Part 5 of “Back to basics in Cybersecurity” series.
Coming next: Incident response essentials
What is the biggest challenge you currently face with logging and detection? Too many logs? Not enough useful alerts? Lack of skilled people to monitor? https://t.co/lQGbXd5oFS
This is Part 4 of the “Back to Basics in Cybersecurity” series.
Coming next:
Part 5: Logging, Monitoring & Detection Basics
Followed by Incident response essentials
What is the biggest challenge: secure configuration, config. drift, lack of baselines? https://t.co/3pugBNOj3L
If you are following EU CRA (Cyber Resilience Act), ETSI (European Telecommunications Standards Institute) published 17 vertical final draft standards, ETSI EN 304 xxx series for cybersecurity requirements for EU CRA. Those are:
- Browsers
- Password Managers
- Antivirus
- VPN
- Network Management Systems
- SIEM
- Boot Managers
- PKI Certificate Issuance Software
- Network Interfaces
- Operating Systems
- Routers, Modems, Switches
- Smart-home Virtual Assistants
- Smart-home Security Products
- Internet Connected Toys
- Personal wearables
- Virtualization Container
- Firewalls
Documents link:
https://t.co/MgZxoTG4ea
For those who didn't have luck and time to visit DEF CON 34 and/or Black Hat 2026 here are the presentations/contents from both events:
https://t.co/OqajWmIwEj
https://t.co/cF4TwL8gbR
#DEFCON#BlackHat
Ah... čak i ako ste instalirali MS patch za RoguePlanet (CVE-2026-50656), problem je na žalost ostao!
RoguePlanet je u kratkim crtama local privilege escalation ranjivost u Microsoft Defender core scanning engine-u koji omogućava da standardni user dobije full SYSTEM-level pristup!
Microsoft has failed to properly patch RoguePlanet (CVE-2026-50656), ShieldBreak, a PoC that demonstrates a full bypass to the previous patch is now public.
https://t.co/YFfn559z6o
The PoC works with the latest August 2026 patch
Meet the Gemma Translator! A fully offline device powered by Gemma 4 E2B built with @Antigravity.
Running entirely on a Raspberry Pi 5 with a connected microphone and speaker, this highly portable prototype is housed inside a custom, 3D-printed case.
Verovatno ste do sada čuli da je nepoznati haker upao u sisteme katastra u Rumuniji i zahtevao otkup (upotrebio je ByteToCrypt ransomware, u komentaru link na tehnički opis), te kako ga nije dobio obrisao je sve podatke. Isti taj haker ili grupa su sada upali u Ministarstvo poljoprivrede Mađarske i za sada još uvek podaci nisu obrisani. Detalji u komentarima...
#cyberattack #Romania #Hungary
https://t.co/6TyU4JJY2b
This is Part 2 of the “Back to basics in cybersecurity” series.
Coming Next:
Part 3: Identity and Access Management fundamentals (the new perimeter)
And more on configuration hardening, logging/detection, incident response, etc.
What is your biggest vulnerability management struggle right now?
- Too many findings?
- Slow patching?
- Cloud or container challenges?
- Legacy infrastructure?
Share in the comments.
#Cybersecurity #VulnerabilityManagement #BackToBasics #NIS2 #RiskManagement #InfoSec #PatchManagement
https://t.co/fVha36QVBz
Nova Microsoft ranjivost CVE-2026-54121, za koju su procenili inicijalno da nije toliko opasna, ali kada je objavljen PoC, stvari su postale ozbiljnije ili kako preuzeti AD uz pomoć ranjivosti na CA serveru.
https://t.co/Asc3IOMFbL
If you are using S1 (SentinelOne) on a macOS, you should wait with upgrade to macOS 26.6, since S1 will detect some of the macOS processess as potential malware!
If you already upgraded to macOS 26.6 current workaround is Policy Override:
{
"General": { "ExclusionOptimizationMode": 0 }
}
GTIG (Google Threat Intelligence Group) je odlučio da sistematizuje nazive “napadača”, tj. grupa koje vrše cybersecurity napade, tzv. threat actors.
https://t.co/svWD6LeRaa