Alexandre Dulaunoy's Avatar

Alexandre Dulaunoy

@adulau.bsky.social

More on fediverse at @adulau@infosec.exchange and @a@paperbay.org Or following @adulau.infosec.exchange.ap.brid.gy or @a.paperbay.org.ap.brid.gy

43 Followers  |  17 Following  |  7 Posts  |  Joined: 27.11.2024  |  1.4401

Latest posts by adulau.bsky.social on Bluesky

Original post on infosec.exchange

Acknowledging Reality in Vulnerability Disclosure.

Every few years, vulnerability disclosure is declared settled. We are told that the ecosystem has matured, that coordinated disclosure is the answer, and that whatever remains outside this model is either irresponsible, obsolete, or simply [โ€ฆ]

08.02.2026 14:57 โ€” ๐Ÿ‘ 1    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
EU Launches GCVE to Track Vulnerabilities Without Relying on US Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread

#Europe launches GCVE to track security vulnerabilities without relying on the US, creating a new independent platform for reporting security flaws in software.

Read: hackread.com/eu-launches-...

#CyberSecurity #InfoSec #Vulnerabilities #EU #GCVE

20.01.2026 16:50 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
GitHub - adulau/the-art-of-pivoting: The Art of Pivoting - Techniques for Intelligence Analysts to Discover New Relationships in a Complex World The Art of Pivoting - Techniques for Intelligence Analysts to Discover New Relationships in a Complex World - adulau/the-art-of-pivoting

The Art of Pivoting - Techniques for Intelligence Analysts to Discover New Relationships in a Complex World

#cybersecurity #cti #threatintelligence #osint #pivoting #threatintel

๐Ÿ”— Source github.com/adulau/the-a...
๐Ÿ”— PDF raw.githubusercontent.com/adulau/the-a...

29.12.2025 21:33 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
GCVE-BCP-02 - Practical Guide to Vulnerability Handling and Disclosure This guide provides actionable recommendations for GCVE GNA, software developers, open source project maintainers, vendors, and organizations to manage vulnerability reports from discovery to resoluti...

GCVE-BCP-02 - Practical Guide to Vulnerability Handling and Disclosure.

version 1.3 published

gcve.eu/bcp/gcve-bcp...

#cve #gcve #cvd #vulnerabilitymanagement

17.12.2025 06:27 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Original post on infosec.exchange

Weโ€™ve published new research from the EU co-funded project NGSOTI: โ€œLearning from large-scale IPv4 blackhole: Behavioral analysis of SNMP trafficโ€.

Over a 12-month period (Nov 2024โ€“Oct 2025), our network telescope captured ~634 million unsolicited SNMP queries from more than 153,000 unique IPv4 [โ€ฆ]

27.11.2025 15:09 โ€” ๐Ÿ‘ 3    ๐Ÿ” 9    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 1
Updated MISP galaxy with more than 480+ UAVs/.

Updated MISP galaxy with more than 480+ UAVs/.

One entry of an UAV in the MISP galaxy.

One entry of an UAV in the MISP galaxy.

The MISP Galaxy now includes an updated knowledge base of UAVs and drones covering both civilian and military models.

It comes with detailed attributes such as manufacturer, cost, and technical specs.
You can now easily classify, model, and share [โ€ฆ]

[Original post on infosec.exchange]

06.11.2025 16:44 โ€” ๐Ÿ‘ 1    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Advancing Vulnerability Tracking and Disclosure Through an Open and Distributed Platform at Unlock Your Bain conference Slides: Advancing Vulnerability Tracking and Disclosure Through an Open and Distributed Platform We presented โ€œAdvancing Vulnerability Tracking and Disclosure Through an Open and Distributed Platf...

We presented โ€œAdvancing Vulnerability Tracking and Disclosure Through an Open and Distributed Platformโ€ at the excellent @uybhys.bsky.social

#cve #vulnerability #opensource #vulnerabilitymanagement #cybersecurity #gcve

๐Ÿ”— www.vulnerability-lookup.org/2025/11/08/u...

