home.social

#incidentresponse โ€” Public Fediverse posts

Live and recent posts from across the Fediverse tagged #incidentresponse, aggregated by home.social.

  1. A suspicious document-sharing email appeared to come from a City of Salem account. SPF, DKIM and DMARC passed; Microsoft marked it internally authenticated. The employee confirmed it was a scam.

    When a public agency learns this happened, should it identify and warn other possible recipients--or is internal remediation enough?

    Details: salemdata.net/johnpress/?p=1123

    #InfoSec #Cybersecurity #Phishing #IncidentResponse #CyberLaw #Privacy #LocalGovernment #GovernmentAccountability #security

  2. A suspicious document-sharing email appeared to come from a City of Salem account. SPF, DKIM and DMARC passed; Microsoft marked it internally authenticated. The employee confirmed it was a scam.

    When a public agency learns this happened, should it identify and warn other possible recipients--or is internal remediation enough?

    Details: salemdata.net/johnpress/?p=1123

    #InfoSec #Cybersecurity #Phishing #IncidentResponse #CyberLaw #Privacy #LocalGovernment #GovernmentAccountability #security

  3. ๐—ช๐—ต๐—ฎ๐˜ ๐—ถ๐—ณ ๐—ฒ๐˜ƒ๐—ฒ๐—ฟ๐˜† ๐—ฎ๐—ป๐—ฎ๐—น๐˜†๐˜€๐˜ ๐—ต๐—ฎ๐—ฑ ๐—ฎ๐—ป ๐—ฒ๐—ป๐˜๐—ถ๐—ฟ๐—ฒ ๐—”๐—œ ๐—ฆ๐—ข๐—– ๐˜„๐—ผ๐—ฟ๐—ธ๐—ถ๐—ป๐—ด ๐—ฎ๐—น๐—ผ๐—ป๐—ด๐˜€๐—ถ๐—ฑ๐—ฒ ๐˜๐—ต๐—ฒ๐—บ?

    technicalciso.com/tc-visual-ai #CyberSecurity #SOC #SecurityOperations #AgenticAI #ArtificialIntelligence #ThreatDetection #ThreatHunting #IncidentResponse

  4. ๐—ช๐—ต๐—ฎ๐˜ ๐—ถ๐—ณ ๐—ฒ๐˜ƒ๐—ฒ๐—ฟ๐˜† ๐—ฎ๐—ป๐—ฎ๐—น๐˜†๐˜€๐˜ ๐—ต๐—ฎ๐—ฑ ๐—ฎ๐—ป ๐—ฒ๐—ป๐˜๐—ถ๐—ฟ๐—ฒ ๐—”๐—œ ๐—ฆ๐—ข๐—– ๐˜„๐—ผ๐—ฟ๐—ธ๐—ถ๐—ป๐—ด ๐—ฎ๐—น๐—ผ๐—ป๐—ด๐˜€๐—ถ๐—ฑ๐—ฒ ๐˜๐—ต๐—ฒ๐—บ?

    technicalciso.com/tc-visual-ai #CyberSecurity #SOC #SecurityOperations #AgenticAI #ArtificialIntelligence #ThreatDetection #ThreatHunting #IncidentResponse

  5. ๐—ช๐—ต๐—ฎ๐˜ ๐—ถ๐—ณ ๐—ฒ๐˜ƒ๐—ฒ๐—ฟ๐˜† ๐—ฎ๐—ป๐—ฎ๐—น๐˜†๐˜€๐˜ ๐—ต๐—ฎ๐—ฑ ๐—ฎ๐—ป ๐—ฒ๐—ป๐˜๐—ถ๐—ฟ๐—ฒ ๐—”๐—œ ๐—ฆ๐—ข๐—– ๐˜„๐—ผ๐—ฟ๐—ธ๐—ถ๐—ป๐—ด ๐—ฎ๐—น๐—ผ๐—ป๐—ด๐˜€๐—ถ๐—ฑ๐—ฒ ๐˜๐—ต๐—ฒ๐—บ?

    technicalciso.com/tc-visual-ai #CyberSecurity #SOC #SecurityOperations #AgenticAI #ArtificialIntelligence #ThreatDetection #ThreatHunting #IncidentResponse

  6. ๐—ช๐—ต๐—ฎ๐˜ ๐—ถ๐—ณ ๐—ฒ๐˜ƒ๐—ฒ๐—ฟ๐˜† ๐—ฎ๐—ป๐—ฎ๐—น๐˜†๐˜€๐˜ ๐—ต๐—ฎ๐—ฑ ๐—ฎ๐—ป ๐—ฒ๐—ป๐˜๐—ถ๐—ฟ๐—ฒ ๐—”๐—œ ๐—ฆ๐—ข๐—– ๐˜„๐—ผ๐—ฟ๐—ธ๐—ถ๐—ป๐—ด ๐—ฎ๐—น๐—ผ๐—ป๐—ด๐˜€๐—ถ๐—ฑ๐—ฒ ๐˜๐—ต๐—ฒ๐—บ?

    technicalciso.com/tc-visual-ai #CyberSecurity #SOC #SecurityOperations #AgenticAI #ArtificialIntelligence #ThreatDetection #ThreatHunting #IncidentResponse

  7. @chrissanders88

    Since most of it is PowerShell or HTA, I'd first check Powershell logs and then check the file system for new HTA files: NTFS, Journal, sysmon, evidence of execution.

