#incident-response — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #incident-response, aggregated by home.social.
-
🔵 THREAT INTELLIGENCE
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
Vulnerability | CRITICAL
CVEs: CVE-2026-83548The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV)...
Full analysis:
https://www.yazoul.net/news/article/cisa-adds-seven-exploited-flaws-as-attackers-deploy-reverse-shells-and-crypto-miby Yazoul AI
-
🔵 THREAT INTELLIGENCE
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
Vulnerability | CRITICAL
CVEs: CVE-2026-83548The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV)...
Full analysis:
https://www.yazoul.net/news/article/cisa-adds-seven-exploited-flaws-as-attackers-deploy-reverse-shells-and-crypto-miby Yazoul AI
-
We Have a DBIR for Breaches. We Have Nothing for AI - Part 2
https://youtu.be/2dNQH4m3xNc #CyberSecurity #ArtificialIntelligence #AISecurity #ThreatIntelligence #InfoSec #CISO #RiskManagement #IncidentResponse #OWASP #AIGovernance -
We Have a DBIR for Breaches. We Have Nothing for AI - Part 2
https://youtu.be/2dNQH4m3xNc #CyberSecurity #ArtificialIntelligence #AISecurity #ThreatIntelligence #InfoSec #CISO #RiskManagement #IncidentResponse #OWASP #AIGovernance -
We Have a DBIR for Breaches. We Have Nothing for AI - Part 2
https://youtu.be/2dNQH4m3xNc #CyberSecurity #ArtificialIntelligence #AISecurity #ThreatIntelligence #InfoSec #CISO #RiskManagement #IncidentResponse #OWASP #AIGovernance -
We Have a DBIR for Breaches. We Have Nothing for AI - Part 2
https://youtu.be/2dNQH4m3xNc #CyberSecurity #ArtificialIntelligence #AISecurity #ThreatIntelligence #InfoSec #CISO #RiskManagement #IncidentResponse #OWASP #AIGovernance -
We Have a DBIR for Breaches. We Have Nothing for AI - Part 2
https://youtu.be/2dNQH4m3xNc #CyberSecurity #ArtificialIntelligence #AISecurity #ThreatIntelligence #InfoSec #CISO #RiskManagement #IncidentResponse #OWASP #AIGovernance -
Security Tip: Prioritize blameless post-mortems in your Incident Response plan. 🛡️ When a breach occurs, the goal shouldn't be to find who to blame, but to understand the systemic weaknesses that allowed the event to happen. Documenting lessons learned and tracking remediation tasks ensures you don't fight the same fire twice. Build your knowledge base: https://cvedatabase.com #InfoSec #CyberSecurity #IncidentResponse #SysAdmin
-
Security Tip: Prioritize blameless post-mortems in your Incident Response plan. 🛡️ When a breach occurs, the goal shouldn't be to find who to blame, but to understand the systemic weaknesses that allowed the event to happen. Documenting lessons learned and tracking remediation tasks ensures you don't fight the same fire twice. Build your knowledge base: https://cvedatabase.com #InfoSec #CyberSecurity #IncidentResponse #SysAdmin
-
ChatGPT, Claude and Grok experienced failures in the same time window. The evidence so far doesn’t indicate a single root cause — but the event highlights risks around shared dependencies and resilience in AI deployments. Read the full analysis: https://wix.to/7WXfVqZ
Key takeaways:
• Timeline of events
• Possible explanations and gaps
• Implications for reliability and business continuity#AI
#Reliability
#TechLeadership
#MachineLearning
#IncidentResponse -
ChatGPT, Claude and Grok experienced failures in the same time window. The evidence so far doesn’t indicate a single root cause — but the event highlights risks around shared dependencies and resilience in AI deployments. Read the full analysis: https://wix.to/7WXfVqZ
Key takeaways:
• Timeline of events
• Possible explanations and gaps
• Implications for reliability and business continuity#AI
#Reliability
#TechLeadership
#MachineLearning
#IncidentResponse -
ChatGPT, Claude and Grok experienced failures in the same time window. The evidence so far doesn’t indicate a single root cause — but the event highlights risks around shared dependencies and resilience in AI deployments. Read the full analysis: https://wix.to/7WXfVqZ
Key takeaways:
• Timeline of events
• Possible explanations and gaps
• Implications for reliability and business continuity#AI
#Reliability
#TechLeadership
#MachineLearning
#IncidentResponse -
