Sign in

Alexandre Dulaunoy

@adulau.infosec.exchange.ap.brid.gy
140 followers 13 following 393 posts

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) […] 🌉 bridged from ⁂ infosec.exchange/@adulau, follow @ap.brid.gy to interact

PostsRepliesMedia
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 15h
There seems to be a remarkably strong correlation on LinkedIn between people warning about the PQC threat and job titles containing “Account Manager” or “Sales”. I’m sure it’s purely coincidental. #pqc #cybersecurity #postquantumcryptography
011
Reposted by Alexandre Dulaunoy
Alexandre Dulaunoy @a.paperbay.org.ap.brid.gy · 05/10/2026
A question for fellow open-source maintainers: Imagine someone uses AI to redevelop your tool in Rust. The result barely works, but they reuse your project’s name and repeatedly jump into discussions about the existing project to promote their version. How would you handle that? I’m usually a […]
paperbay.org
Original post on paperbay.org
329
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 05/10/2026
We are pleased to announce the publication of GCVE BCP-07 version 3.0, extending the Known Exploited Vulnerability (KEV) Assertion Format with support for No Known Exploitable Vulnerability (NKEV) assessments. BCP-07 was initially designed to provide a structured, open and federated way to […]
infosec.exchange
Original post on infosec.exchange
000
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 04/10/2026
Threat-Actor explorer v1.1.0 released with many improvements and upgrade to the latest Pivotick library Latest A standalone, browser-only HTML/JavaScript application for exploring the MISP threat-actor galaxy, UUID-based relationships across every cluster […] [Original post on infosec.exchange]
Overview of the Threat-Actor explorer.
056
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 04/10/2026
We did some improvements in GCVE extension - GCVE BCP-05-X-03 - Vulnerability Handling and Disclosure Timeline. We also review the alignment and interoperability with CSAF 2.1. Now there is a new object field `entities` to represent the entities in the […] [Original post on infosec.exchange]
We also review the alignment and interoperability with CSAF 2.1. GCVE X-03
001
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 01/10/2026
GCVE BCP-05-X-03: Bringing Vulnerability Handling Timelines into Vulnerability Records. Vulnerability records usually provide a good description of what a vulnerability is, which products are affected, how severe it may be, and where additional information […] [Original post on infosec.exchange]
GCVE BCP-05-X-03 - Vulnerability Handling and Disclosure Timeline. Overview.
021
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 30/09/2026
"Dual-fit imperative in security leadership: a grounded theory investigation of CISO role enactment in modern organisations." The thesis has a complete survey with some interesting answers from a small set of CISCO. Now the conclusion/recommendation seems a bit broad and very generic imho. 🔗 […]
infosec.exchange
Original post on infosec.exchange
000
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 29/09/2026
The new AI conglomerates are publishing documents warning about the dangers of semi-open models that defenders can actually use, while those same conglomerates are restricting defenders’ access to their own models. #ai #cybersecurity 🔗🤦 […]
infosec.exchange
Original post on infosec.exchange
113
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 28/09/2026
We were very happy to participate in Vulnopticon 2026 and to meet so many people interested in vulnerability identification, publication, coordination, and management. The discussions during the conference and just as importantly, the conversations around and outside the formal sessions brought […]
infosec.exchange
Original post on infosec.exchange
020
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 23/09/2026
The **GCVE Workshop at Vulnopticon 2026** took place on 22 September in Luxembourg. We discussed decentralized vulnerability allocation, digital sovereignty, CVD workflows, Vulnerability-Lookup, Vulniverse, AI-assisted vulnerability analysis, and the future of GCVE. All slide decks and […]
infosec.exchange
Original post on infosec.exchange
021
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 20/09/2026
VULNARCHIVE and GNA 1988: Automated Vulnerability Identifier Allocation in a Federated GCVE Ecosystem. One of the core ideas behind GCVE is that vulnerability identification does not need to depend on a single central authority. Independent GCVE Numbering Authorities (GNAs) can operate their […]
