I want to share a quick thought for people in cyber security. This will be my longest tweet ever.
Iโve spoken to many lately who are having an existential crisis from the constant posts about โthe end of cybersecurity jobs.โ
Yes, things are changing quickly. This is a significant moment for the tech industry. Change can be uncomfortable. But weโve seen cycles like this before.
โข When GitHub and open source took off, people said software engineers would disappear because code was free.
โข When AWS and cloud computing emerged, people said infrastructure jobs would vanish.
โข When fuzzing and SAST tools improved, people said vulnerability research would disappear.
โข Virtualization would eliminate infrastructure jobs.
โข Mobile computing was going to end desktop dev.
โข Exploit mitigations would end exploitability. It didn't.
Each time automation improved, the amount of software grew faster than the automation. It does feel "different" this time as it's explosive.
Some roles will shrink:
โข repetitive pentesting
โข basic vulnerability scanning
โข tier-1 SOC monitoring
But other areas are expanding rapidly:
โข AI system security
โข supply chain security
โข identity architecture
โข autonomous agent security
โข critical infrastructure protection
Historically, every time we eliminate one class of bugs, new classes emerge. Right now people are vibe-coding entire systems, giving AI access to their machines, crossing trust boundaries, and deploying autonomous agents with excessive permissions. The legal and regulatory world is nowhere close to ready.
There will absolutely be new failure modes. Humans are amazing and always adapt, finding new ways to do things.
The worst thing you can do right now is fall into a doom loop.
...and Iโll be honest, I too have felt the "psychological paralysis" a few times thinking, โIs this time different?โ It's especially impactful when it comes from someone I respect in the community. There are certainly unknowns, in an industry where we've become accustomed to predictability.
But... the majority of those reactions are usually driven by social media, not reality. Platforms like X reward engagement, and sensational doom posts spread faster than measured thinking.
If you see something like:
โHoly #$%^! Opus 66.6 just found every bug in Chrome and replaced 50 startups!โ
โฆmute it and move on.
Instead:
Stay curious.
Learn the new technology.
Adapt your skillsets.
Build things.
Weโll get through this transition the same way we always have. If I'm wrong then Sam Altman better be right about UBI! :) I'm sure that if this tweet gets any engagement that I'll get some heat for it, but a good friend of mine reminds me often to focus on what you have control over. I'll revisit this tweet at DEF CON 40!
On-Prem Red Team Week Giveaway!
Win FREE access to:
โข 1 CRTP seat
โข 1 CRTE seat
How to participate:
1. Like & follow us
2. Comment which course youโre interested in and why
3. Repost
Winners will be announced on Jan 30, 2026.
On-Prem Red Team Week is live (28 Jan โ 3 Feb 2026):
โข 15% off on a single purchase
โข 20% off on 2 or more purchases
โข 25% off on 5 or more purchases
(includes extra 5% Early Bird for first 100)
Use code: REDTEAM2026
For more details: https://t.co/EbnixEzhNg
#RedTeam #OnPremSecurity #CyberSecurity #AlteredSecurity
Interesting read on how red teams approach physical security bypasses and what organizations can learn from it. Worth checking out ๐
https://t.co/XSic67Rf4H
#redteam#physicalsecurity
GIVEAWAY!! ๐ฅ
Weโre giving away 1 seat of @AlteredSecurity Certified Evasion Techniques Professional (CETP) โ Evasion Lab. ๐
๐ How to participate:
1๏ธโฃ Like ๐ this post
2๏ธโฃ Repost๐
3๏ธโฃ Comment ๐ฌ what makes it useful to you
4๏ธโฃ Follow @nikhil_mitt & @AlteredSecurity
A random winner will be announced on Monday, 8th September 2025.
๐ https://t.co/jUUjo8gC5M
#EvasionWithAltSec #CETP #AlteredSecurity #RedTeam #Pentesting #InfoSec #CyberSecurity #Giveaway
Did a grey-box pentest on a web app โ all the right controls in place: no IDOR, solid access control, JWT + proper session management.
Funny part? Deleted a user from admin, but that user could still able to login and do everything ๐คฃNever thought this test case would work!
New Android host validation bypass technique!
[1/4] All parsed URIs in Android are https://t.co/x8giXOfU0w.Uri.StringUri objects. However, the scheme parser only looks for the ":" delimiter