Sign in

CrowdSec

@crowdsec.bsky.social
233 followers 8 following 334 posts

Account run by Alpacas CrowdSec is a CTI tool leveraging crowdsourced data to identify and block malevolent IPs in real time, worldwide. Join our Discord: discord.gg/crowdsec

PostsRepliesMedia
CrowdSec @crowdsec.bsky.social · 5h
Last week, CrowdSec CEO Philippe Humeau presented at the SANS Institute Cyber Leaders event in Brussels. You can check out the prez below 👇 Want to dig into the data yourself? Check IP reputation with IPDEX: ipdex.crowdsec.net Track which IPs are exploiting which CVEs: tracker.crowdsec.net
020
CrowdSec @crowdsec.bsky.social · 30/09/2026
🤖 CrowdSec 1.8’s bot detection uncovered PaperPhone, a scraping network spanning 75K IPs across 43 countries. Our first investigation found suspicious device fingerprints and a geographic footprint that isn’t quite what it seems. Read the full investigation: www.crowdsec.net/blog/the-pap...
001
CrowdSec @crowdsec.bsky.social · 29/09/2026
👻 Is that a real browser… or a bot in disguise? 🤖 CrowdSec 1.8 brings #botdetection to the #WAF. Join our #CommunityOfficeHours on Oct. 29 at 4 PM CET to see it in action and explore what’s new in 1.8. 🎃 No tricks, just treats! Notify Me & save the date → www.youtube.com/live/rHKs3yA...
010
CrowdSec @crowdsec.bsky.social · 28/09/2026
🚨 In this week’s #threatalert, we cover #CVE-2026-87902, a critical WordPress path traversal vulnerability that can lead to #RCE. CrowdSec has observed 30,813 unique IP addresses sending requests matching the exploitation pattern in just five days. Read more: www.crowdsec.net/vulntracking...
020
CrowdSec @crowdsec.bsky.social · 25/09/2026
CrowdSec Blocklists feature a 5% daily rotation, ensuring users always benefit from fresh, up-to-date threat intelligence. To learn more about CrowdSec #Blocklists and how to integrate them with your Sophos #Firewall, watch our full video guide here:  www.youtube.com/watch?v=lmqz...
010
CrowdSec @crowdsec.bsky.social · 24/09/2026
CrowdSec + Suricata: do you actually need both for Linux servers? 🤔 They both detect threats, but they solve different problems. We break down where each fits, when to use them together, and why enforcement matters more than simply collecting alerts. 👉 Read more: www.crowdsec.net/blog/crowdse...
002
CrowdSec @crowdsec.bsky.social · 23/09/2026
How does the attack activity affect your stack? Attack Surge helps you spot major changes, then jump into the underlying alerts to understand what’s driving the spike. Explore it in CrowdSec → docs.crowdsec.net/u/console/se... #cybersecurity #threatdetection #securityoperations
020
CrowdSec @crowdsec.bsky.social · 22/09/2026
Keep your security stack in good shape🛡️ With CrowdSec Stack Health, you can: - See what needs attention - Understand what’s wrong - Get clear guidance on how to fix it - Get your stack back to good health Check it out 👉 doc.crowdsec.net/u/console/st...
000
CrowdSec @crowdsec.bsky.social · 21/09/2026
🚨 This week’s Threat Alert covers CVE-2025-4427, an Ivanti EPMM authentication bypass that can lead to unauthenticated RCE when chained with CVE-2025-4428. CrowdSec has observed 865 unique IPs matching the exploitation pattern since May 2025. Read more: www.crowdsec.net/vulntracking...
crowdsec.net
Ivanti EPMM CVE-2025-4427: Authentication Bypass
CVE-2025-4427 is a medium-severity Ivanti EPMM authentication bypass. CrowdSec observed 3,978 exploitation signals across 89 days.
010
CrowdSec @crowdsec.bsky.social · 18/09/2026
We’ve published a deeper look at the supply chain attack that affected CrowdSec. In this article, our CEO Philippe Humeau shares an honest account of what happened, how we investigated the incident, what we found, and what we’re doing differently as a result. www.crowdsec.net/blog/tanstac...
crowdsec.net
TanStack Supply Chain Attack Analysis
CrowdSec CEO Philippe Humeau shares the full story behind the 2026 supply chain attack, from the source code leak and forensic investigation to the lessons learned.