    If there's Defender for Cloud, it's worth a look.

    And ofc check RunMRU (commands of run dialog) for common lolbins.

    #DFIR #analysis #incidentresponse #cybersecurity #infosec

  8. @chrissanders88

    Since most of it is PowerShell or HTA, I'd first check Powershell logs and then check the file system for new HTA files: NTFS, Journal, sysmon, evidence of execution.

    If there's Defender for Cloud, it's worth a look.

    And ofc check RunMRU (commands of run dialog) for common lolbins.

    #DFIR #analysis #incidentresponse #cybersecurity #infosec

  9. We have backups in multiple locations" and "we have backups an attacker with domain credentials cannot reach" are different claims. Only one survives contact with someone who's done their reconnaissance. haunted.lighthouse.co.im/artic
    #InfoSec #Cybersecurity #IncidentResponse #Backups #DigitalSovereignty

  10. We have backups in multiple locations" and "we have backups an attacker with domain credentials cannot reach" are different claims. Only one survives contact with someone who's done their reconnaissance. haunted.lighthouse.co.im/artic
    #InfoSec #Cybersecurity #IncidentResponse #Backups #DigitalSovereignty

  11. Der Cyber-Erpressungsangriff auf Rumรคniens Grundbuchbehรถrde zeigt wieder einmal, wie wichtig eine widerstandsfรคhige Backup- und Incident-Response-Strategie ist.

    Nachdem die Lรถsegeldzahlung verweigert wurde, lรถschte der Tรคter die Produktivdatenbank und manipulierte auch die Online-Backups. Physisch getrennte Offline-Backups verhinderten zum Glรผck den vollstรคndigen Datenverlust. Die betroffenen Systeme bleiben vorerst isoliert und werden neu aufgebaut.

    Warum isolierte Backups, Segmentierung und Incident Response bei Cyber-Erpressungsangriffen so wichtig sind und welche Rolle Lรถsegeldforderungen dabei spielen, zeige ich in meinem ausfรผhrlichen Artikel รผber Ransomware:

    โžก๏ธ secunis.de/ransomware-druckmit

    :boost_ok:

    #Cybersecurity #Backup #Data #Datenschutz #IncidentResponse #Ransomware #Secunis #ITSecurity

  12. Der Cyber-Erpressungsangriff auf Rumรคniens Grundbuchbehรถrde zeigt wieder einmal, wie wichtig eine widerstandsfรคhige Backup- und Incident-Response-Strategie ist.

    Nachdem die Lรถsegeldzahlung verweigert wurde, lรถschte der Tรคter die Produktivdatenbank und manipulierte auch die Online-Backups. Physisch getrennte Offline-Backups verhinderten zum Glรผck den vollstรคndigen Datenverlust. Die betroffenen Systeme bleiben vorerst isoliert und werden neu aufgebaut.

    Warum isolierte Backups, Segmentierung und Incident Response bei Cyber-Erpressungsangriffen so wichtig sind und welche Rolle Lรถsegeldforderungen dabei spielen, zeige ich in meinem ausfรผhrlichen Artikel รผber Ransomware:

    โžก๏ธ secunis.de/ransomware-druckmit

    :boost_ok:

    #Cybersecurity #Backup #Data #Datenschutz #IncidentResponse #Ransomware #Secunis #ITSecurity

  13. Responding to Cyber Incidents in 2026: Speed Without Chaos

    How to stop an attack, preserve evidence, and get your business back up and running without inadvertently helping the attacker through your own actions.

    pwn-all.com/blog/2026/07/20/re

    #cybersecurity #incidentresponse #pwn-all

  14. New on the FIRST blog: Ken van Wyk, FIRST Member & President and Principal Consultant, KRvW Associates, LLC and #FIRSTCON26 speaker, and Elliott Atkins, FIRST Liaison & Founder and Managing Director, Exercise3 Limited, on the most common incident response problems they've directly observed across hundreds of operations and exercises.
    Most #IncidentResponse teams have the technical chops and business knowledge to get the job done. So why do IR operations still go sideways?

    Two independent data sets, isolated from one another, revealed strikingly similar problems:

    ๐Ÿ“„ IRPs too dense for anyone to actually use in a crisis
    โš ๏ธ Process errors made under pressure: evidence handling, cost tracking, insurance compliance
    ๐Ÿ“Š Severity triage that doesn't reflect real business impact
    ๐Ÿงญ Unclear decision authority when it matters most
    ๐Ÿ‘ค Key personnel unavailable, with no backup empowered to act
    ๐Ÿ—ฃ๏ธ Discussions that never resolve into an actual decision
    โœ… Actions assigned but never tracked
    ๐Ÿ“ข Communication breakdowns, especially with non-technical stakeholders

    Read more: go.first.org/nqUbz

    #cybersecurity

  15. New on the FIRST blog: Ken van Wyk, FIRST Member & President and Principal Consultant, KRvW Associates, LLC and #FIRSTCON26 speaker, and Elliott Atkins, FIRST Liaison & Founder and Managing Director, Exercise3 Limited, on the most common incident response problems they've directly observed across hundreds of operations and exercises.
    Most #IncidentResponse teams have the technical chops and business knowledge to get the job done. So why do IR operations still go sideways?

