#incidentresponse โ Public Fediverse posts
Live and recent posts from across the Fediverse tagged #incidentresponse, aggregated by home.social.
-
A suspicious document-sharing email appeared to come from a City of Salem account. SPF, DKIM and DMARC passed; Microsoft marked it internally authenticated. The employee confirmed it was a scam.
When a public agency learns this happened, should it identify and warn other possible recipients--or is internal remediation enough?
Details: https://salemdata.net/johnpress/?p=1123
#InfoSec #Cybersecurity #Phishing #IncidentResponse #CyberLaw #Privacy #LocalGovernment #GovernmentAccountability #security
-
A suspicious document-sharing email appeared to come from a City of Salem account. SPF, DKIM and DMARC passed; Microsoft marked it internally authenticated. The employee confirmed it was a scam.
When a public agency learns this happened, should it identify and warn other possible recipients--or is internal remediation enough?
Details: https://salemdata.net/johnpress/?p=1123
#InfoSec #Cybersecurity #Phishing #IncidentResponse #CyberLaw #Privacy #LocalGovernment #GovernmentAccountability #security
-
๐ช๐ต๐ฎ๐ ๐ถ๐ณ ๐ฒ๐๐ฒ๐ฟ๐ ๐ฎ๐ป๐ฎ๐น๐๐๐ ๐ต๐ฎ๐ฑ ๐ฎ๐ป ๐ฒ๐ป๐๐ถ๐ฟ๐ฒ ๐๐ ๐ฆ๐ข๐ ๐๐ผ๐ฟ๐ธ๐ถ๐ป๐ด ๐ฎ๐น๐ผ๐ป๐ด๐๐ถ๐ฑ๐ฒ ๐๐ต๐ฒ๐บ?
https://technicalciso.com/tc-visual-ai-soc-agents/ #CyberSecurity #SOC #SecurityOperations #AgenticAI #ArtificialIntelligence #ThreatDetection #ThreatHunting #IncidentResponse
-
๐ช๐ต๐ฎ๐ ๐ถ๐ณ ๐ฒ๐๐ฒ๐ฟ๐ ๐ฎ๐ป๐ฎ๐น๐๐๐ ๐ต๐ฎ๐ฑ ๐ฎ๐ป ๐ฒ๐ป๐๐ถ๐ฟ๐ฒ ๐๐ ๐ฆ๐ข๐ ๐๐ผ๐ฟ๐ธ๐ถ๐ป๐ด ๐ฎ๐น๐ผ๐ป๐ด๐๐ถ๐ฑ๐ฒ ๐๐ต๐ฒ๐บ?
https://technicalciso.com/tc-visual-ai-soc-agents/ #CyberSecurity #SOC #SecurityOperations #AgenticAI #ArtificialIntelligence #ThreatDetection #ThreatHunting #IncidentResponse
-
๐ช๐ต๐ฎ๐ ๐ถ๐ณ ๐ฒ๐๐ฒ๐ฟ๐ ๐ฎ๐ป๐ฎ๐น๐๐๐ ๐ต๐ฎ๐ฑ ๐ฎ๐ป ๐ฒ๐ป๐๐ถ๐ฟ๐ฒ ๐๐ ๐ฆ๐ข๐ ๐๐ผ๐ฟ๐ธ๐ถ๐ป๐ด ๐ฎ๐น๐ผ๐ป๐ด๐๐ถ๐ฑ๐ฒ ๐๐ต๐ฒ๐บ?
https://technicalciso.com/tc-visual-ai-soc-agents/ #CyberSecurity #SOC #SecurityOperations #AgenticAI #ArtificialIntelligence #ThreatDetection #ThreatHunting #IncidentResponse
-
๐ช๐ต๐ฎ๐ ๐ถ๐ณ ๐ฒ๐๐ฒ๐ฟ๐ ๐ฎ๐ป๐ฎ๐น๐๐๐ ๐ต๐ฎ๐ฑ ๐ฎ๐ป ๐ฒ๐ป๐๐ถ๐ฟ๐ฒ ๐๐ ๐ฆ๐ข๐ ๐๐ผ๐ฟ๐ธ๐ถ๐ป๐ด ๐ฎ๐น๐ผ๐ป๐ด๐๐ถ๐ฑ๐ฒ ๐๐ต๐ฒ๐บ?
https://technicalciso.com/tc-visual-ai-soc-agents/ #CyberSecurity #SOC #SecurityOperations #AgenticAI #ArtificialIntelligence #ThreatDetection #ThreatHunting #IncidentResponse
-
Since most of it is PowerShell or HTA, I'd first check Powershell logs and then check the file system for new HTA files: NTFS, Journal, sysmon, evidence of execution.
If there's Defender for Cloud, it's worth a look.
And ofc check RunMRU (commands of run dialog) for common lolbins.
