Changing direction into cybersecurity is mostly a translation problem: you already have skills, and they need to read as relevant. These 69 free entries help with both halves — the learning and the way you talk about it.
Free, senior-taught software engineering courses built for career acceleration, with pathways in web, mobile, cybersecurity, data, and AI-native applied engineering.
Why I recommend it: I often recommend CodePath to clients breaking into tech or leveling up their engineering skills without taking on bootcamp debt. The courses are rigorous, free, and taught by engineers who actually hire.
A Bronx-based nonprofit offering free tech training and career support in web development, data, design, and cybersecurity for underestimated talent in New York, Newark, and Atlanta.
Why I recommend it: I point career changers who cannot afford a bootcamp toward TKH. The program is community-rooted, employer-connected, and focused on economic mobility.
Free courses and free LinkedIn-ready credentials in AI, cybersecurity, data, and cloud computing.
Why I recommend it: One of the few places where both the training and the credential are free. Stack two or three badges in one lane instead of one badge in four lanes.
IBM's free learning platform for job seekers and students, with courses and credentials in AI, cybersecurity, data analysis, and workplace skills. Registration creates a free IBM SkillsBuild ID.
Why I recommend it: Free, employer-branded credentials from a name recruiters know. Pick one track, finish it, and put the badge on your LinkedIn profile.
Okta's grant program giving people in career transition free access to its Identity and Access Management training catalog, practice tests and certification exam. Aimed at people who are unemployed, veterans moving to civilian work, and IT or cybersecurity students.
Why I recommend it: This is a grant you apply for, not an open course library — places are limited and awarded, and past rounds ran as a three-month subscription. Check the eligibility wording and closing date on Okta's own page before planning around it. The training is Okta's own product, so the certification proves you can run Okta, not identity work in general.
Twelve-month paid apprenticeships in Application Development, Cybersecurity, Data Engineering, and Cloud Engineering. Accenture has scaled apprenticeships into a large share of its entry-level hiring in North America.
In plain terms: This program provides paid, entry-level tech and business apprenticeships with mentorship for job seekers without a four-year degree. You can submit an application to gain hands-on training and work toward a full-time role.
Why I recommend it: Client-facing consulting experience is the differentiator here. It teaches you how to talk to business stakeholders, which pays off for the rest of your career.
A technical learning platform with 60,000+ books, 30,000+ hours of video, live online events, and interactive labs and sandboxes from O'Reilly and nearly 200 other publishers.
Why I recommend it: Check your public library card and any school or employer account before paying — many library systems give full O'Reilly access for free, and some live events are open to anyone.
Barclays' technology internship track for software engineering, cybersecurity, infrastructure and product roles, with details on the programme and application process.
Why I recommend it: Worth applying to even if you picture yourself at a tech company — bank engineering internships pay well and teach you scale and security practices you rarely see elsewhere.
A global tech community that partners with major technology companies to run fully funded certification cohorts — including security and data analytics tracks — alongside mentorship, resume workshops, and access to corporate hiring partners.
Why I recommend it: Sponsored certification vouchers are the practical win here. Join the community first, then watch for cohort announcements.
Grant packages combining $5,000 cash, a year of free internet/voice/cybersecurity service, equipment, a professionally produced TV commercial, coaching, and online entrepreneurship courses. Open to all qualifying small businesses in specific participating metro areas during limited annual application windows.
Why I recommend it: Only open in select cities during short annual windows — check comcastrise.com for current cities and dates.
Certificate covering security frameworks, threat detection, Python for security tasks, SIEM tools, and incident response.
Why I recommend it: A credible on-ramp into security work. Combine it with a free conference or local meetup, because in this field who you talk to opens as many doors as what you studied.
Twelve-month paid apprenticeships with full benefits in Cybersecurity, Software Development, Data Science, Cloud Engineering, and Application Development. IBM built these around "new collar" roles that prioritize skills over diplomas.
In plain terms: This program offers year-long paid apprenticeships with benefits across tech fields like software development and cybersecurity. You can apply for entry-level roles that prioritize your skills rather than a college degree.
Why I recommend it: Application windows open in short rolling bursts, sometimes closing within a day. Set a job alert and follow IBM on LinkedIn so you are not late.
The US government's public library of cybersecurity standards, guidance and publications, including the SP 800 series, project pages, news and events.
From the site: CSRC provides access to NIST's cybersecurity- and information security-related projects, publications, news and events.
Why I recommend it: Free and public, no account needed. This is the primary source behind most security "best practice" advice you will read elsewhere, so cite it directly rather than a blog summarising it.
