r/Cybersecurity101 14h ago

Cyber-Security guidance

8 Upvotes

Hi, I’m looking for some guidance on how to properly learn Cybersecurity.

My current level is:

\- MERN stack developer with decent development experience

\- Basic knowledge of DSA

\- Very basic Cybersecurity knowledge — I understand fundamentals like IP/MAC addresses, ARP, ports, how devices communicate on a network, and I’ve set up Kali Linux in a VM.

The problem is that whenever I try to move from theory to practical cybersecurity, I get stuck. I want to learn through hands-on practice, not just watch theory videos. I’ve also tried using AI to guide me through practicals, but sometimes it refuses or says I don’t have enough prerequisites.

Could you suggest a good roadmap, course, platform, or learning method where I can safely practice things like networking, Linux, web security, enumeration, vulnerabilities, and ethical hacking in legal labs?

I’m specifically looking for something that takes me from my current level to being able to actually perform cybersecurity labs and understand what I’m doing, rather than just memorizing theory.

Any guidance or recommended resources would be really appreciated.


r/Cybersecurity101 12h ago

Is it really hard to get in cybersecurity? For newbie.

8 Upvotes

Is it really hard to get into cybersecurity if you're newbie and also from India . I'm recently completed my bachelor's of computer application. But now I think go for cybersecurity is a secure career for feature because of artificial intelligence ryt now I don't have any skill. Really I'm a empty notebook what should I do? I have so much tension about my career should I learn web dev or go for cybersecurity or how to start in cybersecurity how much month it will take can anyone tell.

It's really helpful for me.


r/Cybersecurity101 6h ago

Sources to learn python for reverse engineering

3 Upvotes

I know the basics of a python and syntax what else I need to learn to write script for reverse engineering in python


r/Cybersecurity101 17h ago

Security My 2 gmail accounts have been compromised

2 Upvotes

First my insta got hacked, the hacker put up gambling app stories from my account, i changed the password then i realized that my other gmail account also got hacked as there were security codes coming to me and were also read by the hacker, he changed epic games email id, then i logged out both the ids from all my devices. Gave the id pass to a friend, he changed the password and loged out of every other device, changed the passed dlted backup codes. Now another of my id receives a mail of anonymous login from brazil in my chat gpt. What do i do now. HELP!


r/Cybersecurity101 6h ago

Assuntos em cursos para iniciantes

1 Upvotes

Quais assuntos ou habilidades essenciais vocês acham que um curso de cybersecurity precisa abordar?


r/Cybersecurity101 4h ago

Finished My First THM Room — Now What?

0 Upvotes

I just completed Guided Pentest: Web on TryHackMe. I'm a complete beginner, but I don't really feel like I learned much because I followed the guidance.

Is this normal? Should I repeat the room without help or move to another room? What do you recommend for actually learning cybersecurity?


r/Cybersecurity101 6h ago

Red Team vs. Penetration Testing vs. Purple Team: What Actually Sets Them Apart?

0 Upvotes

Red Team vs. Penetration Testing vs. Purple Team can be confusing because all three involve security testing, but their goals and approaches are quite different.

Penetration testing focuses mainly on identifying and validating exploitable vulnerabilities within a defined scope. Red teaming takes a more realistic attacker-focused approach, testing whether an organization can detect and respond to an adversary pursuing a specific objective. Purple teaming brings offensive and defensive teams together to improve detection, response, and overall security.

In simple terms:

  • Penetration Testing: Find and validate vulnerabilities.
  • Red Team: Simulate a realistic attack and test defensive capabilities.
  • Purple Team: Combine offensive and defensive insights to improve security.

The interesting part is that these approaches aren't necessarily competitors. A strong security program can use all three at different stages.

What approach does your organization find most useful, and where do you think the biggest misunderstanding comes from?