CrowdSec
@crowdsec
Account run by Alpacas CrowdSec is a CTI tool leveraging crowdsourced data to identify and block malevolent IPs in real time, worldwide. Join our Discord:
🚨 In this week’s newsletter, we cover CVE-2024-12847, a critical RCE vulnerability affecting NETGEAR DGN1000 routers that has become the most-attacked flaw tracked by the CrowdSec Network. Read the full analysis and protect your systems 👉 www.crowdsec.net/vulntracking...
Your AI agent is smart. But does it actually know how your software works? 🤖 We built a CrowdSec Skill to replace plausible guesses with product-specific procedures, guardrails, and verification. It even helped us find gaps in our own docs. Read the story 👇 www.crowdsec.net/blog/ai-agen...
🚨 In this week’s newsletter, we cover CVE-2026-2652, an authentication bypass vulnerability affecting MLflow that is seeing active exploitation. Read the full analysis and protect your systems 👉 www.crowdsec.net/vulntracking...
Traefik routes traffic. A WAF inspects it. Learn how to add an open-source WAF to Traefik with CrowdSec for virtual patching and real-time protection—without changing your architecture. 👇 www.crowdsec.net/blog/waf-tra... #Traefik #WAF #CyberSecurity #OpenSource
🚨 In this week’s newsletter, we cover CVE-2026-63030 (WP2Shell), a critical SQL injection-to-RCE vulnerability affecting WordPress core that has rapidly entered the Rapid Escalation phase. 👉https://www.crowdsec.net/vulntracking-report/cve-2026-63030-wordpress-wp2shell-sqli-to-rce
💭 Did you know? Am I Under Attack turns those signals into a simple answer, notifying you when your instance is likely facing a targeted attack—so you can investigate immediately instead of discovering it later. Learn how to enable it 👇 www.crowdsec.net/blog/am-i-un...
Live Exploit Tracker now includes IOCs for tracked CVEs. 👀 See what to look for—not just what is being exploited. Quick demo 👇 tracker.crowdsec.net #CyberSecurity #CVE #ThreatIntel
🤖 The ESRB warns AI is shrinking defenders' response time. CVSS tells you what could happen. Live Exploit Tracker shows what attackers are exploiting right now. Prioritize based on active exploitation, not just severity. 👉 tracker.crowdsec.net
Running NGINX on Ubuntu? Protect your web apps with an open-source WAF backed by real-time threat intelligence. Our step-by-step guide shows you how 👇 www.crowdsec.net/blog/open-so... #NGINX #WAF #CyberSecurity #OpenSource
🚨 In this week’s newsletter, we cover CVE-2026-8451, a high-severity SAML memory overread vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway that is already seeing active exploitation. Read the full analysis and protect your systems 👉 www.crowdsec.net/vulntracking...
Stack Health continuously checks your CrowdSec deployment so you can spot and fix problems before they impact protection. 👉 doc.crowdsec.net/u/console/st... #CyberSecurity #SecOps #Infosec
A new CVE is disclosed. The first question shouldn't be *"What's the CVSS?"* It should be *"Is it being exploited?"* See real-world exploitation as it happens with the Live Exploit Tracker 👇 tracker.crowdsec.net #CyberSecurity #CVE #ThreatIntel
🚨 In this week’s newsletter, we cover CVE-2026-39808, a critical OS command injection vulnerability in Fortinet FortiSandbox now in early exploitation. Read the full analysis and protect your systems 👉 www.crowdsec.net/vulntracking...
🔎 New in CrowdSec CTI: a powerful search bar that helps you build complex threat intelligence queries in just a few clicks. Search by IP, threat, behavior, network, geo, or activity. It's also the first step toward smarter, easier Blocklist creation. 👉https://app.crowdsec.net/cti
🚨 In this week’s newsletter, we cover CVE-2026-20253, a critical authentication bypass vulnerability in Splunk Enterprise and Splunk Cloud Platform now in early exploitation. Read the full analysis and protect your systems 👉 www.crowdsec.net/vulntracking...