ChatGPT, Claude and Grok experienced failures in the same time window. The evidence so far doesn’t indicate a single root cause — but the event highlights risks around shared dependencies and resilience in AI deployments. Read the full analysis: https://wix.to/7WXfVqZ
Key takeaways:
• Timeline of events
• Possible explanations and gaps
• Implications for reliability and business continuity#AI
#Reliability
#TechLeadership
#MachineLearning
#IncidentResponse -
ChatGPT, Claude and Grok experienced failures in the same time window. The evidence so far doesn’t indicate a single root cause — but the event highlights risks around shared dependencies and resilience in AI deployments. Read the full analysis: https://wix.to/7WXfVqZ
Key takeaways:
• Timeline of events
• Possible explanations and gaps
• Implications for reliability and business continuity#AI
#Reliability
#TechLeadership
#MachineLearning
#IncidentResponse -
I understand why companies provide free tiers / trials of their services but from an IR standpoint they are really troublesome.
Phishing could be reduced if they enacted speedbumps to these services.
For example:
Phishing invoices from QuickBooks.
Phishing email and websites through Zoho Desk.
LinkedIn phishing, tricking users to download malware from Dropbox.
Using Calendly for job scams.
-
I understand why companies provide free tiers / trials of their services but from an IR standpoint they are really troublesome.
Phishing could be reduced if they enacted speedbumps to these services.
For example:
Phishing invoices from QuickBooks.
Phishing email and websites through Zoho Desk.
LinkedIn phishing, tricking users to download malware from Dropbox.
Using Calendly for job scams.
-
I understand why companies provide free tiers / trials of their services but from an IR standpoint they are really troublesome.
Phishing could be reduced if they enacted speedbumps to these services.
For example:
Phishing invoices from QuickBooks.
Phishing email and websites through Zoho Desk.
LinkedIn phishing, tricking users to download malware from Dropbox.
Using Calendly for job scams.
-
I understand why companies provide free tiers / trials of their services but from an IR standpoint they are really troublesome.
Phishing could be reduced if they enacted speedbumps to these services.
For example:
Phishing invoices from QuickBooks.
Phishing email and websites through Zoho Desk.
LinkedIn phishing, tricking users to download malware from Dropbox.
Using Calendly for job scams.
-
I understand why companies provide free tiers / trials of their services but from an IR standpoint they are really troublesome.
Phishing could be reduced if they enacted speedbumps to these services.
For example:
Phishing invoices from QuickBooks.
Phishing email and websites through Zoho Desk.
LinkedIn phishing, tricking users to download malware from Dropbox.
Using Calendly for job scams.
-
Loqi has a clean timeline and enough evidence for the incident report. A good day. LogoRRR keeps the searches and surrounding lines close while you write it up.
Image: AI-generated Loqi artwork.
-
Loqi has a clean timeline and enough evidence for the incident report. A good day. LogoRRR keeps the searches and surrounding lines close while you write it up.
Image: AI-generated Loqi artwork.
-
There it is: one odd line buried in a very ordinary million. LogoRRR helps Loqi connect it with the surrounding timestamps, searches, and matching events.
Image: AI-generated Loqi artwork.
-
There it is: one odd line buried in a very ordinary million. LogoRRR helps Loqi connect it with the surrounding timestamps, searches, and matching events.
Image: AI-generated Loqi artwork.
-
Security Tip: Don't let your Incident Response plan gather dust. 🛡️ Regular tabletop exercises (TTX) are essential for technical and leadership teams. They help identify "who does what" during high-pressure events like a zero-day exploit. Use these sessions to refine your playbooks and ensure everyone knows their role. For the latest vulnerability intel to power your scenarios, visit https://cvedatabase.com #InfoSec #CyberSecurity #DFIR #IncidentResponse
-
Want to be part of FIRST LAC 2026? We’d love to have you there, and we’d love to have you as a sponsor.