    Two independent data sets, isolated from one another, revealed strikingly similar problems:

    ๐Ÿ“„ IRPs too dense for anyone to actually use in a crisis
    โš ๏ธ Process errors made under pressure: evidence handling, cost tracking, insurance compliance
    ๐Ÿ“Š Severity triage that doesn't reflect real business impact
    ๐Ÿงญ Unclear decision authority when it matters most
    ๐Ÿ‘ค Key personnel unavailable, with no backup empowered to act
    ๐Ÿ—ฃ๏ธ Discussions that never resolve into an actual decision
    โœ… Actions assigned but never tracked
    ๐Ÿ“ข Communication breakdowns, especially with non-technical stakeholders

    Read more: go.first.org/nqUbz

    #cybersecurity

  16. New on the FIRST blog: Ken van Wyk, FIRST Member & President and Principal Consultant, KRvW Associates, LLC and #FIRSTCON26 speaker, and Elliott Atkins, FIRST Liaison & Founder and Managing Director, Exercise3 Limited, on the most common incident response problems they've directly observed across hundreds of operations and exercises.
    Most #IncidentResponse teams have the technical chops and business knowledge to get the job done. So why do IR operations still go sideways?

    Two independent data sets, isolated from one another, revealed strikingly similar problems:

    ๐Ÿ“„ IRPs too dense for anyone to actually use in a crisis
    โš ๏ธ Process errors made under pressure: evidence handling, cost tracking, insurance compliance
    ๐Ÿ“Š Severity triage that doesn't reflect real business impact
    ๐Ÿงญ Unclear decision authority when it matters most
    ๐Ÿ‘ค Key personnel unavailable, with no backup empowered to act
    ๐Ÿ—ฃ๏ธ Discussions that never resolve into an actual decision
    โœ… Actions assigned but never tracked
    ๐Ÿ“ข Communication breakdowns, especially with non-technical stakeholders

    Read more: go.first.org/nqUbz

    #cybersecurity

  17. New on the FIRST blog: Ken van Wyk, FIRST Member & President and Principal Consultant, KRvW Associates, LLC and #FIRSTCON26 speaker, and Elliott Atkins, FIRST Liaison & Founder and Managing Director, Exercise3 Limited, on the most common incident response problems they've directly observed across hundreds of operations and exercises.
    Most #IncidentResponse teams have the technical chops and business knowledge to get the job done. So why do IR operations still go sideways?

    Two independent data sets, isolated from one another, revealed strikingly similar problems:

    ๐Ÿ“„ IRPs too dense for anyone to actually use in a crisis
    โš ๏ธ Process errors made under pressure: evidence handling, cost tracking, insurance compliance
    ๐Ÿ“Š Severity triage that doesn't reflect real business impact
    ๐Ÿงญ Unclear decision authority when it matters most
    ๐Ÿ‘ค Key personnel unavailable, with no backup empowered to act
    ๐Ÿ—ฃ๏ธ Discussions that never resolve into an actual decision
    โœ… Actions assigned but never tracked
    ๐Ÿ“ข Communication breakdowns, especially with non-technical stakeholders

    Read more: go.first.org/nqUbz

    #cybersecurity

  18. New on the FIRST blog: Ken van Wyk, FIRST Member & President and Principal Consultant, KRvW Associates, LLC and #FIRSTCON26 speaker, and Elliott Atkins, FIRST Liaison & Founder and Managing Director, Exercise3 Limited, on the most common incident response problems they've directly observed across hundreds of operations and exercises.
    Most #IncidentResponse teams have the technical chops and business knowledge to get the job done. So why do IR operations still go sideways?

    Two independent data sets, isolated from one another, revealed strikingly similar problems:

    ๐Ÿ“„ IRPs too dense for anyone to actually use in a crisis
    โš ๏ธ Process errors made under pressure: evidence handling, cost tracking, insurance compliance
    ๐Ÿ“Š Severity triage that doesn't reflect real business impact
    ๐Ÿงญ Unclear decision authority when it matters most
    ๐Ÿ‘ค Key personnel unavailable, with no backup empowered to act
    ๐Ÿ—ฃ๏ธ Discussions that never resolve into an actual decision
    โœ… Actions assigned but never tracked
    ๐Ÿ“ข Communication breakdowns, especially with non-technical stakeholders

    Read more: go.first.org/nqUbz

    #cybersecurity

  19. 14 hour day thanks to 3 PD alerts at once for 3 separate issues. Fuk clickfix and fuck AMOS, and stop making bad code. K thx Bai.

    #cybersecurity #infosec #incidentresponse #dfir

  20. 14 hour day thanks to 3 PD alerts at once for 3 separate issues. Fuk clickfix and fuck AMOS, and stop making bad code. K thx Bai.

