targeted backups • 71% involved confirmed data exfiltration • In some cases, the time between intrusion and impact was only 1.5 days • 56% of attacks against large organizations originated through subsidiaries or partners

But perhaps the most important takeaway is this Attack surfaces are no longer limited to firewalls and VPNs.

Cloud/SaaS platforms, APIs, CI/CD pipelines, IAM systems, helpdesks, third-party providers, and even internal operational processes are now part of the modern attack surface.

At the same time: - Vishing and deepfake-enabled social engineering are becoming more convincing - Quishing attacks are increasing rapidly - Software supply chain compromises continue to escalate - AI is now being integrated into malware operations, not just content generation

This report delivers a clear message Cybersecurity is no longer just a technical control problem. Cyber resilience today requires: Visibility + Detection + Governance + Operational Readiness

Organizations that still reduce security to tools and appliances alone will struggle against the speed, scale, and adaptability of modern attacks.

Special Thanks 🙏♥️😇 Gerome Billois Quentin LENOIR

— CISO as a Service — Strategic Cyber Defense & GRC Resilient Through Knowledge 2026.05.08

https://www.linkedin.com/posts/alirezaghahrood_cert-report-20252026-ugcPost-7458552284524802048-OOoy

D
DeepWeb
@deepwebita
19.1K

⁣🕵️‍♂️ Dark Web sempre più accessibile: il cybercrime “on demand” abbassa la soglia d’ingresso

Nel Dark Web il modello Cybercrime-as-a-Service (CaaS) continua a crescere, trasformando attacchi informatici e strumenti offensivi in veri servizi acquistabili online. Secondo diverse analisi di settore, kit di phishing, malware e accessi compromessi possono essere venduti a costi molto bassi, rendendo il cybercrime accessibile anche a utenti con competenze tecniche limitate.

Gli esperti evidenziano come marketplace clandestini e forum underground funzionino ormai con logiche simili a piattaforme e-commerce: supporto clienti, abbonamenti e perfino servizi “chiavi in mano” per campagne ransomware o furto credenziali. Questo modello ha contribuito alla diffusione di attacchi sempre più rapidi e automatizzati contro aziende e utenti privati.

La crescente industrializzazione del cybercrime sta diventando una delle principali sfide per governi e aziende, soprattutto perché abbassa drasticamente la barriera d’ingresso per nuovi attori malevoli.

🔗 Fonte: TechRadar

#cybersecurity #darkweb #cybercrime #infosec #ransomware #hacking #databreach #phishing

✍🏻 @DeepWebITA 👥 @DeepWebITAGroup

I
IT Recruiter {Hello, World} by Nikita Nikolaev
@helloworldagency
1.9K

В неделе доминирует тема окончательного охлаждения IT-рынка труда в России - вакансии падают, конкуренция растёт, правила игры изменились. Собрали главное 👇

📉 IT-рынок труда в России: перегрев закончился, правила изменились По данным hh.ru, число IT-вакансий за год упало на 39%, а количество резюме выросло на 34%. Рынок окончательно перешёл от кандидата к работодателю: конкуренция достигла 11-22 резюме на вакансию. Дефицит специалистов сохранился только в узких нишах - AI и кибербезопасность.

💰 Зарплаты в IT на 17% превышают средние по России По данным hh.ru за I квартал 2026, медианная зарплата в IT составляет 98 147 руб. при общенациональной медиане 83 556 руб. Однако разрыв сужается, а реальные зарплаты внутри IT сильно варьируются по специализациям и уровням. Рост замедлился до околокоротных показателей.

🎯 Карьерные стратегии в IT: стаж больше не гарантирует рост доходов Опрос Инфостарта показал: после 5-7 лет в IT доход перестаёт расти просто от стажа. Побеждают три стратегии - углубление в нишу, расширение компетенций (гибридные профили выходят на 200-300К+) и переход в архитектуру/управление. Осознанный выбор важнее лет опыта.

✈️ Релокантам стало сложнее найти работу в России Доля компаний, готовых нанимать релокантов, сократилась вдвое - с 9% до 4% (данные SuperJob). Конкуренция выросла с 5,1 до 9,6 резюме на вакансию. Работодатели требуют подтверждение налогового резидентства и фокусируются на реализованных кейсах, а не на опыте работы за рубежом.

🤖 Крупные компании открыто связывают сокращения с внедрением AI Amazon, Pinterest и другие крупные работодатели впервые прямо указывают AI как причину увольнений - раньше это маскировали под "оптимизацию". Meta сократила 8 000 сотрудников в рамках AI-поворота. $725 млрд инвестиций в AI-инфраструктуру концентрируются у четырёх компаний, структурно меняя рынок труда.

