Tootfinder

Opt-in global Mastodon full text search. Join the index!

@deepthoughts10@infosec.exchange
2026-07-26 16:12:05

RE: #cybersecurity

@ErikJonker@mastodon.social
2026-08-27 11:40:13

"Aurora ransomware targets ESXi abuses Cursor Agent for exploitation"
#cybersecurity #gambit #AI

@pixelpusher220@dmv.community
2026-07-26 20:20:12

RE: #DataBreach #CyberSecurity

@adulau@infosec.exchange
2026-07-26 09:40:01

The GCVE Lab is an open space for experimenting with new ideas, tools, formats, and services related to the Global CVE Allocation System initiative.
The lab allows the GCVE community to explore promising concepts without immediately imposing the stability, compatibility, and operational requirements expected from the core GCVE infrastructure.
Open to comments/ideas.
#gcve #cve #cybersecurity
discourse.ossbase.org/t/gcve-l
gcve.eu
@… @…

@danyork@mastodon.social
2026-06-05 09:54:40

I will be at #ICANN86 this coming week in Seville, Spain, speaking on a panel about #cybersecurity and #InternetResilience , moderating a session in the

@kubikpixel@chaos.social
2026-06-29 14:05:06

Vibecoding #Malware Fuels a New Wave Of Stealth Attacks
Vibe coding’s dark side, “vibe hacking,” is on the rise. #Cybersecurity companies such as McAfee and Bitdefender have observed recent spikes in vibe-coded malware, also called “

@groupnebula563@mastodon.social
2026-06-30 10:44:47

any #cybersecurity people interested in getting into a webserver in order to rescue a dying website?
boosts appreciated :P
#cybersec #infosec

@GroupNebula563@mastodon.social
2026-06-30 10:44:47

any #cybersecurity people interested in getting into a webserver in order to rescue a dying website?
boosts appreciated :P
#cybersec #infosec

@deepthoughts10@infosec.exchange
2026-08-24 12:54:24

RE: #cybersecurity

@ErikJonker@mastodon.social
2026-08-27 13:01:44

"Our models are now powerful, persistent, and collaborative enough that, absent sufficient safeguards, they can find and exploit security weaknesses across multiple computer systems. Many external models, including open-source ones, will soon reach comparable capabilities."
#Huggingface #OpenAI #Cybersecurity #AI

@deepthoughts10@infosec.exchange
2026-08-21 04:04:30

Use Defender and Intune? You should be auditing and alerting on high risk administrative actions. Here’s how to do that:
#cybersecurity

@deepthoughts10@infosec.exchange
2026-08-19 13:04:59

Simple but effective control to help prevent abuse of your business network: disable the remote debugging feature of Chrome and Edge. It disrupts the C2 capabilities described here (but used in other attacks as well)
Look for these settings:
RemoteDebuggingAllowed > Disabled
(Intune: Microsoft Edge > Allow remote debugging)
#cybersecurity

@adulau@infosec.exchange
2026-08-24 20:00:49

I spent many hours in vulnogram today and to be honest. I'm glad that a colleague started to work on a replacement called vulniverse. Still early beta but it's promising.
#opensource #vulniverse #cybersecurity #cve #gcve
:github: work in progress github.com/vulnerability-looku

@castarco@hachyderm.io
2026-08-20 18:40:54

If you are developing in #Rustlang then you should check this post: #cybersecurity #infosec #supplychain #supplychainattack

@deepthoughts10@infosec.exchange
2026-08-19 03:41:49

Good article on a Gen Digital-discovered #phishing campaign. More reason to block *.workers.dev (Cloudflare) as it is a key link in this campaign’s kill chain #cybersecurity
gendigital.com/blog/insights/r

