home.social

#incident-response — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #incident-response, aggregated by home.social.

fetched live
  1. Security Tip: Establish Out-of-Band (OOB) communication channels. 🛡️ During a major security incident, your standard communication tools (Email, Slack, Teams) may be compromised. Effective incident response requires a secure and isolated secondary channel to coordinate recovery efforts without tipping off the adversary. Stay informed on the latest threats at cvedatabase.com #InfoSec #CyberSecurity #IncidentResponse #InfosecTips

  2. Security Tip: Establish Out-of-Band (OOB) communication channels. 🛡️ During a major security incident, your standard communication tools (Email, Slack, Teams) may be compromised. Effective incident response requires a secure and isolated secondary channel to coordinate recovery efforts without tipping off the adversary. Stay informed on the latest threats at cvedatabase.com

  3. Security Tip: Is your Incident Response plan battle-tested? 🛡️ Having a PDF document is not enough. Regular tabletop exercises (TTX) are essential to ensure every stakeholder—from IT to Legal—knows their role during a breach. Use these simulations to identify missing logs, communication breakdowns, and technical hurdles. Staying ahead of threats starts with preparation. Track the latest vulnerabilities at cvedatabase.com #InfoSec #CyberSecurity #IncidentResponse

  4. Security Tip: Is your Incident Response plan battle-tested? 🛡️ Having a PDF document is not enough. Regular tabletop exercises (TTX) are essential to ensure every stakeholder—from IT to Legal—knows their role during a breach. Use these simulations to identify missing logs, communication breakdowns, and technical hurdles. Staying ahead of threats starts with preparation. Track the latest vulnerabilities at cvedatabase.com

  5. NEW by me:

    The U.S. military leaked more than 93,000 tips via insecure P3 Global Intel. Has anyone been notified?

    I had reported on the school-related tips in the Navigate360 breach, and then the Crime Stoppers tips. In this post, I looked at the tips to the U.S. military.

    databreaches.net/2026/09/18/th

    #Navigate360 #P3GlobalIntel #databreach #cybersecurity #incidentresponse

    @douglevin

  6. NEW by me:

    The U.S. military leaked more than 93,000 tips via insecure P3 Global Intel. Has anyone been notified?

    I had reported on the school-related tips in the Navigate360 breach, and then the Crime Stoppers tips. In this post, I looked at the tips to the U.S. military.

    databreaches.net/2026/09/18/th

    #Navigate360 #P3GlobalIntel #databreach #cybersecurity #incidentresponse

    @douglevin

  7. NEW by me:

    The U.S. military leaked more than 93,000 tips via insecure P3 Global Intel. Has anyone been notified?

    I had reported on the school-related tips in the Navigate360 breach, and then the Crime Stoppers tips. In this post, I looked at the tips to the U.S. military.

    databreaches.net/2026/09/18/th

    #Navigate360 #P3GlobalIntel #databreach #cybersecurity #incidentresponse

    @douglevin

  8. NEW by me:

    The U.S. military leaked more than 93,000 tips via insecure P3 Global Intel. Has anyone been notified?

    I had reported on the school-related tips in the Navigate360 breach, and then the Crime Stoppers tips. In this post, I looked at the tips to the U.S. military.

    databreaches.net/2026/09/18/th

    #Navigate360 #P3GlobalIntel #databreach #cybersecurity #incidentresponse

    @douglevin

  9. NEW by me:

    The U.S. military leaked more than 93,000 tips via insecure P3 Global Intel. Has anyone been notified?

    I had reported on the school-related tips in the Navigate360 breach, and then the Crime Stoppers tips. In this post, I looked at the tips to the U.S. military.

    databreaches.net/2026/09/18/th

    #Navigate360 #P3GlobalIntel #databreach #cybersecurity #incidentresponse

    @douglevin

  10. An unauthorized ScreenConnect session, a fake WindowsUpdate.exe, and repeated relay traffic were enough to treat a client workstation as potentially compromised.

