Did you know that since v3.0.0 of misp-modules and v3.0.1 of misp-docker/misp-modules it is possible to load custom misp-modules without building your own image? Just drop them in the corresponding /custom/ directory.
github.com/MISP/misp-do...
github.com/MISP/misp-do...
11.03.2025 20:51 β π 0 π 0 π¬ 0 π 0
#homeoffice
14.02.2025 07:46 β π 0 π 0 π¬ 0 π 0
Vulnerability in Billion Electric Router - Use of Hard-coded Credentials. vulnerability.circl.lu/vuln/CVE-202... CVE-2025-1143 ; routers typically used in an industrial environment. #cve #ics
11.02.2025 08:30 β π 0 π 0 π¬ 0 π 0
If youβre using @letsencrypt.bsky.social certificates it becomes time to setup a certificate expiration monitor (if you havenβt done already).
04.02.2025 10:28 β π 0 π 0 π¬ 0 π 0
Well done to all at @europol-eu.bsky.social and other law enforcement agencies involved in this operation. Two online forums allegedly providing a range of cybercriminal services were taken offline resulting in 2 suspects arrested so far.
www.europol.europa.eu/media-press/...
#cybercrime
30.01.2025 13:35 β π 4 π 2 π¬ 0 π 0
PlushDaemon compromises supply chain of Korean VPN service (IPany) by @esetresearch.bsky.social www.welivesecurity.com/en/eset-rese... #CTI
27.01.2025 06:54 β π 0 π 0 π¬ 0 π 0
We are sharing backdoored Ivanti Connect Secure devices that *may* have been compromised as part of a CVE-2025-0282 exploitation campaign (but also we believe may include older or other activity).
379 new backdoored instances found on 2025-01-22:
dashboard.shadowserver.org/statistics/c...
23.01.2025 20:07 β π 8 π 4 π¬ 1 π 0
Need to analyse Windows DNS server logs? Extract hostnames & domains from the DNS server analytical logs, save them to CSVs, and check against @mispproject.bsky.social , all without centralised DNS logging. A quick win for investigations! github.com/cudeso/tools... #cti #automation #itsalwaysdns
23.01.2025 11:21 β π 1 π 1 π¬ 0 π 0
A quick parser to extract whois and country data from the darkweb forum post listing #Fortinet devices victim (?) to CVE-2022-40684.
Parser at github .com/cudeso/tools/blob/master/CVE-2022-40684/README.md
Affected (?) IPs at github.com/arsolutioner...
16.01.2025 15:54 β π 0 π 0 π¬ 0 π 0
Examples of threat actor names to use and to avoid
MISP has introduced a new Threat Actor Naming Standard
www.misp-standard.org/blog/Naming-...
02.01.2025 15:18 β π 18 π 10 π¬ 1 π 3
YouTube video by FIRST
Automating Cyber Threat Intelligence: A Practical Approach to Managing Emerging Vulnerabilities
Watched @datadoghq.bsky.social talk at @firstdotorg.bsky.social CTI on "Automating Cyber Threat Intelligence" www.youtube.com/watch?v=t8M3... Great tips on streamlining vulnerability classification, gather abuse data, and report it to customers. Also check HASH github.com/datadog/HASH #cti
02.01.2025 11:30 β π 2 π 1 π¬ 0 π 0
YouTube video by FIRST
Vulnerability Coordination in the EU
Presentation by ENISA on "Vulnerability Coordination in the EU" during the @firstdotorg.bsky.social VulnCon www.youtube.com/watch?v=MY0W... #CVD #CVE #responsibledisclosure #vulnerability
02.01.2025 10:29 β π 0 π 0 π¬ 0 π 0
MISP Tip of the Week
A collection of tips for using MISP.
Itβs been a while since I posted a new @mispproject.bsky.social tip, but in the meantime you can now also enjoy the tips via a simple HTML page at cudeso.github.io/misp-tip-of-...