The FIRST Regional Symposium for Latin America & the Caribbean is an opportunity to bring together the people, ideas, and organizations working to strengthen incident response across the region.
Support the event as a sponsor and put your organization at the heart of the conversation.
📍 Mendoza, Argentina
📅 October 21–22, 2026Sponsorship opportunities are available now.
🔗 https://www.first.org/events/symposium/latam2026/
#FIRSTLAC26 #FIRSTEvents #Cybersecurity #IncidentResponse #LAC #Sponsorship
-
Want to be part of FIRST LAC 2026? We’d love to have you there, and we’d love to have you as a sponsor.
The FIRST Regional Symposium for Latin America & the Caribbean is an opportunity to bring together the people, ideas, and organizations working to strengthen incident response across the region.
Support the event as a sponsor and put your organization at the heart of the conversation.
📍 Mendoza, Argentina
📅 October 21–22, 2026Sponsorship opportunities are available now.
🔗 https://www.first.org/events/symposium/latam2026/
#FIRSTLAC26 #FIRSTEvents #Cybersecurity #IncidentResponse #LAC #Sponsorship
-
Want to be part of FIRST LAC 2026? We’d love to have you there, and we’d love to have you as a sponsor.
The FIRST Regional Symposium for Latin America & the Caribbean is an opportunity to bring together the people, ideas, and organizations working to strengthen incident response across the region.
Support the event as a sponsor and put your organization at the heart of the conversation.
📍 Mendoza, Argentina
📅 October 21–22, 2026Sponsorship opportunities are available now.
🔗 https://www.first.org/events/symposium/latam2026/
#FIRSTLAC26 #FIRSTEvents #Cybersecurity #IncidentResponse #LAC #Sponsorship
-
Want to be part of FIRST LAC 2026? We’d love to have you there, and we’d love to have you as a sponsor.
The FIRST Regional Symposium for Latin America & the Caribbean is an opportunity to bring together the people, ideas, and organizations working to strengthen incident response across the region.
Support the event as a sponsor and put your organization at the heart of the conversation.
📍 Mendoza, Argentina
📅 October 21–22, 2026Sponsorship opportunities are available now.
🔗 https://www.first.org/events/symposium/latam2026/
#FIRSTLAC26 #FIRSTEvents #Cybersecurity #IncidentResponse #LAC #Sponsorship
-
Want to be part of FIRST LAC 2026? We’d love to have you there, and we’d love to have you as a sponsor.
The FIRST Regional Symposium for Latin America & the Caribbean is an opportunity to bring together the people, ideas, and organizations working to strengthen incident response across the region.
Support the event as a sponsor and put your organization at the heart of the conversation.
📍 Mendoza, Argentina
📅 October 21–22, 2026Sponsorship opportunities are available now.
🔗 https://www.first.org/events/symposium/latam2026/
#FIRSTLAC26 #FIRSTEvents #Cybersecurity #IncidentResponse #LAC #Sponsorship
-
New blog post! Yes another one!
Incident Story Time is a weekly ritual that gives us a chance to share and learn from incidents.
-
New blog post! Yes another one!
Incident Story Time is a weekly ritual that gives us a chance to share and learn from incidents.
-
New blog post! Yes another one!
Incident Story Time is a weekly ritual that gives us a chance to share and learn from incidents.
-
New blog post! Yes another one!
Incident Story Time is a weekly ritual that gives us a chance to share and learn from incidents.
-
New blog post! Yes another one!
Incident Story Time is a weekly ritual that gives us a chance to share and learn from incidents.
-
🌐 In this week's "Improving Security Across Nations with FIRST" video series, we spotlight Ken van Wyk, FIRST Member & President and Principal Consultant, KRvW Associates, LLC and #FIRSTCON26 speaker.
He shares how the friendships built outside the conference room are what make global incident response possible:
💡 A founding perspective - A FIRST member since the organization's start, with 11 years on the Steering Committee and Board of Directors
🗣️ Denver, 1992 - Recalls an evening after a long conference day that turned into hours of conversation with colleagues, swapping stories about life, not just work, and turning strangers into lifelong friends
🤝 Trust across borders - "Nobody has an agenda. It's just fun – and from that fun comes trust." That trust means calling a person you know when an incident hits, not just a national CSIRT
📺 Watch below!