    I wrote up the investigation, including what quarantine and a clean second scan did—and did not—prove.

    kylereddoch.me/blog/from-the-f

    #Cybersecurity #IncidentResponse #MSP #ScreenConnect

  11. An unauthorized ScreenConnect session, a fake WindowsUpdate.exe, and repeated relay traffic were enough to treat a client workstation as potentially compromised.

    I wrote up the investigation, including what quarantine and a clean second scan did—and did not—prove.

    kylereddoch.me/blog/from-the-f

    #Cybersecurity #IncidentResponse #MSP #ScreenConnect

  12. An unauthorized ScreenConnect session, a fake WindowsUpdate.exe, and repeated relay traffic were enough to treat a client workstation as potentially compromised.

    I wrote up the investigation, including what quarantine and a clean second scan did—and did not—prove.

    kylereddoch.me/blog/from-the-f

    #Cybersecurity #IncidentResponse #MSP #ScreenConnect

  13. An unauthorized ScreenConnect session, a fake WindowsUpdate.exe, and repeated relay traffic were enough to treat a client workstation as potentially compromised.

    I wrote up the investigation, including what quarantine and a clean second scan did—and did not—prove.

    kylereddoch.me/blog/from-the-f

    #Cybersecurity #IncidentResponse #MSP #ScreenConnect

  14. An unauthorized ScreenConnect session, a fake WindowsUpdate.exe, and repeated relay traffic were enough to treat a client workstation as potentially compromised.

    I wrote up the investigation, including what quarantine and a clean second scan did—and did not—prove.

    kylereddoch.me/blog/from-the-f

    #Cybersecurity #IncidentResponse #MSP #ScreenConnect

  15. Security Teams Struggle to Connect Dots in Cross-Environment Attacks

    Attacks are getting more complex, with 43% of incidents spreading across four or more environments - and in some cases, as many as eight. Security teams struggle to piece together these cross-environment attacks, making it crucial to connect the dots between disparate signals.

    osintsights.com/security-teams

    #CrossEnvironmentAttacks #IncidentResponse #CloudSecurity #EndpointSecurity #IdentitySecurity

  16. I agree with this blog post - the more we have AI handling outages, repairing things, etc. the less humans will know about the systems they run.

    Not much can replace hands on experience, troubleshooting, and learning systems design. I work in consulting (all things VMware) and if I stop learning, I'm out of date. I've held that position for a while and that's not changing in the age of AI. In fact, it's even more important.

    #ai #engineering #handsonexperience #knowledgework #incidentresponse #learning #it #work

    sylvainkalache.com/blog/ai-han

  17. I agree with this blog post - the more we have AI handling outages, repairing things, etc. the less humans will know about the systems they run.

    Not much can replace hands on experience, troubleshooting, and learning systems design. I work in consulting (all things VMware) and if I stop learning, I'm out of date. I've held that position for a while and that's not changing in the age of AI. In fact, it's even more important.

    #ai #engineering #handsonexperience #knowledgework #incidentresponse #learning #it #work

    sylvainkalache.com/blog/ai-han

  18. I agree with this blog post - the more we have AI handling outages, repairing things, etc. the less humans will know about the systems they run.

    Not much can replace hands on experience, troubleshooting, and learning systems design. I work in consulting (all things VMware) and if I stop learning, I'm out of date. I've held that position for a while and that's not changing in the age of AI. In fact, it's even more important.

    #ai #engineering #handsonexperience #knowledgework #incidentresponse #learning #it #work

    sylvainkalache.com/blog/ai-han

  19. I agree with this blog post - the more we have AI handling outages, repairing things, etc. the less humans will know about the systems they run.

    Not much can replace hands on experience, troubleshooting, and learning systems design. I work in consulting (all things VMware) and if I stop learning, I'm out of date. I've held that position for a while and that's not changing in the age of AI. In fact, it's even more important.

    #ai #engineering #handsonexperience #knowledgework #incidentresponse #learning #it #work

    sylvainkalache.com/blog/ai-han

  20. I agree with this blog post - the more we have AI handling outages, repairing things, etc. the less humans will know about the systems they run.

    Not much can replace hands on experience, troubleshooting, and learning systems design. I work in consulting (all things VMware) and if I stop learning, I'm out of date. I've held that position for a while and that's not changing in the age of AI. In fact, it's even more important.