Not every CVE deserves the same level of attention. The real question is: which ones are attackers actually exploiting? Our latest report looks at real-world exploitation patterns 👇 www.crowdsec.net/vulnerabilit... #CyberSecurity #CVE #ThreatIntel
CVSS tells you what could happen. Live exploitation tells you what is happening. That's the thinking behind CISA's new BOD 26-04—and why exploitation intelligence matters more than ever. www.crowdsec.net/blog/cisa-bo...
🚨 In this week’s newsletter, we cover CVE-2026-10520, a critical pre-authentication OS command injection vulnerability in Ivanti Sentry now under active exploitation. Read the full analysis and protect your systems 👉 www.crowdsec.net/vulntracking...
OWASP CRS is powerful. But static rules alone can’t keep up with evolving attacks. Combine it with CrowdSec’s real-time threat intelligence for stronger protection 👇 www.crowdsec.net/blog/protect... #WAF #CyberSecurity #DevSecOps
🚨 In this week’s newsletter, we cover CVE-2026-8181, a critical authentication bypass vulnerability in the WordPress Burst Statistics plugin now under active exploitation. Read the full analysis and protect your systems 👉 www.crowdsec.net/vulntracking...
👀 What's being cooked at CrowdSec? Your WAF already knows *what* requests are doing. What if it could also help answer *who* is behind them? More soon! #CyberSecurity #WAF #BotDetection #ThreatIntelligence
A suspicious IP alone doesn’t tell you much. The context around it does. Attack history, targeted services, observed behaviors, confidence signals — that’s what helps analysts decide what actually matters. Try investigating your latest suspicious IP 👇 app.crowdsec.net/cti
🚨 In this week’s newsletter, we cover CVE-2026-9082, a Drupal JSON: API SQL injection vulnerability now under active exploitation. We break down how attackers are targeting exposed /jsonapi/ endpoints and what defenders should do next. 👉 www.crowdsec.net/vulntracking...
New CVE? The clock starts immediately ⏱️ How do you validate impact, assess exploitability, and deploy protections fast enough? Watch the full session 👇 youtube.com/live/oedE1_y... #CyberSecurity #CVE #SecOps
Security shouldn’t become a deployment bottleneck. Modern DevSecOps needs protection that fits naturally into CI/CD, GitOps, and cloud-native workflows. Here’s how CrowdSec integrates without friction 👇 www.crowdsec.net/blog/devseco... #DevSecOps #CyberSecurity #CIcd
🚨 In this week’s newsletter, we cover CVE-2024-9643, a Four-Faith router authentication bypass now moving into mass exploitation. Read the full analysis and protect your systems 👉 www.crowdsec.net/vulntracking...
🔥 The edge is the new endpoint. VPNs, firewalls, and reverse proxies are now frontline targets — and when edge CVEs go hot, response time matters. How do you reduce exposure before exploitation spreads? 👇 www.crowdsec.net/blog/edge-is... #CyberSecurity #EdgeSecurity #CVE
Critical infrastructure needs proactive defense ⚡ ButanGas is using CrowdSec’s CTI + Platinum Blocklists to block hundreds of malicious connections daily. Real-world protection for critical energy operations 👇 www.crowdsec.net/blog/securin... #CyberSecurity #ThreatIntel #EnergySector
Suspicious IP in your logs? 👀 Check it instantly against CrowdSec’s threat intelligence with IPDEX. Fast investigation. Real-world context. No setup. 👇 ipdex.crowdsec.net #CyberSecurity #ThreatIntel #Infosec
🚨 In this week’s newsletter, we cover CVE-2025-20362, a Cisco ASA & FTD VPN authentication bypass still actively targeting internet-facing firewalls. Read the full analysis and protect your systems 👉 www.crowdsec.net/vulntracking...