-
Since most of it is PowerShell or HTA, I'd first check Powershell logs and then check the file system for new HTA files: NTFS, Journal, sysmon, evidence of execution.
If there's Defender for Cloud, it's worth a look.
And ofc check RunMRU (commands of run dialog) for common lolbins.
-
We have backups in multiple locations" and "we have backups an attacker with domain credentials cannot reach" are different claims. Only one survives contact with someone who's done their reconnaissance. https://haunted.lighthouse.co.im/articles/so-you-think-your-backups-are-secure/
#InfoSec #Cybersecurity #IncidentResponse #Backups #DigitalSovereignty -
We have backups in multiple locations" and "we have backups an attacker with domain credentials cannot reach" are different claims. Only one survives contact with someone who's done their reconnaissance. https://haunted.lighthouse.co.im/articles/so-you-think-your-backups-are-secure/
#InfoSec #Cybersecurity #IncidentResponse #Backups #DigitalSovereignty -
Der Cyber-Erpressungsangriff auf Rumรคniens Grundbuchbehรถrde zeigt wieder einmal, wie wichtig eine widerstandsfรคhige Backup- und Incident-Response-Strategie ist.
Nachdem die Lรถsegeldzahlung verweigert wurde, lรถschte der Tรคter die Produktivdatenbank und manipulierte auch die Online-Backups. Physisch getrennte Offline-Backups verhinderten zum Glรผck den vollstรคndigen Datenverlust. Die betroffenen Systeme bleiben vorerst isoliert und werden neu aufgebaut.
Warum isolierte Backups, Segmentierung und Incident Response bei Cyber-Erpressungsangriffen so wichtig sind und welche Rolle Lรถsegeldforderungen dabei spielen, zeige ich in meinem ausfรผhrlichen Artikel รผber Ransomware:
โก๏ธ https://www.secunis.de/ransomware-druckmittel/
:boost_ok:
#Cybersecurity #Backup #Data #Datenschutz #IncidentResponse #Ransomware #Secunis #ITSecurity
-
Der Cyber-Erpressungsangriff auf Rumรคniens Grundbuchbehรถrde zeigt wieder einmal, wie wichtig eine widerstandsfรคhige Backup- und Incident-Response-Strategie ist.
Nachdem die Lรถsegeldzahlung verweigert wurde, lรถschte der Tรคter die Produktivdatenbank und manipulierte auch die Online-Backups. Physisch getrennte Offline-Backups verhinderten zum Glรผck den vollstรคndigen Datenverlust. Die betroffenen Systeme bleiben vorerst isoliert und werden neu aufgebaut.
Warum isolierte Backups, Segmentierung und Incident Response bei Cyber-Erpressungsangriffen so wichtig sind und welche Rolle Lรถsegeldforderungen dabei spielen, zeige ich in meinem ausfรผhrlichen Artikel รผber Ransomware:
โก๏ธ https://www.secunis.de/ransomware-druckmittel/
:boost_ok:
#Cybersecurity #Backup #Data #Datenschutz #IncidentResponse #Ransomware #Secunis #ITSecurity
-
Responding to Cyber Incidents in 2026: Speed Without Chaos
How to stop an attack, preserve evidence, and get your business back up and running without inadvertently helping the attacker through your own actions.
https://pwn-all.com/blog/2026/07/20/responding-to-cyber-incidents-in-2026-speed-without-chaos.html
-
Hugging Face breached by autonomous AI agent https://www.byteseu.com/2212067/ #AgenticAi #AI #ArtificialIntelligence #HuggingFace #IncidentResponse #IntrusionDetection #LLMs #MachineLearning
-
New on the FIRST blog: Ken van Wyk, FIRST Member & President and Principal Consultant, KRvW Associates, LLC and #FIRSTCON26 speaker, and Elliott Atkins, FIRST Liaison & Founder and Managing Director, Exercise3 Limited, on the most common incident response problems they've directly observed across hundreds of operations and exercises.
Most #IncidentResponse teams have the technical chops and business knowledge to get the job done. So why do IR operations still go sideways?Two independent data sets, isolated from one another, revealed strikingly similar problems:
๐ IRPs too dense for anyone to actually use in a crisis
โ ๏ธ Process errors made under pressure: evidence handling, cost tracking, insurance compliance
๐ Severity triage that doesn't reflect real business impact
๐งญ Unclear decision authority when it matters most
๐ค Key personnel unavailable, with no backup empowered to act
๐ฃ๏ธ Discussions that never resolve into an actual decision
โ Actions assigned but never tracked
๐ข Communication breakdowns, especially with non-technical stakeholdersRead more: https://go.first.org/nqUbz
-
New on the FIRST blog: Ken van Wyk, FIRST Member & President and Principal Consultant, KRvW Associates, LLC and #FIRSTCON26 speaker, and Elliott Atkins, FIRST Liaison & Founder and Managing Director, Exercise3 Limited, on the most common incident response problems they've directly observed across hundreds of operations and exercises.
