mastodontech.de ist einer von vielen unabhängigen Mastodon-Servern, mit dem du dich im Fediverse beteiligen kannst.
Offen für alle (über 16) und bereitgestellt von Markus'Blog

Serverstatistik:

1,5 Tsd.
aktive Profile

#csirt

0 Beiträge0 Beteiligte0 Beiträge heute

This is a timely reminder to ensure any third-parties with access to your systems follow the same cyber policies you'd expect your internal staff to follow.

#ScatteredSpider are particularly good at #SocialEngineering their way via a third-party to other victims.

For clarity, #ScatteredSpider are considered the initial access group, #DragonForce #ransomware is the malware deployed once #ScatteredSpider are inside your network.

bleepingcomputer.com/news/secu

Support for #STIX and #TAXII in #IntelMQ

For collecting and processing #threatintel feeds, #IntelMQ is a good tool. Simple to deploy and configure, used by several #CSIRT teams.
For long time, it was sufficient for me, however, with recent changes in #ESET #ThreatIntelligence feeds, I realized that IntelMQ lacks support for TAXII protocol and STIX language and objects...

After hours of studying the STIX/TAXII documentation, I decided to develop some basic support for collecting the feeds from TAXII servers and parsing the STIX indicators objects.
This way, IntelMQ can process not only the current #ETI feeds, but also some other sources.

The commits are currently waiting in pull request in IntelMQ GitHub:
github.com/certtools/intelmq/p

GitHubTAXII Collector bot and STIX Parser bot by laciKE · Pull Request #2611 · certtools/intelmqVon laciKE

Thanks to our #TurrisSentinel #security #research program, #CZNIC #CSIRT team discovered large scale #FTP #attack. Coming from 45.78.4.0/22, it is #bruteforcing #slowly - it takes it 19 day to get through it's #passwords. Big thanks to everybody who helps us by running our #minipots on their devices! Report in #Czech is available on CSIRT website csirt.cz/cs/kyberbezpecnost/ak

csirt.czDistribuovaný FTP bruteforcer - Aktuálně z bezpečnosti - CSIRTAktuálně z bezpečnosti

We are excited to announce that CIRCL has three open positions available.

As a team strongly oriented towards open-source development, we value contributions that drive innovation and strengthen the cybersecurity community. These roles are open to EU citizens, with the workplace based in Luxembourg. If you’re passionate about cybersecurity and open-source collaboration, we encourage you to apply and make a meaningful impact.

  • CIRCL - Software Engineer and Intelligence Analyst (software-engineering-analyst)

🔗 circl.lu/projects/position/sof

  • CIRCL - Security Analyst and Researcher (Security-Analyst-and-Researcher)

🔗 circl.lu/projects/position/sec

  • CIRCL - Incident and Vulnerability Disclosure Coordinator/Analyst (nis2-incident-analyst)

🔗 circl.lu/projects/position/nis

@circl

www.circl.luCIRCL » CIRCL - Software Engineer and Intelligence Analyst (software-engineering-analyst)CIRCL » CIRCL - Software Engineer and Intelligence Analyst (software-engineering-analyst)

FIRST hosted another successful TF-CSIRT Meeting & FIRST Regional Symposium Europe in beautiful Monte Carlo, Monaco this month, co-organized by TF-CSIRT and hosted by CERT Monaco.

The event brought together incident response experts for intensive training, informative sessions and valuable networking opportunities, fostering collaboration within the global cybersecurity community.

Special thanks to FIRST CEO Chris Gibson and our Board of Directors who attended: Dr. Serge Droz, Carlos Leonardo, Michael Hausding, Olivier Caleff, Carlos Alvarez, Mona Elisabeth Østvang, Nadia Yousef, Tracy Bills, Yukako Uchida and Audrey Mnisi Mireku.

Learn more about the event here: go.first.org/J5Lnf

#FIRSTEU25 #cybersecurity
#IncidentResponse #CSIRT

One thing's clear: if you send an abuse notification to NiceNIC, it ends up being really 'nice' for the criminals.

This reminded me of an idea for proxy filtering: filtering based on the domain registrar. Another practical use case for the WHOIS history database.

Is there an open and public list of the worst registrars?

Good news for everyone involved in meetings where TLP classifications play a crucial role! I've just updated my repository with the latest, second edition of the TLP Classification Meeting Posters. These are handy tools to explicitly display the TLP classification in use during your meetings.

🔗 Grab the PDF and ODT versions here - git.foo.be/adulau/tlp-meeting

Updates are welcome, like better design, translation or alike.

#tlp#classification#meeting

Die #DigitalEurope Ausschreibung DIGITAL-ECCC-2022-CYBER-B-03-SOC "Capacity building of Security Operation Centres" läuft noch bis zum 06.07.2023. Es sind Projektanträge 📄 geeignet, die eine bessere Detektion 🔎 und Analyse 💻 von Cyber-Angriffen ermöglichen. Threat-Intelligence inkl. -Sharing Vorhaben kommen ebenfalls infrage.

Ausschreibungsunterlagen im EU Funding & tender opportunities Portal 👇
ec.europa.eu/info/funding-tend

#DigitalEU#SOC#Detection