#incidentresponse — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #incidentresponse, aggregated by home.social.
-
A suspicious document-sharing email appeared to come from a City of Salem account. SPF, DKIM and DMARC passed; Microsoft marked it internally authenticated. The employee confirmed it was a scam.
When a public agency learns this happened, should it identify and warn other possible recipients--or is internal remediation enough?
Details: https://salemdata.net/johnpress/?p=1123
#InfoSec #Cybersecurity #Phishing #IncidentResponse #CyberLaw #Privacy #LocalGovernment #GovernmentAccountability #security
-
A suspicious document-sharing email appeared to come from a City of Salem account. SPF, DKIM and DMARC passed; Microsoft marked it internally authenticated. The employee confirmed it was a scam.
When a public agency learns this happened, should it identify and warn other possible recipients--or is internal remediation enough?
Details: https://salemdata.net/johnpress/?p=1123
#InfoSec #Cybersecurity #Phishing #IncidentResponse #CyberLaw #Privacy #LocalGovernment #GovernmentAccountability #security
-
𝗪𝗵𝗮𝘁 𝗶𝗳 𝗲𝘃𝗲𝗿𝘆 𝗮𝗻𝗮𝗹𝘆𝘀𝘁 𝗵𝗮𝗱 𝗮𝗻 𝗲𝗻𝘁𝗶𝗿𝗲 𝗔𝗜 𝗦𝗢𝗖 𝘄𝗼𝗿𝗸𝗶𝗻𝗴 𝗮𝗹𝗼𝗻𝗴𝘀𝗶𝗱𝗲 𝘁𝗵𝗲𝗺?
https://technicalciso.com/tc-visual-ai-soc-agents/ #CyberSecurity #SOC #SecurityOperations #AgenticAI #ArtificialIntelligence #ThreatDetection #ThreatHunting #IncidentResponse
-
𝗪𝗵𝗮𝘁 𝗶𝗳 𝗲𝘃𝗲𝗿𝘆 𝗮𝗻𝗮𝗹𝘆𝘀𝘁 𝗵𝗮𝗱 𝗮𝗻 𝗲𝗻𝘁𝗶𝗿𝗲 𝗔𝗜 𝗦𝗢𝗖 𝘄𝗼𝗿𝗸𝗶𝗻𝗴 𝗮𝗹𝗼𝗻𝗴𝘀𝗶𝗱𝗲 𝘁𝗵𝗲𝗺?
https://technicalciso.com/tc-visual-ai-soc-agents/ #CyberSecurity #SOC #SecurityOperations #AgenticAI #ArtificialIntelligence #ThreatDetection #ThreatHunting #IncidentResponse
-
Since most of it is PowerShell or HTA, I'd first check Powershell logs and then check the file system for new HTA files: NTFS, Journal, sysmon, evidence of execution.
If there's Defender for Cloud, it's worth a look.
And ofc check RunMRU (commands of run dialog) for common lolbins.
-
Since most of it is PowerShell or HTA, I'd first check Powershell logs and then check the file system for new HTA files: NTFS, Journal, sysmon, evidence of execution.
If there's Defender for Cloud, it's worth a look.
And ofc check RunMRU (commands of run dialog) for common lolbins.
-
We have backups in multiple locations" and "we have backups an attacker with domain credentials cannot reach" are different claims. Only one survives contact with someone who's done their reconnaissance. https://haunted.lighthouse.co.im/articles/so-you-think-your-backups-are-secure/
#InfoSec #Cybersecurity #IncidentResponse #Backups #DigitalSovereignty -
We have backups in multiple locations" and "we have backups an attacker with domain credentials cannot reach" are different claims. Only one survives contact with someone who's done their reconnaissance. https://haunted.lighthouse.co.im/articles/so-you-think-your-backups-are-secure/
#InfoSec #Cybersecurity #IncidentResponse #Backups #DigitalSovereignty -
Der Cyber-Erpressungsangriff auf Rumäniens Grundbuchbehörde zeigt wieder einmal, wie wichtig eine widerstandsfähige Backup- und Incident-Response-Strategie ist.
Nachdem die Lösegeldzahlung verweigert wurde, löschte der Täter die Produktivdatenbank und manipulierte auch die Online-Backups. Physisch getrennte Offline-Backups verhinderten zum Glück den vollständigen Datenverlust. Die betroffenen Systeme bleiben vorerst isoliert und werden neu aufgebaut.