Most #IncidentResponse teams have the technical chops and business knowledge to get the job done. So why do IR operations still go sideways?Two independent data sets, isolated from one another, revealed strikingly similar problems:
๐ IRPs too dense for anyone to actually use in a crisis
โ ๏ธ Process errors made under pressure: evidence handling, cost tracking, insurance compliance
๐ Severity triage that doesn't reflect real business impact
๐งญ Unclear decision authority when it matters most
๐ค Key personnel unavailable, with no backup empowered to act
๐ฃ๏ธ Discussions that never resolve into an actual decision
โ Actions assigned but never tracked
๐ข Communication breakdowns, especially with non-technical stakeholdersRead more: https://go.first.org/nqUbz
-
New on the FIRST blog: Ken van Wyk, FIRST Member & President and Principal Consultant, KRvW Associates, LLC and #FIRSTCON26 speaker, and Elliott Atkins, FIRST Liaison & Founder and Managing Director, Exercise3 Limited, on the most common incident response problems they've directly observed across hundreds of operations and exercises.
Most #IncidentResponse teams have the technical chops and business knowledge to get the job done. So why do IR operations still go sideways?Two independent data sets, isolated from one another, revealed strikingly similar problems:
๐ IRPs too dense for anyone to actually use in a crisis
โ ๏ธ Process errors made under pressure: evidence handling, cost tracking, insurance compliance
๐ Severity triage that doesn't reflect real business impact
๐งญ Unclear decision authority when it matters most
๐ค Key personnel unavailable, with no backup empowered to act
๐ฃ๏ธ Discussions that never resolve into an actual decision
โ Actions assigned but never tracked
๐ข Communication breakdowns, especially with non-technical stakeholdersRead more: https://go.first.org/nqUbz
-
New on the FIRST blog: Ken van Wyk, FIRST Member & President and Principal Consultant, KRvW Associates, LLC and #FIRSTCON26 speaker, and Elliott Atkins, FIRST Liaison & Founder and Managing Director, Exercise3 Limited, on the most common incident response problems they've directly observed across hundreds of operations and exercises.
Most #IncidentResponse teams have the technical chops and business knowledge to get the job done. So why do IR operations still go sideways?Two independent data sets, isolated from one another, revealed strikingly similar problems:
๐ IRPs too dense for anyone to actually use in a crisis
โ ๏ธ Process errors made under pressure: evidence handling, cost tracking, insurance compliance
๐ Severity triage that doesn't reflect real business impact
๐งญ Unclear decision authority when it matters most
๐ค Key personnel unavailable, with no backup empowered to act
๐ฃ๏ธ Discussions that never resolve into an actual decision
โ Actions assigned but never tracked
๐ข Communication breakdowns, especially with non-technical stakeholdersRead more: https://go.first.org/nqUbz
-
New on the FIRST blog: Ken van Wyk, FIRST Member & President and Principal Consultant, KRvW Associates, LLC and #FIRSTCON26 speaker, and Elliott Atkins, FIRST Liaison & Founder and Managing Director, Exercise3 Limited, on the most common incident response problems they've directly observed across hundreds of operations and exercises.
Most #IncidentResponse teams have the technical chops and business knowledge to get the job done. So why do IR operations still go sideways?Two independent data sets, isolated from one another, revealed strikingly similar problems:
๐ IRPs too dense for anyone to actually use in a crisis
โ ๏ธ Process errors made under pressure: evidence handling, cost tracking, insurance compliance
๐ Severity triage that doesn't reflect real business impact
๐งญ Unclear decision authority when it matters most
๐ค Key personnel unavailable, with no backup empowered to act
๐ฃ๏ธ Discussions that never resolve into an actual decision
โ Actions assigned but never tracked
๐ข Communication breakdowns, especially with non-technical stakeholdersRead more: https://go.first.org/nqUbz
-
14 hour day thanks to 3 PD alerts at once for 3 separate issues. Fuk clickfix and fuck AMOS, and stop making bad code. K thx Bai.
-
14 hour day thanks to 3 PD alerts at once for 3 separate issues. Fuk clickfix and fuck AMOS, and stop making bad code. K thx Bai.
-
Security Tip: A written Incident Response (IR) plan is only half the battle. ๐ก๏ธ Don't let a real breach be the first time you test your procedures. Conduct quarterly Tabletop Exercises (TTX) involving IT, Legal, and PR to identify bottlenecks and technical gaps. Preparation is the best defense. Track the latest vulnerabilities to build better scenarios at https://cvedatabase.com #InfoSec #CyberSecurity #IncidentResponse #BlueTeam
-
๐ต THREAT INTELLIGENCE
Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
Vulnerability | CRITICAL
CVEs: CVE-2026-15409, CVE-2026-15410SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day...