022
CrowdSec @crowdsec.bsky.social · 17/09/2026
We’re sharing a transparent update about a source code exposure that occurred in May 2026. Our investigation found that no customer data or credentials were exposed. We’ve taken precautionary steps and continue to monitor the situation. Read our full statement: www.crowdsec.net/blog/crowdse...
crowdsec.net
CrowdSec Statement: Source Code Exposure in May 2026
CrowdSec update on a source code exposure that occurred in May 2026, including the scope, impact, investigation, and security measures taken.
010
CrowdSec @crowdsec.bsky.social · 16/09/2026
Copy-pasting your CrowdSec question into an LLM? Sometimes you get the answer. Sometimes you get confidently assembled gibberish. 🤖 So we gave it a better map: the CrowdSec Skill. ✨ Get the details here: www.crowdsec.net/blog/ai-agen... Because “sounds right” is not quite the same as “works.” 😏
010
CrowdSec @crowdsec.bsky.social · 15/09/2026
New in CrowdSec: Alerts Explorer. See how alerts break down across your stack, group activity by source IP, then use interactive facets to jump straight into what you want to investigate. Explore it → app.crowdsec.net/alerts-v2
000
CrowdSec @crowdsec.bsky.social · 14/09/2026
🚨 This week’s Threat Alert covers CVE-2026-75650 (StyleSmuggler), a critical RCE affecting Adobe Commerce & Magento. Exploited before the patch, it escalated to mass scanning, with 500+ IPs observed. Read the full analysis and protection recommendations: www.crowdsec.net/vulntracking...
000
CrowdSec @crowdsec.bsky.social · 09/09/2026
🤖 robots.txt: “Please don’t crawl my site.” Bots: “lol.” Thankfully, CrowdSec 1.8 brings self-hosted bot protection: proof-of-work + browser fingerprinting to separate real browsers from scripts wearing browser costumes.  Learn more 👉 www.crowdsec.net/blog/nginx-b...
000
CrowdSec @crowdsec.bsky.social · 07/09/2026
🚨 In this week’s newsletter, we cover CVE-2023-54391, a critical authentication bypass affecting Proxmox VE that is seeing exploitation attempts. Read the full analysis and protect your systems 👉 www.crowdsec.net/vulntracking...
000
CrowdSec @crowdsec.bsky.social · 04/09/2026
You find an unfamiliar IP in your logs. The IP alone tells you very little. The useful part is the context behind it: reputation, behavior and observed attack activity. See an IP you don't recognize? Look it up with IPDEX. 👉 ipdex.crowdsec.net #ThreatIntel #CyberSecurity #SecOps
000
CrowdSec @crowdsec.bsky.social · 01/09/2026
CrowdSec 1.8 is here 🚀 🤖 Bot Detection for CrowdSec WAF ☸️ Dedicated Kubernetes datasource ⚡ Major LAPI ↔ bouncer performance improvements 🔎 Revamped Console alerts experience 🧠 Expanded CrowdSec Skill for LLMs 👇 www.crowdsec.net/blog/crowdse... #CrowdSec #CyberSecurity #OpenSource
021
CrowdSec @crowdsec.bsky.social · 31/08/2026
🚨 In this week’s newsletter, we cover CVE-2026-33497, a high-severity path traversal vulnerability affecting Langflow that is seeing active exploitation. Read the full analysis and protect your systems 👉 www.crowdsec.net/vulntracking...
000
CrowdSec @crowdsec.bsky.social · 25/08/2026
A compromised device can become infrastructure for the next attack. Evooo1Bot is a recent example, turning compromised edge devices into infrastructure for further malicious activity. A reminder of why recent observed behavior matters for IP reputation. 👉 www.crowdsec.net/blocklists
000
CrowdSec @crowdsec.bsky.social · 17/08/2026
🚨 In this week’s newsletter, we cover CVE-2024-12847, a critical RCE vulnerability affecting NETGEAR DGN1000 routers that has become the most-attacked flaw tracked by the CrowdSec Network. Read the full analysis and protect your systems 👉 www.crowdsec.net/vulntracking...
000
CrowdSec @crowdsec.bsky.social · 12/08/2026
Your AI agent is smart. But does it actually know how your software works? 🤖 We built a CrowdSec Skill to replace plausible guesses with product-specific procedures, guardrails, and verification. It even helped us find gaps in our own docs. Read the story 👇 www.crowdsec.net/blog/ai-agen...
000
CrowdSec @crowdsec.bsky.social · 10/08/2026
🚨 In this week’s newsletter, we cover CVE-2026-2652, an authentication bypass vulnerability affecting MLflow that is seeing active exploitation. Read the full analysis and protect your systems 👉 www.crowdsec.net/vulntracking...