Warum isolierte Backups, Segmentierung und Incident Response bei Cyber-Erpressungsangriffen so wichtig sind und welche Rolle Lösegeldforderungen dabei spielen, zeige ich in meinem ausführlichen Artikel über Ransomware:
➡️ https://www.secunis.de/ransomware-druckmittel/
:boost_ok:
#Cybersecurity #Backup #Data #Datenschutz #IncidentResponse #Ransomware #Secunis #ITSecurity
-
Der Cyber-Erpressungsangriff auf Rumäniens Grundbuchbehörde zeigt wieder einmal, wie wichtig eine widerstandsfähige Backup- und Incident-Response-Strategie ist.
Nachdem die Lösegeldzahlung verweigert wurde, löschte der Täter die Produktivdatenbank und manipulierte auch die Online-Backups. Physisch getrennte Offline-Backups verhinderten zum Glück den vollständigen Datenverlust. Die betroffenen Systeme bleiben vorerst isoliert und werden neu aufgebaut.
Warum isolierte Backups, Segmentierung und Incident Response bei Cyber-Erpressungsangriffen so wichtig sind und welche Rolle Lösegeldforderungen dabei spielen, zeige ich in meinem ausführlichen Artikel über Ransomware:
➡️ https://www.secunis.de/ransomware-druckmittel/
:boost_ok:
#Cybersecurity #Backup #Data #Datenschutz #IncidentResponse #Ransomware #Secunis #ITSecurity
-
Responding to Cyber Incidents in 2026: Speed Without Chaos
How to stop an attack, preserve evidence, and get your business back up and running without inadvertently helping the attacker through your own actions.
https://pwn-all.com/blog/2026/07/20/responding-to-cyber-incidents-in-2026-speed-without-chaos.html
-
Hugging Face breached by autonomous AI agent https://www.byteseu.com/2212067/ #AgenticAi #AI #ArtificialIntelligence #HuggingFace #IncidentResponse #IntrusionDetection #LLMs #MachineLearning
-
New on the FIRST blog: Ken van Wyk, FIRST Member & President and Principal Consultant, KRvW Associates, LLC and #FIRSTCON26 speaker, and Elliott Atkins, FIRST Liaison & Founder and Managing Director, Exercise3 Limited, on the most common incident response problems they've directly observed across hundreds of operations and exercises.
Most #IncidentResponse teams have the technical chops and business knowledge to get the job done. So why do IR operations still go sideways?Two independent data sets, isolated from one another, revealed strikingly similar problems:
📄 IRPs too dense for anyone to actually use in a crisis
⚠️ Process errors made under pressure: evidence handling, cost tracking, insurance compliance
📊 Severity triage that doesn't reflect real business impact
🧭 Unclear decision authority when it matters most
👤 Key personnel unavailable, with no backup empowered to act
🗣️ Discussions that never resolve into an actual decision
✅ Actions assigned but never tracked
📢 Communication breakdowns, especially with non-technical stakeholdersRead more: https://go.first.org/nqUbz
-
New on the FIRST blog: Ken van Wyk, FIRST Member & President and Principal Consultant, KRvW Associates, LLC and #FIRSTCON26 speaker, and Elliott Atkins, FIRST Liaison & Founder and Managing Director, Exercise3 Limited, on the most common incident response problems they've directly observed across hundreds of operations and exercises.
Most #IncidentResponse teams have the technical chops and business knowledge to get the job done. So why do IR operations still go sideways?Two independent data sets, isolated from one another, revealed strikingly similar problems:
📄 IRPs too dense for anyone to actually use in a crisis
⚠️ Process errors made under pressure: evidence handling, cost tracking, insurance compliance
📊 Severity triage that doesn't reflect real business impact
🧭 Unclear decision authority when it matters most
👤 Key personnel unavailable, with no backup empowered to act
🗣️ Discussions that never resolve into an actual decision
✅ Actions assigned but never tracked
📢 Communication breakdowns, especially with non-technical stakeholdersRead more: https://go.first.org/nqUbz
-
New on the FIRST blog: Ken van Wyk, FIRST Member & President and Principal Consultant, KRvW Associates, LLC and #FIRSTCON26 speaker, and Elliott Atkins, FIRST Liaison & Founder and Managing Director, Exercise3 Limited, on the most common incident response problems they've directly observed across hundreds of operations and exercises.
