#mitre — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #mitre, aggregated by home.social.
-
Yes, were elected to reinvent the wheel, and oh by the way, we are not very good at it!
US Government looks to centralize software vulnerability management with 'Gold Eagle' cybersecurity clearinghouse. https://www.techradar.com/pro/security/white-house-launches-gold-eagle-cybersecurity-clearinghouse-to-share-and-patch-ai-discovered-software-flaws
We already have this NOW - its called NIST NVE and CVE processes coordinated by MITRE. https://nvd.nist.gov/general #CyberSecurity #Security #NIST #MITRE #CVE #NVE #Software #AI #GoldEagle #CyberAttack #USGov #CyberThreat #DataSecurity #ReinventtheWheel
-
Mitre (MTRE3) vê vendas despencarem 32% no 2T26 e termina trimestre sem lançamentos
🇧🇷 Leia mais: https://guiadoinvestidor.com.br/mercado/mitre-mtre3-ve-vendas-despencarem-32-no-2t26-e-termina-trimestre-sem-lancamentos/
-
Mitre (MTRE3) anuncia dividendos de R$ 9 milhões; veja quem tem direito
🇧🇷 Leia mais: https://guiadoinvestidor.com.br/mercado/mitre-mtre3-anuncia-dividendos-de-r-9-milhoes-veja-quem-tem-direito/
-
Simulate T1562.001 (Disable Windows Defender) with Atomic Red Team. Invoke-AtomicTest -GetPrereqs installs dependencies, -ExecutionLog tracks, -Cleanup reverts registry changes. Clean, scripted adversary simulation on Windows 10/Server 2019+.
#mitre #atomic-red-team #ValtersIThttps://www.valtersit.com/vault/atomic-red-team-t1562001-test-execution-with-artifact-cleanu-d17fc1/
-
From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5and Confluence - https://www.redpacketsecurity.com/from-edge-appliance-to-enterprise-compromise-multi-stage-linux-intrusion-via-f5and-confluence/
#threatintel
#edge-appliances
#linux-intrusion
#confluence
#credential-relay
#mitre-attack-techniques -
Mitre (MTRE3) reforça controle acionário e mercado monitora próximos movimentos
🇧🇷 Leia mais: https://guiadoinvestidor.com.br/mercado/mitre-mtre3-reforca-controle-acionario-e-mercado-monitora-proximos-movimentos/
-
Resulting from funding gaps and idiotic shifts in priorities the U.S.A. is now woefully under investing in our core CyberDefense Ecosystem....
National Institute of Standards and Technology (NIST) is no longer enhancing all Common Vulnerabilities and Exposures (CVEs) with analysis and severity indicators, and instead NIST will prioritize enriching a much narrower set of security vulnerabilities.
Related: In April 2025, a funding gap by in DHS appropriations threatened to cease CVE operations entirely —which would have creating systemic risk for global vulnerability management. An emergency funding extension was implemented to avoid a full on crisis. https://www.justsecurity.org/136914/nist-cant-keep-up/ #NIST #MITRE #CVEs #NVD #Security #Risk #CyberSecurity #CyberDefence #CyberInfrastructure #AI #AISecurity #CISA #DHS #Vulnerability #ThreatIntelligence
-
Accelerating detection engineering using AI-assisted synthetic attack logsgeneration - https://www.redpacketsecurity.com/accelerating-detection-engineering-using-ai-assisted-synthetic-attack-logsgeneration/
#threatintel
#AI-assisted-logs
#synthetic-logs
#detection-engineering
#MITRE-ATT&CK
#cybersecurity-logs -
Extracted CAPEC to CWE Mappings (first 10 examples)...
Total CVEs with CAPEC relationships found: 6 -
Cyrela (CYRE3), Mitre (MTRE3) e Even (EVEN3): prévias dividem mercado, mas qualidade melhora
🇧🇷 Leia mais: https://guiadoinvestidor.com.br/mercado/cyrela-cyre3-mitre-mtre3-e-even-even3-previas-dividem-mercado-mas-qualidade-melhora/
-
Mitre (MTRE3) dispara lançamentos em 195%, mas vendas preocupam mercado
🇧🇷 Leia mais: https://guiadoinvestidor.com.br/mercado/mitre-mtre3-dispara-lancamentos-em-195-mas-vendas-preocupam-mercado/
-
ClearWater — обзор нового шифровальщика
Приветствую, сегодня я расскажу про новый шифровальщик, который мне удалось обнаружить на просторах Интернета. Первые упоминания ClearWater появились ещё в январе 2026 года. Исследуя всемирную паутину, я ещё не находил ни одной нормальной статьи по этому вредоносу, поэтому решил сам написать такую. Данный шифровальщик не отличается какой-то технической сложностью или необычными приемами поэтому его обзор несёт больше информативный характер и предназначен для Malware и TI-аналитиков.
https://habr.com/ru/articles/1018822/
#ClearWater #шифровальщик #вредонос #вредоносное_по #реверсинжиниринг #реверс #анализ_вредоносов #yara #mitre
-
@bitpirate while this is laughable it seems like a complete failure of the CNA (VULSec Labs). I would think RustDesk would have a decent complaint to make to MITRE
-
Менеджеры паролей — решение извечной проблемы слабой парольной политики
Привет всем! На связи аналитики из команды PT Cyber Analytics. Мы сопровождаем red‑team‑проекты и помогаем клиентам разобраться в результатах работы белых хакеров. Детально анализируем результаты тестирований на проникновение, оцениваем риски, связанные с обнаруженными уязвимостями, определяем уровень защищенности компаний и разрабатываем рекомендации по устранению слабых мест в инфраструктуре. В этой статье мы проанализируем практики безопасного использования менеджеров паролей. Рассмотрим принципы работы различных типов менеджеров и их архитектуру, методы защиты, возможные угрозы безопасности, некоторые примеры взломов, а также способы минимизации рисков. Кроме того, уделим внимание рекомендациям по мониторингу и реагированию на инциденты, связанные с менеджерами паролей.
https://habr.com/ru/companies/pt/articles/1008480/
#менеджер_паролей #onpremises #saas #уязвимости #mitre #keepass #2faаутентификация #sso
-
Manipulating AI memory for profit: The rise of AI Recommendation Poisoning - https://www.redpacketsecurity.com/manipulating-ai-memory-for-profit-the-rise-of-ai-recommendation-poisoning/
#threatintel
#AI memory poisoning
#prompt injection
#AI security
#memory persistence
#MITRE ATLAS AML.T0080 -
I don't seem to get any response from MITRE Corporation requesting CVE IDs. Multiple requests have been silently ignored. What can I do ... except becoming my own CNA?
-
Turning threat reports into detection insights with AI - https://www.redpacketsecurity.com/turning-threat-reports-into-detection-insights-with-ai/
#threatintel
#threat-intelligence
#mitre-attck
#detection-engineering
#ai-for-security
#ttp-extraction -
Is there a good #MITRE ATT&CK technique to point out a attacker used incremented Identifiers do discover devices easily?