home.social

#incidentresponse — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #incidentresponse, aggregated by home.social.

  1. 📈 El requerimiento de profesionales forenses crece 🔍 conoce todas las capacidades de Autopsy 🛡️ ☠️ Curso Autopsy Digital Forensics 2026 🥇 Miércoles 29 y Viernes 31 de Julio ✨ De 8:00 pm a 11:00 pm (UTC -05:00) 📲 WhatsApp: https://wa.me/51949304030 🌎 Info: https://www.reydes.com/archivos/cursos/Curso_Autopsy.pdf #DFIR #DigitalForensics #CyberInvestigation #CyberCrime #OSINT #CyberSecurity #BlueTeam #Malware #IncidentResponse
  2. In January 2025, the WA attorney general sued T-Mobile over a data breach that affected 2M residents (this was the 79M T-Mobile breach). One of the issues in the litigation was that T-Mobile didn't properly notify those affected of the breach -- it omitted telling them in SMS notifications that their SSN had been acquired.

    For background, see atg.wa.gov/news/news-releases/

    Now a court has agreed with the state that the text message notifications did not comply with the state's breach notification law:

    seattletimes.com/business/t-mo

    T-Mobile says it will appeal.

    #databreach #incidentresponse #notifications #TMobile

  3. In January 2025, the WA attorney general sued T-Mobile over a data breach that affected 2M residents (this was the 79M T-Mobile breach). One of the issues in the litigation was that T-Mobile didn't properly notify those affected of the breach -- it omitted telling them in SMS notifications that their SSN had been acquired.

    For background, see atg.wa.gov/news/news-releases/

    Now a court has agreed with the state that the text message notifications did not comply with the state's breach notification law:

    seattletimes.com/business/t-mo

    T-Mobile says it will appeal.

    #databreach #incidentresponse #notifications #TMobile

  4. In January 2025, the WA attorney general sued T-Mobile over a data breach that affected 2M residents (this was the 79M T-Mobile breach). One of the issues in the litigation was that T-Mobile didn't properly notify those affected of the breach -- it omitted telling them in SMS notifications that their SSN had been acquired.

    For background, see atg.wa.gov/news/news-releases/

    Now a court has agreed with the state that the text message notifications did not comply with the state's breach notification law:

    seattletimes.com/business/t-mo

    T-Mobile says it will appeal.

    #databreach #incidentresponse #notifications #TMobile

  5. In January 2025, the WA attorney general sued T-Mobile over a data breach that affected 2M residents (this was the 79M T-Mobile breach). One of the issues in the litigation was that T-Mobile didn't properly notify those affected of the breach -- it omitted telling them in SMS notifications that their SSN had been acquired.

    For background, see atg.wa.gov/news/news-releases/

    Now a court has agreed with the state that the text message notifications did not comply with the state's breach notification law:

    seattletimes.com/business/t-mo

    T-Mobile says it will appeal.

    #databreach #incidentresponse #notifications #TMobile

  6. In January 2025, the WA attorney general sued T-Mobile over a data breach that affected 2M residents (this was the 79M T-Mobile breach). One of the issues in the litigation was that T-Mobile didn't properly notify those affected of the breach -- it omitted telling them in SMS notifications that their SSN had been acquired.

    For background, see atg.wa.gov/news/news-releases/

    Now a court has agreed with the state that the text message notifications did not comply with the state's breach notification law:

    seattletimes.com/business/t-mo

    T-Mobile says it will appeal.

    #databreach #incidentresponse #notifications #TMobile

  7. 🎙️New FIRST Impressions Podcast Episode: Tim Brown (Team8)

    Recorded live at #FIRSTCON26 following his opening keynote, Tim Brown, CISO-in-Residence at Team8 and former SolarWinds CISO, shares an incredibly candid conversation about leading through one of cybersecurity's most consequential incidents.

    From the technical realities of incident response to the often-overlooked human impact of prolonged crisis, Tim discusses resilience, recovery, leadership, and why taking care of your team is just as important as protecting your infrastructure.

    Whether you're an incident responder, security leader, or simply interested in the people behind cybersecurity, this episode offers thoughtful lessons that extend far beyond technology.