000
CrowdSec @crowdsec.bsky.social · 30/07/2026
Traefik routes traffic. A WAF inspects it. Learn how to add an open-source WAF to Traefik with CrowdSec for virtual patching and real-time protection—without changing your architecture. 👇 www.crowdsec.net/blog/waf-tra... #Traefik #WAF #CyberSecurity #OpenSource
010
CrowdSec @crowdsec.bsky.social · 28/07/2026
🚨 In this week’s newsletter, we cover CVE-2026-63030 (WP2Shell), a critical SQL injection-to-RCE vulnerability affecting WordPress core that has rapidly entered the Rapid Escalation phase. 👉https://www.crowdsec.net/vulntracking-report/cve-2026-63030-wordpress-wp2shell-sqli-to-rce
010
CrowdSec @crowdsec.bsky.social · 22/07/2026
💭 Did you know? Am I Under Attack turns those signals into a simple answer, notifying you when your instance is likely facing a targeted attack—so you can investigate immediately instead of discovering it later. Learn how to enable it 👇 www.crowdsec.net/blog/am-i-un...
000
CrowdSec @crowdsec.bsky.social · 17/07/2026
Live Exploit Tracker now includes IOCs for tracked CVEs. 👀 See what to look for—not just what is being exploited. Quick demo 👇 tracker.crowdsec.net #CyberSecurity #CVE #ThreatIntel
000
CrowdSec @crowdsec.bsky.social · 15/07/2026
🤖 The ESRB warns AI is shrinking defenders' response time. CVSS tells you what could happen. Live Exploit Tracker shows what attackers are exploiting right now. Prioritize based on active exploitation, not just severity. 👉 tracker.crowdsec.net
010
CrowdSec @crowdsec.bsky.social · 10/07/2026
Running NGINX on Ubuntu? Protect your web apps with an open-source WAF backed by real-time threat intelligence. Our step-by-step guide shows you how 👇 www.crowdsec.net/blog/open-so... #NGINX #WAF #CyberSecurity #OpenSource
040
CrowdSec @crowdsec.bsky.social · 06/07/2026
🚨 In this week’s newsletter, we cover CVE-2026-8451, a high-severity SAML memory overread vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway that is already seeing active exploitation. Read the full analysis and protect your systems 👉 www.crowdsec.net/vulntracking...
000
CrowdSec @crowdsec.bsky.social · 03/07/2026
Stack Health continuously checks your CrowdSec deployment so you can spot and fix problems before they impact protection. 👉 doc.crowdsec.net/u/console/st... #CyberSecurity #SecOps #Infosec
000
CrowdSec @crowdsec.bsky.social · 01/07/2026
A new CVE is disclosed. The first question shouldn't be *"What's the CVSS?"* It should be *"Is it being exploited?"* See real-world exploitation as it happens with the Live Exploit Tracker 👇 tracker.crowdsec.net #CyberSecurity #CVE #ThreatIntel
000
CrowdSec @crowdsec.bsky.social · 29/06/2026
🚨 In this week’s newsletter, we cover CVE-2026-39808, a critical OS command injection vulnerability in Fortinet FortiSandbox now in early exploitation. Read the full analysis and protect your systems 👉 www.crowdsec.net/vulntracking...
000
CrowdSec @crowdsec.bsky.social · 24/06/2026
🔎 New in CrowdSec CTI: a powerful search bar that helps you build complex threat intelligence queries in just a few clicks. Search by IP, threat, behavior, network, geo, or activity. It's also the first step toward smarter, easier Blocklist creation. 👉https://app.crowdsec.net/cti
000
CrowdSec @crowdsec.bsky.social · 22/06/2026
🚨 In this week’s newsletter, we cover CVE-2026-20253, a critical authentication bypass vulnerability in Splunk Enterprise and Splunk Cloud Platform now in early exploitation. Read the full analysis and protect your systems 👉 www.crowdsec.net/vulntracking...
000
CrowdSec @crowdsec.bsky.social · 19/06/2026
Not every CVE deserves the same level of attention. The real question is: which ones are attackers actually exploiting? Our latest report looks at real-world exploitation patterns 👇 www.crowdsec.net/vulnerabilit... #CyberSecurity #CVE #ThreatIntel
000
CrowdSec @crowdsec.bsky.social · 16/06/2026
CVSS tells you what could happen. Live exploitation tells you what is happening. That's the thinking behind CISA's new BOD 26-04—and why exploitation intelligence matters more than ever. www.crowdsec.net/blog/cisa-bo...
