New: warm up Reddit accounts. You own them.
Rankhog
Subreddit guides

r/cybersecurity rules, stats, and what to post

A source-backed Rankhog guide to r/cybersecurity: public rules, community context, posting fit, and startup-promotion risk before you publish.

By Anthony Riera, founder and operator of Rankhog.

Subreddit guides combine public Reddit source URLs, captured rules, visible verification dates, and Rankhog's account-safety workflow.

Current public stats

Members
1,520,304
Verified
September 8, 2026
Category
Technical product and developer communities

Rules can change, so Rankhog keeps verification dates and the original public Reddit sources visible.

Rule summary

  • Read the FAQ before posting: Please read the [FAQ](https://www.reddit.com/r/cybersecurity/wiki/faq) before posting a question, as it may contain the answer you are looking for. Please also check the collections we have, such as the [Breaking In to Cybersecurity](https://www.reddit.com/r/cybersecurity/wiki/faq/breaking_in) FAQ, which contains a *ton* of useful information for people looking to go into cybersecurity! Due to repetition, posts containing questions which are answered in the FAQ will be removed.
  • Must be relevant to cybersecurity professionals: This is a discussion-oriented sub for people who are, or aspire to be, cybersecurity professionals. The rule of thumb we apply is: if professionals would find it insightful or would enjoy insightful discussions around it, then it's appropriate here. Questions about personal or "home" cybersecurity MUST be posted on r/cybersecurity_help or r/techsupport. Memes, "security fails," homework help, etc. historically don't drive conversation, and will generally be removed.
  • No low effort / poor quality posts: This is a community of cybersecurity professionals - the people reading and replying to threads are actual people taking time out of their day. If you aren't putting effort into writing something, why should anyone put effort into reading it? "AI"/machine generated content, whether linked to or posted directly, is explicitly forbidden across this subreddit and will be removed when discovered. Copywritten content, SEO farming, and other slop are similarly forbidden.
  • Security first / no editorializing: This is the guiding principle for all posts. No editorializing and no political agendas. Posts discussing political issues that affect security are fine, but the post must be geared towards the security implication. Such posts will be heavily monitored and comments may be locked as needed.
  • No advertising: Want to share information or resources? Please review these guidelines: https://www.reddit.com/r/cybersecurity/wiki/advertising_guidelines You would rather build a relationship with the /r/CyberSecurity community than get banned! Educational articles or blogs that contain advertisement to a service are to flair their posts with "Corporate Blog." Soliciting DMs/calls/etc instead of posting answers directly has been used by marketers to try to circumvent this rule, and may also result in a ban.
  • No excessive promotion: All promotion (i.e. self-promotion) on this subreddit must be both: * Under 10% of your posts and comments on this subreddit. * Once per week at most per promoted entity. This rule is enforced to curb spam and unwanted promotional posts by non-community-members. We must always be a community member *first*, and self-interested *second*. A full explanation with examples is available on our [wiki](https://www.reddit.com/r/cybersecurity/wiki/rules/promotion).
  • No personally-identifiable information.: Do not post personally-identifiable information, unless the source has consented to it. Moderation staff can and will request proof. Do not request personally identifiable information, or link to sites gating information/articles/documents/etc. and requiring personally identifiable information to proceed. A "free" sign-up to view content requiring your email is not "free as in freedom."
  • Civility: We're all professionals. Be excellent to each other.
  • Ongoing security incidents are to be collated into one thread: During ongoing major incidents - hacks, vulnerabilities, etc - in order to collate all discussion into one area, threads will be locked or removed and discussion redirected to one or few megathreads.

Works well

  • An original writeup of a new threat or vulnerability you discovered, with technical detail and no product pitch.
  • A deep analysis of an emerging attack pattern, shared as a discussion starter rather than a lead magnet.
  • A Corporate Blog flaired post linking to an educational article on your company blog, kept under the 10 percent promotion limit and posted once per week at most.
  • A question about a professional security topic that is not covered in the FAQ, framed to invite insight from other professionals.
  • A contribution to an ongoing incident megathread with useful context or findings.

Avoid

  • Posting questions that are already answered in the FAQ or the Breaking In wiki.
  • Sharing personal or home cybersecurity questions, which belong on r/cybersecurity_help or r/techsupport.
  • Posting AI generated or machine generated content, whether linked or posted directly.
  • Linking to sites that require an email sign up or any personally identifiable information to view content.
  • Editorializing your post or pushing a political agenda rather than focusing on the security implication.
  • Soliciting DMs, calls, or private conversations instead of answering directly in the thread.

What actually works in r/cybersecurity

These are the highest scoring posts Rankhog observed in r/cybersecurity over the past month, with what each one did differently. Rankhog watches this community continuously, so it sees posts when they are published and again as they climb.