    🎧 Tune in to hear one of FIRSTCON26's keynote speakers reflect on leadership, resilience, and finding growth through adversity.

    media.first.org/podcasts/FIRST

    #FIRSTCON26 #FIRSTImpressions #Cybersecurity #IncidentResponse #Leadership #Team8 #CISO #Resilience #SecurityLeadership

  8. 🎙️New FIRST Impressions Podcast Episode: Tim Brown (Team8)

    Recorded live at #FIRSTCON26 following his opening keynote, Tim Brown, CISO-in-Residence at Team8 and former SolarWinds CISO, shares an incredibly candid conversation about leading through one of cybersecurity's most consequential incidents.

    From the technical realities of incident response to the often-overlooked human impact of prolonged crisis, Tim discusses resilience, recovery, leadership, and why taking care of your team is just as important as protecting your infrastructure.

    Whether you're an incident responder, security leader, or simply interested in the people behind cybersecurity, this episode offers thoughtful lessons that extend far beyond technology.

    🎧 Tune in to hear one of FIRSTCON26's keynote speakers reflect on leadership, resilience, and finding growth through adversity.

    media.first.org/podcasts/FIRST

    #FIRSTCON26 #FIRSTImpressions #Cybersecurity #IncidentResponse #Leadership #Team8 #CISO #Resilience #SecurityLeadership

  9. 🎙️New FIRST Impressions Podcast Episode: Tim Brown (Team8)

    Recorded live at #FIRSTCON26 following his opening keynote, Tim Brown, CISO-in-Residence at Team8 and former SolarWinds CISO, shares an incredibly candid conversation about leading through one of cybersecurity's most consequential incidents.

    From the technical realities of incident response to the often-overlooked human impact of prolonged crisis, Tim discusses resilience, recovery, leadership, and why taking care of your team is just as important as protecting your infrastructure.

    Whether you're an incident responder, security leader, or simply interested in the people behind cybersecurity, this episode offers thoughtful lessons that extend far beyond technology.

    🎧 Tune in to hear one of FIRSTCON26's keynote speakers reflect on leadership, resilience, and finding growth through adversity.

    media.first.org/podcasts/FIRST

    #FIRSTCON26 #FIRSTImpressions #Cybersecurity #IncidentResponse #Leadership #Team8 #CISO #Resilience #SecurityLeadership

  10. 🎙️New FIRST Impressions Podcast Episode: Tim Brown (Team8)

    Recorded live at #FIRSTCON26 following his opening keynote, Tim Brown, CISO-in-Residence at Team8 and former SolarWinds CISO, shares an incredibly candid conversation about leading through one of cybersecurity's most consequential incidents.

    From the technical realities of incident response to the often-overlooked human impact of prolonged crisis, Tim discusses resilience, recovery, leadership, and why taking care of your team is just as important as protecting your infrastructure.

    Whether you're an incident responder, security leader, or simply interested in the people behind cybersecurity, this episode offers thoughtful lessons that extend far beyond technology.

    🎧 Tune in to hear one of FIRSTCON26's keynote speakers reflect on leadership, resilience, and finding growth through adversity.

    media.first.org/podcasts/FIRST

    #FIRSTCON26 #FIRSTImpressions #Cybersecurity #IncidentResponse #Leadership #Team8 #CISO #Resilience #SecurityLeadership

  11. 🎙️New FIRST Impressions Podcast Episode: Tim Brown (Team8)

    Recorded live at #FIRSTCON26 following his opening keynote, Tim Brown, CISO-in-Residence at Team8 and former SolarWinds CISO, shares an incredibly candid conversation about leading through one of cybersecurity's most consequential incidents.

    From the technical realities of incident response to the often-overlooked human impact of prolonged crisis, Tim discusses resilience, recovery, leadership, and why taking care of your team is just as important as protecting your infrastructure.

    Whether you're an incident responder, security leader, or simply interested in the people behind cybersecurity, this episode offers thoughtful lessons that extend far beyond technology.