000
CrowdSec @crowdsec.bsky.social · 15/06/2026
🚨 In this week’s newsletter, we cover CVE-2026-10520, a critical pre-authentication OS command injection vulnerability in Ivanti Sentry now under active exploitation. Read the full analysis and protect your systems 👉 www.crowdsec.net/vulntracking...
000
CrowdSec @crowdsec.bsky.social · 10/06/2026
OWASP CRS is powerful. But static rules alone can’t keep up with evolving attacks. Combine it with CrowdSec’s real-time threat intelligence for stronger protection 👇 www.crowdsec.net/blog/protect... #WAF #CyberSecurity #DevSecOps
000
CrowdSec @crowdsec.bsky.social · 08/06/2026
🚨 In this week’s newsletter, we cover CVE-2026-8181, a critical authentication bypass vulnerability in the WordPress Burst Statistics plugin now under active exploitation. Read the full analysis and protect your systems 👉 www.crowdsec.net/vulntracking...
000
CrowdSec @crowdsec.bsky.social · 05/06/2026
👀 What's being cooked at CrowdSec? Your WAF already knows *what* requests are doing. What if it could also help answer *who* is behind them? More soon! #CyberSecurity #WAF #BotDetection #ThreatIntelligence
000
CrowdSec @crowdsec.bsky.social · 04/06/2026
⚠️ CVE tells you a vulnerability exists. CVSS tells you its theoretical severity. KEV tells you it has already been exploited. But what tells you what's being exploited right now? Our latest report explores the missing link: real-world exploitation telemetry. 📥 www.crowdsec.net/vulnerabilit...
000
CrowdSec @crowdsec.bsky.social · 03/06/2026
A suspicious IP alone doesn’t tell you much. The context around it does. Attack history, targeted services, observed behaviors, confidence signals — that’s what helps analysts decide what actually matters. Try investigating your latest suspicious IP 👇 app.crowdsec.net/cti
010
CrowdSec @crowdsec.bsky.social · 25/05/2026
🚨 In this week’s newsletter, we cover CVE-2026-9082, a Drupal JSON: API SQL injection vulnerability now under active exploitation. We break down how attackers are targeting exposed /jsonapi/ endpoints and what defenders should do next. 👉 www.crowdsec.net/vulntracking...
000
CrowdSec @crowdsec.bsky.social · 22/05/2026
New CVE? The clock starts immediately ⏱️ How do you validate impact, assess exploitability, and deploy protections fast enough? Watch the full session 👇 youtube.com/live/oedE1_y... #CyberSecurity #CVE #SecOps
000
CrowdSec @crowdsec.bsky.social · 20/05/2026
Security shouldn’t become a deployment bottleneck. Modern DevSecOps needs protection that fits naturally into CI/CD, GitOps, and cloud-native workflows. Here’s how CrowdSec integrates without friction 👇 www.crowdsec.net/blog/devseco... #DevSecOps #CyberSecurity #CIcd
000
CrowdSec @crowdsec.bsky.social · 19/05/2026
🚨 Disclosure no longer buys defenders time. Our latest CrowdSec report shows how vulnerabilities now move from CVE publication to mass exploitation in hours, not weeks. Download the 2025 Crowd-Powered Vulnerability & Exploitation Report 👇 www.crowdsec.net/vulnerabilit...
000
CrowdSec @crowdsec.bsky.social · 18/05/2026
🚨 In this week’s newsletter, we cover CVE-2024-9643, a Four-Faith router authentication bypass now moving into mass exploitation. Read the full analysis and protect your systems 👉 www.crowdsec.net/vulntracking...
000
CrowdSec @crowdsec.bsky.social · 15/05/2026
🔥 The edge is the new endpoint. VPNs, firewalls, and reverse proxies are now frontline targets — and when edge CVEs go hot, response time matters. How do you reduce exposure before exploitation spreads? 👇 www.crowdsec.net/blog/edge-is... #CyberSecurity #EdgeSecurity #CVE
000
CrowdSec @crowdsec.bsky.social · 14/05/2026
Critical infrastructure needs proactive defense ⚡ ButanGas is using CrowdSec’s CTI + Platinum Blocklists to block hundreds of malicious connections daily. Real-world protection for critical energy operations 👇 www.crowdsec.net/blog/securin... #CyberSecurity #ThreatIntel #EnergySector
000