Most #IncidentResponse teams have the technical chops and business knowledge to get the job done. So why do IR operations still go sideways?Two independent data sets, isolated from one another, revealed strikingly similar problems:
📄 IRPs too dense for anyone to actually use in a crisis
⚠️ Process errors made under pressure: evidence handling, cost tracking, insurance compliance
📊 Severity triage that doesn't reflect real business impact
🧭 Unclear decision authority when it matters most
👤 Key personnel unavailable, with no backup empowered to act
🗣️ Discussions that never resolve into an actual decision
✅ Actions assigned but never tracked
📢 Communication breakdowns, especially with non-technical stakeholdersRead more: https://go.first.org/nqUbz
-
New on the FIRST blog: Ken van Wyk, FIRST Member & President and Principal Consultant, KRvW Associates, LLC and #FIRSTCON26 speaker, and Elliott Atkins, FIRST Liaison & Founder and Managing Director, Exercise3 Limited, on the most common incident response problems they've directly observed across hundreds of operations and exercises.
Most #IncidentResponse teams have the technical chops and business knowledge to get the job done. So why do IR operations still go sideways?Two independent data sets, isolated from one another, revealed strikingly similar problems:
📄 IRPs too dense for anyone to actually use in a crisis
⚠️ Process errors made under pressure: evidence handling, cost tracking, insurance compliance
📊 Severity triage that doesn't reflect real business impact
🧭 Unclear decision authority when it matters most
👤 Key personnel unavailable, with no backup empowered to act
🗣️ Discussions that never resolve into an actual decision
✅ Actions assigned but never tracked
📢 Communication breakdowns, especially with non-technical stakeholdersRead more: https://go.first.org/nqUbz
-
New on the FIRST blog: Ken van Wyk, FIRST Member & President and Principal Consultant, KRvW Associates, LLC and #FIRSTCON26 speaker, and Elliott Atkins, FIRST Liaison & Founder and Managing Director, Exercise3 Limited, on the most common incident response problems they've directly observed across hundreds of operations and exercises.
Most #IncidentResponse teams have the technical chops and business knowledge to get the job done. So why do IR operations still go sideways?Two independent data sets, isolated from one another, revealed strikingly similar problems:
📄 IRPs too dense for anyone to actually use in a crisis
⚠️ Process errors made under pressure: evidence handling, cost tracking, insurance compliance
📊 Severity triage that doesn't reflect real business impact
🧭 Unclear decision authority when it matters most
👤 Key personnel unavailable, with no backup empowered to act
🗣️ Discussions that never resolve into an actual decision
✅ Actions assigned but never tracked
📢 Communication breakdowns, especially with non-technical stakeholdersRead more: https://go.first.org/nqUbz
-
14 hour day thanks to 3 PD alerts at once for 3 separate issues. Fuk clickfix and fuck AMOS, and stop making bad code. K thx Bai.
-
14 hour day thanks to 3 PD alerts at once for 3 separate issues. Fuk clickfix and fuck AMOS, and stop making bad code. K thx Bai.
-
Security Tip: A written Incident Response (IR) plan is only half the battle. 🛡️ Don't let a real breach be the first time you test your procedures. Conduct quarterly Tabletop Exercises (TTX) involving IT, Legal, and PR to identify bottlenecks and technical gaps. Preparation is the best defense. Track the latest vulnerabilities to build better scenarios at https://cvedatabase.com #InfoSec #CyberSecurity #IncidentResponse #BlueTeam
-
🔵 THREAT INTELLIGENCE
Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
Vulnerability | CRITICAL
CVEs: CVE-2026-15409, CVE-2026-15410SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day...
Full analysis:
https://www.yazoul.net/news/article/two-sonicwall-sma-1000-zero-days-exploited-one-could-enable-admin-commands -
📬 FIRST's Q2FY26 Newsletter is here! Here's a look at what's inside:
🎉 #FIRSTCON26 Recap
A look back on the 38th Annual Conference in Denver — five days, 100+ presentations, and lively networking that reflected the event's collaborative spirit. Outgoing PC Chair Merike Kaeo delivered an outstanding program, and Martijn van der Heide now takes the reins to prepare #FIRSTCON27 in Bangkok.
🗳️ AGM & Board Elections
The Annual General Meeting confirmed a refreshed Board: Serge Droz, Carlos Leonardo, and Olivier Caleff re-elected, Mona Elisabeth Østvang returns after a year away, and Logan Wilkins joins for the first time.
👩💻 Women of FIRST Mentorship ProgramA new 6–9 month mentorship pilot launches in Q3 2026 — interest survey closes July 20.