  1. Screenshot of a post in r/cybersecurity titled "LG smart TVs caught logging audio with screen off!" with 2.0k upvotes
    Upvotes
    2.0k
    Comments
    188
    Posted
    Sep 7, 2026

    Read the full thread on Reddit

  2. Screenshot of a post in r/cybersecurity titled "CrowdStrike is forcing you to use an AI to open support tickets and it's awful." with 802 upvotes
    Upvotes
    802
    Comments
    139
    Posted
    Sep 9, 2026

    Why it worked

    • Kept short enough to read in one pass

    Read the full thread on Reddit

  3. Screenshot of a post in r/cybersecurity titled "The Berlin Mega-Leak: Inside the Massive 5.26 TB Leak of the City’s Most Sensitive Documents" with 659 upvotes
    Upvotes
    659
    Comments
    34
    Posted
    Sep 4, 2026

    Read the full thread on Reddit

  4. Screenshot of a post in r/cybersecurity titled "Reports: FBI investigates alleged cybersecurity breach at ID verification company" with 398 upvotes
    Upvotes
    398
    Comments
    30
    Posted
    Sep 8, 2026

    Read the full thread on Reddit

  5. Screenshot of a post in r/cybersecurity titled "Someone factored the RSA keys of a Certificate Authority from the 90s" with 363 upvotes
    Upvotes
    363
    Comments
    24
    Posted
    Sep 8, 2026

    Read the full thread on Reddit

  6. Screenshot of a post in r/cybersecurity titled "MITRE Releases List of Top 25 Most Dangerous Software Vulnerabilities" with 341 upvotes
    Upvotes
    341
    Comments
    22
    Posted
    Sep 10, 2026

    Why it worked

    • Short paragraphs rather than one block of text

    Read the full thread on Reddit

  7. Screenshot of a post in r/cybersecurity titled "Someone accidentally logged hundreds of thousands of phone calls to military bases" with 313 upvotes
    Upvotes
    313
    Comments
    16
    Posted
    Sep 5, 2026

    Read the full thread on Reddit

  8. Screenshot of a post in r/cybersecurity titled "ShinyHunters claims breach of Florida DMV, threatens data leak" with 286 upvotes
    Upvotes
    286
    Comments
    21
    Posted
    Sep 8, 2026

    Read the full thread on Reddit

  9. Screenshot of a post in r/cybersecurity titled "FBI cyber leader details bureau’s first unclassified cyber strategy" with 283 upvotes
    Upvotes
    283
    Comments
    72
    Posted
    Sep 10, 2026

    Read the full thread on Reddit

  10. Screenshot of a post in r/cybersecurity titled "153M drivers' licenses exposed on the Dark Web" with 267 upvotes
    Upvotes
    267
    Comments
    18
    Posted
    Sep 4, 2026

    Why it worked

    • Leads with a concrete number

    Read the full thread on Reddit

What r/cybersecurity Is For

This community is for discussing cybersecurity topics, research, and emergent threats or findings. The audience is people who are or aspire to be cybersecurity professionals. The moderators apply a simple test: if professionals would find a post insightful or would enjoy an insightful discussion around it, the post belongs. Personal or home cybersecurity questions do not belong here and must go to r/cybersecurity_help or r/techsupport instead. Memes, security fails, and homework help are also not welcome because they historically do not drive conversation.

Rules That Matter Before Posting

The rules that matter most for a founder are Must be relevant to cybersecurity professionals, No low effort / poor quality posts, No advertising, and No excessive promotion. The No low effort / poor quality posts rule is the one that bans AI generated content outright, so anything machine written will be removed. The No advertising rule points you to their advertising guidelines and requires a Corporate Blog flair for educational articles that advertise a service. The No excessive promotion rule sets a hard limit: under 10 percent of your posts and comments here, and once per week at most per promoted entity. The No personally-identifiable information rule also matters because it bans linking to sites that require an email sign up to view content.

What To Post

A good post here is a genuinely insightful piece of security research, analysis, or discussion that a working professional would find valuable. If you are a founder with a cybersecurity product, the safest entry is to share original research or a technical breakdown that stands on its own merit, not a product pitch. If your content lives on a corporate blog that also advertises a service, you must flair the post as Corporate Blog. Keep your self promotion under 10 percent of your total activity in this subreddit and promote any single entity at most once per week. Everything you share should be freely accessible with no email gate or sign up wall, because the No personally-identifiable information rule treats email gated content as a violation.

What To Avoid

Avoid anything that is already answered in the FAQ, because those posts will be removed. Avoid personal or home security questions, memes, security fails, and homework help. Avoid AI generated content entirely, whether you post it directly or link to it. Avoid editorializing or pushing a political agenda, and if you discuss a political issue, keep it focused on the security implication. Avoid advertising without reviewing the advertising guidelines first, and never solicit DMs or calls instead of answering in the thread. Avoid exceeding the 10 percent self promotion limit or promoting the same entity more than once per week. Avoid linking to sites that require an email or any personally identifiable information to view content. During a major ongoing incident, avoid creating a standalone thread and look for the megathread instead.

Use Rankhog before posting in r/cybersecurity

Want the version that does not run out? Subscribers get unlimited tool runs and more careful checks before posting.

Get my free Reddit SEO audit

Start your 3-day free trial. Card required. $99/month after trial. Next, connect a verified Reddit account; no strategy starts until you explicitly start Rankhog.

Common questions about r/cybersecurity

Can I promote my cybersecurity product or blog here?

Yes, but it is conditional. Your self promotion must be under 10 percent of your total posts and comments here, and you may promote a given entity at most once per week. You also need to review the advertising guidelines linked in the rules.

Can I post content written by AI?

No. The rules explicitly forbid AI and machine generated content across the subreddit, whether linked or posted directly.

Can I link to a gated article that requires an email to read?

No. The rules say a free sign up requiring your email is not truly free, and linking to such sites is not allowed.

Can I ask a beginner question about getting into cybersecurity?

No. Personal or home cybersecurity questions must go to r/cybersecurity_help or r/techsupport instead.

What happens during a major ongoing security incident?

If it is a hack, vulnerability, or other major incident, moderators may lock or remove individual threads and redirect discussion to a megathread. Check for an existing megathread before posting.

Related subreddit guides