    🎧 Tune in to hear one of FIRSTCON26's keynote speakers reflect on leadership, resilience, and finding growth through adversity.

    media.first.org/podcasts/FIRST

    #FIRSTCON26 #FIRSTImpressions #Cybersecurity #IncidentResponse #Leadership #Team8 #CISO #Resilience #SecurityLeadership

  12. Security Tip: A technical incident response plan is only half the battle. 🛡️

    Conduct regular tabletop exercises that include stakeholders from Legal, Communications, and Executive leadership. Simulating a breach helps identify communication gaps and decision-making bottlenecks that technical logs won't show. Practice makes your response cohesive and fast.

    Stay informed on the latest threats: cvedatabase.com

  13. 📢 Cybersecurity professionals, this is your reminder to register!

    📅 The 2026 FIRST Regional Symposium for Asia Pacific & Joint APCERT AGM is headed to Busan, Republic of Korea, on November 5-6, 2026.

    Connect with leading incident response teams, cybersecurity experts, and practitioners from across the Asia Pacific region and beyond. Whether you're looking to expand your network, gain fresh insights, or enhance your team's capabilities, this event is designed for you.

    ⏳ Seats are filling quickly, so secure your spot and join us for two days of learning, collaboration, and community.

    🔗go.first.org/wXQlW

    #FIRSTAP26 #APCERT #IncidentResponse #CyberResilience

  14. 📢 Cybersecurity professionals, this is your reminder to register!

    📅 The 2026 FIRST Regional Symposium for Asia Pacific & Joint APCERT AGM is headed to Busan, Republic of Korea, on November 5-6, 2026.

    Connect with leading incident response teams, cybersecurity experts, and practitioners from across the Asia Pacific region and beyond. Whether you're looking to expand your network, gain fresh insights, or enhance your team's capabilities, this event is designed for you.

    ⏳ Seats are filling quickly, so secure your spot and join us for two days of learning, collaboration, and community.

    🔗go.first.org/wXQlW

    #FIRSTAP26 #APCERT #IncidentResponse #CyberResilience

  15. Security Tip: Don't wait for a breach to find the gaps in your Incident Response plan. 🛡️

    Run regular Tabletop Exercises (TTX) to test your workflows, decision-making, and communication channels. A plan on paper is just a theory until it's practiced. Refine your playbooks before you actually need them.

    Research vulnerabilities and stay ahead of the curve: cvedatabase.com

  16. Security Tip: Don't wait for a breach to find the gaps in your Incident Response plan. 🛡️

    Run regular Tabletop Exercises (TTX) to test your workflows, decision-making, and communication channels. A plan on paper is just a theory until it's practiced. Refine your playbooks before you actually need them.

    Research vulnerabilities and stay ahead of the curve: cvedatabase.com

    #InfoSec #CyberSecurity #IncidentResponse #CVE #CISO

  17. Security Tip: Don't wait for a breach to find the gaps in your Incident Response plan. 🛡️

    Run regular Tabletop Exercises (TTX) to test your workflows, decision-making, and communication channels. A plan on paper is just a theory until it's practiced. Refine your playbooks before you actually need them.

    Research vulnerabilities and stay ahead of the curve: cvedatabase.com

    #InfoSec #CyberSecurity #IncidentResponse #CVE #CISO

  18. Weekly Crypto Alert: $3.1M drained from 431 wallets on May 27 via Ill Bloom flaw. Older mobile wallets with weak random-number generators are at risk. Check your seed phrase at illbloom.org. Hardware wallets and most software wallets are safe. Stay secure! #CryptoSafety #IllBloomAlert

    Source: thehackernews.com/2026/07/atta

    #infosec #cve #pentesting #threatintel #malwareanalysis #incidentresponse #redteam #ethicalhacking #networksecurity #zerotrust #bugbounty

  19. 🔵 THREAT INTELLIGENCE

    Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access

    Vulnerability | CRITICAL
    CVEs: CVE-2026-16232

    Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company's SmartConsole graphical user...

    Full analysis:
    yazoul.net/news/article/check-

    #CyberSecurity #APT #IncidentResponse

  20. 🔵 THREAT INTELLIGENCE

    Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access

    Vulnerability | CRITICAL
    CVEs: CVE-2026-16232

    Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company's SmartConsole graphical user...