🏅 Member Spotlight: Art Manion & Jay Jacobs
Two of the driving forces behind FIRST's vulnerability management work: Jay Jacobs (co-Chair, EPSS SIG) and Art Manion (Chair, VRDX-SIG and Vulnerability Coordination SIG). Their contributions to CVSS and EPSS have given the community core frameworks for vulnerability assessment and prioritization, and both have been key organizers of VulnCon — most recently leading a session in Scottsdale titled "A Paradigm Shift in Vulnerability Identity: Why Vulnerability Databases Struggle."
🕰️ New SIG Alert: Time Security
With the Unix epoch overflow arriving January 19, 2038 — plus an NTP rollover as soon as 2036 and a GPS week rollover later in 2038 — the new Time Security SIG is coordinating the community's response. Now 60+ participants strong, its work is already feeding into ITU-T and IEEE standards efforts.
🛡️Additional SIG Updates
✅ Metrics SIG released v1.1, completing metrics coverage across all five CSIRT Services Framework areas
✅ DNS Abuse SIG published v1.3 of the DNS Abuse Techniques Matrix — the first update since 2023
✅ Insider Threat SIG held its inaugural in-person meetup in Denver
✅ EPSS v5 went live June 15 with improved calibration and new exploit-detection signals
✅ Policy SIG published a brief on AI's impact across the cybersecurity ecosystem🌍 Capacity Building
FIRST launched a new initiative under the G7-ECOWAS Platform for Advancing Cybersecurity, working with ECOWAS and GIZ to support regional cyber confidence-building measures across West Africa.
Read more 👉 https://go.first.org/AXSBi
-
📬 FIRST's Q2FY26 Newsletter is here! Here's a look at what's inside:
🎉 #FIRSTCON26 Recap
A look back on the 38th Annual Conference in Denver — five days, 100+ presentations, and lively networking that reflected the event's collaborative spirit. Outgoing PC Chair Merike Kaeo delivered an outstanding program, and Martijn van der Heide now takes the reins to prepare #FIRSTCON27 in Bangkok.
🗳️ AGM & Board Elections
The Annual General Meeting confirmed a refreshed Board: Serge Droz, Carlos Leonardo, and Olivier Caleff re-elected, Mona Elisabeth Østvang returns after a year away, and Logan Wilkins joins for the first time.
👩💻 Women of FIRST Mentorship ProgramA new 6–9 month mentorship pilot launches in Q3 2026 — interest survey closes July 20.
🏅 Member Spotlight: Art Manion & Jay Jacobs
Two of the driving forces behind FIRST's vulnerability management work: Jay Jacobs (co-Chair, EPSS SIG) and Art Manion (Chair, VRDX-SIG and Vulnerability Coordination SIG). Their contributions to CVSS and EPSS have given the community core frameworks for vulnerability assessment and prioritization, and both have been key organizers of VulnCon — most recently leading a session in Scottsdale titled "A Paradigm Shift in Vulnerability Identity: Why Vulnerability Databases Struggle."
🕰️ New SIG Alert: Time Security
With the Unix epoch overflow arriving January 19, 2038 — plus an NTP rollover as soon as 2036 and a GPS week rollover later in 2038 — the new Time Security SIG is coordinating the community's response. Now 60+ participants strong, its work is already feeding into ITU-T and IEEE standards efforts.
🛡️Additional SIG Updates
✅ Metrics SIG released v1.1, completing metrics coverage across all five CSIRT Services Framework areas
✅ DNS Abuse SIG published v1.3 of the DNS Abuse Techniques Matrix — the first update since 2023
✅ Insider Threat SIG held its inaugural in-person meetup in Denver
✅ EPSS v5 went live June 15 with improved calibration and new exploit-detection signals
✅ Policy SIG published a brief on AI's impact across the cybersecurity ecosystem🌍 Capacity Building
FIRST launched a new initiative under the G7-ECOWAS Platform for Advancing Cybersecurity, working with ECOWAS and GIZ to support regional cyber confidence-building measures across West Africa.
Read more 👉 https://go.first.org/AXSBi
-
📬 FIRST's Q2FY26 Newsletter is here! Here's a look at what's inside:
🎉 #FIRSTCON26 Recap
A look back on the 38th Annual Conference in Denver — five days, 100+ presentations, and lively networking that reflected the event's collaborative spirit. Outgoing PC Chair Merike Kaeo delivered an outstanding program, and Martijn van der Heide now takes the reins to prepare #FIRSTCON27 in Bangkok.
🗳️ AGM & Board Elections
The Annual General Meeting confirmed a refreshed Board: Serge Droz, Carlos Leonardo, and Olivier Caleff re-elected, Mona Elisabeth Østvang returns after a year away, and Logan Wilkins joins for the first time.