-
🌐 In this week's "Improving Security Across Nations with FIRST" video series, we spotlight Ken van Wyk, FIRST Member & President and Principal Consultant, KRvW Associates, LLC and #FIRSTCON26 speaker.
He shares how the friendships built outside the conference room are what make global incident response possible:
💡 A founding perspective - A FIRST member since the organization's start, with 11 years on the Steering Committee and Board of Directors
🗣️ Denver, 1992 - Recalls an evening after a long conference day that turned into hours of conversation with colleagues, swapping stories about life, not just work, and turning strangers into lifelong friends
🤝 Trust across borders - "Nobody has an agenda. It's just fun – and from that fun comes trust." That trust means calling a person you know when an incident hits, not just a national CSIRT
📺 Watch below!
-
🌐 In this week's "Improving Security Across Nations with FIRST" video series, we spotlight Ken van Wyk, FIRST Member & President and Principal Consultant, KRvW Associates, LLC and #FIRSTCON26 speaker.
He shares how the friendships built outside the conference room are what make global incident response possible:
💡 A founding perspective - A FIRST member since the organization's start, with 11 years on the Steering Committee and Board of Directors
🗣️ Denver, 1992 - Recalls an evening after a long conference day that turned into hours of conversation with colleagues, swapping stories about life, not just work, and turning strangers into lifelong friends
🤝 Trust across borders - "Nobody has an agenda. It's just fun – and from that fun comes trust." That trust means calling a person you know when an incident hits, not just a national CSIRT
📺 Watch below!
-
🌐 In this week's "Improving Security Across Nations with FIRST" video series, we spotlight Ken van Wyk, FIRST Member & President and Principal Consultant, KRvW Associates, LLC and #FIRSTCON26 speaker.
He shares how the friendships built outside the conference room are what make global incident response possible:
💡 A founding perspective - A FIRST member since the organization's start, with 11 years on the Steering Committee and Board of Directors
🗣️ Denver, 1992 - Recalls an evening after a long conference day that turned into hours of conversation with colleagues, swapping stories about life, not just work, and turning strangers into lifelong friends
🤝 Trust across borders - "Nobody has an agenda. It's just fun – and from that fun comes trust." That trust means calling a person you know when an incident hits, not just a national CSIRT
📺 Watch below!
-
🌐 In this week's "Improving Security Across Nations with FIRST" video series, we spotlight Ken van Wyk, FIRST Member & President and Principal Consultant, KRvW Associates, LLC and #FIRSTCON26 speaker.
He shares how the friendships built outside the conference room are what make global incident response possible:
💡 A founding perspective - A FIRST member since the organization's start, with 11 years on the Steering Committee and Board of Directors
🗣️ Denver, 1992 - Recalls an evening after a long conference day that turned into hours of conversation with colleagues, swapping stories about life, not just work, and turning strangers into lifelong friends
🤝 Trust across borders - "Nobody has an agenda. It's just fun – and from that fun comes trust." That trust means calling a person you know when an incident hits, not just a national CSIRT
📺 Watch below!