Full analysis:
https://www.yazoul.net/news/article/two-sonicwall-sma-1000-zero-days-exploited-one-could-enable-admin-commands -
Wisconsin-based TruStage shuts down network after cybersecurity incident #TruStage #CybersecurityIncident #NetworkOutage #CreditUnions #IncidentResponse #Wisconsin https://dysruptionhub.com/trustage-cyber-incident-claims-outage/
-
Wisconsin-based TruStage shuts down network after cybersecurity incident #TruStage #CybersecurityIncident #NetworkOutage #CreditUnions #IncidentResponse #Wisconsin https://dysruptionhub.com/trustage-cyber-incident-claims-outage/
-
Wisconsin-based TruStage shuts down network after cybersecurity incident #TruStage #CybersecurityIncident #NetworkOutage #CreditUnions #IncidentResponse #Wisconsin https://dysruptionhub.com/trustage-cyber-incident-claims-outage/
-
Wisconsin-based TruStage shuts down network after cybersecurity incident #TruStage #CybersecurityIncident #NetworkOutage #CreditUnions #IncidentResponse #Wisconsin https://dysruptionhub.com/trustage-cyber-incident-claims-outage/
-
๐ฌ FIRST's Q2FY26 Newsletter is here! Here's a look at what's inside:
๐ #FIRSTCON26 Recap
A look back on the 38th Annual Conference in Denver โ five days, 100+ presentations, and lively networking that reflected the event's collaborative spirit. Outgoing PC Chair Merike Kaeo delivered an outstanding program, and Martijn van der Heide now takes the reins to prepare #FIRSTCON27 in Bangkok.
๐ณ๏ธ AGM & Board Elections
The Annual General Meeting confirmed a refreshed Board: Serge Droz, Carlos Leonardo, and Olivier Caleff re-elected, Mona Elisabeth รstvang returns after a year away, and Logan Wilkins joins for the first time.
๐ฉโ๐ป Women of FIRST Mentorship ProgramA new 6โ9 month mentorship pilot launches in Q3 2026 โ interest survey closes July 20.
๐ Member Spotlight: Art Manion & Jay Jacobs
Two of the driving forces behind FIRST's vulnerability management work: Jay Jacobs (co-Chair, EPSS SIG) and Art Manion (Chair, VRDX-SIG and Vulnerability Coordination SIG). Their contributions to CVSS and EPSS have given the community core frameworks for vulnerability assessment and prioritization, and both have been key organizers of VulnCon โ most recently leading a session in Scottsdale titled "A Paradigm Shift in Vulnerability Identity: Why Vulnerability Databases Struggle."
๐ฐ๏ธ New SIG Alert: Time Security
With the Unix epoch overflow arriving January 19, 2038 โ plus an NTP rollover as soon as 2036 and a GPS week rollover later in 2038 โ the new Time Security SIG is coordinating the community's response. Now 60+ participants strong, its work is already feeding into ITU-T and IEEE standards efforts.
๐ก๏ธAdditional SIG Updates
โ Metrics SIG released v1.1, completing metrics coverage across all five CSIRT Services Framework areas
โ DNS Abuse SIG published v1.3 of the DNS Abuse Techniques Matrix โ the first update since 2023
โ Insider Threat SIG held its inaugural in-person meetup in Denver
โ EPSS v5 went live June 15 with improved calibration and new exploit-detection signals
โ Policy SIG published a brief on AI's impact across the cybersecurity ecosystem๐ Capacity Building
FIRST launched a new initiative under the G7-ECOWAS Platform for Advancing Cybersecurity, working with ECOWAS and GIZ to support regional cyber confidence-building measures across West Africa.
Read more ๐ https://go.first.org/AXSBi
-
๐ฌ FIRST's Q2FY26 Newsletter is here! Here's a look at what's inside:
๐ #FIRSTCON26 Recap
A look back on the 38th Annual Conference in Denver โ five days, 100+ presentations, and lively networking that reflected the event's collaborative spirit. Outgoing PC Chair Merike Kaeo delivered an outstanding program, and Martijn van der Heide now takes the reins to prepare #FIRSTCON27 in Bangkok.
๐ณ๏ธ AGM & Board Elections
The Annual General Meeting confirmed a refreshed Board: Serge Droz, Carlos Leonardo, and Olivier Caleff re-elected, Mona Elisabeth รstvang returns after a year away, and Logan Wilkins joins for the first time.
๐ฉโ๐ป Women of FIRST Mentorship ProgramA new 6โ9 month mentorship pilot launches in Q3 2026 โ interest survey closes July 20.