The US National Security Agency's AI Security Center: published guidance, joint advisories and best-practice sheets on securing AI systems against attack. Free to read and download.
Why I recommend it: Practical, specific security guidance you can hand to a technical team. It is written from a national-security standpoint, so priorities reflect government threat models more than everyday consumer risk.
One of the largest technology staffing and IT services firms in North America, hiring for software, data, cloud, cybersecurity, help desk, and project delivery roles at enterprise clients.
Why I recommend it: If you want tech work at a large company without a referral, TEKsystems is often the actual hiring channel. Keep your resume keyword-clean for their recruiters, and ask directly which clients and rates a req covers before interviewing.
Upcoming cybersecurity conference calendar with virtual and in-person events, dates, locations, and registration links.
From the site: Find cybersecurity conferences happening this week. Virtual & in‑person events. Get dates, locations, and last‑minute registration links now.
Why I recommend it: Useful for staying current on security trends and finding networking events if you are pivoting into cybersecurity, tech policy, or IT operations.
An autonomous AI agent for penetration testing and security research, running through one command-line interface across several major models.
Why I recommend it: If you are moving toward security work, tools like this are what the job looks like now. Learn the agent, but learn the fundamentals it is automating too.
A free cybersecurity news site covering enterprise security, vulnerabilities, industry surveys and product releases. Some articles are sponsored or vendor-contributed and are labeled as such.
Free internet routing lookup tool for exploring Border Gateway Protocol paths, autonomous system numbers, prefixes, and network relationships. Includes a super looking glass and traceroute from distributed probes.
Site and writing of security researcher Marcus Hutchins, known for stopping the WannaCry ransomware attack — malware analysis, security explainers and reflections from an unconventional path into cybersecurity.
Why I recommend it: A strong example of a self-taught technical career — worth following if you are breaking into security without a degree.
Independent, free benchmarks testing leading AI models on real-world finance, software, science and safety tasks, with cost and latency alongside accuracy.
From the site: Private, domain-specific benchmarks in legal, tax, and finance.
Why I recommend it: When someone claims a model is "the best," check here — these are independent evaluations, not vendor marketing.
Annual global study on cybersecurity hiring, skills gaps, budget pressure, and what helps practitioners grow their careers.
Why I recommend it: Details: use the hiring and skills-gap data to decide which security certifications and skills are actually in demand before you spend money on training.
Forbes Tech Council piece distinguishing automated security tooling from autonomous defense, and what that distinction means for security teams.
Why I recommend it: A clear reminder that buying automation is not the same as being protected. Good framing if you are moving into a security or IT role.
Bugcrowd's library of security guides, ebooks, research reports and customer stories, including its Ultimate Guide to AI Security (2026) and Ultimate Guide to Red Teaming. A reasonable free way into how bug bounty and penetration testing programmes actually run.
Why I recommend it: Free, but several downloads ask for your work email and it is a vendor's marketing library, so the conclusion is usually that you need a bug bounty platform. Read it for the vocabulary and process, then check claims against a neutral source.
Free Substack newsletter by a principal cybersecurity engineer sharing career tips and cybersecurity news, including a recurring 14-day U.S. cyber threat forecast (e.g. the September 22, 2026 VECTR-CAST report on actively exploited Cisco, ScreenConnect and VMware vulnerabilities).
Why I recommend it: Good for people moving into cybersecurity who want a practitioner's read on current threats. The threat levels and forecasts are the author's own analysis, not an official CISA rating — cross-check CVEs against the CISA KEV catalog.
Futu News report on attackers stealing AI service accounts and cloud computing resources. Described from its title; the page did not load for automated checks.
Help Net Security summarizes the SANS 2026 threat hunting survey: 50% of respondents named data quality as the top barrier, ahead of skilled staff (45%) and budget (42%). Survey figures are self-reported by practitioners.
A free newsletter and news site for IT professionals from Morning Brew, published four times a week, covering cybersecurity, cloud, hardware, IT operations, software and the practical side of AI adoption inside companies. Stories are short, reported, and written from the perspective of the people who have to run the systems — patching, asset inventories, wi-fi troubleshooting, legacy migration — rather than the vendors selling to them. Also runs free virtual events and digital guides.
Why I recommend it: Free to read on the site and free to subscribe — the subscribe box asks for an email, but nothing is paywalled. This is one of the better free ways to learn the vocabulary of an IT job you have not had yet, because it covers the unglamorous work that interviews actually ask about. Two things to keep in mind: it is ad and sponsor funded, so sponsored posts sit alongside the reporting and you should check the byline and any 'presented by' line; and it is written for people already inside IT departments, so expect jargon on first read.
