Thibault 'bui' Koechlin @SecBui
Open sauce & security. From breaking to building. CTO @Crowd_Security github.com/buixor Internet Joined December 2009-
Tweets323
-
Followers152
-
Following174
-
Likes2K
Log into first new dedi in a long time. Journalctl -f go brr. Install crowdsec. Logs quiet.
(🧵Thread) Breaking threat alert from DigitalOcean and Microsoft Azure! Mass exploitation campaign detected by actor codenamed Goofy Khaki Flamecrest. Find out about the 4 key events that characterized the campaign 👇 On the 15th of April, we detected a coordinated exploitation effort that included over 1,300 machines at its peak. The machines were small to medium-sized VPCs in public clouds such as Microsoft Azure and DigitalOcean. Using our comprehensive threat intelligence data, we were able to get a clear view of the exploitation campaign. (🧵1/4)
👾 Introducing the CrowdSec VulnTracking Report! 👾 Stay ahead of threats with our new monthly series, delivering key insights into trending CVEs and exploitation attempts. For March, we added detection for 34 vulnerabilities and/or exploits to our database. What we noticed: • There is a noticeable gap between media hype and actual attacker interest in certain CVEs. • Surprisingly, older vulnerabilities like CVE-2021-43798 and CVE-2019-17538 are making a comeback, attracting significant malicious activity. Want the full breakdown? Read the report: crowdsec.net/blog/vulntrack…
Have you tried the CrowdSec Remediation Component for Apache yet? This powerful component integrates seamlessly with Apache’s module mechanism to block malicious IPs, keeping your infrastructure secure and protected against threats, before they hit. 🛡️ Ready to get started? You can check out the documentation here: docs.crowdsec.net/u/bouncers/apa… It is still in the beta phase, so any feedback or bugs you find please share them on GitHub: github.com/crowdsecurity/… #Apache #Cybersecurity
🚨 CVE-2024-27292 exploitation campaign detected! (thread) What is the CVE-2024-27292 vulnerability? CVE-2024-27292 is a path traversal vulnerability in Docassemble. It allows unauthenticated attackers to access arbitrary files, such as /etc/passwd via specially crafted URL parameters. The root cause is improper sanitization of user-supplied inputs, making it possible for attackers to probe system-level files. Over the past few days, CrowdSec telemetry has identified a significant and accelerating wave of exploit attempts targeting the URI pattern: /interview?i=/etc/passwd. Docassembe is a free, open source expert system for guided interviews and document assembly, based on Python, YAML, and Markdown. This pattern aligns with an exploit attempt for CVE-2024-27292, a vulnerability disclosed in late 2024 affecting Docassemble (v1.4.53 to v1.4.96).
🚀 Congrats to the Pangolin team on v1.0.0! 🎉 This self-hosted reverse proxy securely exposes private resources without open ports, now with CrowdSec integration for added security! 🔒✨ Check it out 👉 github.com/fosrl/pangolin
🚀 Exciting to see Traefik featured in LRVT's Security Blog! 🛡️ The post highlights how #Traefik utilizes #CrowdSec and its Cyber Threat Intelligence (CTI) to ban malicious threat actors probing our exposed HTTP services in a collaborative manner. hubs.ly/Q030ww6H0
Say hello to our 3 newest Crowdsec ambassadors, dedicated community members who are advancing our CrowdSec mission and strengthening the collaborative cybersecurity community: @flaviuvlaicu Haneef Haroon Killian Prin-Abeil Apply to become an ambassador- hubs.ly/Q033JvtM0
🚀 If you're looking for a new year's goal, why not become a CrowdSec Ambassador and make the internet safer together?! Share your knowledge, represent #CrowdSec, and earn rewards for your contributions. Let’s build a safer future together! Apply now:👉 hubs.ly/Q031fml_0
