AlteredCoder
42 posts

AlteredCoder retweetledi

🚨 CVE-2024-27292 exploitation campaign detected! (thread)
What is the CVE-2024-27292 vulnerability?
CVE-2024-27292 is a path traversal vulnerability in Docassemble. It allows unauthenticated attackers to access arbitrary files, such as /etc/passwd via specially crafted URL parameters. The root cause is improper sanitization of user-supplied inputs, making it possible for attackers to probe system-level files.
Over the past few days, CrowdSec telemetry has identified a significant and accelerating wave of exploit attempts targeting the URI pattern: /interview?i=/etc/passwd.
Docassembe is a free, open source expert system for guided interviews and document assembly, based on Python, YAML, and Markdown.
This pattern aligns with an exploit attempt for CVE-2024-27292, a vulnerability disclosed in late 2024 affecting Docassemble (v1.4.53 to v1.4.96).

English

One week ago, I added three CrowdSec Blocklists on a VPS running WordPress and NGINX.
With the CrowdSec NGINX RC's stats feature, I was able to see how effective CrowdSec Blocklists are! In just a week, they blocked 70% of HTTP requests coming from malicious IPs.
#crowdsec

English
AlteredCoder retweetledi

Jumping from New York to Milan for some shopping? Within … 30 minutes? 🧐 That seems a bit sus, wouldn’t you agree?
Follow this tutorial and learn how to use the new conditional feature to detect impossible travel 🌍 and other suspicious IP behaviors.
hubs.ly/Q023bNWQ0
English
AlteredCoder retweetledi

We are thrilled to announce the release of the CrowdSec Majority Report! 🎉
Explore global #cyberthreats, the myth of #VPN ’s popularity in cybercriminal activities, and the most accurate method of evaluating #AutonomousSystems.
hubs.ly/Q01YZ4630
#cybersecurityreport

English

@THESMASHY Hello, what issues or errors did you face while upgrading crowdsec ?
We are available on Discord if you need help debugging your crowdsec :)
discord.gg/crowdsec
English
AlteredCoder retweetledi

New scenarios for the CVE-2022-40684 and CVE-2022-26134 are on the Hub.
See them here:
CVE-2022-40684 👉 hub.crowdsec.net/author/crowdse…
CVE-2022-26134 👉 hub.crowdsec.net/author/crowdse…
English
AlteredCoder retweetledi

🚨Pesky Forti auth bypass (CVE-2022-40684) is no match for CrowdSec! We just released a scenario to aid in detecting these attacks which you will find here 👉 hub.crowdsec.net/author/crowdse…

English
AlteredCoder retweetledi

Proud to announce a €14M Series A round led by @SupernovaInvest and joined by @BreegaVC. This is a big step forward in our goal of combating cybercrime and positioning ourselves as the world’s largest crowdsourced CTI network 🚀
👉 crowdsec.net/blog/crowdsec-…
#CyberSecurity

English
AlteredCoder retweetledi

@Crowd_Security The top 5 IP's are already blocked by @Crowd_Security community blocklist another is also stated but coverage of 6/10 based on IP reputation is great start to protecting your websites!

English
AlteredCoder retweetledi

We’re announcing our exciting collaboration with CrowdSec - the only integration of its kind and is set to mark a pivotal moment in WordPress security.
buff.ly/3TueYyh
#crowdsec #secruity #wordpress #wordpresssecurity
English

The CrowdSec Console: Monitor cyber threats on your online services producthunt.com/posts/the-crow… by @philippe_humeau h/t @kevinwdavid for hunting!
English
AlteredCoder retweetledi

We are still looking for alpha testers of our Windows agent and bouncer, would love to hear your feedback!
docs.crowdsec.net/docs/next/gett…
CrowdSec@Crowd_Security
🚨🪟 We’ve released an ALPHA version of our Windows port! It comes with a few #Windows-specific collections and a Windows Firewall bouncer. Check out the documentation on how to get started: docs.crowdsec.net/docs/next/gett… Feel free to share your feedback on Discord or in GitHub Issues.
English
AlteredCoder retweetledi

The new version of the CrowdSec @nginx bouncer is out! It comes with stream mode support, reCAPTCHA v2, and more.
Read our latest blog post for the full list of new features and how-to install tutorial 👇👇👇
crowdsec.net/blog/nginx-bou…
English
AlteredCoder retweetledi

🎉 Yesterday, our community shared 1+ MILLION signals! 🎉 On one single day!
The detection capabilities of CrowdSec are now growing exponentially. Our users exchange threat signal data with each other daily, generating the greatest CTI network. 🚀🚀🚀
Join Us!
#CyberSecurity

English
AlteredCoder retweetledi

Parse and detect attacks with CrowdSec for free.
Check out our latest article to learn how to write CrowdSec parsers and scenarios (on the example of @asteriskpbx) 👇
crowdsec.net/blog/how-to-wr…
#cybersecurity #opensource
English
AlteredCoder retweetledi

💥 PwnKit: find out how to detect and alert on privilege escalation vulnerability (CVE-2021-4034) with CrowdSec. Learn more in our latest article:
crowdsec.net/blog/pwnkit-av…
#linux #CybersecurityNews #Pwnkit
English
AlteredCoder retweetledi

🥳 Merry Christmas and Happy Holidays, everyone!
Enjoy the time with your loved ones. CrowdSec will take care of the security of your IT assets. 🎄🦙🦙🦙 #safertogether
#Christmas #CyberSecurity #infosec #infosecurity

English
AlteredCoder retweetledi

🚀Over this year, CrowdSec blocked 1+ MILLION malicious IPs. And is now used in 120+ countries and 2K+ locations.🥳
We thank our community of #opensource enthusiasts and inspired #CyberSecurity professionals for being here with us, outnumbering cybercriminals together!💪

English
AlteredCoder retweetledi

List of IP addresses exploiting the #log4j #CVE-2021-44228 vulnerability, as reported by our network. (Updated several time/day).
Courtesy of the CrowdSec community. gist.github.com/blotus/f87ed46…
Stay safe.
English