๐ Member Spotlight: Art Manion & Jay Jacobs
Two of the driving forces behind FIRST's vulnerability management work: Jay Jacobs (co-Chair, EPSS SIG) and Art Manion (Chair, VRDX-SIG and Vulnerability Coordination SIG). Their contributions to CVSS and EPSS have given the community core frameworks for vulnerability assessment and prioritization, and both have been key organizers of VulnCon โ most recently leading a session in Scottsdale titled "A Paradigm Shift in Vulnerability Identity: Why Vulnerability Databases Struggle."
๐ฐ๏ธ New SIG Alert: Time Security
With the Unix epoch overflow arriving January 19, 2038 โ plus an NTP rollover as soon as 2036 and a GPS week rollover later in 2038 โ the new Time Security SIG is coordinating the community's response. Now 60+ participants strong, its work is already feeding into ITU-T and IEEE standards efforts.
๐ก๏ธAdditional SIG Updates
โ Metrics SIG released v1.1, completing metrics coverage across all five CSIRT Services Framework areas
โ DNS Abuse SIG published v1.3 of the DNS Abuse Techniques Matrix โ the first update since 2023
โ Insider Threat SIG held its inaugural in-person meetup in Denver
โ EPSS v5 went live June 15 with improved calibration and new exploit-detection signals
โ Policy SIG published a brief on AI's impact across the cybersecurity ecosystem๐ Capacity Building
FIRST launched a new initiative under the G7-ECOWAS Platform for Advancing Cybersecurity, working with ECOWAS and GIZ to support regional cyber confidence-building measures across West Africa.
Read more ๐ https://go.first.org/AXSBi
-
๐ฌ FIRST's Q2FY26 Newsletter is here! Here's a look at what's inside:
๐ #FIRSTCON26 Recap
A look back on the 38th Annual Conference in Denver โ five days, 100+ presentations, and lively networking that reflected the event's collaborative spirit. Outgoing PC Chair Merike Kaeo delivered an outstanding program, and Martijn van der Heide now takes the reins to prepare #FIRSTCON27 in Bangkok.
๐ณ๏ธ AGM & Board Elections
The Annual General Meeting confirmed a refreshed Board: Serge Droz, Carlos Leonardo, and Olivier Caleff re-elected, Mona Elisabeth รstvang returns after a year away, and Logan Wilkins joins for the first time.
๐ฉโ๐ป Women of FIRST Mentorship ProgramA new 6โ9 month mentorship pilot launches in Q3 2026 โ interest survey closes July 20.
๐ Member Spotlight: Art Manion & Jay Jacobs
Two of the driving forces behind FIRST's vulnerability management work: Jay Jacobs (co-Chair, EPSS SIG) and Art Manion (Chair, VRDX-SIG and Vulnerability Coordination SIG). Their contributions to CVSS and EPSS have given the community core frameworks for vulnerability assessment and prioritization, and both have been key organizers of VulnCon โ most recently leading a session in Scottsdale titled "A Paradigm Shift in Vulnerability Identity: Why Vulnerability Databases Struggle."
๐ฐ๏ธ New SIG Alert: Time Security
With the Unix epoch overflow arriving January 19, 2038 โ plus an NTP rollover as soon as 2036 and a GPS week rollover later in 2038 โ the new Time Security SIG is coordinating the community's response. Now 60+ participants strong, its work is already feeding into ITU-T and IEEE standards efforts.
๐ก๏ธAdditional SIG Updates
โ Metrics SIG released v1.1, completing metrics coverage across all five CSIRT Services Framework areas
โ DNS Abuse SIG published v1.3 of the DNS Abuse Techniques Matrix โ the first update since 2023
โ Insider Threat SIG held its inaugural in-person meetup in Denver
โ EPSS v5 went live June 15 with improved calibration and new exploit-detection signals
โ Policy SIG published a brief on AI's impact across the cybersecurity ecosystem๐ Capacity Building
FIRST launched a new initiative under the G7-ECOWAS Platform for Advancing Cybersecurity, working with ECOWAS and GIZ to support regional cyber confidence-building measures across West Africa.
Read more ๐ https://go.first.org/AXSBi
-
๐ฌ FIRST's Q2FY26 Newsletter is here! Here's a look at what's inside:
๐ #FIRSTCON26 Recap
A look back on the 38th Annual Conference in Denver โ five days, 100+ presentations, and lively networking that reflected the event's collaborative spirit. Outgoing PC Chair Merike Kaeo delivered an outstanding program, and Martijn van der Heide now takes the reins to prepare #FIRSTCON27 in Bangkok.
๐ณ๏ธ AGM & Board Elections
The Annual General Meeting confirmed a refreshed Board: Serge Droz, Carlos Leonardo, and Olivier Caleff re-elected, Mona Elisabeth รstvang returns after a year away, and Logan Wilkins joins for the first time.
๐ฉโ๐ป Women of FIRST Mentorship ProgramA new 6โ9 month mentorship pilot launches in Q3 2026 โ interest survey closes July 20.