    #cybersecurity #infosec #incidentresponse #dfir

  21. Security Tip: A written Incident Response (IR) plan is only half the battle. ๐Ÿ›ก๏ธ Don't let a real breach be the first time you test your procedures. Conduct quarterly Tabletop Exercises (TTX) involving IT, Legal, and PR to identify bottlenecks and technical gaps. Preparation is the best defense. Track the latest vulnerabilities to build better scenarios at cvedatabase.com

  22. ๐Ÿ”ต THREAT INTELLIGENCE

    Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands

    Vulnerability | CRITICAL
    CVEs: CVE-2026-15409, CVE-2026-15410

    SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day...

    Full analysis:
    yazoul.net/news/article/two-so

    #ThreatIntel #SecurityNews #IncidentResponse

  23. ๐Ÿ“ฌ FIRST's Q2FY26 Newsletter is here! Here's a look at what's inside:

    ๐ŸŽ‰ #FIRSTCON26 Recap

    A look back on the 38th Annual Conference in Denver โ€” five days, 100+ presentations, and lively networking that reflected the event's collaborative spirit. Outgoing PC Chair Merike Kaeo delivered an outstanding program, and Martijn van der Heide now takes the reins to prepare #FIRSTCON27 in Bangkok.

    ๐Ÿ—ณ๏ธ AGM & Board Elections

    The Annual General Meeting confirmed a refreshed Board: Serge Droz, Carlos Leonardo, and Olivier Caleff re-elected, Mona Elisabeth ร˜stvang returns after a year away, and Logan Wilkins joins for the first time.

    ๐Ÿ‘ฉโ€๐Ÿ’ป Women of FIRST Mentorship Program

    A new 6โ€“9 month mentorship pilot launches in Q3 2026 โ€” interest survey closes July 20.

    ๐Ÿ… Member Spotlight: Art Manion & Jay Jacobs

    Two of the driving forces behind FIRST's vulnerability management work: Jay Jacobs (co-Chair, EPSS SIG) and Art Manion (Chair, VRDX-SIG and Vulnerability Coordination SIG). Their contributions to CVSS and EPSS have given the community core frameworks for vulnerability assessment and prioritization, and both have been key organizers of VulnCon โ€” most recently leading a session in Scottsdale titled "A Paradigm Shift in Vulnerability Identity: Why Vulnerability Databases Struggle."

    ๐Ÿ•ฐ๏ธ New SIG Alert: Time Security

    With the Unix epoch overflow arriving January 19, 2038 โ€” plus an NTP rollover as soon as 2036 and a GPS week rollover later in 2038 โ€” the new Time Security SIG is coordinating the community's response. Now 60+ participants strong, its work is already feeding into ITU-T and IEEE standards efforts.

    ๐Ÿ›ก๏ธAdditional SIG Updates

    โœ… Metrics SIG released v1.1, completing metrics coverage across all five CSIRT Services Framework areas
    โœ… DNS Abuse SIG published v1.3 of the DNS Abuse Techniques Matrix โ€” the first update since 2023
    โœ… Insider Threat SIG held its inaugural in-person meetup in Denver
    โœ… EPSS v5 went live June 15 with improved calibration and new exploit-detection signals
    โœ… Policy SIG published a brief on AI's impact across the cybersecurity ecosystem

    ๐ŸŒ Capacity Building

    FIRST launched a new initiative under the G7-ECOWAS Platform for Advancing Cybersecurity, working with ECOWAS and GIZ to support regional cyber confidence-building measures across West Africa.

    Read more ๐Ÿ‘‰ go.first.org/AXSBi

    #CyberDefense #cybersecurity #IncidentResponse #infosec

  24. ๐Ÿ“ฌ FIRST's Q2FY26 Newsletter is here! Here's a look at what's inside:

    ๐ŸŽ‰ #FIRSTCON26 Recap

    A look back on the 38th Annual Conference in Denver โ€” five days, 100+ presentations, and lively networking that reflected the event's collaborative spirit. Outgoing PC Chair Merike Kaeo delivered an outstanding program, and Martijn van der Heide now takes the reins to prepare #FIRSTCON27 in Bangkok.

    ๐Ÿ—ณ๏ธ AGM & Board Elections

    The Annual General Meeting confirmed a refreshed Board: Serge Droz, Carlos Leonardo, and Olivier Caleff re-elected, Mona Elisabeth ร˜stvang returns after a year away, and Logan Wilkins joins for the first time.

    ๐Ÿ‘ฉโ€๐Ÿ’ป Women of FIRST Mentorship Program

    A new 6โ€“9 month mentorship pilot launches in Q3 2026 โ€” interest survey closes July 20.

    ๐Ÿ… Member Spotlight: Art Manion & Jay Jacobs

    Two of the driving forces behind FIRST's vulnerability management work: Jay Jacobs (co-Chair, EPSS SIG) and Art Manion (Chair, VRDX-SIG and Vulnerability Coordination SIG). Their contributions to CVSS and EPSS have given the community core frameworks for vulnerability assessment and prioritization, and both have been key organizers of VulnCon โ€” most recently leading a session in Scottsdale titled "A Paradigm Shift in Vulnerability Identity: Why Vulnerability Databases Struggle."

