Not all bots look like bots. 🤖 Modern bots can run real browsers, use residential IPs, and mimic legitimate traffic.
CrowdSec’s WAF Bot Detection uses fingerprinting and proof of work to distinguish them, helping stop scraping, scalping, and other aggressive automation.
Watch how to set it up 👇
Get the guide here: https://t.co/HzdQNFWIDM
#WAF #botdetection #appsec #cybersecurity
New in CrowdSec: Alerts Explorer.
See how alerts break down across your stack, group activity by source IP, then use interactive facets to jump straight into what you want to investigate.
Explore it → https://t.co/bXwB9pYyMH
(🧵Thread) Breaking threat alert from DigitalOcean and Microsoft Azure! Mass exploitation campaign detected by actor codenamed Goofy Khaki Flamecrest. Find out about the 4 key events that characterized the campaign 👇
On the 15th of April, we detected a coordinated exploitation effort that included over 1,300 machines at its peak. The machines were small to medium-sized VPCs in public clouds such as Microsoft Azure and DigitalOcean. Using our comprehensive threat intelligence data, we were able to get a clear view of the exploitation campaign.
(🧵1/4)
👾 Introducing the CrowdSec VulnTracking Report! 👾
Stay ahead of threats with our new monthly series, delivering key insights into trending CVEs and exploitation attempts.
For March, we added detection for 34 vulnerabilities and/or exploits to our database. What we noticed:
• There is a noticeable gap between media hype and actual attacker interest in certain CVEs.
• Surprisingly, older vulnerabilities like CVE-2021-43798 and CVE-2019-17538 are making a comeback, attracting significant malicious activity.
Want the full breakdown? Read the report: https://t.co/Z9F682bac2
Have you tried the CrowdSec Remediation Component for Apache yet?
This powerful component integrates seamlessly with Apache’s module mechanism to block malicious IPs, keeping your infrastructure secure and protected against threats, before they hit. 🛡️
Ready to get started? You can check out the documentation here: https://t.co/LJXUzOh0K0
It is still in the beta phase, so any feedback or bugs you find please share them on GitHub: https://t.co/kCVLFqGkUh
#Apache #Cybersecurity
🚨 CVE-2024-27292 exploitation campaign detected! (thread)
What is the CVE-2024-27292 vulnerability?
CVE-2024-27292 is a path traversal vulnerability in Docassemble. It allows unauthenticated attackers to access arbitrary files, such as /etc/passwd via specially crafted URL parameters. The root cause is improper sanitization of user-supplied inputs, making it possible for attackers to probe system-level files.
Over the past few days, CrowdSec telemetry has identified a significant and accelerating wave of exploit attempts targeting the URI pattern: /interview?i=/etc/passwd.
Docassembe is a free, open source expert system for guided interviews and document assembly, based on Python, YAML, and Markdown.
This pattern aligns with an exploit attempt for CVE-2024-27292, a vulnerability disclosed in late 2024 affecting Docassemble (v1.4.53 to v1.4.96).
🚀 Congrats to the Pangolin team on v1.0.0! 🎉
This self-hosted reverse proxy securely exposes private resources without open ports, now with CrowdSec integration for added security! 🔒✨
Check it out 👉 https://t.co/YNC5FIjwqg
🚀 Exciting to see Traefik featured in LRVT's Security Blog! 🛡️
The post highlights how #Traefik utilizes #CrowdSec and its Cyber Threat Intelligence (CTI) to ban malicious threat actors probing our exposed HTTP services in a collaborative manner.
https://t.co/8N0SbsGXtZ
Say hello to our 3 newest Crowdsec ambassadors, dedicated community members who are advancing our CrowdSec mission and strengthening the collaborative cybersecurity community:
@flaviuvlaicu
Haneef Haroon
Killian Prin-Abeil
Apply to become an ambassador- https://t.co/0OdF3yzetG
🚀 If you're looking for a new year's goal, why not become a CrowdSec Ambassador and make the internet safer together?!
Share your knowledge, represent #CrowdSec, and earn rewards for your contributions. Let’s build a safer future together! Apply now:👉 https://t.co/8L51fYrt6e
Big announcement! We are introducing the #CrowdSec Guide to Cost-Effective Security Operations! Available to download now!
This resource is designed to help security teams and decision-makers achieve operational excellence without breaking the budget-https://t.co/X59O29vINJ
#CrowdSec Security Engine 1.6.3 is out! 🎉
What may look like a minor release is in fact packed with important updates and several improvements.
Check out the v.1.6.3 release notes for all the juicy details! https://t.co/qf5FZPaCah
#cybersecurity#securityengine
Always love when FOSS moves fast. Shoutout to the guys of https://t.co/3xeL2AVslD for merging and releasing overnight! 1.6.3 release for Windows is now fixed (cf. https://t.co/YHH05yg1d2)
The award-winning Qualys Threat Research Unit (TRU) has discovered a critical vulnerability in OpenSSH, designated CVE-2024-6387 and aptly named "regreSSHion." This Remote Code Execution bug grants full root access, posing a significant exploitation risk. https://t.co/uDHHSuzd5f
@OlivLiliv https://t.co/pEI5tR0wNn
"Do not use cscli explain on big log files, as this command will buffer a lot of information in memory to achieve this. If you want to check crowdsec's behaviour on big log files, please see replay mode."
On devrait rendre le warning plus explicite :)