👩💻 Women of FIRST Mentorship ProgramA new 6–9 month mentorship pilot launches in Q3 2026 — interest survey closes July 20.
🏅 Member Spotlight: Art Manion & Jay Jacobs
Two of the driving forces behind FIRST's vulnerability management work: Jay Jacobs (co-Chair, EPSS SIG) and Art Manion (Chair, VRDX-SIG and Vulnerability Coordination SIG). Their contributions to CVSS and EPSS have given the community core frameworks for vulnerability assessment and prioritization, and both have been key organizers of VulnCon — most recently leading a session in Scottsdale titled "A Paradigm Shift in Vulnerability Identity: Why Vulnerability Databases Struggle."
🕰️ New SIG Alert: Time Security
With the Unix epoch overflow arriving January 19, 2038 — plus an NTP rollover as soon as 2036 and a GPS week rollover later in 2038 — the new Time Security SIG is coordinating the community's response. Now 60+ participants strong, its work is already feeding into ITU-T and IEEE standards efforts.
🛡️Additional SIG Updates
✅ Metrics SIG released v1.1, completing metrics coverage across all five CSIRT Services Framework areas
✅ DNS Abuse SIG published v1.3 of the DNS Abuse Techniques Matrix — the first update since 2023
✅ Insider Threat SIG held its inaugural in-person meetup in Denver
✅ EPSS v5 went live June 15 with improved calibration and new exploit-detection signals
✅ Policy SIG published a brief on AI's impact across the cybersecurity ecosystem🌍 Capacity Building
FIRST launched a new initiative under the G7-ECOWAS Platform for Advancing Cybersecurity, working with ECOWAS and GIZ to support regional cyber confidence-building measures across West Africa.
Read more 👉 https://go.first.org/AXSBi
-
📬 FIRST's Q2FY26 Newsletter is here! Here's a look at what's inside:
🎉 #FIRSTCON26 Recap
A look back on the 38th Annual Conference in Denver — five days, 100+ presentations, and lively networking that reflected the event's collaborative spirit. Outgoing PC Chair Merike Kaeo delivered an outstanding program, and Martijn van der Heide now takes the reins to prepare #FIRSTCON27 in Bangkok.
🗳️ AGM & Board Elections
The Annual General Meeting confirmed a refreshed Board: Serge Droz, Carlos Leonardo, and Olivier Caleff re-elected, Mona Elisabeth Østvang returns after a year away, and Logan Wilkins joins for the first time.
👩💻 Women of FIRST Mentorship ProgramA new 6–9 month mentorship pilot launches in Q3 2026 — interest survey closes July 20.
🏅 Member Spotlight: Art Manion & Jay Jacobs
Two of the driving forces behind FIRST's vulnerability management work: Jay Jacobs (co-Chair, EPSS SIG) and Art Manion (Chair, VRDX-SIG and Vulnerability Coordination SIG). Their contributions to CVSS and EPSS have given the community core frameworks for vulnerability assessment and prioritization, and both have been key organizers of VulnCon — most recently leading a session in Scottsdale titled "A Paradigm Shift in Vulnerability Identity: Why Vulnerability Databases Struggle."
🕰️ New SIG Alert: Time Security
With the Unix epoch overflow arriving January 19, 2038 — plus an NTP rollover as soon as 2036 and a GPS week rollover later in 2038 — the new Time Security SIG is coordinating the community's response. Now 60+ participants strong, its work is already feeding into ITU-T and IEEE standards efforts.
🛡️Additional SIG Updates
✅ Metrics SIG released v1.1, completing metrics coverage across all five CSIRT Services Framework areas
✅ DNS Abuse SIG published v1.3 of the DNS Abuse Techniques Matrix — the first update since 2023
✅ Insider Threat SIG held its inaugural in-person meetup in Denver
✅ EPSS v5 went live June 15 with improved calibration and new exploit-detection signals
✅ Policy SIG published a brief on AI's impact across the cybersecurity ecosystem🌍 Capacity Building
FIRST launched a new initiative under the G7-ECOWAS Platform for Advancing Cybersecurity, working with ECOWAS and GIZ to support regional cyber confidence-building measures across West Africa.
Read more 👉 https://go.first.org/AXSBi
-
📬 FIRST's Q2FY26 Newsletter is here! Here's a look at what's inside:
🎉 #FIRSTCON26 Recap
A look back on the 38th Annual Conference in Denver — five days, 100+ presentations, and lively networking that reflected the event's collaborative spirit. Outgoing PC Chair Merike Kaeo delivered an outstanding program, and Martijn van der Heide now takes the reins to prepare #FIRSTCON27 in Bangkok.