๐ Member Spotlight: Art Manion & Jay Jacobs
Two of the driving forces behind FIRST's vulnerability management work: Jay Jacobs (co-Chair, EPSS SIG) and Art Manion (Chair, VRDX-SIG and Vulnerability Coordination SIG). Their contributions to CVSS and EPSS have given the community core frameworks for vulnerability assessment and prioritization, and both have been key organizers of VulnCon โ most recently leading a session in Scottsdale titled "A Paradigm Shift in Vulnerability Identity: Why Vulnerability Databases Struggle."
๐ฐ๏ธ New SIG Alert: Time Security
With the Unix epoch overflow arriving January 19, 2038 โ plus an NTP rollover as soon as 2036 and a GPS week rollover later in 2038 โ the new Time Security SIG is coordinating the community's response. Now 60+ participants strong, its work is already feeding into ITU-T and IEEE standards efforts.
๐ก๏ธAdditional SIG Updates
โ Metrics SIG released v1.1, completing metrics coverage across all five CSIRT Services Framework areas
โ DNS Abuse SIG published v1.3 of the DNS Abuse Techniques Matrix โ the first update since 2023
โ Insider Threat SIG held its inaugural in-person meetup in Denver
โ EPSS v5 went live June 15 with improved calibration and new exploit-detection signals
โ Policy SIG published a brief on AI's impact across the cybersecurity ecosystem๐ Capacity Building
FIRST launched a new initiative under the G7-ECOWAS Platform for Advancing Cybersecurity, working with ECOWAS and GIZ to support regional cyber confidence-building measures across West Africa.
Read more ๐ https://go.first.org/AXSBi
-
๐ฌ FIRST's Q2FY26 Newsletter is here! Here's a look at what's inside:
๐ #FIRSTCON26 Recap
A look back on the 38th Annual Conference in Denver โ five days, 100+ presentations, and lively networking that reflected the event's collaborative spirit. Outgoing PC Chair Merike Kaeo delivered an outstanding program, and Martijn van der Heide now takes the reins to prepare #FIRSTCON27 in Bangkok.
๐ณ๏ธ AGM & Board Elections
The Annual General Meeting confirmed a refreshed Board: Serge Droz, Carlos Leonardo, and Olivier Caleff re-elected, Mona Elisabeth รstvang returns after a year away, and Logan Wilkins joins for the first time.
๐ฉโ๐ป Women of FIRST Mentorship ProgramA new 6โ9 month mentorship pilot launches in Q3 2026 โ interest survey closes July 20.
๐ Member Spotlight: Art Manion & Jay Jacobs
Two of the driving forces behind FIRST's vulnerability management work: Jay Jacobs (co-Chair, EPSS SIG) and Art Manion (Chair, VRDX-SIG and Vulnerability Coordination SIG). Their contributions to CVSS and EPSS have given the community core frameworks for vulnerability assessment and prioritization, and both have been key organizers of VulnCon โ most recently leading a session in Scottsdale titled "A Paradigm Shift in Vulnerability Identity: Why Vulnerability Databases Struggle."
๐ฐ๏ธ New SIG Alert: Time Security
With the Unix epoch overflow arriving January 19, 2038 โ plus an NTP rollover as soon as 2036 and a GPS week rollover later in 2038 โ the new Time Security SIG is coordinating the community's response. Now 60+ participants strong, its work is already feeding into ITU-T and IEEE standards efforts.
๐ก๏ธAdditional SIG Updates
โ Metrics SIG released v1.1, completing metrics coverage across all five CSIRT Services Framework areas
โ DNS Abuse SIG published v1.3 of the DNS Abuse Techniques Matrix โ the first update since 2023
โ Insider Threat SIG held its inaugural in-person meetup in Denver
โ EPSS v5 went live June 15 with improved calibration and new exploit-detection signals
โ Policy SIG published a brief on AI's impact across the cybersecurity ecosystem๐ Capacity Building
FIRST launched a new initiative under the G7-ECOWAS Platform for Advancing Cybersecurity, working with ECOWAS and GIZ to support regional cyber confidence-building measures across West Africa.
Read more ๐ https://go.first.org/AXSBi
-
Working in cyber in 2026, we spend so much of our time connecting through screens. But every year, #FIRSTCON reminds us that the strongest partnerships are still built face to face.
You can exchange emails for years, join countless video calls, and collaborate across continents, but there's something irreplaceable about sharing a meal, raising a glass, and getting to know the person behind the job title. Those moments build the trust that matters when the pressure is on. When an incident strikes, you're not reaching out to a stranger, you're calling a friend.
Our #FIRSTCON26 recap reflects on the conversations, connections, and community that made this year's conference in Denver so memorable.
Read the full blog here: https://www.first.org/blog/20260703-When-FIRSTCON26-Rode-into-Denver
#FIRSTCON26 #CyberSecurity #IncidentResponse #Community #FIRST
-
Working in cyber in 2026, we spend so much of our time connecting through screens. But every year, #FIRSTCON reminds us that the strongest partnerships are still built face to face.