CrowdSec Security Engine imported in OpenBSD ports tree - Port maintained by Robert Nagy - cc @Crowd_Security #Infosec #OpenBSD github.com/openbsd/ports/…
Big announcement! We are introducing the #CrowdSec Guide to Cost-Effective Security Operations! Available to download now! This resource is designed to help security teams and decision-makers achieve operational excellence without breaking the budget-hubs.ly/Q02-Vs900
#CrowdSec Security Engine 1.6.3 is out! 🎉 What may look like a minor release is in fact packed with important updates and several improvements. Check out the v.1.6.3 release notes for all the juicy details! hubs.ly/Q02QLpkL0 #cybersecurity #securityengine
Always love when FOSS moves fast. Shoutout to the guys of github.com/wasilibs/go-re2 for merging and releasing overnight! 1.6.3 release for Windows is now fixed (cf. github.com/wasilibs/go-re…)
The award-winning Qualys Threat Research Unit (TRU) has discovered a critical vulnerability in OpenSSH, designated CVE-2024-6387 and aptly named "regreSSHion." This Remote Code Execution bug grants full root access, posing a significant exploitation risk. blog.qualys.com/vulnerabilitie…
@OlivLiliv doc.crowdsec.net/u/troubleshoot… "Do not use cscli explain on big log files, as this command will buffer a lot of information in memory to achieve this. If you want to check crowdsec's behaviour on big log files, please see replay mode." On devrait rendre le warning plus explicite :)
@OlivLiliv @aderumier Par défaut c'est ~365 jours, pas sur que ce soit ça!
@OlivLiliv @aderumier Hello, n’hésite pas a passer sur discord.gg/crowdsec pour obtenir de l'aide, ça semble bizarre :)
The recent exploit for D-Link NAS devices #CVE20243273 is being used aggressively by botnets hijacking IoT devices. See the information gathered by the CrowdSec Network on the endpoints targeted, payloads used, and IoCs for the most extreme attackers. hubs.ly/Q02wFd5D0
mcquestion71890 @mcquestion46545
9 Followers 254 Following
Marc Fpsb @Marcfpsb
1K Followers 101 Following
Teshi @TeshiV5pRWcc
44 Followers 5K Following
Jona Azizaj👩🏻�... @jonatoni
2K Followers 934 Following Community Builder @Crowd_Security | #FLOSS Hacktivist 📢 | #Community #DevRel #DEI 💙 @fedora🐧 @libreoffice @osdiversity 🌼 @MLPrague | she/her
Thibault Koechlin @KoechlinT
0 Followers 2 Following
Antoine Vastel @xopek59
747 Followers 251 Following Hunting bad bots and fraudsters @ https://t.co/2Z726AxaAl Detecting (residential) proxies: https://t.co/LQh9XkRzGq
Ninapepite | DevSecOp... @Ninapepite_
109 Followers 459 Following Engineer DevSecOps mais je préfère dev quand même 😝 https://t.co/qNuskenq76
Justin Young @JustinY14293
5 Followers 9 Following 🏃♂️I have been running since I've been alive, never known surrender, so you've been advised.💯 Fun Fact: Did you know you can ban IP's before they attack?🤌
Loni @Loni36250871
33 Followers 711 Following
Wakedxy @Wakedxy1
7K Followers 221 Following 🛡 Pentester | Bug Hunter | @hackthebox_eu ambassador | OSCP | CRTP | eWPT | CBBH | Youtuber
riemannesco @riemannesco
1 Followers 153 Following
Courtney Austin @CourtneyA1_1
6 Followers 46 Following I am an international marketing executive that helps people and organisations become transformational leaders. All tweets represent my own viewpoint.
zeysh @zeysh13
91 Followers 2K Following
Roger Chtarponne @boblesurfeur
53 Followers 209 Following Auteur, compositeur, champion de roue arrière en mini vélo, mari de Samantha FOX
Matthieu Jung @JMamat
166 Followers 2K Following
Kaiz3r63 🇨🇵 �... @Kaiz3r631
178 Followers 466 Following 38 ans Informatique & Photographie Administrateur système #opensource #linux #selfhosted #virtualize #Arduino #3dPrint #Linux homelab : https://t.co/5oYPMFy7ut
[email protected]... @wdesportes
244 Followers 1K Following Expert en développement Web chez Wdes SAS. Gestion d'infrastructures. Accompagnement et refactoring IT.