🐹 Nikita Nikolaev | Quant Scout & HFT Career Coach

አንድሮሜዳ (Sirnhatty)
@andromedainfo
1.1K

📌 Registration Requirements – INSA Cyber Talent Challenge 2026 • Registration must be completed using a National ID (except for foreign nationals). • After completing National ID verification/registration, applicants must proceed to the main portal and complete the application form. • Any Ethiopian citizen aged 11 years and above with talent and passion is eligible to apply. . Registration Deadline ⏰ May 17 • The summer camp will be hosted at the following universities: 1. Addis Ababa Science and Technology University 2. Bahir Dar University 3. Haramaya University  4. Jimma University 5. Debre Berhan University 6. Wolaita Sodo University Preferred Fields/Streams Applicants should demonstrate interest, talent, and passion in areas such as: • Cybersecurity • Software Development • Embedded Systems • Aerospace • Emerging Technologies Selection Criteria Applicants should: • Successfully pass the INSA’s selection test/challenge • Be willing and ready to learn new skills and participate in practical activities • Have strong problem-solving ability and self-learning discipline • Maintain good ethical behavior and discipline ❌ Individuals Not Eligible for Registration 1. Applicants who do not have genuine interest, passion, and talent in Cybersecurity and related technology fields. 2. Individuals who previously participated in the 4-round INSA summer camp/program are not eligible to register again. ⚠️ Important Notice: Submitting fully AI-generated responses in the application form is strictly prohibited. The system only provides a one-time warning and will not tolerate repeated attempts. Continued violations may result in automatic disqualification from the registration process. 🎯 Benefits for Participants Selected participants may gain access to: • Employment opportunities at INSA • Startup and innovation opportunities • Additional training and career development benefits 👉 More information: https://t.me/insactc 👉 Registration Portal: https://ctc.insa.gov.et/registration

D
DeepWeb
@deepwebita
15.3K

⁣🔐 Verifica età UE nel mirino: test di sicurezza rivelano falle nel nuovo sistema digitale

Il nuovo sistema europeo di verifica dell’età online, pensato per proteggere i minori senza condividere dati personali, è stato rapidamente messo alla prova da ricercatori di cybersecurity. Le analisi mostrano che alcune implementazioni dell’app potrebbero essere aggirate in pochi minuti, sfruttando debolezze nella gestione locale di PIN cifrati e nel legame con il vault dell’identità digitale.

Secondo esperti del settore, il problema non è tanto il concetto di base basato su zero-knowledge proof, quanto la sua prima implementazione pratica, che potrebbe esporre a rischi di accesso non autorizzato e bypass dei controlli biometrici. La Commissione UE ha precisato che si tratta di una versione sperimentale e che il codice è aperto proprio per favorire audit e correzioni.

Il caso riapre il dibattito sulla difficoltà di bilanciare privacy dei minori e sicurezza reale dei sistemi di autenticazione su larga scala.

🔗 Fonte: BleepingComputer

#cybersecurity #privacy #UE #infosec #zeroknowledge #dataprotection

✍🏻 @DeepWebITA 👥 @DeepWebITAGroup

R
RED Security
@redsecurity_co
1.4K

Эти пароли злоумышленники взламывают за доли секунды

Несмотря на многочисленные утечки и громкие кейсы взлома, рейтинг самых популярных паролей составляют старые добрые:

123456

admin

12345678

password

Aa123456

qwerty

Список можно смело продолжить другими комбинациями. Пишите ваши варианты «гениальных» паролей в комментариях ⬇️

✨ Во Всемирный день пароля хотим напомнить о прописных истинах: ⚫️минимальная длина от 14 символов

⚫️использование разных регистров, цифр и спецсимволов

⚫️подключение многофакторной аутентификации

⚫️табу на словарные слова, последовательности, имена и названия компаний в парольных фразах

⚫️принцип «один пароль — один сервис»

😊 База базой, но очевидные комбинации до сих пор существуют и хранятся в заметках или стикерах рядом с рабочей техникой ваших сотрудников. А это повод задуматься о развитии культуры кибербезопасности в вашей организации.

↗️ Оценить реальный уровень киберграмотности команды и внедрить полезные практики кибергигиены поможет сервис Security Awareness

C
Cyber Security Jobs
@cybersecurityjobs
3.5K

Splunk Architect VA-Alexandria, I have direct hire onsite Splunk Architect positions at Fort Belvoir, Virginia. The hiring company provides tailored cybersecurity, artificial intelligence, systems engineering services to public and private sectors. Benefits for employees- medical, dental, vision, 401K, flexible spending accounts, short-term and long-term disability, life insurance, vacation and personal leave and additional bene

http://jobview.monster.com/Splunk-Architect-Job-Alexandria-VA-US-293389394.aspx

#US #Splunk Architect

W
WE ARE KILLNET
@wearekillnet_channel
9.1K

😒OverTOR — открытый форум для IT-специалистов и исследователей кибербезопасности. Площадка для обмена знаниями, инструментами в сферах белого хакинга, анализа уязвимостей и автоматизации!

🔥Вступить: https://t.me/OverTOR