You can exchange emails for years, join countless video calls, and collaborate across continents, but there's something irreplaceable about sharing a meal, raising a glass, and getting to know the person behind the job title. Those moments build the trust that matters when the pressure is on. When an incident strikes, you're not reaching out to a stranger, you're calling a friend.
Our #FIRSTCON26 recap reflects on the conversations, connections, and community that made this year's conference in Denver so memorable.
Read the full blog here: https://www.first.org/blog/20260703-When-FIRSTCON26-Rode-into-Denver
#FIRSTCON26 #CyberSecurity #IncidentResponse #Community #FIRST
-
Working in cyber in 2026, we spend so much of our time connecting through screens. But every year, #FIRSTCON reminds us that the strongest partnerships are still built face to face.
You can exchange emails for years, join countless video calls, and collaborate across continents, but there's something irreplaceable about sharing a meal, raising a glass, and getting to know the person behind the job title. Those moments build the trust that matters when the pressure is on. When an incident strikes, you're not reaching out to a stranger, you're calling a friend.
Our #FIRSTCON26 recap reflects on the conversations, connections, and community that made this year's conference in Denver so memorable.
Read the full blog here: https://www.first.org/blog/20260703-When-FIRSTCON26-Rode-into-Denver
#FIRSTCON26 #CyberSecurity #IncidentResponse #Community #FIRST
-
Working in cyber in 2026, we spend so much of our time connecting through screens. But every year, #FIRSTCON reminds us that the strongest partnerships are still built face to face.
You can exchange emails for years, join countless video calls, and collaborate across continents, but there's something irreplaceable about sharing a meal, raising a glass, and getting to know the person behind the job title. Those moments build the trust that matters when the pressure is on. When an incident strikes, you're not reaching out to a stranger, you're calling a friend.
Our #FIRSTCON26 recap reflects on the conversations, connections, and community that made this year's conference in Denver so memorable.
Read the full blog here: https://www.first.org/blog/20260703-When-FIRSTCON26-Rode-into-Denver
#FIRSTCON26 #CyberSecurity #IncidentResponse #Community #FIRST
-
Working in cyber in 2026, we spend so much of our time connecting through screens. But every year, #FIRSTCON reminds us that the strongest partnerships are still built face to face.
You can exchange emails for years, join countless video calls, and collaborate across continents, but there's something irreplaceable about sharing a meal, raising a glass, and getting to know the person behind the job title. Those moments build the trust that matters when the pressure is on. When an incident strikes, you're not reaching out to a stranger, you're calling a friend.
Our #FIRSTCON26 recap reflects on the conversations, connections, and community that made this year's conference in Denver so memorable.
Read the full blog here: https://www.first.org/blog/20260703-When-FIRSTCON26-Rode-into-Denver
#FIRSTCON26 #CyberSecurity #IncidentResponse #Community #FIRST
-
Security Tip: Prioritize forensics during Incident Response. ๐ก๏ธ When a breach occurs, the instinct is to wipe and rebuild immediately. However, without capturing volatile memory (RAM) and disk images first, you lose the "how" and "who." Establish a standard procedure for evidence preservation to ensure your team can conduct a proper post-mortem and prevent recurrence. Stay informed on the latest threats at https://cvedatabase.com #InfoSec #IncidentResponse #CyberSecurity
-
Security Tip: Prioritize forensics during Incident Response. ๐ก๏ธ When a breach occurs, the instinct is to wipe and rebuild immediately. However, without capturing volatile memory (RAM) and disk images first, you lose the "how" and "who." Establish a standard procedure for evidence preservation to ensure your team can conduct a proper post-mortem and prevent recurrence. Stay informed on the latest threats at https://cvedatabase.com #InfoSec #IncidentResponse #CyberSecurity
-
Security Tip: The 'Blameless Post-Mortem' is a vital Incident Response tool. ๐ก๏ธ When a security event occurs, the goal should be understanding how the system allowed the mistake, not who made it. Focus on improving technical controls and documentation. This builds a culture where teams report issues early rather than hiding them. Use https://cvedatabase.com to track vulnerabilities that might affect your stack. #InfoSec #CyberSecurity #IncidentResponse #IT
-
----------------
๐ฏ AI
===================Sygnia: AI-Supercharged 72-Hour Cloud Attack Investigation
Sygnia published findings from an incident response engagement where a threat actor compromised an AWS-based environment, progressing from initial access to broad cloud compromise in approximately 72 hours. The case is notable not for novel techniques, but for the apparent use of AI to accelerate familiar cloud attack methods.
