2026-06-30 10:44:47
any #cybersecurity people interested in getting into a webserver in order to rescue a dying website?
boosts appreciated :P
#cybersec #infosec
any #cybersecurity people interested in getting into a webserver in order to rescue a dying website?
boosts appreciated :P
#cybersec #infosec
any #cybersecurity people interested in getting into a webserver in order to rescue a dying website?
boosts appreciated :P
#cybersec #infosec
Vibecoding #Malware Fuels a New Wave Of Stealth Attacks
Vibe coding’s dark side, “vibe hacking,” is on the rise. #Cybersecurity companies such as McAfee and Bitdefender have observed recent spikes in vibe-coded malware, also called “
RE: #cybersecurity
I will be at #ICANN86 this coming week in Seville, Spain, speaking on a panel about #cybersecurity and #InternetResilience , moderating a session in the
You should hunt for the MFA-Themed Domains referenced in Palo Alto’s repo:
FQDN - FIRST DATE OBSERVED:
mfaoptions[.]com - 8/26/26
mfa-options[.]com - 8/26/26
mfaregister[.]com - 8/27/26
register-mfa[.]com - 8/27/26
and this one too:
mfa-register[.]com - 8/27/26
#cybersecurity
Proposed changes in the CVE program CNA document
"Update 4.2.6 from SHOULD to MUST: "CNAs MUST assign different CVE IDs to separate Vulnerabilities""
🔗 #cve #vulnerabilitymanagement #cybersecurity
"Aurora ransomware targets ESXi abuses Cursor Agent for exploitation"
#cybersecurity #gambit #AI
RE: #cybersecurity at a company and use Intune to manage your desktop/laptop fleet, propose a project for next year to start managing browser extensions. It’s a fair amount of work to get started, but once under management you can put in place processes for your help desk to handle requests for unallowed extensions.
https://msendpointmgr.com/2025/10/04/taming-browser-extensions-with-intune/
RE: #cybersecurity
A standalone, browser-only HTML/JavaScript application for exploring the MISP threat-actor galaxy, UUID-based relationships across every cluster in the MISP Galaxy repository, and shared MISP Galaxy metadata. Graph rendering is performed by Pivotick.
Source code: #misp #cti #threatintelligence #opensource #threatactor #cybersecurity
RE: #cybersecurity
RE: #cybersecurity
The GCVE Lab is an open space for experimenting with new ideas, tools, formats, and services related to the Global CVE Allocation System initiative.
The lab allows the GCVE community to explore promising concepts without immediately imposing the stability, compatibility, and operational requirements expected from the core GCVE infrastructure.
Open to comments/ideas.
#gcve #cve #cybersecurity
https://discourse.ossbase.org/t/gcve-lab-proposal/1117
https://gcve.eu
@… @…
RE: #cybersecurity
RE: #cybersecurity
GCVE Workshop - 22 September 2026 (14:00-18:00), Luxembourg Before The Vulnopticon Conference
We are pleased to announce a GCVE workshop on 22 September 2026, from 14:00 to 18:00, hosted at the CIRCL/LHC offices in Luxembourg, just before the VulnOpticon conference.
The workshop is free and open to everyone, but registration is required.
🔗 #cve #gcve #luxembourg #cybersecurity #vulnerabilitymanagement
RE: #cybersecurity conference.
RE: #cybersecurity
RE: #cybersecurity
"Our models are now powerful, persistent, and collaborative enough that, absent sufficient safeguards, they can find and exploit security weaknesses across multiple computer systems. Many external models, including open-source ones, will soon reach comparable capabilities."
#Huggingface #OpenAI #Cybersecurity #AI
If you are developing in #Rustlang then you should check this post: #cybersecurity #infosec #supplychain #supplychainattack
RE: #cybersecurity
RE: #cybersecurity
Sightings have long been a major topic of discussion in the CTI community, particularly in the field of vulnerability management. We have now published a GCVE BCP to standardise the format that has been implemented, tested and used operationally in Vulnerability-Lookup for some time.