    Full analysis:
    yazoul.net/news/article/check-

    #CyberSecurity #APT #IncidentResponse

  21. 🕸️ Hoy Jueves 23 de Julio a las 3:00 pm (UTC -05:00) iniciamos el Curso Forense de Redes 2026 🕷️ 🚀 Jueves 23, Martes 28, Jueves 30 Julio y Martes 4 agosto 🎯 De 3:00 pm a 6:00 pm (UTC -05:00) 👁‍🗨 WhatsApp: https://wa.me/51949304030 👌 Info: https://www.reydes.com/archivos/cursos/Curso_Forense_Redes.pdf #DFIR #NetworkForensics #IncidentResponse #CyberSecurity #Wireshark #NetworkSecurity #ThreatHunting #PCAP
  22. A suspicious document-sharing email appeared to come from a City of Salem account. SPF, DKIM and DMARC passed; Microsoft marked it internally authenticated. The employee confirmed it was a scam.

    When a public agency learns this happened, should it identify and warn other possible recipients--or is internal remediation enough?

    Details: salemdata.net/johnpress/?p=1123

    #InfoSec #Cybersecurity #Phishing #IncidentResponse #CyberLaw #Privacy #LocalGovernment #GovernmentAccountability #security

  23. A suspicious document-sharing email appeared to come from a City of Salem account. SPF, DKIM and DMARC passed; Microsoft marked it internally authenticated. The employee confirmed it was a scam.

    When a public agency learns this happened, should it identify and warn other possible recipients--or is internal remediation enough?

    Details: salemdata.net/johnpress/?p=1123

    #InfoSec #Cybersecurity #Phishing #IncidentResponse #CyberLaw #Privacy #LocalGovernment #GovernmentAccountability #security

  24. 𝗪𝗵𝗮𝘁 𝗶𝗳 𝗲𝘃𝗲𝗿𝘆 𝗮𝗻𝗮𝗹𝘆𝘀𝘁 𝗵𝗮𝗱 𝗮𝗻 𝗲𝗻𝘁𝗶𝗿𝗲 𝗔𝗜 𝗦𝗢𝗖 𝘄𝗼𝗿𝗸𝗶𝗻𝗴 𝗮𝗹𝗼𝗻𝗴𝘀𝗶𝗱𝗲 𝘁𝗵𝗲𝗺?

    technicalciso.com/tc-visual-ai #CyberSecurity #SOC #SecurityOperations #AgenticAI #ArtificialIntelligence #ThreatDetection #ThreatHunting #IncidentResponse

  25. 𝗪𝗵𝗮𝘁 𝗶𝗳 𝗲𝘃𝗲𝗿𝘆 𝗮𝗻𝗮𝗹𝘆𝘀𝘁 𝗵𝗮𝗱 𝗮𝗻 𝗲𝗻𝘁𝗶𝗿𝗲 𝗔𝗜 𝗦𝗢𝗖 𝘄𝗼𝗿𝗸𝗶𝗻𝗴 𝗮𝗹𝗼𝗻𝗴𝘀𝗶𝗱𝗲 𝘁𝗵𝗲𝗺?

    technicalciso.com/tc-visual-ai #CyberSecurity #SOC #SecurityOperations #AgenticAI #ArtificialIntelligence #ThreatDetection #ThreatHunting #IncidentResponse

  26. 𝗪𝗵𝗮𝘁 𝗶𝗳 𝗲𝘃𝗲𝗿𝘆 𝗮𝗻𝗮𝗹𝘆𝘀𝘁 𝗵𝗮𝗱 𝗮𝗻 𝗲𝗻𝘁𝗶𝗿𝗲 𝗔𝗜 𝗦𝗢𝗖 𝘄𝗼𝗿𝗸𝗶𝗻𝗴 𝗮𝗹𝗼𝗻𝗴𝘀𝗶𝗱𝗲 𝘁𝗵𝗲𝗺?

    technicalciso.com/tc-visual-ai #CyberSecurity #SOC #SecurityOperations #AgenticAI #ArtificialIntelligence #ThreatDetection #ThreatHunting #IncidentResponse