    ๐Ÿ•ฐ๏ธ New SIG Alert: Time Security

    With the Unix epoch overflow arriving January 19, 2038 โ€” plus an NTP rollover as soon as 2036 and a GPS week rollover later in 2038 โ€” the new Time Security SIG is coordinating the community's response. Now 60+ participants strong, its work is already feeding into ITU-T and IEEE standards efforts.

    ๐Ÿ›ก๏ธAdditional SIG Updates

    โœ… Metrics SIG released v1.1, completing metrics coverage across all five CSIRT Services Framework areas
    โœ… DNS Abuse SIG published v1.3 of the DNS Abuse Techniques Matrix โ€” the first update since 2023
    โœ… Insider Threat SIG held its inaugural in-person meetup in Denver
    โœ… EPSS v5 went live June 15 with improved calibration and new exploit-detection signals
    โœ… Policy SIG published a brief on AI's impact across the cybersecurity ecosystem

    ๐ŸŒ Capacity Building

    FIRST launched a new initiative under the G7-ECOWAS Platform for Advancing Cybersecurity, working with ECOWAS and GIZ to support regional cyber confidence-building measures across West Africa.

    Read more ๐Ÿ‘‰ go.first.org/AXSBi

    #CyberDefense #cybersecurity #IncidentResponse #infosec

  25. ๐Ÿ“ฌ FIRST's Q2FY26 Newsletter is here! Here's a look at what's inside:

    ๐ŸŽ‰ #FIRSTCON26 Recap

    A look back on the 38th Annual Conference in Denver โ€” five days, 100+ presentations, and lively networking that reflected the event's collaborative spirit. Outgoing PC Chair Merike Kaeo delivered an outstanding program, and Martijn van der Heide now takes the reins to prepare #FIRSTCON27 in Bangkok.

    ๐Ÿ—ณ๏ธ AGM & Board Elections

    The Annual General Meeting confirmed a refreshed Board: Serge Droz, Carlos Leonardo, and Olivier Caleff re-elected, Mona Elisabeth ร˜stvang returns after a year away, and Logan Wilkins joins for the first time.

    ๐Ÿ‘ฉโ€๐Ÿ’ป Women of FIRST Mentorship Program

    A new 6โ€“9 month mentorship pilot launches in Q3 2026 โ€” interest survey closes July 20.

    ๐Ÿ… Member Spotlight: Art Manion & Jay Jacobs

    Two of the driving forces behind FIRST's vulnerability management work: Jay Jacobs (co-Chair, EPSS SIG) and Art Manion (Chair, VRDX-SIG and Vulnerability Coordination SIG). Their contributions to CVSS and EPSS have given the community core frameworks for vulnerability assessment and prioritization, and both have been key organizers of VulnCon โ€” most recently leading a session in Scottsdale titled "A Paradigm Shift in Vulnerability Identity: Why Vulnerability Databases Struggle."

    ๐Ÿ•ฐ๏ธ New SIG Alert: Time Security

    With the Unix epoch overflow arriving January 19, 2038 โ€” plus an NTP rollover as soon as 2036 and a GPS week rollover later in 2038 โ€” the new Time Security SIG is coordinating the community's response. Now 60+ participants strong, its work is already feeding into ITU-T and IEEE standards efforts.

    ๐Ÿ›ก๏ธAdditional SIG Updates

    โœ… Metrics SIG released v1.1, completing metrics coverage across all five CSIRT Services Framework areas
    โœ… DNS Abuse SIG published v1.3 of the DNS Abuse Techniques Matrix โ€” the first update since 2023
    โœ… Insider Threat SIG held its inaugural in-person meetup in Denver
    โœ… EPSS v5 went live June 15 with improved calibration and new exploit-detection signals
    โœ… Policy SIG published a brief on AI's impact across the cybersecurity ecosystem

    ๐ŸŒ Capacity Building

    FIRST launched a new initiative under the G7-ECOWAS Platform for Advancing Cybersecurity, working with ECOWAS and GIZ to support regional cyber confidence-building measures across West Africa.

    Read more ๐Ÿ‘‰ go.first.org/AXSBi

    #CyberDefense #cybersecurity #IncidentResponse #infosec

  26. ๐Ÿ“ฌ FIRST's Q2FY26 Newsletter is here! Here's a look at what's inside:

    ๐ŸŽ‰ #FIRSTCON26 Recap

    A look back on the 38th Annual Conference in Denver โ€” five days, 100+ presentations, and lively networking that reflected the event's collaborative spirit. Outgoing PC Chair Merike Kaeo delivered an outstanding program, and Martijn van der Heide now takes the reins to prepare #FIRSTCON27 in Bangkok.

    ๐Ÿ—ณ๏ธ AGM & Board Elections

    The Annual General Meeting confirmed a refreshed Board: Serge Droz, Carlos Leonardo, and Olivier Caleff re-elected, Mona Elisabeth ร˜stvang returns after a year away, and Logan Wilkins joins for the first time.