infosec.exchange
Original post on infosec.exchange
002
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 18/09/2026
Tired of drafting vulnerability advisories from Git patches? We developed patch2vuln to facilitate the creation of security advisories directly from Git patches. With a single command, patch2vuln can assist an analyst throughout the advisory creation process: analyzing the patch, drafting the […]
infosec.exchange
Original post on infosec.exchange
021
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 15/09/2026
Pivotick v2.0.0 has been released. Pull more graph out of wherever your data lives, and you choose what lands. History is the way back out of anything that does. Actually you can update, pivot graph and review. This release also includes many new other features […]
infosec.exchange
Original post on infosec.exchange
020
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 14/09/2026
hack.lu 2026 agenda is live! (the 20th Edition) including more details about the keynote. 🔗 2026.hack.lu/blog/hack.lu-2026-agen… #conference #hacklu #cybersecurity
2026.hack.lu
hack.lu 2026 agenda is live! (the 20th Edition)
We are happy to announce that the hack.lu 2026 agenda is now published!
013
Reposted by Alexandre Dulaunoy
Anne Applebaum @anneapplebaum.wsocial.eu · 14/09/2026
Your regular reminder: If the Russians stop fighting, the war ends. If the Ukrainians stop fighting, their land will be occupied, their leaders will be killed, their history and language will be erased, their children will be kidnapped to serve Russia.
5953725813394
Reposted by Alexandre Dulaunoy
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 02/09/2026
GCVE Workshop - 22 September 2026 (14:00-18:00), Luxembourg Before The Vulnopticon Conference We are pleased to announce a GCVE workshop on 22 September 2026, from 14:00 to 18:00, hosted at the CIRCL/LHC offices in Luxembourg, just before the VulnOpticon conference. The workshop is free and […]
infosec.exchange
Original post on infosec.exchange
004
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 11/09/2026
I love to see clever use of the @gcve ecosystem and @SaschaRommelfangen did a cool GNA which is automatically creating GCVE records and structured security advisories from full-disclosure mailing-list or alike: 🔗 Project details vuln.freearchive.org 🔗 As it's a GNA, it's part of the […]
infosec.exchange
Original post on infosec.exchange
011
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 11/09/2026
We had difficulties automatically classifying chats, messaging channels, and forums. So we tested several open-weight large language models for our use case. The benchmark is published below, along with a tool supporting the classification process. This helps us avoid manually classifying […]
infosec.exchange
Original post on infosec.exchange
023
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 09/09/2026
The @gcve BCP-07 KEV format has been updated to allow the `Withdrawn` and `Reasserted` KEV Assertions. This allows to support case like CVE-2026-69836 . 🔗 gcve.eu/bcp/gcve-bcp-07/#withdrawn-… #cve #gcve #kev […] [Original post on infosec.exchange]
GCVE BCP-07 - Withdrawn and Reasserted KEV Assertions
001
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 06/09/2026
Doing some statistics on the persistence of information published on security and threat intelligence blogs. A surprising number of the domains in the list below are NXDOMAIN nowadays. Don't assume that security information and threat intelligence will remain accessible over time, especially […]
infosec.exchange
Original post on infosec.exchange
101
Reposted by Alexandre Dulaunoy
Tim (Wadhwa-)Brown :donor: @timb.me.uk · 05/09/2026
Interesting Git repos of the week: Bugs: * github.com/MSNightmare/FalconFlank - everyone's favourite new source of 0day pops CrowdStrike Falcon * github.com/MSNightmare/HardBreacher - everyone's favourite new source of 0day pops Kaspersky AV Hard hacks: * […]
infosec.exchange
Original post on infosec.exchange
004
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 04/09/2026
ptrclassify is a small, dependency-free Python library and CLI that infers likely IP usage and location from reverse-DNS PTR hostnames. Version 0.3 released including new rules and CSV tool. #ptrclassify #infosec #cybersecurity 🔗 github.com/adulau/ptrclassify
github.com
GitHub - adulau/ptrclassify: ptrclassify is a small, dependency-free Python library and CLI that infers likely IP usage and location from reverse-DNS PTR hostnames
ptrclassify is a small, dependency-free Python library and CLI that infers likely IP usage and location from reverse-DNS PTR hostnames - adulau/ptrclassify