-
Neue HiWay-Podcast-Folge: „Stimme, Kultur, Netzwerke: Was Frauen in der IT nach vorn bringt“ https://youtu.be/H23n3miURNo
Frauen anzustellen allein reicht nicht. Dafür zu sorgen, dass sie bleiben und aufsteigen, ist mindestens genauso wichtig. Linda Schwarz arbeitet als Security Consultant in der digitalen Forensik und kennt die IT-Sicherheit als Branche, in der Frauen deutlich in der Unterzahl sind. Im Gespräch mit Jaqueline Nayis erklärt sie, was Unternehmen verändern müssen, damit aus dem Einstieg eine langfristige Karriere werden kann.YouTube: https://youtu.be/H23n3miURNo
Spotify: https://open.spotify.com/show/6FwPurxOj5ND2H7UcVizA4
Apple: https://podcasts.apple.com/us/podcast/hiway-wegweiser-f%C3%BCr-digitalisierung-und-sicherheit/id1789738836Moderierte Expertentalks zu Themen, Trends & Herausforderungen aus
✔️ Cybersecurity
✔️ Digitale Transformation
✔️ Business Continuity & Krisenmanagement
✔️ IT-Management
✔️ Regulatorik, Compliance & GovernanceDie nächste HiWay-Folge erscheint am 16.09.2026
#incidentresponse #womenintech #cybersecurity #femaleleadership
-
Neue HiWay-Podcast-Folge: „Stimme, Kultur, Netzwerke: Was Frauen in der IT nach vorn bringt“ https://youtu.be/H23n3miURNo
Frauen anzustellen allein reicht nicht. Dafür zu sorgen, dass sie bleiben und aufsteigen, ist mindestens genauso wichtig. Linda Schwarz arbeitet als Security Consultant in der digitalen Forensik und kennt die IT-Sicherheit als Branche, in der Frauen deutlich in der Unterzahl sind. Im Gespräch mit Jaqueline Nayis erklärt sie, was Unternehmen verändern müssen, damit aus dem Einstieg eine langfristige Karriere werden kann.YouTube: https://youtu.be/H23n3miURNo
Spotify: https://open.spotify.com/show/6FwPurxOj5ND2H7UcVizA4
Apple: https://podcasts.apple.com/us/podcast/hiway-wegweiser-f%C3%BCr-digitalisierung-und-sicherheit/id1789738836Moderierte Expertentalks zu Themen, Trends & Herausforderungen aus
✔️ Cybersecurity
✔️ Digitale Transformation
✔️ Business Continuity & Krisenmanagement
✔️ IT-Management
✔️ Regulatorik, Compliance & GovernanceDie nächste HiWay-Folge erscheint am 16.09.2026
#incidentresponse #womenintech #cybersecurity #femaleleadership
-
Neue HiWay-Podcast-Folge: „Stimme, Kultur, Netzwerke: Was Frauen in der IT nach vorn bringt“ https://youtu.be/H23n3miURNo
Frauen anzustellen allein reicht nicht. Dafür zu sorgen, dass sie bleiben und aufsteigen, ist mindestens genauso wichtig. Linda Schwarz arbeitet als Security Consultant in der digitalen Forensik und kennt die IT-Sicherheit als Branche, in der Frauen deutlich in der Unterzahl sind. Im Gespräch mit Jaqueline Nayis erklärt sie, was Unternehmen verändern müssen, damit aus dem Einstieg eine langfristige Karriere werden kann.YouTube: https://youtu.be/H23n3miURNo
Spotify: https://open.spotify.com/show/6FwPurxOj5ND2H7UcVizA4
Apple: https://podcasts.apple.com/us/podcast/hiway-wegweiser-f%C3%BCr-digitalisierung-und-sicherheit/id1789738836Moderierte Expertentalks zu Themen, Trends & Herausforderungen aus
✔️ Cybersecurity
✔️ Digitale Transformation
✔️ Business Continuity & Krisenmanagement
✔️ IT-Management
✔️ Regulatorik, Compliance & GovernanceDie nächste HiWay-Folge erscheint am 16.09.2026
#incidentresponse #womenintech #cybersecurity #femaleleadership
-
Neue HiWay-Podcast-Folge: „Stimme, Kultur, Netzwerke: Was Frauen in der IT nach vorn bringt“ https://youtu.be/H23n3miURNo
Frauen anzustellen allein reicht nicht. Dafür zu sorgen, dass sie bleiben und aufsteigen, ist mindestens genauso wichtig. Linda Schwarz arbeitet als Security Consultant in der digitalen Forensik und kennt die IT-Sicherheit als Branche, in der Frauen deutlich in der Unterzahl sind. Im Gespräch mit Jaqueline Nayis erklärt sie, was Unternehmen verändern müssen, damit aus dem Einstieg eine langfristige Karriere werden kann.YouTube: https://youtu.be/H23n3miURNo