🗳️ AGM & Board Elections
The Annual General Meeting confirmed a refreshed Board: Serge Droz, Carlos Leonardo, and Olivier Caleff re-elected, Mona Elisabeth Østvang returns after a year away, and Logan Wilkins joins for the first time.
👩💻 Women of FIRST Mentorship ProgramA new 6–9 month mentorship pilot launches in Q3 2026 — interest survey closes July 20.
🏅 Member Spotlight: Art Manion & Jay Jacobs
Two of the driving forces behind FIRST's vulnerability management work: Jay Jacobs (co-Chair, EPSS SIG) and Art Manion (Chair, VRDX-SIG and Vulnerability Coordination SIG). Their contributions to CVSS and EPSS have given the community core frameworks for vulnerability assessment and prioritization, and both have been key organizers of VulnCon — most recently leading a session in Scottsdale titled "A Paradigm Shift in Vulnerability Identity: Why Vulnerability Databases Struggle."
🕰️ New SIG Alert: Time Security
With the Unix epoch overflow arriving January 19, 2038 — plus an NTP rollover as soon as 2036 and a GPS week rollover later in 2038 — the new Time Security SIG is coordinating the community's response. Now 60+ participants strong, its work is already feeding into ITU-T and IEEE standards efforts.
🛡️Additional SIG Updates
✅ Metrics SIG released v1.1, completing metrics coverage across all five CSIRT Services Framework areas
✅ DNS Abuse SIG published v1.3 of the DNS Abuse Techniques Matrix — the first update since 2023
✅ Insider Threat SIG held its inaugural in-person meetup in Denver
✅ EPSS v5 went live June 15 with improved calibration and new exploit-detection signals
✅ Policy SIG published a brief on AI's impact across the cybersecurity ecosystem🌍 Capacity Building
FIRST launched a new initiative under the G7-ECOWAS Platform for Advancing Cybersecurity, working with ECOWAS and GIZ to support regional cyber confidence-building measures across West Africa.
Read more 👉 https://go.first.org/AXSBi
-
Working in cyber in 2026, we spend so much of our time connecting through screens. But every year, #FIRSTCON reminds us that the strongest partnerships are still built face to face.
You can exchange emails for years, join countless video calls, and collaborate across continents, but there's something irreplaceable about sharing a meal, raising a glass, and getting to know the person behind the job title. Those moments build the trust that matters when the pressure is on. When an incident strikes, you're not reaching out to a stranger, you're calling a friend.
Our #FIRSTCON26 recap reflects on the conversations, connections, and community that made this year's conference in Denver so memorable.
Read the full blog here: https://www.first.org/blog/20260703-When-FIRSTCON26-Rode-into-Denver
#FIRSTCON26 #CyberSecurity #IncidentResponse #Community #FIRST
-
Working in cyber in 2026, we spend so much of our time connecting through screens. But every year, #FIRSTCON reminds us that the strongest partnerships are still built face to face.
You can exchange emails for years, join countless video calls, and collaborate across continents, but there's something irreplaceable about sharing a meal, raising a glass, and getting to know the person behind the job title. Those moments build the trust that matters when the pressure is on. When an incident strikes, you're not reaching out to a stranger, you're calling a friend.
Our #FIRSTCON26 recap reflects on the conversations, connections, and community that made this year's conference in Denver so memorable.
Read the full blog here: https://www.first.org/blog/20260703-When-FIRSTCON26-Rode-into-Denver
#FIRSTCON26 #CyberSecurity #IncidentResponse #Community #FIRST
-
Working in cyber in 2026, we spend so much of our time connecting through screens. But every year, #FIRSTCON reminds us that the strongest partnerships are still built face to face.
You can exchange emails for years, join countless video calls, and collaborate across continents, but there's something irreplaceable about sharing a meal, raising a glass, and getting to know the person behind the job title. Those moments build the trust that matters when the pressure is on. When an incident strikes, you're not reaching out to a stranger, you're calling a friend.
Our #FIRSTCON26 recap reflects on the conversations, connections, and community that made this year's conference in Denver so memorable.
Read the full blog here: https://www.first.org/blog/20260703-When-FIRSTCON26-Rode-into-Denver
#FIRSTCON26 #CyberSecurity #IncidentResponse #Community #FIRST
-
Working in cyber in 2026, we spend so much of our time connecting through screens. But every year, #FIRSTCON reminds us that the strongest partnerships are still built face to face.
