CrowdSec
CrowdSec is a CTI tool leveraging crowdsourced data to identify and block malevolent IPs in real time worldwide. Join our Discord: http://discord.gg/crowdsec
#ButanGas, a major player in Italy’s energy sector, is taking its cybersecurity to the next level ⚡
With CrowdSec’s real-time threat intelligence and Platinum Blocklists, they’re now blocking hundreds of malicious connections daily, while keeping false positives under 1%.
Even better? Clear visibility, actionable insights, and a smarter, proactive firewall protecting critical LPG distribution across the country.
Read the full story here: https://www.crowdsec.net/blog/securing-lpg-distribution-butangas-and-crowdsec
#cyberSecurity #threatintelligence #energysector #successstory
You asked for more than the standard Premium CTI quota for your SOC/HomeLab/SIEM. We listened.
CrowdSec CTI has always been powered by the community. As your use cases grew, so did your need for data.
Today, we’re rolling out Self-Service CTI API Key options 🚀
Whether you’re:
• A cybersecurity pro scaling research
• An SMB/SecOps team integrating into your SIEM/SOAR (like our Microsoft Sentinel Playbook)
• An Enterprise power-user running heavy investigations
You can now scale your quota to match your real usage. No friction, just more of the world’s best crowdsourced IP reputation data 🔐
Check out how to scale your CTI access: https://app.crowdsec.net/pricing
Kubernetes networking is evolving 🌐 with the rise of the Gateway API, offering more flexible and extensible traffic management.
CrowdSec continues to support Ingress-NGINX during its final lifecycle, while helping users migrate to modern ingress controllers like Traefik and HAProxy, or Gateway API integrations, for future-proof security 🔒.
Read our latest article for details: https://www.crowdsec.net/blog/crowdsec-support-kubernetes-ingress-nginx
💭 Did you know? CrowdSec helps reduce alert fatigue by 80% by blocking threats automatically.
This means that instead of chasing endless alerts, your security team can focus on real incidents, while CrowdSec handles the noise in real time. 🔥
Learn more about how CrowdSec automates threat blocking: https://www.crowdsec.net/blocklists
Cybersecurity doesn’t fail from a lack of effort.
It fails due to wrong assumptions.
Swipe through to see which myth might be increasing your risk 👇
And read our article to get all the details: https://www.crowdsec.net/blog/5-common-vulnerability-myths
Cybersecurity in healthcare isn’t only about protecting data, it’s about maintaining continuity of care.
That requires:
– Early threat detection
– Automated remediation
– Reduced operational complexity
– Shared intelligence across organizations
Learn 4 practical ways to strengthen your posture:
https://www.crowdsec.net/blog/4-ways-to-strengthen-healthcare-cybersecurity-posture
AI crawlers are becoming a new class of automated traffic.
They:
– Ignore robots.txt
– Continuously scrape content
– Consume bandwidth and resources
This isn’t just about visibility; it’s about control.
A proactive approach (like blocklists) helps reduce unwanted load and protect your data.
Read more:
https://www.crowdsec.net/blog/protect-against-ai-crawlers
🚨 In this week’s threat alert, CrowdSec reports on CVE-2026-1207, a critical Django SQL injection vulnerability now actively exploited in the wild. Attackers are targeting GeoDjango setups using PostGIS with focused reconnaissance. Notably, this vulnerability hasn’t yet been added to the CISA KEV catalog.
Learn how the vulnerability works and how to secure your systems in our latest article: https://www.crowdsec.net/vulntracking-report/cve-2026-1207
New Console Feature Drop: Attack Map is LIVE! 🌍⚡
Get a powerful visual view of your threat landscape:
🔍 Replay attacks from the last 24h or 48h
📊 Volumetric insights over 24h, 48h, 7d, or 30d
🎥 One-click GIF export to share your attack activity instantly
See exactly where attacks are coming from, identify top scenarios, and track malicious IPs, all in an interactive map.
Check it out: https://app.crowdsec.net/alerts
Join us next week for an interactive Community Office Hours!
Get an exclusive preview of what’s coming next for the CrowdSec WAF. We’ll unveil upcoming features, including:
🔎 Smarter bot detection
⚙️Easier rule creation via the local MCP
👀 Take a peek at the roadmap, get practical tips, ask your questions live, and see how these innovations can strengthen your security posture.
📅 Don’t miss it, join us here: https://www.youtube.com/live/UlAamXEZh1I
🎥 Missed our webinar with
@suricata_ids@bird.makeup? The replay is live!
CrowdSec CTO Thibault Koechlin breaks down the CrowdSec + Suricata integration, from parsing logs to blocking malicious IPs, with a live demo to show it in action.
👉 Watch now: https://youtube.com/watch?v=af_KAJ9kswQ
💭 Did you know? ⟶ Am I Under Attack monitors your Security Engine alerts 24/7 so you don’t have to.