Yann Hirou @YannHirou
110 Followers 381 Following #linux #opensource #management #python #devops #netops #secops #ops. chez @cfm_am @cfmtech - personal account.
ᴇᴅ ᴅᴀɴɪᴇ�... @esdaniel
1K Followers 2K Following Passionate abt #OpenSource, #IoT, #AnySec, #AnyOps, #AnySecOps, #CloudComputing, #ITSM. Watching #PlatformEngineering emerge & curious about #AI and #ML too.
👾 𝚗𝚎𝚝𝚌... @h4knet
204 Followers 1K Following
Rob Ragan @sweepthatleg
2K Followers 2K Following SΞCURITΨ ΛUTØMΛTIØN RΞSΞΛRCHΞR. я в 💡∞ 🧠 https://t.co/0yCIFAl5P1 ⚡️https://t.co/WqqPVjy5vu
Alexandre Derumier�... @aderumier
2K Followers 340 Following Ingénieur système et réseau. #AS34993 Contributeur #proxmox. Fan de #ceph et des solutions libres. BlueSky : https://t.co/tkRmb3lmTi
MYFT | Cloud @myftcloud
65 Followers 275 Following Top superpowered complete platform for the WordPress.
@benborges.xyz on Blu... @benbnews
2K Followers 3K Following Information aggregation of the 🇷🇺 War against Ukraine 🇺🇦 - Ukraine War Telegram Archive at https://t.co/GtVFn6P3ai
Pedro Joaquín @_hkm
5K Followers 4K Following My passion: #cybersecurity #pentesting #ai / @_tropicon / https://t.co/zWuNCo05RM / https://t.co/rFkim1CBxo / @_websec / @GuadalajaraCON / M3x4
佛祖保佑 永无BU... @arphanetx
982 Followers 2K Following not human, just an angry bot, security engineer, gamer, some times like to nerd around with more bots, sometimes on my own. the joke is on you.
ne0uf @ne0uf
87 Followers 421 Following
Najihel @najihel
511 Followers 798 Following Ingénieur Réseaux 🛠️ @FreePro (Was @Jaguar_Network) #AS30781 & @OuestNetwork #AS49451 #AperoTelco #TelcoNantes
@RelativeSure@infosec... @RelativeSure
86 Followers 704 Following 27 | Love working with Linux and OSS | Hit me up on mastodon: https://t.co/jbaNU9ERqQ
CyberMind @CyberMindFR
29 Followers 220 Following OpenSource Code CyberSecurity experienced, free as in free beer, long time code contributor.
b0br @0xb0br
139 Followers 738 Following #CyberSec #InfoSec #Dex2Jar #MobileSec #NOC #SOC #NToskrnlSEC #Systemd #NMAP #Fail2Ban #TraceRoute V2luZG93cyBpcyBhbHNvIGFuIG9wdGlvbi4gYjBici4
Kyzoe.be @Kyzoebe
907 Followers 2K Following Kyzoe verzorgt hosting, om uw website op te bouwen, voordelige paketten vanaf 65€ gratis verhuis van mail en website.