Spotify: https://open.spotify.com/show/6FwPurxOj5ND2H7UcVizA4
Apple: https://podcasts.apple.com/us/podcast/hiway-wegweiser-f%C3%BCr-digitalisierung-und-sicherheit/id1789738836Moderierte Expertentalks zu Themen, Trends & Herausforderungen aus
✔️ Cybersecurity
✔️ Digitale Transformation
✔️ Business Continuity & Krisenmanagement
✔️ IT-Management
✔️ Regulatorik, Compliance & GovernanceDie nächste HiWay-Folge erscheint am 16.09.2026
#incidentresponse #womenintech #cybersecurity #femaleleadership
-
Neue HiWay-Podcast-Folge: „Stimme, Kultur, Netzwerke: Was Frauen in der IT nach vorn bringt“ https://youtu.be/H23n3miURNo
Frauen anzustellen allein reicht nicht. Dafür zu sorgen, dass sie bleiben und aufsteigen, ist mindestens genauso wichtig. Linda Schwarz arbeitet als Security Consultant in der digitalen Forensik und kennt die IT-Sicherheit als Branche, in der Frauen deutlich in der Unterzahl sind. Im Gespräch mit Jaqueline Nayis erklärt sie, was Unternehmen verändern müssen, damit aus dem Einstieg eine langfristige Karriere werden kann.YouTube: https://youtu.be/H23n3miURNo
Spotify: https://open.spotify.com/show/6FwPurxOj5ND2H7UcVizA4
Apple: https://podcasts.apple.com/us/podcast/hiway-wegweiser-f%C3%BCr-digitalisierung-und-sicherheit/id1789738836Moderierte Expertentalks zu Themen, Trends & Herausforderungen aus
✔️ Cybersecurity
✔️ Digitale Transformation
✔️ Business Continuity & Krisenmanagement
✔️ IT-Management
✔️ Regulatorik, Compliance & GovernanceDie nächste HiWay-Folge erscheint am 16.09.2026
#incidentresponse #womenintech #cybersecurity #femaleleadership
-
This is an old blog post we made during Covid times.
What is interesting, however, is that most of the tools we talk about here are still ruling the roost in IR.
CyLR and Vol2 are pretty much the only things I wouldn't use today. If you add UAC, AVML, and Kunai, the list would be just as good in 2026 as it was in 2020!
Have I missed any new, awesome, developments?
https://www.halkynconsulting.co.uk/a/2020/11/dfir-with-low-cost-or-free-tools/
-
This is an old blog post we made during Covid times.
What is interesting, however, is that most of the tools we talk about here are still ruling the roost in IR.
CyLR and Vol2 are pretty much the only things I wouldn't use today. If you add UAC, AVML, and Kunai, the list would be just as good in 2026 as it was in 2020!
Have I missed any new, awesome, developments?
https://www.halkynconsulting.co.uk/a/2020/11/dfir-with-low-cost-or-free-tools/
-
This is an old blog post we made during Covid times.
What is interesting, however, is that most of the tools we talk about here are still ruling the roost in IR.
CyLR and Vol2 are pretty much the only things I wouldn't use today. If you add UAC, AVML, and Kunai, the list would be just as good in 2026 as it was in 2020!
Have I missed any new, awesome, developments?
https://www.halkynconsulting.co.uk/a/2020/11/dfir-with-low-cost-or-free-tools/
-
This is an old blog post we made during Covid times.
What is interesting, however, is that most of the tools we talk about here are still ruling the roost in IR.
CyLR and Vol2 are pretty much the only things I wouldn't use today. If you add UAC, AVML, and Kunai, the list would be just as good in 2026 as it was in 2020!
Have I missed any new, awesome, developments?
https://www.halkynconsulting.co.uk/a/2020/11/dfir-with-low-cost-or-free-tools/
-
This is an old blog post we made during Covid times.
What is interesting, however, is that most of the tools we talk about here are still ruling the roost in IR.
CyLR and Vol2 are pretty much the only things I wouldn't use today. If you add UAC, AVML, and Kunai, the list would be just as good in 2026 as it was in 2020!