    ๐Ÿ‘ฉโ€๐Ÿ’ป Women of FIRST Mentorship Program

    A new 6โ€“9 month mentorship pilot launches in Q3 2026 โ€” interest survey closes July 20.

    ๐Ÿ… Member Spotlight: Art Manion & Jay Jacobs

    Two of the driving forces behind FIRST's vulnerability management work: Jay Jacobs (co-Chair, EPSS SIG) and Art Manion (Chair, VRDX-SIG and Vulnerability Coordination SIG). Their contributions to CVSS and EPSS have given the community core frameworks for vulnerability assessment and prioritization, and both have been key organizers of VulnCon โ€” most recently leading a session in Scottsdale titled "A Paradigm Shift in Vulnerability Identity: Why Vulnerability Databases Struggle."

    ๐Ÿ•ฐ๏ธ New SIG Alert: Time Security

    With the Unix epoch overflow arriving January 19, 2038 โ€” plus an NTP rollover as soon as 2036 and a GPS week rollover later in 2038 โ€” the new Time Security SIG is coordinating the community's response. Now 60+ participants strong, its work is already feeding into ITU-T and IEEE standards efforts.

    ๐Ÿ›ก๏ธAdditional SIG Updates

    โœ… Metrics SIG released v1.1, completing metrics coverage across all five CSIRT Services Framework areas
    โœ… DNS Abuse SIG published v1.3 of the DNS Abuse Techniques Matrix โ€” the first update since 2023
    โœ… Insider Threat SIG held its inaugural in-person meetup in Denver
    โœ… EPSS v5 went live June 15 with improved calibration and new exploit-detection signals
    โœ… Policy SIG published a brief on AI's impact across the cybersecurity ecosystem

    ๐ŸŒ Capacity Building

    FIRST launched a new initiative under the G7-ECOWAS Platform for Advancing Cybersecurity, working with ECOWAS and GIZ to support regional cyber confidence-building measures across West Africa.

    Read more ๐Ÿ‘‰ go.first.org/AXSBi

    #CyberDefense #cybersecurity #IncidentResponse #infosec

  27. ๐Ÿ“ฌ FIRST's Q2FY26 Newsletter is here! Here's a look at what's inside:

    ๐ŸŽ‰ #FIRSTCON26 Recap

    A look back on the 38th Annual Conference in Denver โ€” five days, 100+ presentations, and lively networking that reflected the event's collaborative spirit. Outgoing PC Chair Merike Kaeo delivered an outstanding program, and Martijn van der Heide now takes the reins to prepare #FIRSTCON27 in Bangkok.

    ๐Ÿ—ณ๏ธ AGM & Board Elections

    The Annual General Meeting confirmed a refreshed Board: Serge Droz, Carlos Leonardo, and Olivier Caleff re-elected, Mona Elisabeth ร˜stvang returns after a year away, and Logan Wilkins joins for the first time.

    ๐Ÿ‘ฉโ€๐Ÿ’ป Women of FIRST Mentorship Program

    A new 6โ€“9 month mentorship pilot launches in Q3 2026 โ€” interest survey closes July 20.

    ๐Ÿ… Member Spotlight: Art Manion & Jay Jacobs

    Two of the driving forces behind FIRST's vulnerability management work: Jay Jacobs (co-Chair, EPSS SIG) and Art Manion (Chair, VRDX-SIG and Vulnerability Coordination SIG). Their contributions to CVSS and EPSS have given the community core frameworks for vulnerability assessment and prioritization, and both have been key organizers of VulnCon โ€” most recently leading a session in Scottsdale titled "A Paradigm Shift in Vulnerability Identity: Why Vulnerability Databases Struggle."

    ๐Ÿ•ฐ๏ธ New SIG Alert: Time Security

    With the Unix epoch overflow arriving January 19, 2038 โ€” plus an NTP rollover as soon as 2036 and a GPS week rollover later in 2038 โ€” the new Time Security SIG is coordinating the community's response. Now 60+ participants strong, its work is already feeding into ITU-T and IEEE standards efforts.

    ๐Ÿ›ก๏ธAdditional SIG Updates

    โœ… Metrics SIG released v1.1, completing metrics coverage across all five CSIRT Services Framework areas
    โœ… DNS Abuse SIG published v1.3 of the DNS Abuse Techniques Matrix โ€” the first update since 2023
    โœ… Insider Threat SIG held its inaugural in-person meetup in Denver
    โœ… EPSS v5 went live June 15 with improved calibration and new exploit-detection signals
    โœ… Policy SIG published a brief on AI's impact across the cybersecurity ecosystem

    ๐ŸŒ Capacity Building

    FIRST launched a new initiative under the G7-ECOWAS Platform for Advancing Cybersecurity, working with ECOWAS and GIZ to support regional cyber confidence-building measures across West Africa.

    Read more ๐Ÿ‘‰ go.first.org/AXSBi

    #CyberDefense #cybersecurity #IncidentResponse #infosec

  28. Working in cyber in 2026, we spend so much of our time connecting through screens. But every year, #FIRSTCON reminds us that the strongest partnerships are still built face to face.