    #ai #engineering #handsonexperience #knowledgework #incidentresponse #learning #it #work

    sylvainkalache.com/blog/ai-han

  21. 🔵 THREAT INTELLIGENCE

    Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

    Vulnerability | CRITICAL
    CVEs: CVE-2026-76460

    Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in...

    Full analysis:
    yazoul.net/news/article/cisco-

    by Yazoul AI

    #InfoSec #Ransomware #IncidentResponse

  22. Spain's AEPD disclosed the first notified breach where an AI agent chained multiple attack stages autonomously. It moves beyond AI-assisted phishing to agent-driven execution across the kill chain, with major implications for detection and breach reporting. #AgenticAI #DataBreach #IncidentResponse

    cyberworldops.eu/en/spain-inve

  23. Spain's AEPD disclosed the first notified breach where an AI agent chained multiple attack stages autonomously. It moves beyond AI-assisted phishing to agent-driven execution across the kill chain, with major implications for detection and breach reporting. #AgenticAI #DataBreach #IncidentResponse

    cyberworldops.eu/en/spain-inve

  24. DORA-Audits schaffen Dokumentation, aber echte Resilienz zeigt sich erst im Ernstfall: Sind Ihre Sicherheitsprozesse auch praktisch einsatzbereit? Nur regelmäßige, realistische Incident-Response-Übungen machen IT-Teams wirklich krisenfest.
    #Aktuell #Security #DORA #IncidentResponse #Resilienz #SecuritybyDesign #x26SDZT #ZeroTrust
    it-finanzmagazin.de/audit-best...
    it-finanzmagazin.de/audit-best

  25. DORA-Audits schaffen Dokumentation, aber echte Resilienz zeigt sich erst im Ernstfall: Sind Ihre Sicherheitsprozesse auch praktisch einsatzbereit? Nur regelmäßige, realistische Incident-Response-Übungen machen IT-Teams wirklich krisenfest.
    #Aktuell #Security #DORA #IncidentResponse #Resilienz #SecuritybyDesign #x26SDZT #ZeroTrust
    it-finanzmagazin.de/audit-best...
    it-finanzmagazin.de/audit-best

  26. Want to be part of FIRST LAC 2026? We’d love to have you there, and we’d love to have you as a sponsor.

    The FIRST Regional Symposium for Latin America & the Caribbean is an opportunity to bring together the people, ideas, and organizations working to strengthen incident response across the region.

    Support the event as a sponsor and put your organization at the heart of the conversation.

    📍 Mendoza, Argentina
    📅 October 21–22, 2026

    Sponsorship opportunities are available now.

    🔗 first.org/events/symposium/lat

    #FIRSTLAC26 #FIRSTEvents #Cybersecurity #IncidentResponse #LAC #Sponsorship

  27. Want to be part of FIRST LAC 2026? We’d love to have you there, and we’d love to have you as a sponsor.

    The FIRST Regional Symposium for Latin America & the Caribbean is an opportunity to bring together the people, ideas, and organizations working to strengthen incident response across the region.

    Support the event as a sponsor and put your organization at the heart of the conversation.

    📍 Mendoza, Argentina
    📅 October 21–22, 2026

    Sponsorship opportunities are available now.

    🔗 first.org/events/symposium/lat

    #FIRSTLAC26 #FIRSTEvents #Cybersecurity #IncidentResponse #LAC #Sponsorship

  28. Want to be part of FIRST LAC 2026? We’d love to have you there, and we’d love to have you as a sponsor.

    The FIRST Regional Symposium for Latin America & the Caribbean is an opportunity to bring together the people, ideas, and organizations working to strengthen incident response across the region.

    Support the event as a sponsor and put your organization at the heart of the conversation.

    📍 Mendoza, Argentina
    📅 October 21–22, 2026

    Sponsorship opportunities are available now.

    🔗 first.org/events/symposium/lat

    #FIRSTLAC26 #FIRSTEvents #Cybersecurity #IncidentResponse #LAC #Sponsorship

  29. Want to be part of FIRST LAC 2026? We’d love to have you there, and we’d love to have you as a sponsor.

    The FIRST Regional Symposium for Latin America & the Caribbean is an opportunity to bring together the people, ideas, and organizations working to strengthen incident response across the region.