Have I missed any new, awesome, developments?
https://www.halkynconsulting.co.uk/a/2020/11/dfir-with-low-cost-or-free-tools/
-
I've tried to create a Log2Timeline parser that will handle Kunai data. It is still very much an "alpha" version, but I'd welcome any feedback.
https://github.com/TazWake/Kunai_Parser_Plaso-l2t
#linux #dfir #log2timeline #incidentresponse #investigations #cybersecurity
-
I've tried to create a Log2Timeline parser that will handle Kunai data. It is still very much an "alpha" version, but I'd welcome any feedback.
https://github.com/TazWake/Kunai_Parser_Plaso-l2t
#linux #dfir #log2timeline #incidentresponse #investigations #cybersecurity
-
I've tried to create a Log2Timeline parser that will handle Kunai data. It is still very much an "alpha" version, but I'd welcome any feedback.
https://github.com/TazWake/Kunai_Parser_Plaso-l2t
#linux #dfir #log2timeline #incidentresponse #investigations #cybersecurity
-
I've tried to create a Log2Timeline parser that will handle Kunai data. It is still very much an "alpha" version, but I'd welcome any feedback.
https://github.com/TazWake/Kunai_Parser_Plaso-l2t
#linux #dfir #log2timeline #incidentresponse #investigations #cybersecurity
-
I've tried to create a Log2Timeline parser that will handle Kunai data. It is still very much an "alpha" version, but I'd welcome any feedback.
https://github.com/TazWake/Kunai_Parser_Plaso-l2t
#linux #dfir #log2timeline #incidentresponse #investigations #cybersecurity
-
Some logs should stay on the machine that collected them. LogoRRR opens and analyzes local files on your desktop. Loqi can investigate without sending the evidence elsewhere.
Image: AI-generated Loqi artwork.
-
Some logs should stay on the machine that collected them. LogoRRR opens and analyzes local files on your desktop. Loqi can investigate without sending the evidence elsewhere.
Image: AI-generated Loqi artwork.
-
Microsoft observed TerminalFix, a ClickFix variant using fake CAPTCHAs on compromised sites. Victims paste a preloaded PowerShell command into Windows Terminal, believing it is a verification step. Unlike typical ClickFix info-stealer campaigns, this establishes reverse tunnels into corporate networks. #ThreatIntel #IncidentResponse #CyberSecurity
https://cyberworldops.eu/en/terminalfix-turns-fake-captchas-into-tunnels-into-corporate-networks
-
Microsoft observed TerminalFix, a ClickFix variant using fake CAPTCHAs on compromised sites. Victims paste a preloaded PowerShell command into Windows Terminal, believing it is a verification step. Unlike typical ClickFix info-stealer campaigns, this establishes reverse tunnels into corporate networks. #ThreatIntel #IncidentResponse #CyberSecurity
https://cyberworldops.eu/en/terminalfix-turns-fake-captchas-into-tunnels-into-corporate-networks
-
https://www.europesays.com/ie/666078/ KnowBe4 launches Google Workspace email security Defend #AiSecurity #ArtificialIntelligence(AI) #BusinessEmailCompromise #CloudSecurity #Cybersecurity #Éire #EmailSecurity #EnterpriseSecurity #ExplainableAI #Gmail #Google #GoogleWorkspace #IE #IncidentResponse #infosec #Ireland #KnowBe4 #MachineLearning(ML) #Phishing #SecurityOperationsCentres(SOCs) #SocialEngineering #Technology #ThreatDetection #ThreatIntelligence #WorkforceTechnology
-
Fire Ant Evolves: From Hypervisors to Trusted Infrastructure
Fire Ant, first reported in 2025, remained active in 2026 and expanded its operations beyond hypervisors into the trusted infrastructure that routes traffic, authenticates administrators, manages access, and records activity. The main finding is that the actor was no longer targeting only individual systems, it was targeting the infrastructure layer that controls how entire environments connect and operate both within and across organizational boundaries.
https://www.sygnia.co/blog/fire-ant-evolves-from-hypervisors-to-trusted-infrastructure/
#sygnia #incidentresponse #infosec #infrastructure #fireant #chain