    You can exchange emails for years, join countless video calls, and collaborate across continents, but there's something irreplaceable about sharing a meal, raising a glass, and getting to know the person behind the job title. Those moments build the trust that matters when the pressure is on. When an incident strikes, you're not reaching out to a stranger, you're calling a friend.

    Our #FIRSTCON26 recap reflects on the conversations, connections, and community that made this year's conference in Denver so memorable.

    Read the full blog here: first.org/blog/20260703-When-F

    #FIRSTCON26 #CyberSecurity #IncidentResponse #Community #FIRST

  29. Working in cyber in 2026, we spend so much of our time connecting through screens. But every year, #FIRSTCON reminds us that the strongest partnerships are still built face to face.

    You can exchange emails for years, join countless video calls, and collaborate across continents, but there's something irreplaceable about sharing a meal, raising a glass, and getting to know the person behind the job title. Those moments build the trust that matters when the pressure is on. When an incident strikes, you're not reaching out to a stranger, you're calling a friend.

    Our #FIRSTCON26 recap reflects on the conversations, connections, and community that made this year's conference in Denver so memorable.

    Read the full blog here: first.org/blog/20260703-When-F

    #FIRSTCON26 #CyberSecurity #IncidentResponse #Community #FIRST

  30. Working in cyber in 2026, we spend so much of our time connecting through screens. But every year, #FIRSTCON reminds us that the strongest partnerships are still built face to face.

    You can exchange emails for years, join countless video calls, and collaborate across continents, but there's something irreplaceable about sharing a meal, raising a glass, and getting to know the person behind the job title. Those moments build the trust that matters when the pressure is on. When an incident strikes, you're not reaching out to a stranger, you're calling a friend.

    Our #FIRSTCON26 recap reflects on the conversations, connections, and community that made this year's conference in Denver so memorable.

    Read the full blog here: first.org/blog/20260703-When-F

    #FIRSTCON26 #CyberSecurity #IncidentResponse #Community #FIRST

  31. Working in cyber in 2026, we spend so much of our time connecting through screens. But every year, #FIRSTCON reminds us that the strongest partnerships are still built face to face.

    You can exchange emails for years, join countless video calls, and collaborate across continents, but there's something irreplaceable about sharing a meal, raising a glass, and getting to know the person behind the job title. Those moments build the trust that matters when the pressure is on. When an incident strikes, you're not reaching out to a stranger, you're calling a friend.

    Our #FIRSTCON26 recap reflects on the conversations, connections, and community that made this year's conference in Denver so memorable.

    Read the full blog here: first.org/blog/20260703-When-F

    #FIRSTCON26 #CyberSecurity #IncidentResponse #Community #FIRST

  32. Working in cyber in 2026, we spend so much of our time connecting through screens. But every year, #FIRSTCON reminds us that the strongest partnerships are still built face to face.

    You can exchange emails for years, join countless video calls, and collaborate across continents, but there's something irreplaceable about sharing a meal, raising a glass, and getting to know the person behind the job title. Those moments build the trust that matters when the pressure is on. When an incident strikes, you're not reaching out to a stranger, you're calling a friend.

    Our #FIRSTCON26 recap reflects on the conversations, connections, and community that made this year's conference in Denver so memorable.

    Read the full blog here: first.org/blog/20260703-When-F

    #FIRSTCON26 #CyberSecurity #IncidentResponse #Community #FIRST

  33. Security Tip: Prioritize forensics during Incident Response. ๐Ÿ›ก๏ธ When a breach occurs, the instinct is to wipe and rebuild immediately. However, without capturing volatile memory (RAM) and disk images first, you lose the "how" and "who." Establish a standard procedure for evidence preservation to ensure your team can conduct a proper post-mortem and prevent recurrence. Stay informed on the latest threats at cvedatabase.com #InfoSec #IncidentResponse #CyberSecurity

  34. Security Tip: Prioritize forensics during Incident Response. ๐Ÿ›ก๏ธ When a breach occurs, the instinct is to wipe and rebuild immediately. However, without capturing volatile memory (RAM) and disk images first, you lose the "how" and "who." Establish a standard procedure for evidence preservation to ensure your team can conduct a proper post-mortem and prevent recurrence. Stay informed on the latest threats at cvedatabase.com

  35. Security Tip: The 'Blameless Post-Mortem' is a vital Incident Response tool. ๐Ÿ›ก๏ธ When a security event occurs, the goal should be understanding how the system allowed the mistake, not who made it. Focus on improving technical controls and documentation. This builds a culture where teams report issues early rather than hiding them. Use cvedatabase.com to track vulnerabilities that might affect your stack.

  36. ----------------

    ๐ŸŽฏ AI
    ===================

    Sygnia: AI-Supercharged 72-Hour Cloud Attack Investigation

    Sygnia published findings from an incident response engagement where a threat actor compromised an AWS-based environment, progressing from initial access to broad cloud compromise in approximately 72 hours. The case is notable not for novel techniques, but for the apparent use of AI to accelerate familiar cloud attack methods.

