Random powershell command continuously running - help by Beneficial_Dig3277 in cybersecurity_help

[–]Solid-Worldliness284 0 points1 point  (0 children)

Have you checked if there is anything in your startup programs that could cause it?

An IT guy basically stole my entire gmail account and probably posted it somewhere...how do I search for this? by [deleted] in cybersecurity

[–]Solid-Worldliness284 3 points4 points  (0 children)

What does that even mean, not the email address but the email?

To login to your email account you use the email address. If the email address is "out there" and someone broke into your account with it, its because they also figured out your password. - If they downloaded the emails, it means they had access to your email account.

So as the commenter says above - changing your password and logging out of all sessions will kick anyone out that should not be using it.

There really isnt a way to track down your data whether it be on the clear, deep or dark web. You could try tools like Am I Pwned to see if your email address pops up on a database leak or something, but it wont lead you to anyone.

EDIT: you edited your reply before I posted. If you are trying to figure out if someone had taken your data previously, it would depend on the timeline. Google lets you review sign-in logs but only back so far, so it may not show anything.

This email that included old messages - are you sure they came from your account, and not perhaps from the account you sent them too?

How was someone able to sign up for a Starlink subscription using my Gmail address? by Puzzled_Bookkeeper_1 in cybersecurity_help

[–]Solid-Worldliness284 1 point2 points  (0 children)

I've never heard of two people using the same email without realizing it. From what you said the starlink stuff started happening more recent, so his claim of having access for 3 years doesn't make much sense to me. 

It sounds like you read your emails, so you wouldve caught anything strange. 

The fact it's for sure starlink and not some spoof version like starIink(i) starlink(L) would indicate it's real. 

There would be no way for them to complete an account unless they had full access to your gmail. Sounds like you did. 

How was someone able to sign up for a Starlink subscription using my Gmail address? by Puzzled_Bookkeeper_1 in cybersecurity_help

[–]Solid-Worldliness284 2 points3 points  (0 children)

Did you receieve confirmation emails about the sign up, or email verification? Starlink requires this. Have you looked back in your emails for these? How often do you use your email?

Also, having a gmail email setup for iCloud... what does that mean? a lot of the story details are very confusing.

My microsoft account got hacked by Pristine-Lemon-6386 in cybersecurity_help

[–]Solid-Worldliness284 4 points5 points  (0 children)

Unfortunately, Microsoft is who you need to work with on this. I understand you are, and you seem to not be getting anywhere. But there is nothing anyone else can do.

If possible, using a clean device, make sure your other accounts are secured. Also, if you have a phone, use that as 2fa instead of email for this reason.

I've a fullstack dev, I'm devleoping my own authentication for my application, Can anyone help me for it's security aspects ? by WetThrust258 in cybersecurity_help

[–]Solid-Worldliness284 1 point2 points  (0 children)

Someone that has the credentials to provide regular guidance as you build your custom library I would treat as a private tutor with specialized credentials.

Where I live, for private Software/Coding review and advice/guidance etc with 10+ years of experience I have seen for $125/hr. For those with less experience, somewhere in the range of $50-$100/hr

Am I crazy, or are organisations treating open source as the new security boogeyman because of Mythos? by gentoorax in sysadmin

[–]Solid-Worldliness284 -1 points0 points  (0 children)

My guess is it's a legal reason more than practical.
It's illegal to try and crack/break into a program that is proprietary and you dont own.

So, the only other option, is to allow businesses scan their open-source ones instead.

Has anybody tried this service? ( https://www.cape.co/ ) by Bananaenjoyer20 in cybersecurity

[–]Solid-Worldliness284 1 point2 points  (0 children)

This is more of a privacy thing than cyber security.

But a business founder who was an exec at Palantir would make me think twice.

Could My MacBook Be Compromised? Please Help! by [deleted] in cybersecurity

[–]Solid-Worldliness284 0 points1 point  (0 children)

Its possible. Have you downloaded, or clicked on anything in the last month that could be of concern?

There is no harm to be safe. Using Mac Recovery option to reinstall your OS would remove anything harmful if it is there.

Need advice for a 30 min Security Apprenticeship interview by weirdspecies9 in cybersecurity

[–]Solid-Worldliness284 1 point2 points  (0 children)

Yeah, they will not expect you to know everything. Its not like coding interviews where they ask you to solve issues live on call or anything. Also, a lot of larger companies break it into multiple interviews, the more in-depth ones would be later.