You can exchange emails for years, join countless video calls, and collaborate across continents, but there's something irreplaceable about sharing a meal, raising a glass, and getting to know the person behind the job title. Those moments build the trust that matters when the pressure is on. When an incident strikes, you're not reaching out to a stranger, you're calling a friend.
Our #FIRSTCON26 recap reflects on the conversations, connections, and community that made this year's conference in Denver so memorable.
Read the full blog here: https://www.first.org/blog/20260703-When-FIRSTCON26-Rode-into-Denver
#FIRSTCON26 #CyberSecurity #IncidentResponse #Community #FIRST
-
Working in cyber in 2026, we spend so much of our time connecting through screens. But every year, #FIRSTCON reminds us that the strongest partnerships are still built face to face.
You can exchange emails for years, join countless video calls, and collaborate across continents, but there's something irreplaceable about sharing a meal, raising a glass, and getting to know the person behind the job title. Those moments build the trust that matters when the pressure is on. When an incident strikes, you're not reaching out to a stranger, you're calling a friend.
Our #FIRSTCON26 recap reflects on the conversations, connections, and community that made this year's conference in Denver so memorable.
Read the full blog here: https://www.first.org/blog/20260703-When-FIRSTCON26-Rode-into-Denver
#FIRSTCON26 #CyberSecurity #IncidentResponse #Community #FIRST
-
Security Tip: Prioritize forensics during Incident Response. 🛡️ When a breach occurs, the instinct is to wipe and rebuild immediately. However, without capturing volatile memory (RAM) and disk images first, you lose the "how" and "who." Establish a standard procedure for evidence preservation to ensure your team can conduct a proper post-mortem and prevent recurrence. Stay informed on the latest threats at https://cvedatabase.com #InfoSec #IncidentResponse #CyberSecurity
-
----------------
🎯 AI
===================Sygnia: AI-Supercharged 72-Hour Cloud Attack Investigation
Sygnia published findings from an incident response engagement where a threat actor compromised an AWS-based environment, progressing from initial access to broad cloud compromise in approximately 72 hours. The case is notable not for novel techniques, but for the apparent use of AI to accelerate familiar cloud attack methods.
Key Findings
• The intrusion expanded across applications, cloud infrastructure, source-control systems, CI/CD pipelines, and runtime services
• No zero-day exploits or novel malware were observed. Every technique mapped to established MITRE ATT&CK behaviors
• Multiple artifacts suggested AI-assisted or agentic workflows: attacker-created scripts, structured reporting artifacts, and highly parallel activity
• The threat actor repeatedly leveraged newly acquired credentials to restart discovery, secrets harvesting, persistence, and impact activities
• The primary defensive challenge was the speed and scale of execution, not the novelty of individual techniquesWhere AI Changed the Equation
The report identifies several indicators of AI involvement:
• Rapid generation of environment-specific scripts and tooling
• Structured, formatted reporting artifacts consistent with AI-generated output
• Highly parallel discovery and exploitation activities across multiple surfaces
• Compressed timeline for reconnaissance, adaptation, and operational execution inconsistent with purely manual operationsAttack Path
1. Initial access to AWS environment
2. Credential harvesting and secrets discovery
3. Lateral movement across applications and cloud services
4. Persistence through compromised identity and deployment workflows
5. Expansion into source-control and CI/CD systems
6. Impact across cloud, identity, and application layersEach credential acquisition restarted the cycle.
Defensive Gaps
• Fragmented visibility across cloud, identity, and application layers
• Monitoring gaps that delayed detection and correlation
• Absence of predefined incident response procedures
• Weak secrets management and identity governance
• Overly permissive cloud and CI/CD permissionsRemediation
Sygnia recommends adapting IR playbooks for AI-enabled threats, prioritizing broad containment over precision when speed matters, rotating credentials aggressively, treating identity as the primary security boundary, and automating defensive responses. Infrastructure rebuilds may be necessary for broadly compromised environments.
Known weaknesses get exploited faster and at broader scale when AI assistance is available. End-to-end visibility and predefined containment procedures are prerequisites, not aspirations.
🔹 AI #CloudSecurity #IncidentResponse #Sygnia #MITREATTACK
🔗 Source: https://www.sygnia.co/blog/inside-an-ai-assisted-cloud-attack/
-
How can you use your AI agent to transform raw threat notes into a well-sourced CTI report draft? Use my MCP server with my new CTI report template and writing guidance. Your sensitive data stays local.