    Key Findings
    โ€ข The intrusion expanded across applications, cloud infrastructure, source-control systems, CI/CD pipelines, and runtime services
    โ€ข No zero-day exploits or novel malware were observed. Every technique mapped to established MITRE ATT&CK behaviors
    โ€ข Multiple artifacts suggested AI-assisted or agentic workflows: attacker-created scripts, structured reporting artifacts, and highly parallel activity
    โ€ข The threat actor repeatedly leveraged newly acquired credentials to restart discovery, secrets harvesting, persistence, and impact activities
    โ€ข The primary defensive challenge was the speed and scale of execution, not the novelty of individual techniques

    Where AI Changed the Equation

    The report identifies several indicators of AI involvement:
    โ€ข Rapid generation of environment-specific scripts and tooling
    โ€ข Structured, formatted reporting artifacts consistent with AI-generated output
    โ€ข Highly parallel discovery and exploitation activities across multiple surfaces
    โ€ข Compressed timeline for reconnaissance, adaptation, and operational execution inconsistent with purely manual operations

    Attack Path

    1. Initial access to AWS environment
    2. Credential harvesting and secrets discovery
    3. Lateral movement across applications and cloud services
    4. Persistence through compromised identity and deployment workflows
    5. Expansion into source-control and CI/CD systems
    6. Impact across cloud, identity, and application layers

    Each credential acquisition restarted the cycle.

    Defensive Gaps
    โ€ข Fragmented visibility across cloud, identity, and application layers
    โ€ข Monitoring gaps that delayed detection and correlation
    โ€ข Absence of predefined incident response procedures
    โ€ข Weak secrets management and identity governance
    โ€ข Overly permissive cloud and CI/CD permissions

    Remediation

    Sygnia recommends adapting IR playbooks for AI-enabled threats, prioritizing broad containment over precision when speed matters, rotating credentials aggressively, treating identity as the primary security boundary, and automating defensive responses. Infrastructure rebuilds may be necessary for broadly compromised environments.

    Known weaknesses get exploited faster and at broader scale when AI assistance is available. End-to-end visibility and predefined containment procedures are prerequisites, not aspirations.

    ๐Ÿ”น AI #CloudSecurity #IncidentResponse #Sygnia #MITREATTACK

    ๐Ÿ”— Source: sygnia.co/blog/inside-an-ai-as

  37. Security Tip: Establish out-of-band (OOB) communication channels for your Incident Response team. ๐Ÿ›ก๏ธ

    If an attacker gains access to your primary email or chat platforms, they can monitor your response efforts or even disrupt them. Prepare a secure, separate channel (like Signal or a dedicated offline instance) in advance to maintain command and control.

    Stay informed on the latest vulnerabilities at: cvedatabase.com

  38. How can you use your AI agent to transform raw threat notes into a well-sourced CTI report draft? Use my MCP server with my new CTI report template and writing guidance. Your sensitive data stays local.

    zeltser.com/cyber-threat-intel

    #threatintelligence #incidentresponse

  39. How can you use your AI agent to transform raw threat notes into a well-sourced CTI report draft? Use my MCP server with my new CTI report template and writing guidance. Your sensitive data stays local.

    zeltser.com/cyber-threat-intel

    #threatintelligence #incidentresponse

  40. โ„๏ธ Save the Date! โ„๏ธ
    Cold Incident Response 2026 โ€ข Tue Oct 13 โ€“ Thu Oct 15 โ€ข Oslo, Norway

    Hosted by our Norwegian FIRST Teams ๐ŸŒ

    Bundle up, block your calendars, and get ready for three days of cool minds, cold cases studies with warm Nordic hospitality.

    ๐Ÿ”—go.first.org/ASews

    #technicalcolloquium #incidentresponse

  41. โ„๏ธ Save the Date! โ„๏ธ
    Cold Incident Response 2026 โ€ข Tue Oct 13 โ€“ Thu Oct 15 โ€ข Oslo, Norway

    Hosted by our Norwegian FIRST Teams ๐ŸŒ

    Bundle up, block your calendars, and get ready for three days of cool minds, cold cases studies with warm Nordic hospitality.

    ๐Ÿ”—go.first.org/ASews

    #technicalcolloquium #incidentresponse

  42. Security Tip: Is your Incident Response (IR) plan just a document on a shelf? ๐Ÿ›ก๏ธ

    A plan is only effective if your team knows how to execute it. Conduct regular tabletop exercises to simulate real-world scenarios. This helps identify bottlenecks, communication failures, and technical gaps before an actual breach occurs.

    Actionable awareness is key to resilience. Use cvedatabase.com to track the latest threats.

  43. Security Tip: An Incident Response (IR) plan is only as good as its last test. ๐Ÿ›ก๏ธ

    Conduct regular tabletop exercises involving both technical teams and stakeholders (Legal, PR, Execs). These simulations reveal bottlenecks and communication gaps that documentation alone can't find. Proactive preparation is the difference between a controlled recovery and chaos.

    Track the latest threats at cvedatabase.com