122
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 03/09/2026
Proposed changes in the CVE program CNA document "Update 4.2.6 from SHOULD to MUST: "CNAs MUST assign different CVE IDs to separate Vulnerabilities"" 🔗 github.com/CVEProject/cve-documents… #cve #vulnerabilitymanagement #cybersecurity
000
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 02/09/2026
GCVE Workshop - 22 September 2026 (14:00-18:00), Luxembourg Before The Vulnopticon Conference We are pleased to announce a GCVE workshop on 22 September 2026, from 14:00 to 18:00, hosted at the CIRCL/LHC offices in Luxembourg, just before the VulnOpticon conference. The workshop is free and […]
infosec.exchange
Original post on infosec.exchange
004
Reposted by Alexandre Dulaunoy
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 01/09/2026
GCVE BCP-07, the Known Exploited Vulnerability (KEV) Assertion Format, has been updated to version 2.2. A key addition is the formalisation of the GCVE KEV Directory, a simple machine-readable directory allowing organisations to announce where their KEV catalogues and exploitation assertions are […]
infosec.exchange
Original post on infosec.exchange
011
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 01/09/2026
GCVE BCP-07, the Known Exploited Vulnerability (KEV) Assertion Format, has been updated to version 2.2. A key addition is the formalisation of the GCVE KEV Directory, a simple machine-readable directory allowing organisations to announce where their KEV catalogues and exploitation assertions are […]
infosec.exchange
Original post on infosec.exchange
011
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 31/08/2026
CVSS and WRONG models are just the same. #cvss #infosec
000
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 24/08/2026
I spent many hours in vulnogram today and to be honest. I'm glad that a colleague started to work on a replacement called `vulniverse`. Still early beta but it's promising. #opensource #vulniverse #cybersecurity #cve #gcve :github: work in progress […]
infosec.exchange
Original post on infosec.exchange
011
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 23/08/2026
I just released `ptrclassify` is a small, dependency-free Python library and CLI that infers likely IP usage from reverse-DNS PTR hostnames. It is intentionally heuristic and multi-label. PTR naming is operator-controlled and is not authoritative evidence of how an address is actually used. The […]
infosec.exchange
Original post on infosec.exchange
025
Reposted by Alexandre Dulaunoy
Alexandre Dulaunoy @a.paperbay.org.ap.brid.gy · 22/08/2026
endless hope, Belgium 2026 #photography #photo #river #water #leica
endless hope, Belgium 2026
072
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 18/08/2026
CCWget is a lightweight Python client for searching and retrieving archived web objects from a CIRCL Common Crawl indexing service. @Thanat0s did a pretty cool tool to search the Common Crawl. The service is quite resource intensive but if you are a security researcher, you could get access […]
infosec.exchange
Original post on infosec.exchange
000
Reposted by Alexandre Dulaunoy
Stephen Shaffer @t0sche.infosec.exchange.ap.brid.gy · 17/08/2026
RE: infosec.exchange/@adulau/1170761984… Couldn’t have imagined a better way for this idea to be picked up and implemented. #Kudos to @circl, @adulau, and @cedric 👏🫶
102
Reposted by Alexandre Dulaunoy
Alexandre Dulaunoy @a.paperbay.org.ap.brid.gy · 15/08/2026
How mature is this repository? My long quest for open-source software metrics When I discover an open-source software project for the first time, how can I estimate whether it is mature, healthy and usable? I just released OSSTRL - Open Source Software Technology Readiness Level to help me […]
paperbay.org
Original post on paperbay.org
135
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 13/08/2026
If you are curious about (nearly) everything we did the past months at the GCVE.eu initiative: gcve.eu/2026/08/13/gcve-recent-acti… We published a recap blog post. #gcve #cve #vulnerability […] [Original post on infosec.exchange]
GCVE recent activities: standards, software and a growing GNA community
021
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 12/08/2026
vulnerability-lookup 6.0 will be released this week with many (really, many!) new features. One of the smaller, but important, additions is support for multiple SSVC views alongside CVSS. When SSVC information is available from an ADP (such as CISA) , or […] [Original post on infosec.exchange]
vulnerability-lookup 6.0 will be released this week with many (really, many!) new features.