  27. 𝗪𝗵𝗮𝘁 𝗶𝗳 𝗲𝘃𝗲𝗿𝘆 𝗮𝗻𝗮𝗹𝘆𝘀𝘁 𝗵𝗮𝗱 𝗮𝗻 𝗲𝗻𝘁𝗶𝗿𝗲 𝗔𝗜 𝗦𝗢𝗖 𝘄𝗼𝗿𝗸𝗶𝗻𝗴 𝗮𝗹𝗼𝗻𝗴𝘀𝗶𝗱𝗲 𝘁𝗵𝗲𝗺?

    technicalciso.com/tc-visual-ai #CyberSecurity #SOC #SecurityOperations #AgenticAI #ArtificialIntelligence #ThreatDetection #ThreatHunting #IncidentResponse

  28. @chrissanders88

    Since most of it is PowerShell or HTA, I'd first check Powershell logs and then check the file system for new HTA files: NTFS, Journal, sysmon, evidence of execution.

    If there's Defender for Cloud, it's worth a look.

    And ofc check RunMRU (commands of run dialog) for common lolbins.

    #DFIR #analysis #incidentresponse #cybersecurity #infosec

  29. @chrissanders88

    Since most of it is PowerShell or HTA, I'd first check Powershell logs and then check the file system for new HTA files: NTFS, Journal, sysmon, evidence of execution.

    If there's Defender for Cloud, it's worth a look.

    And ofc check RunMRU (commands of run dialog) for common lolbins.

    #DFIR #analysis #incidentresponse #cybersecurity #infosec

  30. We have backups in multiple locations" and "we have backups an attacker with domain credentials cannot reach" are different claims. Only one survives contact with someone who's done their reconnaissance. haunted.lighthouse.co.im/artic
    #InfoSec #Cybersecurity #IncidentResponse #Backups #DigitalSovereignty

  31. We have backups in multiple locations" and "we have backups an attacker with domain credentials cannot reach" are different claims. Only one survives contact with someone who's done their reconnaissance. haunted.lighthouse.co.im/artic
    #InfoSec #Cybersecurity #IncidentResponse #Backups #DigitalSovereignty

  32. Der Cyber-Erpressungsangriff auf Rumäniens Grundbuchbehörde zeigt wieder einmal, wie wichtig eine widerstandsfähige Backup- und Incident-Response-Strategie ist.

    Nachdem die Lösegeldzahlung verweigert wurde, löschte der Täter die Produktivdatenbank und manipulierte auch die Online-Backups. Physisch getrennte Offline-Backups verhinderten zum Glück den vollständigen Datenverlust. Die betroffenen Systeme bleiben vorerst isoliert und werden neu aufgebaut.

    Warum isolierte Backups, Segmentierung und Incident Response bei Cyber-Erpressungsangriffen so wichtig sind und welche Rolle Lösegeldforderungen dabei spielen, zeige ich in meinem ausführlichen Artikel über Ransomware:

    ➡️ secunis.de/ransomware-druckmit

    :boost_ok:

    #Cybersecurity #Backup #Data #Datenschutz #IncidentResponse #Ransomware #Secunis #ITSecurity

  33. Der Cyber-Erpressungsangriff auf Rumäniens Grundbuchbehörde zeigt wieder einmal, wie wichtig eine widerstandsfähige Backup- und Incident-Response-Strategie ist.

    Nachdem die Lösegeldzahlung verweigert wurde, löschte der Täter die Produktivdatenbank und manipulierte auch die Online-Backups. Physisch getrennte Offline-Backups verhinderten zum Glück den vollständigen Datenverlust. Die betroffenen Systeme bleiben vorerst isoliert und werden neu aufgebaut.

    Warum isolierte Backups, Segmentierung und Incident Response bei Cyber-Erpressungsangriffen so wichtig sind und welche Rolle Lösegeldforderungen dabei spielen, zeige ich in meinem ausführlichen Artikel über Ransomware:

    ➡️ secunis.de/ransomware-druckmit

    :boost_ok:

    #Cybersecurity #Backup #Data #Datenschutz #IncidentResponse #Ransomware #Secunis #ITSecurity

  34. Der Cyber-Erpressungsangriff auf Rumäniens Grundbuchbehörde zeigt wieder einmal, wie wichtig eine widerstandsfähige Backup- und Incident-Response-Strategie ist.