    Support the event as a sponsor and put your organization at the heart of the conversation.

    📍 Mendoza, Argentina
    📅 October 21–22, 2026

    Sponsorship opportunities are available now.

    🔗 first.org/events/symposium/lat

    #FIRSTLAC26 #FIRSTEvents #Cybersecurity #IncidentResponse #LAC #Sponsorship

  30. Want to be part of FIRST LAC 2026? We’d love to have you there, and we’d love to have you as a sponsor.

    The FIRST Regional Symposium for Latin America & the Caribbean is an opportunity to bring together the people, ideas, and organizations working to strengthen incident response across the region.

    Support the event as a sponsor and put your organization at the heart of the conversation.

    📍 Mendoza, Argentina
    📅 October 21–22, 2026

    Sponsorship opportunities are available now.

    🔗 first.org/events/symposium/lat

    #FIRSTLAC26 #FIRSTEvents #Cybersecurity #IncidentResponse #LAC #Sponsorship

  31. Ransomware Recovery Plans Routinely Crumble Under Attack

    The harsh reality is that most ransomware recovery plans fail to deliver, with a staggering 99.5% of over 800 clients assessed by Fenix24 missing their 24-48 hour recovery targets. Even partial recoveries were rare, and full operations often took weeks to restore.

    osintsights.com/ransomware-rec

    #Ransomware #RansomwareRecovery #IncidentResponse #Fenix24 #StateOfRecoverability

  32. Sysdig reports a human operator exploited CVE-2026-39987, a pre-auth RCE in Marimo, and pivoted from the notebook to an SSH bastion in eight seconds with a custom Python toolkit. It shows manual tradecraft can match automation speed, shrinking detection windows for exposed dev infrastructure. #MarimoRce #SshBastion #IncidentResponse

    cyberworldops.eu/en/human-oper

  33. Meet our keynote speaker: Edward Sakocius, Network Intrusion Forensic Analyst with the U.S. Secret Service.

    With 18 years of law enforcement experience, Special Agent Sakocius brings valuable expertise in digital forensics and incident response through the Empire State Cyber Fraud Task Force.

    Standard tickets are $280 but prices increase to $380 on September 20. Register now!
    eventzilla.net/e/rochester-sec
    #RochesterSecuritySummit #Cybersecurity #DigitalForensics #IncidentResponse #GRC #RochesterNY

  34. Meet our keynote speaker: Edward Sakocius, Network Intrusion Forensic Analyst with the U.S. Secret Service.

    With 18 years of law enforcement experience, Special Agent Sakocius brings valuable expertise in digital forensics and incident response through the Empire State Cyber Fraud Task Force.

    Standard tickets are $280 but prices increase to $380 on September 20. Register now!
    eventzilla.net/e/rochester-sec
    #RochesterSecuritySummit #Cybersecurity #DigitalForensics #IncidentResponse #GRC #RochesterNY

  35. 🔵 THREAT INTELLIGENCE

    CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

    Vulnerability | CRITICAL
    CVEs: CVE-2026-42016

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise...

    Full analysis:
    yazoul.net/news/article/cisa-a

    by Yazoul AI

    #ThreatIntel #SecurityNews #IncidentResponse

  36. Security Tip: The best IR plan is one that has been practiced. 🛡️ Tabletop Exercises (TTX) are low-cost, high-impact simulations where stakeholders discuss roles during a hypothetical security incident. Benefits: Identifies gaps in the plan, clarifies roles, and improves communication. Don't wait for a real CVE to test your team. Resources: cvedatabase.com #CVE #InfoSec #CyberSecurity #IncidentResponse

  37. Security Tip: The best IR plan is one that has been practiced. 🛡️ Tabletop Exercises (TTX) are low-cost, high-impact simulations where stakeholders discuss roles during a hypothetical security incident. Benefits: Identifies gaps in the plan, clarifies roles, and improves communication. Don't wait for a real CVE to test your team. Resources: cvedatabase.com