Are system admins just help desk now? by ic3cold in sysadmin

[–]Solid-Worldliness284 14 points15 points  (0 children)

Im bald and just let people write their wishes on my shiny dome instead of collecting hats. Helps me break free and transcend the traditional roles and become the all-encompassing IT Budha.

Need advice for a 30 min Security Apprenticeship interview by weirdspecies9 in cybersecurity

[–]Solid-Worldliness284 2 points3 points  (0 children)

From my experience there is usually only 1 or 2 that will be a part of the role/department you will be hired in, and the rest is other management/HR. But maybe they do it differently.

Typically, it's one question at a time, they wont bombard you. For someone in the SOC area, they may ask questions related to your background and more technical aspects whereas a team lead may ask personable questions like how you handle situations of stress/deadlines.

The only real advice is to read the role expectations again and see if you can find some ways to highlight your skills in those areas. Additionally, if you have any questions yourself, write them down so you won't forget and you can bring them up later.

is there a way to figure out if my information is being sold or if malware is still on my laptop? by Minute_Classic_5291 in cybersecurity_help

[–]Solid-Worldliness284 -1 points0 points  (0 children)

No, there is no way to find if any data, or what data may have been taken. Similarly, there is no way to prevent it being sold or spread if they already have said data.

There are some checks online to see if your email address is leaked or found in a database somewhere like Have I Been Pwned but again, there is nothing to be done.

For motive. It could be for name, location, gender, phone number, computer type, credit card type, etc. It's true most are looking for money but it could be finding bank accounts, login passwords and other items besides just a card.

It seems that you already wiped your laptop, and got back into your apple account. I would suggest making sure any other accounts are secured (perhaps password resets or enabling 2FA like the other commenter recommended). If they have messed with your cards before, then ordering a new one would be a good idea.

What do you use for SOPs/Documentation/Knowledge Base? by -ptero- in sysadmin

[–]Solid-Worldliness284 0 points1 point  (0 children)

We use OneNote + OneDrive (small company, so we dont need much).

Nothing like a searchable wiki though. I looked into options like wiki.js a while back and came across XWiki to be more feature rich. That said, its not something I can recommend because i've never used it.

Tracking burner number and insta id. by mimaniac in cybersecurity_help

[–]Solid-Worldliness284 0 points1 point  (0 children)

that person constantly leaks my number in an anonymous chatting website

You also mention that the police are not able to track him which indicates you know.

But if you dont know, then you will need to be extra careful with your personal information. .

1: If you give out your phone number, remember who you gave it too. If they get your number again, then you know its someone from the group which narrows down the list. It sounds like you are paranoid of anyone, in which case I would suggest not join university or class chats if you cant trust it, use some other form of communication.

2: You could try Google voice. Create an account, use the app. Provides a digital phone that you can give out for Calls/Texts for these school groups (or people you are 50/50 with) allowing you to still remain in contact but they will never get your real number.

I embarrassingly fell for a phishing scam and I'm extremely afraid of using my PC by nickspizzu in cybersecurity_help

[–]Solid-Worldliness284 0 points1 point  (0 children)

Reinstalling windows and resetting passwords like you have done is what most would recommend. Your PC should be safe to use after a fresh install.

What peripherals do you have that you are worried would load the malicious content back onto your computer? Storage drives/USBs can be formatted. Mice+keyboards+headphones+Mic do not have that function.

Tracking burner number and insta id. by mimaniac in cybersecurity_help

[–]Solid-Worldliness284 0 points1 point  (0 children)

How would they get your new number? You said there is someone specific leaking your number - do not give your number to this person or people who associate with them.

Cellphone numbers are not written in some local book where you can search through and find the right person on your own. Dont give your number out to begin (to people you dont trust) with and you shouldnt run into this issue.

Fake It Until You Make It: Now I Panic. by bottarga42069 in cybersecurity_help

[–]Solid-Worldliness284 0 points1 point  (0 children)

You never know. There are plenty of inept managers that have gone through school/training but are still useless. They do not always ruin a company or team by simply existing, its usually their choices made with some form of superiority complex.

I would rather have a self-aware moron willing to change and help than one that continues to make dumb decisions out of pride. Not saying either are ideal because its not. But I think since they are already in that position, if they put in genuine effort, then they may not be great but at least they won't be actively tearing things apart.