    Nachdem die Lösegeldzahlung verweigert wurde, löschte der Täter die Produktivdatenbank und manipulierte auch die Online-Backups. Physisch getrennte Offline-Backups verhinderten zum Glück den vollständigen Datenverlust. Die betroffenen Systeme bleiben vorerst isoliert und werden neu aufgebaut.

    Warum isolierte Backups, Segmentierung und Incident Response bei Cyber-Erpressungsangriffen so wichtig sind und welche Rolle Lösegeldforderungen dabei spielen, zeige ich in meinem ausführlichen Artikel über Ransomware:

    ➡️ secunis.de/ransomware-druckmit

    :boost_ok:

    #Cybersecurity #Backup #Data #Datenschutz #IncidentResponse #Ransomware #Secunis #ITSecurity

  35. Der Cyber-Erpressungsangriff auf Rumäniens Grundbuchbehörde zeigt wieder einmal, wie wichtig eine widerstandsfähige Backup- und Incident-Response-Strategie ist.

    Nachdem die Lösegeldzahlung verweigert wurde, löschte der Täter die Produktivdatenbank und manipulierte auch die Online-Backups. Physisch getrennte Offline-Backups verhinderten zum Glück den vollständigen Datenverlust. Die betroffenen Systeme bleiben vorerst isoliert und werden neu aufgebaut.

    Warum isolierte Backups, Segmentierung und Incident Response bei Cyber-Erpressungsangriffen so wichtig sind und welche Rolle Lösegeldforderungen dabei spielen, zeige ich in meinem ausführlichen Artikel über Ransomware:

    ➡️ secunis.de/ransomware-druckmit

    :boost_ok:

    #Cybersecurity #Backup #Data #Datenschutz #IncidentResponse #Ransomware #Secunis #ITSecurity

  36. Responding to Cyber Incidents in 2026: Speed Without Chaos

    How to stop an attack, preserve evidence, and get your business back up and running without inadvertently helping the attacker through your own actions.

    pwn-all.com/blog/2026/07/20/re

    #cybersecurity #incidentresponse #pwn-all

  37. New on the FIRST blog: Ken van Wyk, FIRST Member & President and Principal Consultant, KRvW Associates, LLC and #FIRSTCON26 speaker, and Elliott Atkins, FIRST Liaison & Founder and Managing Director, Exercise3 Limited, on the most common incident response problems they've directly observed across hundreds of operations and exercises.
    Most #IncidentResponse teams have the technical chops and business knowledge to get the job done. So why do IR operations still go sideways?

    Two independent data sets, isolated from one another, revealed strikingly similar problems:

    📄 IRPs too dense for anyone to actually use in a crisis
    ⚠️ Process errors made under pressure: evidence handling, cost tracking, insurance compliance
    📊 Severity triage that doesn't reflect real business impact
    🧭 Unclear decision authority when it matters most
    👤 Key personnel unavailable, with no backup empowered to act
    🗣️ Discussions that never resolve into an actual decision
    ✅ Actions assigned but never tracked
    📢 Communication breakdowns, especially with non-technical stakeholders

    Read more: go.first.org/nqUbz

    #cybersecurity

  38. New on the FIRST blog: Ken van Wyk, FIRST Member & President and Principal Consultant, KRvW Associates, LLC and #FIRSTCON26 speaker, and Elliott Atkins, FIRST Liaison & Founder and Managing Director, Exercise3 Limited, on the most common incident response problems they've directly observed across hundreds of operations and exercises.
    Most #IncidentResponse teams have the technical chops and business knowledge to get the job done. So why do IR operations still go sideways?

    Two independent data sets, isolated from one another, revealed strikingly similar problems:

    📄 IRPs too dense for anyone to actually use in a crisis
    ⚠️ Process errors made under pressure: evidence handling, cost tracking, insurance compliance
    📊 Severity triage that doesn't reflect real business impact
    🧭 Unclear decision authority when it matters most
    👤 Key personnel unavailable, with no backup empowered to act
    🗣️ Discussions that never resolve into an actual decision
    ✅ Actions assigned but never tracked
    📢 Communication breakdowns, especially with non-technical stakeholders

    Read more: go.first.org/nqUbz

    #cybersecurity

  39. New on the FIRST blog: Ken van Wyk, FIRST Member & President and Principal Consultant, KRvW Associates, LLC and #FIRSTCON26 speaker, and Elliott Atkins, FIRST Liaison & Founder and Managing Director, Exercise3 Limited, on the most common incident response problems they've directly observed across hundreds of operations and exercises.
    Most #IncidentResponse teams have the technical chops and business knowledge to get the job done. So why do IR operations still go sideways?