#ai adoption#career in it#cloud computing#cybersecurity#enterprise technology#hardware#help desk#it operations#newsletter#research#sysadmin
News report on Indian researcher Nisarga Adhikary being listed in the US Department of Justice's security Hall of Fame after reporting a critical flaw.
Why I recommend it: MSN republishes other outlets' stories, and the flaw details come from the researcher himself. I could not open the page, so I wrote this from the title — please check it.
OpenAI's announcement of GPT-6 Astra, its most capable model, with reported results on computer use, browsing, software engineering, cybersecurity, and professional work.
Why I recommend it: Read the capability list as a job-task list. Whatever a model does well this year reshapes entry-level work the next.
Independent cybersecurity and technology news site covering malware, ransomware, data breaches, privacy, and support guides for Windows, Linux and macOS.
From the site: BleepingComputer is a premier destination for cybersecurity news for over 20 years, delivering breaking stories on the latest hacks, malware threats, and how to protect your devices.
Why I recommend it: Free to read and ad-supported. Use it as a practical incident tracker and a source of plain-language security guidance, not as a single source for attribution.
A long-running cybersecurity news site covering breaches, vulnerabilities and, increasingly, AI-related security incidents.
From the site: The Hacker News is the top cybersecurity news platform, delivering real-time updates, threat intelligence, data breach reports, expert analysis, and actionable insights for infosec professionals and decision-makers.
Why I recommend it: Free to read with ads and newsletter prompts. Good for spotting AI security stories early; headlines can be urgent in tone, so check the underlying advisory.
#cybersecurity#news#ai-security#technology
The Hacker NewsAdded Sep 19, 20260 opens
Live events and competitions
Dates you can put in a calendar and meet people at.
A multi-tiered free cybersecurity skills-training scholarship aimed at students and career changers seeking a cybersecurity job within about 1.5 years.
Details: Page describes this as for "WiCyS members" -- confirm whether WiCyS membership itself is free before publishing.
One of the oldest and largest capture-the-flag competitions, designed as an entry-level jeopardy-style CTF for students breaking into security, with a September qualifying round and a November final round. Run by NYU's student security group.
Details: A CTF placement is real, checkable evidence of security skill. Enter the qualifier even if you only solve a couple of challenges.
A free online jeopardy-style capture-the-flag run by Cyber Hacktics with U.S. Air Force veterans for Cybersecurity Awareness Month. 17 October 2026, 14:00 UTC to 19 October 2026, 00:00 UTC.
From the site: DEADFACE CTF features jeopardy-style challenges and is hosted by Cyber Hacktics and veterans of the United States Air...
Details: Beginner-friendly as CTFs go, and a real thing to point at in an interview. Free to play.
Nov 6, 2026 – Nov 7, 2026HKCERT / Hong Kong Productivity CouncilRegister by Oct 20, 2026
Free jeopardy-style capture-the-flag qualifying round from Hong Kong's CERT, with an Open division alongside student categories; top teams advance to an in-person Hong Kong final.
Details: The event page doesn't state a fee explicitly, but HKCERT's CTF has historically been a free, HKPC-backed community competition. Confirm the Open division's eligibility for non-Hong-Kong participants before committing.
A free capture-the-flag run by George Mason University's Competitive Cyber Club, played in teams.
Details: Free to play. The scoreboard shows a start of 11 September 2026 and no published end time, so check the site for the current round before planning around it.
A no-cost SBA webinar on protecting a small business from common cyber threats: the tricks attackers use, simple security steps, and where to get help.
Details: Free, plain-language and aimed at owners rather than IT staff. A sensible hour if nobody at your business owns security.
Nov 6, 2026 – Nov 7, 2026New Jersey Institute of Technology
A free online jeopardy-style capture-the-flag organised by the New Jersey Institute of Technology. 6 November 2026, 17:00 UTC to 7 November 2026, 17:00 UTC.
From the site: REGISTRATION IS NOW AVAILABLE! BOO!! Welcome to SpookyCTF 2026! Organized by the New Jersey Institute of Techno...
Details: Registration is open. A 24-hour format, so it fits into one weekend rather than eating a week.
No. What matters is one piece of finished, visible work plus a clear line about why you are moving. Both are cheaper to build than most people expect.
What should I do in the first month?
Finish one short course or project from the first section, then update how you describe your experience so the new direction is obvious in the first two lines.