2026-07-26 16:12:05
RE: #cybersecurity
RE: #cybersecurity
"Aurora ransomware targets ESXi abuses Cursor Agent for exploitation"
#cybersecurity #gambit #AI
The GCVE Lab is an open space for experimenting with new ideas, tools, formats, and services related to the Global CVE Allocation System initiative.
The lab allows the GCVE community to explore promising concepts without immediately imposing the stability, compatibility, and operational requirements expected from the core GCVE infrastructure.
Open to comments/ideas.
#gcve #cve #cybersecurity
https://discourse.ossbase.org/t/gcve-lab-proposal/1117
https://gcve.eu
@… @…
I will be at #ICANN86 this coming week in Seville, Spain, speaking on a panel about #cybersecurity and #InternetResilience , moderating a session in the
Vibecoding #Malware Fuels a New Wave Of Stealth Attacks
Vibe coding’s dark side, “vibe hacking,” is on the rise. #Cybersecurity companies such as McAfee and Bitdefender have observed recent spikes in vibe-coded malware, also called “
any #cybersecurity people interested in getting into a webserver in order to rescue a dying website?
boosts appreciated :P
#cybersec #infosec
any #cybersecurity people interested in getting into a webserver in order to rescue a dying website?
boosts appreciated :P
#cybersec #infosec
RE: #cybersecurity
"Our models are now powerful, persistent, and collaborative enough that, absent sufficient safeguards, they can find and exploit security weaknesses across multiple computer systems. Many external models, including open-source ones, will soon reach comparable capabilities."
#Huggingface #OpenAI #Cybersecurity #AI
Use Defender and Intune? You should be auditing and alerting on high risk administrative actions. Here’s how to do that:
#cybersecurity
Simple but effective control to help prevent abuse of your business network: disable the remote debugging feature of Chrome and Edge. It disrupts the C2 capabilities described here (but used in other attacks as well)
Look for these settings:
RemoteDebuggingAllowed > Disabled
(Intune: Microsoft Edge > Allow remote debugging)
#cybersecurity
I spent many hours in vulnogram today and to be honest. I'm glad that a colleague started to work on a replacement called vulniverse. Still early beta but it's promising.
#opensource #vulniverse #cybersecurity #cve #gcve
work in progress https://github.com/vulnerability-lookup/vulniverse
If you are developing in #Rustlang then you should check this post: #cybersecurity #infosec #supplychain #supplychainattack
Good article on a Gen Digital-discovered #phishing campaign. More reason to block *.workers.dev (Cloudflare) as it is a key link in this campaign’s kill chain #cybersecurity
https://www.gendigital.com/blog/insights/research/the-phishing-link-that-died-on-purpose
I just released ptrclassify is a small, dependency-free Python library and CLI that infers likely IP usage from reverse-DNS PTR hostnames.
It is intentionally heuristic and multi-label. PTR naming is operator-controlled and is not authoritative evidence of how an address is actually used. The output therefore includes a confidence score, the text that matched, and the rule IDs that produced each label.
To summarize, the library is trying to guess usage (and a bit location) of an IP address based on its PTR records. It's based on a set of rules which can be updated easily.
#osint #cybersecurity #ptrclassify #opensource #dns
https://github.com/adulau/ptrclassify
module https://pypi.org/project/ptrclassify/
RE: #cybersecurity
CCWget is a lightweight Python client for searching and retrieving archived web objects from a CIRCL Common Crawl indexing service.
@… did a pretty cool tool to search the Common Crawl. The service is quite resource intensive but if you are a security researcher, you could get access.
#cybersecurity #commoncrawl #cti #threatintel
🔗 https://github.com/ail-project/CCWget
RE: #cybersecurity conference.
RE: #cybersecurity
RE: #cybersecurity
RE: #cybersecurity
RE: #cybersecurity
RE: #cybersecurity
MISP Galaxy Threat Actor Explorer v1.0.0 released
#cti #cybersecurity #misp #threatintelligence #threatintel
@…
If you are curious about (nearly) everything we did the past months at the GCVE.eu initiative:
#gcve #cve #vulnerability #vulnerabilitymanagement #cra #cybersecurity #openstandard #opensource
Recommendations on Naming Threat Actors.
The MISP standard has been updated including the new tracking of naming origin from security vendor.
#cti #threatintelligence #soc #cybersecurity #threatintel
🔗 https://www.misp-standard.org/rfc/threat-actor-naming.html#name-misp-galaxy-threat-actor-na
A standalone, browser-only HTML/JavaScript application for exploring the MISP threat-actor galaxy, UUID-based relationships across every cluster in the MISP Galaxy repository, and shared MISP Galaxy metadata. Graph rendering is performed by Pivotick.
Source code: #misp #cti #threatintelligence #opensource #threatactor #cybersecurity
Sightings have long been a major topic of discussion in the CTI community, particularly in the field of vulnerability management. We have now published a GCVE BCP to standardise the format that has been implemented, tested and used operationally in Vulnerability-Lookup for some time.
Thanks to everyone (Cédric Bonhomme, Éireann Leverett, Andras Iklody, Sami Mokaddem and many more) who participated in discussions and worked on the implementation details of sightings over the past several years. These efforts had a strong focus on practical implementation, while BCP-12 specifically addresses sightings in the context of vulnerability management.
BCP-12 is still a draft open for review, but it already provides a strong foundation for existing implementations.
#cve #cra #gcve #vulnerabilitymanagement #cybersecurity #openstandard
A new version of the BCP-11 "Community Contribution Fragments for Existing CVE Records" proposal has been published.
#gcve #cve #cybersecurity #vulnerabilitymanagement
@…