    Two independent data sets, isolated from one another, revealed strikingly similar problems:

    📄 IRPs too dense for anyone to actually use in a crisis
    ⚠️ Process errors made under pressure: evidence handling, cost tracking, insurance compliance
    📊 Severity triage that doesn't reflect real business impact
    🧭 Unclear decision authority when it matters most
    👤 Key personnel unavailable, with no backup empowered to act
    🗣️ Discussions that never resolve into an actual decision
    ✅ Actions assigned but never tracked
    📢 Communication breakdowns, especially with non-technical stakeholders

    Read more: go.first.org/nqUbz

    #cybersecurity

  40. New on the FIRST blog: Ken van Wyk, FIRST Member & President and Principal Consultant, KRvW Associates, LLC and #FIRSTCON26 speaker, and Elliott Atkins, FIRST Liaison & Founder and Managing Director, Exercise3 Limited, on the most common incident response problems they've directly observed across hundreds of operations and exercises.
    Most #IncidentResponse teams have the technical chops and business knowledge to get the job done. So why do IR operations still go sideways?

    Two independent data sets, isolated from one another, revealed strikingly similar problems:

    📄 IRPs too dense for anyone to actually use in a crisis
    ⚠️ Process errors made under pressure: evidence handling, cost tracking, insurance compliance
    📊 Severity triage that doesn't reflect real business impact
    🧭 Unclear decision authority when it matters most
    👤 Key personnel unavailable, with no backup empowered to act
    🗣️ Discussions that never resolve into an actual decision
    ✅ Actions assigned but never tracked
    📢 Communication breakdowns, especially with non-technical stakeholders

    Read more: go.first.org/nqUbz

    #cybersecurity

  41. New on the FIRST blog: Ken van Wyk, FIRST Member & President and Principal Consultant, KRvW Associates, LLC and #FIRSTCON26 speaker, and Elliott Atkins, FIRST Liaison & Founder and Managing Director, Exercise3 Limited, on the most common incident response problems they've directly observed across hundreds of operations and exercises.
    Most #IncidentResponse teams have the technical chops and business knowledge to get the job done. So why do IR operations still go sideways?

    Two independent data sets, isolated from one another, revealed strikingly similar problems:

    📄 IRPs too dense for anyone to actually use in a crisis
    ⚠️ Process errors made under pressure: evidence handling, cost tracking, insurance compliance
    📊 Severity triage that doesn't reflect real business impact
    🧭 Unclear decision authority when it matters most
    👤 Key personnel unavailable, with no backup empowered to act
    🗣️ Discussions that never resolve into an actual decision
    ✅ Actions assigned but never tracked
    📢 Communication breakdowns, especially with non-technical stakeholders

    Read more: go.first.org/nqUbz

    #cybersecurity

  42. 14 hour day thanks to 3 PD alerts at once for 3 separate issues. Fuk clickfix and fuck AMOS, and stop making bad code. K thx Bai.

    #cybersecurity #infosec #incidentresponse #dfir

  43. 14 hour day thanks to 3 PD alerts at once for 3 separate issues. Fuk clickfix and fuck AMOS, and stop making bad code. K thx Bai.

    #cybersecurity #infosec #incidentresponse #dfir

  44. Security Tip: A written Incident Response (IR) plan is only half the battle. 🛡️ Don't let a real breach be the first time you test your procedures. Conduct quarterly Tabletop Exercises (TTX) involving IT, Legal, and PR to identify bottlenecks and technical gaps. Preparation is the best defense. Track the latest vulnerabilities to build better scenarios at cvedatabase.com

  45. 🔵 THREAT INTELLIGENCE

    Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands

    Vulnerability | CRITICAL
    CVEs: CVE-2026-15409, CVE-2026-15410

    SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day...

    Full analysis:
    yazoul.net/news/article/two-so

    #ThreatIntel #SecurityNews #IncidentResponse