-
How can you use your AI agent to transform raw threat notes into a well-sourced CTI report draft? Use my MCP server with my new CTI report template and writing guidance. Your sensitive data stays local.
-
❄️ Save the Date! ❄️
Cold Incident Response 2026 • Tue Oct 13 – Thu Oct 15 • Oslo, NorwayHosted by our Norwegian FIRST Teams 🌍
Bundle up, block your calendars, and get ready for three days of cool minds, cold cases studies with warm Nordic hospitality.
-
The Treachery of Postmortems is a really great cure for the post incident review blues. Thank you @gallego !
https://resilienceinsoftware.org/news/11547831
#RISF #ResilienceInSoftwareFoundation #ResilienceInSoftware #Resilience #Postmortem #PIRWriteup #IncidentManagement #IncidentResponse #LearningReview
-
The Treachery of Postmortems is a really great cure for the post incident review blues. Thank you @gallego !
https://resilienceinsoftware.org/news/11547831
#RISF #ResilienceInSoftwareFoundation #ResilienceInSoftware #Resilience #Postmortem #PIRWriteup #IncidentManagement #IncidentResponse #LearningReview
-
Want to support one of the community's most practitioner-focused events? https://www.coldincidentresponse.no/
The 2026 FIRST TC: #ColdIncidentResponse takes place 13–15 October in Oslo, Norway. We're looking for sponsors to help fund food, refreshments, and the community dinner for 400 attendees.
No sponsor stands. No paid talks. Just community.
-
My new template for cyber threat intelligence reports covers tactical, operational, and strategic aspects of threat activity. A companion brief captures the key takeaways for decision-makers. You can also use it with your AI agent.
-
New episode!
Cardboard Confidential
Sometimes the biggest cybersecurity lessons arrive in the most ordinary packaging.
Real story.
Real lessons.
No blame.Listen now: https://ithorrorstories.eu/#ep17
#technology #podcast #cybersecurity #infosec #IT #IncidentResponse #InformationSecurity #Infrastructure #RiskManagement #ProjectManagement
-
New episode!
Cardboard Confidential
Sometimes the biggest cybersecurity lessons arrive in the most ordinary packaging.
Real story.
Real lessons.
No blame.Listen now: https://ithorrorstories.eu/#ep17
#technology #podcast #cybersecurity #infosec #IT #IncidentResponse #InformationSecurity #Infrastructure #RiskManagement #ProjectManagement
-
Pennington County, South Dakota, closes offices during cybersecurity response #CyberIncident #IncidentResponse #CISA #SouthDakota #PublicSafety #cybersecurity https://dysruptionhub.com/pennington-county-sd-cyber-incident/
-
Pennington County, South Dakota, closes offices during cybersecurity response #CyberIncident #IncidentResponse #CISA #SouthDakota #PublicSafety #cybersecurity https://dysruptionhub.com/pennington-county-sd-cyber-incident/
-
Security Tip: Centralized and immutable logging is a cornerstone of Incident Response. 🛡️ If an attacker compromises a system, they will attempt to wipe local logs to hide their activity. By streaming logs to a centralized, write-once-read-many (WORM) storage system, you preserve the evidence needed for a forensic investigation. Start building your visibility today. Research historical CVEs at https://cvedatabase.com #CyberSecurity #InfoSec #DFIR #IncidentResponse #Logging
-
Threat attribution works at 3 levels: Tactical examines the incident, operational characterizes the campaign, and strategic asks who's responsible and why. Disciplined analysts weigh the same 6 signals at every level.
-
Threat attribution works at 3 levels: Tactical examines the incident, operational characterizes the campaign, and strategic asks who's responsible and why. Disciplined analysts weigh the same 6 signals at every level.
-
Want to support one of the community's most practitioner-focused events? https://www.coldincidentresponse.no/
The 2026 FIRST TC: #ColdIncidentResponse takes place 13–15 October in Oslo, Norway. We're looking for sponsors to help fund food, refreshments, and the community dinner for 400 attendees.
No sponsor stands. No paid talks. Just community.
-
This template for a security incident report not only helps with documentation, but also offers guidance when capturing findings during the incident. Take it, customize it, use it.
-
Some people turn to Kali or Parrot OS but those were not designed for #OSINT purposes. Tsurugi #Linux is different. It's specifically tailored for #incidentresponse and OSINT investigations
Here we showed what Tsurugi Linux is, how to install it and the features it has for OSINT
https://hackers-arise.com/open-source-intelligence-osint-is-tsurugi-linux-the-best-operating-system-for-osint-investigations/