Tristan At Work @TristanAtWork
16 Followers 201 Following Twitter account for work. Otherwise i'm at @yodabzh .
zebleer @zebleerpo1
4K Followers 1 Following I'm not using this Twitter account anymore. Don't trust it. My new Twitter = @zebleerguy & you can verify that on my website and Telegram
Jona Azizaj👩🏻�... @jonatoni
2K Followers 934 Following Community Builder @Crowd_Security | #FLOSS Hacktivist 📢 | #Community #DevRel #DEI 💙 @fedora🐧 @libreoffice @osdiversity 🌼 @MLPrague | she/her
vx-underground @vxunderground
438K Followers 357 Following The largest collection of malware source code, samples, and papers on the internet. Password: infected
Maxim Dounin @mdounin
545 Followers 80 Following
Ville de Nantes @nantesfr
147K Followers 1K Following Compte officiel de la Ville de Nantes. Solidarité, égalité, vie dans les quartiers, culture, sport, santé, nature... suivez ici l’actualité nantaise !
Justin Young @JustinY14293
5 Followers 9 Following 🏃♂️I have been running since I've been alive, never known surrender, so you've been advised.💯 Fun Fact: Did you know you can ban IP's before they attack?🤌
Arthur Mensch @arthurmensch
61K Followers 853 Following Co-founder and CEO @MistralAI. Talk to le Chat https://t.co/ZMZG8rAlWz https://t.co/ydSK6xG4Ce https://t.co/b1uf0UK5U8
Olivier Cochard @ocochardlabbe
1K Followers 458 Following Senior software engineer in test at Netflix, founder of FreeNAS and BSD Router Project, FreeBSD ports committer.
Grzegorz Tworek @0gtweet
38K Followers 2K Following My own research, unless stated otherwise. Not necessarily "safe when taken as directed". GIT d- s+: a+ C++++ !U !L !M w++++$ b++++ G-
mgeeky | Mariusz Bana... @mariuszbit
14K Followers 950 Following 🔴 Offensive Security Developer @ Outflank, Red Team operator, ex-AV dev, ex- malware researcher 🫖 Green tea lover
b33f | 🇺🇦✊ @FuzzySec
33K Followers 1K Following 意志 / mobile research @ ▓▓▓▓▓ / Team 501 / ex IBM Capability Lead & FireEye TORE / I rewrite pointers and read memory / AI Psychoanalyst / Teaching @CalypsoLabs
Justin Elze @HackingLZ
71K Followers 5K Following CTO @TrustedSec | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars
Will Dormann is on Ma... @wdormann
27K Followers 1K Following I play with vulnerabilities and exploits. I used to be here on Twitter but now I'm here: @[email protected] https://t.co/hXggdAVkSQ
The Haag™ @M_haggis
10K Followers 2K Following ⚔️ Prevention Engineering at MagicSword | Co-Host of Atomics on a Friday | LOLDrivers & Atomic Red Team Maintainer
Jack Fryer @alpajacka
6 Followers 24 Following #opensource community manager @ CrowdSec! Building a #crowdsourced cyber threat intelligence community 🦙 💡Join the pack and make the internet a safer place
Yann LeCun @ylecun
1.2M Followers 787 Following Professor at NYU & Executive Chairman at AMI Labs. Ex-Chief AI Scientist at Meta. Researcher in AI, Machine Learning, Robotics, etc. ACM Turing Award Laureate.
Courtney Austin @CourtneyA1_1
6 Followers 46 Following I am an international marketing executive that helps people and organisations become transformational leaders. All tweets represent my own viewpoint.
Clandestine @akaclandestine
60K Followers 5K Following | Security | Osint | Threat Research | Opsec | Threat Intelligence | Infosec | Threat Hunting | Humint |Xavier Mertens @xme@i... @xme
15K Followers 1K Following Freelance | Blogger | SANS ISC Handler | FOR610/FOR710 Instructor | BruCON co-organizer | BlueTeam | DFIR | MTB | PGP: 0xEB583912514B3E1F | Tweets are mine!