09.11.2025 10:31 โ€” ๐Ÿ‘ 6    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image Post image Post image Post image

Gestion des vulnรฉrabilitรฉs par @adulau.bsky.social et C.Bonhomme du #CIRCL๐Ÿ‡ฑ๐Ÿ‡บ ร  #UYBHYS2025, agrรจgent et corrรจlent 27 sources ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ‡จ๐Ÿ‡ณ ๐Ÿ‡ช๐Ÿ‡บ...๐Ÿ‘๐Ÿป
Prรฉdiction par IA de la sรฉvรฉritรฉ ร  partir des descriptions textes ๐Ÿคฉ
#GCVE permet ร  chacun de publier des vulnรฉrabilitรฉs gcve.eu
www.vulnerability-lookup.org

08.11.2025 10:48 โ€” ๐Ÿ‘ 6    ๐Ÿ” 4    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

What might one pay for this amount of excellence? Google suggests to me that $136,365.99 will get you ONE ENTIRE YEAR of the ability to use the product.

17.01.2024 19:56 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

๐Ÿš€ Kunai pushes further integration with MISP!

This week, we've made significant progress in bridging Kunai with @misp to enhance threat intelligence sharing. Our focus has been on developing kunai-to-misp, a new tool available at [โ€ฆ]

[Original post on infosec.exchange]

07.02.2025 10:14 โ€” ๐Ÿ‘ 0    ๐Ÿ” 5    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Original post on infosec.exchange

During the hackathon.lu, we thought about making large datasets available locally to enable participants to conduct experiments or develop new open-source security tools.

A full Common Crawl dataset will be accessible, along with extensive passive DNS dumps.

If you think of a large open [โ€ฆ]

09.02.2025 09:08 โ€” ๐Ÿ‘ 0    ๐Ÿ” 5    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Original post on infosec.exchange

Sonicwall (SonicOS) vulnerabilities.

SonicOS SSLVPN Authentication Bypass Vulnerability. CVE-2024-53704 sounds not very good but the others seem quite critical too.

Bundle created in @vulnerability_lookup from a imgur reference.

๐Ÿ”— [โ€ฆ]

07.01.2025 12:44 โ€” ๐Ÿ‘ 1    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
cvelistv5 - CVE-2023-34990 Vulnerability-Lookup - Fast vulnerability lookup correlation from different sources.

A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specially crafted web requests.

vulnerability.circl.lu/cve/CVE-2023...

#vulnerability #fortinet #cybersecurity

18.12.2024 14:49 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Improving Cybersecurity Impact Taxonomies Personal webpage of Alexandre Dulaunoy - from information security to open source and art

New blog post: Improving Cybersecurity Taxonomies Describing Impact and Cyber Harms Against Organizations

Iโ€™ve introduced a new MISP taxonomy & shared insights into the critical role of impact description in information sharing.

#CyberSecurity #MISP #taxonomies #taxonomy

foo.be/2024/12/Impr...

08.12.2024 13:06 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
cve-2024-53054 withdrawn from NVD but published in GHSA.

cve-2024-53054 withdrawn from NVD but published in GHSA.

Ever wondered what happens to rejected CVEs that still appear in other sources? Tools like vulnerability-lookup highlight these cases...

#vulnerability #cve #cybersecurity #opensource #opendata #linuxkernel

๐Ÿ”— vulnerability.circl.lu/vuln/cve-202...

29.11.2024 09:28 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Alexandre Dulaunoy (@adulau@infosec.exchange) 971 Posts, 2.85K Following, 2.1K Followers ยท Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a@paperbay.org (photography, art and free so...

I'm more using the #fediverse infosec.exchange/@adulau and paperbay.org/@a

27.11.2024 13:36 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@adulau is following 16 prominent accounts