One of the smaller, but important, additions is support for multiple SSVC views alongside CVSS. When SSVC information is available from an ADP (such as CISA) , or from additional sources such as GCVE, it is now displayed by default.


This allows users to more easily compare the different severity and prioritization assessments associated with a vulnerability.
020
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 11/08/2026
From a research paper to running open-source code in just a few days. We (with @cedric) have been experimenting in Vulnerability-Lookup with the concept of Local Exploit Hazard, based on the recent research paper “Modeling Local Exploit Hazard — A Bayesian […] [Original post on infosec.exchange]
Implementation of the paper in vulnerability-lookup
135
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 09/08/2026
Working on a first super beta implementation of @gcve BCP-11 "Community-Proposed Updates to Existing CVE Records" To validate if the BCP-11 can be published. #cve #gcve #vulnerability #opensource #opendata Discussions […] [Original post on infosec.exchange]
BCP-11 first implementation UI - to propose changes to existing CVE records.BCP-11 first implementation UI - to propose changes to existing CVE records.
030
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 09/08/2026
Pretty cool idea from @nyanbinary - a bot to analyse fucked up references from the CVE records. @fuckeduprefs_bot Maybe we could imagine an archive bot at the same time to ensure that the references don't get lost. Just like archive.org or similar. Maybe something for @gcve to look into. #cve […]
infosec.exchange
Original post on infosec.exchange
001
Reposted by Alexandre Dulaunoy
Alexandre Dulaunoy @a.paperbay.org.ap.brid.gy · 08/08/2026
Maybe the AI bots trying to find endlessly new content on my blog post? Drive me these questions « Is human generated content what AI bot are only interesting in? Does this mean that human contribution is the only way to keep the system running before it collapse or read its peak? Is the AI […]
paperbay.org
Original post on paperbay.org
002
Reposted by Alexandre Dulaunoy
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 28/07/2026
The Radio Image Framing Protocol (RIFP) 1.0 is an experimental, extensible standard for sending images over low-rate radio links. The default rifp-cpfsk-4800 profile uses binary continuous-phase FSK and can be deployed around 433.92 MHz where local […] [Original post on infosec.exchange]
Radio Image Framing Protocol (RIFP) - test image (RLE)
038
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 06/08/2026
Recommendations on Naming Threat Actors. The MISP standard has been updated including the new tracking of naming origin from security vendor. #cti #threatintelligence #soc #cybersecurity #threatintel 🔗 www.misp-standard.org/rfc/threat-ac…
000
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 03/08/2026
A standalone, browser-only HTML/JavaScript application for exploring the MISP threat-actor galaxy, UUID-based relationships across every cluster in the MISP Galaxy repository, and shared MISP Galaxy metadata. Graph rendering is performed by Pivotick. Source […] [Original post on infosec.exchange]
A Threat-Actor explorer (browser-local) from the MISP galaxy dataset.

Selection of the producer to limit the view to a specific vendor-naming.A standalone, browser-only HTML/JavaScript application for exploring the MISP threat-actor galaxy, UUID-based relationships across every cluster in the MISP Galaxy repository, and shared MISP Galaxy metadata. Graph rendering is performed by Pivotick.
131
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 03/08/2026
Have you seen any evidence of the famous « collect encrypt data and decrypt later » in incident response ? Until now, I haven’t. #pqc #crypto #cryptography #dfir
101
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 01/08/2026
Sightings have long been a major topic of discussion in the CTI community, particularly in the field of vulnerability management. We have now published a GCVE BCP to standardise the format that has been implemented, tested and used operationally in […] [Original post on infosec.exchange]
Sighting overview on a vulnerability-lookup instance. db.gcve.eu
101
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 30/07/2026
A new version of the BCP-11 "Community Contribution Fragments for Existing CVE Records" proposal has been published […]
infosec.exchange
Original post on infosec.exchange
000
Reposted by Alexandre Dulaunoy
Will Dormann @wdormann.infosec.exchange.ap.brid.gy · 30/07/2026
Actual cryptographer Matthew Green wrote some words about this: blog.cryptographyengineering.com/20… > This result initially sounds more exciting, since most people hear “attack on AES” and panic. However, this is also the result that’s […]
infosec.exchange
Original post on infosec.exchange
019
Reposted by Alexandre Dulaunoy
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 01/08/2025
When I added the threat-actor @misp galaxy type on Mar 4, 2016, I didn’t expect that, years later, vendors would still invent new names for already known threat actors, avoid using UUIDs, reuse similar names for different actors, and create confusing names […] [Original post on infosec.exchange]
misp-galaxy website - Threat-actor galaxy and relationships with other galaxy clusters.Seeing all the synonyms from a threat-actor on the misp-galaxy.org websiteThreat-actor database in MISP
1417
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 28/07/2026
The Radio Image Framing Protocol (RIFP) 1.0 is an experimental, extensible standard for sending images over low-rate radio links. The default rifp-cpfsk-4800 profile uses binary continuous-phase FSK and can be deployed around 433.92 MHz where local […] [Original post on infosec.exchange]
Radio Image Framing Protocol (RIFP) - test image (RLE)
038
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 27/07/2026
Pivotick is an open-source network graph library to facilitate pivoting. Version 1.4.0 has been released and also includes a security fix. Release notes github.com/Pivotick/Pivotick/releas… Documentation […] [Original post on infosec.exchange]
Pivotick Library documentation
044
Alexandre Dulaunoy @adulau.infosec.exchange.ap.brid.gy · 27/07/2026
So finally Kimi-k3 is not really open-source huggingface.co/moonshotai/Kimi-K3/b… I'm a bit disappointed. #kimi #ai #opensource
huggingface.co
LICENSE · moonshotai/Kimi-K3 at main
We’re on a journey to advance and democratize artificial intelligence through open source and open science.
263