Thanks to everyone (Cédric Bonhomme, Éireann Leverett, Andras Iklody, Sami Mokaddem and many more) who participated in discussions and worked on the implementation details of sightings over the past several years. These efforts had a strong focus on practical implementation, while BCP-12 specifically addresses sightings in the context of vulnerability management.
BCP-12 is still a draft open for review, but it already provides a strong foundation for existing implementations.
#cve #cra #gcve #vulnerabilitymanagement #cybersecurity #openstandard
GCVE BCP-07, the Known Exploited Vulnerability (KEV) Assertion Format, has been updated to version 2.2. A key addition is the formalisation of the GCVE KEV Directory, a simple machine-readable directory allowing organisations to announce where their KEV catalogues and exploitation assertions are published.
We particularly encourage software and hardware vendors to publish their own KEV catalogues. Vendors are often in the best position to confirm exploitation affecting their products, and publishing this information in a machine-readable form can significantly improve vulnerability prioritisation for users, CSIRTs and vulnerability-management platforms.
For more details #GCVE #GNA #vulnerabilityintelligence #opensource #KEV #cybersecurity
@…
RE: #cybersecurity
Use Defender and Intune? You should be auditing and alerting on high risk administrative actions. Here’s how to do that:
#cybersecurity
Good article on a Gen Digital-discovered #phishing campaign. More reason to block *.workers.dev (Cloudflare) as it is a key link in this campaign’s kill chain #cybersecurity
https://www.gendigital.com/blog/insights/research/the-phishing-link-that-died-on-purpose
A new version of the BCP-11 "Community Contribution Fragments for Existing CVE Records" proposal has been published.
#gcve #cve #cybersecurity #vulnerabilitymanagement
@…
Simple but effective control to help prevent abuse of your business network: disable the remote debugging feature of Chrome and Edge. It disrupts the C2 capabilities described here (but used in other attacks as well)
Look for these settings:
RemoteDebuggingAllowed > Disabled
(Intune: Microsoft Edge > Allow remote debugging)
#cybersecurity
I spent many hours in vulnogram today and to be honest. I'm glad that a colleague started to work on a replacement called vulniverse. Still early beta but it's promising.
#opensource #vulniverse #cybersecurity #cve #gcve
work in progress https://github.com/vulnerability-lookup/vulniverse
RE: #cybersecurity
I just released ptrclassify is a small, dependency-free Python library and CLI that infers likely IP usage from reverse-DNS PTR hostnames.
It is intentionally heuristic and multi-label. PTR naming is operator-controlled and is not authoritative evidence of how an address is actually used. The output therefore includes a confidence score, the text that matched, and the rule IDs that produced each label.
To summarize, the library is trying to guess usage (and a bit location) of an IP address based on its PTR records. It's based on a set of rules which can be updated easily.
#osint #cybersecurity #ptrclassify #opensource #dns
https://github.com/adulau/ptrclassify
module https://pypi.org/project/ptrclassify/
CCWget is a lightweight Python client for searching and retrieving archived web objects from a CIRCL Common Crawl indexing service.
@… did a pretty cool tool to search the Common Crawl. The service is quite resource intensive but if you are a security researcher, you could get access.
#cybersecurity #commoncrawl #cti #threatintel
🔗 https://github.com/ail-project/CCWget
MISP Galaxy Threat Actor Explorer v1.0.0 released
#cti #cybersecurity #misp #threatintelligence #threatintel
@…
If you are curious about (nearly) everything we did the past months at the GCVE.eu initiative:
#gcve #cve #vulnerability #vulnerabilitymanagement #cra #cybersecurity #openstandard #opensource
Recommendations on Naming Threat Actors.
The MISP standard has been updated including the new tracking of naming origin from security vendor.
#cti #threatintelligence #soc #cybersecurity #threatintel
🔗 https://www.misp-standard.org/rfc/threat-actor-naming.html#name-misp-galaxy-threat-actor-na