cts🌸 @gf_256
67K Followers 981 Following founder and hacker @zellic_io @v12sec @pb_ctf yt https://t.co/nlNai6iQCn
J. A. Guerrero-Saade @juanandres_gs
16K Followers 430 Following VP Intelligence & Sr Technical Fellow (AI Research) @ SentinelOne | Distinguished Fellow @SAISHopkins Alperovitch | https://t.co/9Mj3l5xmcW | Three Buddy Problem
CERT Arkéa @CertArkea
283 Followers 183 Following Le CERT-CSIRT Arkéa est en charge de gérer les incidents de sécurité et de cybercriminalité relatifs au groupe Crédit Mutuel Arkéa. GPG: 0xB580152D7959BCAF
Santiago @svpino
452K Followers 564 Following Computer scientist. I teach hard-core AI/ML Engineering at https://t.co/THCAAZcBMu. YouTube: https://t.co/pROi08OZYJ
Jack Rhysider 🏴... @JackRhysider
171K Followers 4K Following Creator of @DarknetDiaries. Tell me a good hacker story. 💻🔦⤵️🐰🕳️ Discord: https://t.co/qxanMuJ5X2
Have I Been Pwned @haveibeenpwned
175K Followers 1 Following Check if you have an email address or password that has been compromised in a data breach. Created and maintained by @troyhunt.
Pedro Joaquín @_hkm
5K Followers 4K Following My passion: #cybersecurity #pentesting #ai / @_tropicon / https://t.co/zWuNCo05RM / https://t.co/rFkim1CBxo / @_websec / @GuadalajaraCON / M3x4
佛祖保佑 永无BU... @arphanetx
982 Followers 2K Following not human, just an angry bot, security engineer, gamer, some times like to nerd around with more bots, sometimes on my own. the joke is on you.
Vincent Bernat @vince2_
4K Followers 553 Following Network engineer at AS12322. Debian and free software developer. C, Python, or Go. He/him. 🐘 @[email protected] — 🦋 https://t.co/KFz94XUfng
reflets.info @_reflets_
35K Followers 2K Following ./rebuild.sh online-newspapers Journal en ligne d'investigation Nos articles sont faits à la main, à base de produits frais, bios, et uniques.
Techno Tim @TechnoTimLive
27K Followers 1K Following Engineer. Builder. Creator. | From Code to Cloud
Nÿco ⭐ Libre Produ... @nyconyco
3K Followers 2K Following Fractional Product Director | OpenSource + B2B + AI
raptor @0xdea
14K Followers 17 Following When cryptography is outlawed, bayl bhgynjf jvyy unir cevinpl.
Gabor Pop @gaborpop
255 Followers 227 Following CMO at @Crowd_Security, the Waze of cybersecurity. Passionate about Infosec and IoT.
Troy Hunt @troyhunt
248K Followers 1K Following Creator of @haveibeenpwned. Microsoft Regional Director. Pluralsight author. Online security, technology and “The Cloud”. Australian.
Breega @BreegaVC
3K Followers 3K Following Breega is a European #vc built by #founders to propel #hightech #startups to global success.
VCs Congratulating Th... @VCBrags
287K Followers 5K Following They're adding value™ And they're very proud of it. @BragsVentures
Buanzo 🌿/ QUANTUM ... @buanzo
1K Followers 1K Following Padre x 3, Esposo, Programador, Linuxero, Autor, Músico #fail2ban #crowdsec #nmap #oldschool #guitarra #gobierno #cancilleria #diablo3wizard #elitedangerous
crowdsec_hub @CrowdSec_Hub
73 Followers 1 Following Regular updates of CrowdSec Hub. Browse collections, configurations & bouncers to protect your IT assets for free. Main account @Crowd_Security
Nicolas Krassas @Dinosn
157K Followers 766 Following Head of Threat & Vulnerability Mgmt @ Henkel AG & Co. KGaA https://t.co/NC1orlKZLB Posting content that I find interesting.
Securityblog @Securityblog
12K Followers 14K Following There are 10 types of people in the world. Those who understand binary, and those who don't. All opinions and views are my own. #BsidesDub organizer
