Key Findings
โข The intrusion expanded across applications, cloud infrastructure, source-control systems, CI/CD pipelines, and runtime services
โข No zero-day exploits or novel malware were observed. Every technique mapped to established MITRE ATT&CK behaviors
โข Multiple artifacts suggested AI-assisted or agentic workflows: attacker-created scripts, structured reporting artifacts, and highly parallel activity
โข The threat actor repeatedly leveraged newly acquired credentials to restart discovery, secrets harvesting, persistence, and impact activities
โข The primary defensive challenge was the speed and scale of execution, not the novelty of individual techniquesWhere AI Changed the Equation
The report identifies several indicators of AI involvement:
โข Rapid generation of environment-specific scripts and tooling
โข Structured, formatted reporting artifacts consistent with AI-generated output
โข Highly parallel discovery and exploitation activities across multiple surfaces
โข Compressed timeline for reconnaissance, adaptation, and operational execution inconsistent with purely manual operationsAttack Path
1. Initial access to AWS environment
2. Credential harvesting and secrets discovery
3. Lateral movement across applications and cloud services
4. Persistence through compromised identity and deployment workflows
5. Expansion into source-control and CI/CD systems
6. Impact across cloud, identity, and application layersEach credential acquisition restarted the cycle.
Defensive Gaps
โข Fragmented visibility across cloud, identity, and application layers
โข Monitoring gaps that delayed detection and correlation
โข Absence of predefined incident response procedures
โข Weak secrets management and identity governance
โข Overly permissive cloud and CI/CD permissionsRemediation
Sygnia recommends adapting IR playbooks for AI-enabled threats, prioritizing broad containment over precision when speed matters, rotating credentials aggressively, treating identity as the primary security boundary, and automating defensive responses. Infrastructure rebuilds may be necessary for broadly compromised environments.
Known weaknesses get exploited faster and at broader scale when AI assistance is available. End-to-end visibility and predefined containment procedures are prerequisites, not aspirations.
๐น AI #CloudSecurity #IncidentResponse #Sygnia #MITREATTACK
๐ Source: https://www.sygnia.co/blog/inside-an-ai-assisted-cloud-attack/
-
Security Tip: Establish out-of-band (OOB) communication channels for your Incident Response team. ๐ก๏ธ
If an attacker gains access to your primary email or chat platforms, they can monitor your response efforts or even disrupt them. Prepare a secure, separate channel (like Signal or a dedicated offline instance) in advance to maintain command and control.
Stay informed on the latest vulnerabilities at: https://cvedatabase.com
-
How can you use your AI agent to transform raw threat notes into a well-sourced CTI report draft? Use my MCP server with my new CTI report template and writing guidance. Your sensitive data stays local.
-
How can you use your AI agent to transform raw threat notes into a well-sourced CTI report draft? Use my MCP server with my new CTI report template and writing guidance. Your sensitive data stays local.
-
โ๏ธ Save the Date! โ๏ธ
Cold Incident Response 2026 โข Tue Oct 13 โ Thu Oct 15 โข Oslo, NorwayHosted by our Norwegian FIRST Teams ๐
Bundle up, block your calendars, and get ready for three days of cool minds, cold cases studies with warm Nordic hospitality.
-
โ๏ธ Save the Date! โ๏ธ
Cold Incident Response 2026 โข Tue Oct 13 โ Thu Oct 15 โข Oslo, NorwayHosted by our Norwegian FIRST Teams ๐
Bundle up, block your calendars, and get ready for three days of cool minds, cold cases studies with warm Nordic hospitality.
-
The Treachery of Postmortems is a really great cure for the post incident review blues. Thank you @gallego !
https://resilienceinsoftware.org/news/11547831
#RISF #ResilienceInSoftwareFoundation #ResilienceInSoftware #Resilience #Postmortem #PIRWriteup #IncidentManagement #IncidentResponse #LearningReview
-
The Treachery of Postmortems is a really great cure for the post incident review blues. Thank you @gallego !
https://resilienceinsoftware.org/news/11547831
#RISF #ResilienceInSoftwareFoundation #ResilienceInSoftware #Resilience #Postmortem #PIRWriteup #IncidentManagement #IncidentResponse #LearningReview
-
Security Tip: Is your Incident Response (IR) plan just a document on a shelf? ๐ก๏ธ
A plan is only effective if your team knows how to execute it. Conduct regular tabletop exercises to simulate real-world scenarios. This helps identify bottlenecks, communication failures, and technical gaps before an actual breach occurs.
Actionable awareness is key to resilience. Use https://cvedatabase.com to track the latest threats.
-
Security Tip: An Incident Response (IR) plan is only as good as its last test. ๐ก๏ธ
Conduct regular tabletop exercises involving both technical teams and stakeholders (Legal, PR, Execs). These simulations reveal bottlenecks and communication gaps that documentation alone can't find. Proactive preparation is the difference between a controlled recovery and chaos.
Track the latest threats at https://cvedatabase.com