October 1, 2026
30 Days of Cybersecurity: My Hacktober Learning Challenge
October is here, and I am turning it into a month dedicated to cybersecurity.

By Shamita
2 min read
For the next 30 days, I am taking on a simple challenge:
Learn. Practice. Document. Build. Repeat.
Rather than treating cybersecurity as something that can be learned by simply reading definitions and watching tutorials, I want to use this month to explore the concepts behind the field and, wherever possible, put them into practice through labs, experiments, small exercises, and projects.
This is Day 1.
Why 30 Days of Cybersecurity?
Cybersecurity is a field where knowing the terminology is only the beginning.
It is easy to recognize terms such as phishing, SQL injection, encryption, SIEM, DNS, threat modeling, or ransomware. The harder and more valuable part is understanding what happens underneath these concepts.
Why does an attack work?
What makes a system vulnerable?
How can the vulnerability be detected?
What does exploitation actually look like in a controlled environment?
And, most importantly, how can the problem be prevented?
These are the questions I want to explore throughout October.
I also want this challenge to be a record of my learning rather than a collection of isolated posts. Each topic will build on the previous ones, gradually moving from fundamental concepts toward practical security topics.
What I Will Cover
Over the next 30 days, I will explore several areas of cybersecurity.
I will start with fundamentals such as the CIA Triad, authentication, password security, networking, DNS, HTTP, and Linux.
From there, I will move into areas such as OSINT, web application security, SQL injection, XSS, CSRF, access control, cryptography, and malware.
The final part of the month will focus more on defensive security and practical security operations, including incident response, SIEM, log analysis, threat modeling, and cloud security.
The month will conclude with something equally important: reflecting on what I learned and how I can turn that knowledge into a stronger cybersecurity portfolio.
What I Hope to Gain
At the end of these 30 days, I do not expect to become an expert in cybersecurity.
That would be an unrealistic goal.
Instead, I want to achieve three things.
First, I want to strengthen my fundamentals. Cybersecurity is built on understanding systems, networks, applications, operating systems, and users. A strong foundation matters regardless of which security specialization I eventually pursue.
Second, I want to become better at learning independently. Security changes constantly, so being able to investigate an unfamiliar technology, understand a vulnerability, test an idea, and document the results is a skill in itself.
Finally, I want to create something tangible from the month.
By October 31, I want this series to represent more than 30 published articles. I want it to contain a collection of notes, practical exercises, experiments, diagrams, and lessons that I can look back on and build upon.
The 30-Day Roadmap
The journey will roughly follow this progression:
Days 1โ6: Cybersecurity fundamentals and the human element
Days 7โ11: Networking, web communication, DNS, ports, and Linux
Days 12โ14: OSINT, digital footprints, and web security
Days 15โ18: Common web vulnerabilities and access control
Days 19โ21: Encryption, cryptography, and digital signatures
Days 22โ24: Malware, ransomware, and incident response
Days 25โ28: SIEM, security logs, threat modeling, and cloud security
Days 29โ30: Career development, portfolio building, and reflection
The topics may evolve as I work through them. If an experiment leads to an interesting question, I would rather investigate it properly than force the series to follow a rigid checklist.