@adulau@infosec.exchange
2026-08-23 09:56:48

I just released ptrclassify is a small, dependency-free Python library and CLI that infers likely IP usage from reverse-DNS PTR hostnames.
It is intentionally heuristic and multi-label. PTR naming is operator-controlled and is not authoritative evidence of how an address is actually used. The output therefore includes a confidence score, the text that matched, and the rule IDs that produced each label.
To summarize, the library is trying to guess usage (and a bit location) of an IP address based on its PTR records. It's based on a set of rules which can be updated easily.
#osint #cybersecurity #ptrclassify #opensource #dns
:github: github.com/adulau/ptrclassify
:python: module pypi.org/project/ptrclassify/

@deepthoughts10@infosec.exchange
2026-08-12 04:40:50

RE: #cybersecurity #blueteam #ransomware

@deepthoughts10@infosec.exchange
2026-08-04 22:56:12

RE: #cybersecurity

@adulau@infosec.exchange
2026-08-18 20:15:06

CCWget is a lightweight Python client for searching and retrieving archived web objects from a CIRCL Common Crawl indexing service.
@… did a pretty cool tool to search the Common Crawl. The service is quite resource intensive but if you are a security researcher, you could get access.
#cybersecurity #commoncrawl #cti #threatintel
🔗 github.com/ail-project/CCWget

@deepthoughts10@infosec.exchange
2026-07-28 12:42:37

RE: #cybersecurity conference.

@deepthoughts10@infosec.exchange
2026-07-28 22:42:52

RE: #cybersecurity

@deepthoughts10@infosec.exchange
2026-07-28 22:18:07

RE: #cybersecurity

@deepthoughts10@infosec.exchange
2026-07-28 12:46:06

RE: #cybersecurity

@deepthoughts10@infosec.exchange
2026-07-28 12:53:55

RE: #cybersecurity

@deepthoughts10@infosec.exchange
2026-07-28 13:00:09

RE: #cybersecurity

@adulau@infosec.exchange
2026-08-04 20:30:25

MISP Galaxy Threat Actor Explorer v1.0.0 released
#cti #cybersecurity #misp #threatintelligence #threatintel
@…

@adulau@infosec.exchange
2026-08-13 15:21:01

If you are curious about (nearly) everything we did the past months at the GCVE.eu initiative:
#gcve #cve #vulnerability #vulnerabilitymanagement #cra #cybersecurity #openstandard #opensource

@adulau@infosec.exchange
2026-08-06 20:46:11

Recommendations on Naming Threat Actors.
The MISP standard has been updated including the new tracking of naming origin from security vendor.
#cti #threatintelligence #soc #cybersecurity #threatintel
🔗 misp-standard.org/rfc/threat-a

@adulau@infosec.exchange
2026-08-03 17:34:45

A standalone, browser-only HTML/JavaScript application for exploring the MISP threat-actor galaxy, UUID-based relationships across every cluster in the MISP Galaxy repository, and shared MISP Galaxy metadata. Graph rendering is performed by Pivotick.
Source code: #misp #cti #threatintelligence #opensource #threatactor #cybersecurity

@adulau@infosec.exchange
2026-08-01 08:20:08

Sightings have long been a major topic of discussion in the CTI community, particularly in the field of vulnerability management. We have now published a GCVE BCP to standardise the format that has been implemented, tested and used operationally in Vulnerability-Lookup for some time.
Thanks to everyone (Cédric Bonhomme, Éireann Leverett, Andras Iklody, Sami Mokaddem and many more) who participated in discussions and worked on the implementation details of sightings over the past several years. These efforts had a strong focus on practical implementation, while BCP-12 specifically addresses sightings in the context of vulnerability management.
BCP-12 is still a draft open for review, but it already provides a strong foundation for existing implementations.
#cve #cra #gcve #vulnerabilitymanagement #cybersecurity #openstandard

@adulau@infosec.exchange
2026-07-30 06:14:45

A new version of the BCP-11 "Community Contribution Fragments for Existing CVE Records" proposal has been published.
#gcve #cve #cybersecurity #vulnerabilitymanagement
@…