11.12.2024 18:25 β π 0 π 0 π¬ 0 π 0
The NCA reports on βOperation Destabilise', exposes and disrupts a Russian money laundering network. MO consists of, ao., collecting funds in one country and make the equivalent value available in another, often by swapping cryptocurrency for cash.
www.nationalcrimeagency.gov.uk/news/operati...
06.12.2024 21:42 β π 0 π 0 π¬ 0 π 0
YouTube video by Virus Bulletin
Reviewing 2022 KA SAT incident & implications for distributed communication environments -Joe Slowik
Remember the wiper attack against KA-SAT/Viasat during Russia's invasion of Ukraine? Joe (@pylos.co) provides a great overview of this campaign. The talk also covers alignment with #Sandworm, a little-known DHCP DoS attack and risks with satellite comms for ICS/SCADA.
youtu.be/0a-qza6YSZA
04.12.2024 09:51 β π 4 π 4 π¬ 0 π 0
MISP playbooks
MISP Playbooks
You can now browse the @mispproject.bsky.social playbooks on GitHub Pages: misp.github.io/misp-playboo... . The playbooks are automatically converted into easy-to-navigate HTML pages. Dive in and explore!
03.12.2024 13:34 β π 2 π 2 π¬ 0 π 0
Reverse engineer / malware analyst. On the hunt for domain generation algorithms.
We build software for cyber #threatintelligence analysts.
https://www.dogesec.com/
π π Unique collaborative ecosystem & program for promoting the Transatlantic cooperation for Next Generation Internet technologies πͺπΊ πΊπΈ π¨π¦
Funded by #HorizonEurope - @ngi4eu.bsky.social
π ngisargasso.eu
Cybersecurity Researcher and Assist Prof in ΔVUT University. Machine Learning. AI. Detection with IDS/IPS in the network. Reinforcement Learning. Agents. Attacking/Defending. DNS. VPNs. Honeypots. Malware analysis.
Co-leader OWASP Cornucopia. If you like what we do for open source, visit our code repository https://github.com/OWASP/cornucopia and give us a star β
π Β«Difference is of the essence of humanityΒ» π¦ β John Hume
#appsec #owasp #cornucopia #threatmodeling
Astrophotographer, Flight Simmer, Site Reliability Engineer/DevOps. Welcome to my world of job hunting and career advice!
Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, PacketCache, #PolarProxy and RawCap.
Website: https://www.netresec.com/
Mastodon: @netresec@infosec.exchange
More on fediverse at @adulau@infosec.exchange and @a@paperbay.org
Or following @adulau.infosec.exchange.ap.brid.gy or @a.paperbay.org.ap.brid.gy
Hunting ghosts in wires and boxes, Head of CTI, former NCSC-PL, PL Navy #fightingthreats | @PIVOTcon.bsky.social co-founder & Chief Meme Officer
Former Head of CERT-FR. Former Head of Operations at ANSSI
A #SOCplatform boosted by #AI and #threatintelligence, combining #SIEM, #SOAR, #Automation in a single solution. Used by End-users, MSSP and APIs
Intel 471 specializes in delivering intelligence related to threat actors, threat hunting, financial cybercrime, ransomware, vulnerabilities, malware and underground marketplaces. Listen to our podcast, Cybercrime Exposed, on Spotify and Apple. #infosec
Our mission is to make the Internet more secure by bringing to light vulnerabilities, malicious activity and emerging threats. Join our Alliance!
https://shadowserver.org/partner
β Cybersecurity reporter
β
Newsletters at Risky Business
#infosec #cybersecurity
https://risky.biz
GreyNoise analyzes Internet background noise. Use GreyNoise to remove pointless security alerts, find compromised devices, or identify emerging threats.
π¬π§ | Senior Threat Intelligence Advisor at Team Cymru | Co-author SANS FOR589 | Co-founder Curated Intel
Bringing together intelligence researchers and incident responders. #TrackThePlanet π curatedintel.org