This means that while CrowdSec’s AI keeps an eye on unusual patterns and potential threats around the clock, your team can focus on critical security tasks instead of sifting through endless logs 🔥
Learn more about how to activate Am I Under Attack and stay ahead of targeted attacks: https://www.crowdsec.net/blog/am-i-under-attack
🚨 In this week’s newsletter, we cover CVE-2026-21445, a Langflow authentication bypass now under active exploitation. We break down how PoCs turned into real attacks and what defenders should do next.
Read the full analysis and protect your systems 👉 https://www.crowdsec.net/vulntracking-report/cve-2026-21445-langflow-authentication-bypass-exploitation
📶 Web application security requires multiple layers.
OWASP CRS provides rule-based protection, while CrowdSec adds real-time, collaborative threat intelligence.
Combining both helps defend against both known and evolving threats.
Read more:
https://www.crowdsec.net/blog/protecting-your-web-applications-with-owasp-crs-and-crowdsec
🚨 CVE-2025-4396 is seeing a surge in exploitation attempts.
This SQL injection vulnerability in the WordPress Relevanssi plugin has attracted over 16,500 attacking IPs, mostly targeting small sites with limited security.
We break down the attack and how to defend against it 👇
https://www.crowdsec.net/vulntracking-report/cve-2025-4396-wordpress-relevanssi-sql-injection
Writing WAF rules shouldn’t feel like decoding ancient YAML scrolls 📜
So we built a Model Context Protocol (MCP) for CrowdSec that lets your favorite LLM generate production-ready WAF rules, with validation and feedback loops built in 🤖
Think “USB port for AI”: connect tools, reduce hallucinations, ship faster.
Learn more and get started 👉 https://crowdsec.net/blog/crowdsec-mcp-use-ai-to-write-waf-rules-automatically
A vulnerability is a weakness.
A threat is who can exploit it.
Risk is the likelihood × impact.
Confusing them leads to bad prioritization and preventable incidents.
In our latest article, we break down the vulnerability lifecycle (discovery → disclosure → patching) and what it means for developers and maintainers.
Read now 👉 https://crowdsec.net/blog/vulnerability-101-understanding-security-weaknesses
🚨 In this week’s threat alert, we dive into CVE-2025-20281, a critical Cisco Identity Services Engine (ISE) RCE vulnerability, as CrowdSec Threat Intelligence observes a new wave of exploitation attempts. We break down how the vulnerability works, why attackers are now incorporating it into opportunistic exploit kits, and what defenders should do to stay protected.
Read the full analysis and protect your systems 👉 https://www.crowdsec.net/vulntracking-report/cve-2025-20281-cisco-ise-rce-exploitation
🛑 Stop known attackers before they reach your network.
Here’s how to plug🔌 CrowdSec’s IP endpoint into Sophos Firewall and instantly benefit from global threat intelligence.
Watch the full video here: https://youtu.be/lmqzFpHpYyw?si=uprax6B9SDKjLqVH
Thousands of CVEs. But which ones are actually being exploited right now?
Live Exploit Tracker cuts✂️ through the noise by showing vulnerabilities that attackers are actively exploiting in the wild, based on real attacks observed across hundreds of thousands of production systems.
With Live Exploit Tracker, you can:
• Prioritize remediation based on real-world exploitation
• Accelerate mitigation with high-confidence, actionable intelligence
• Anticipate emerging CVEs by observing exploit behavior in real time
Learn more 👉 https://www.crowdsec.net/live-exploit-tracker
Le Monde leverages CrowdSec to automate firewall updates, block malicious IPs, and defend against phishing, scans, and other threats, while saving valuable time for its IT team.
Discover the story behind their security strategy 👉 https://www.crowdsec.net/blog/le-monde-automates-security-maximizes-efficiency
🚀 CrowdSec is hiring!
We’re growing our data team and looking for:
• Data Analyst
• Data Analyst Intern
If you enjoy working with data, uncovering patterns, and contributing to real-world security, this is your chance to make an impact.
🔗 Apply now:
👉 Data Analyst: https://lnkd.in/e7_qrxDu
👉 Data Analyst - Internship: https://lnkd.in/evavHewv
#Hiring #DataAnalyst #CyberSecurity #OpenSource #Infosec #Careers
🚨 This week’s CrowdSec Threat Alert: CVE-2026-21859, a critical SSRF vulnerability in Mailpit, is being actively exploited to map internal networks and access sensitive infrastructure.
See how the exploit works, what targeted reconnaissance reveals, and why exposed dev tools can become high-impact entry points in our latest article 👉 https://crowdsec.net/vulntracking-report/cve-2026-21859
We’re just 15 minutes away from our Community Office Hours!
Join us live here 👉 https://youtube.com/watch?v=oedE1_ycS4o
Today, we’re diving into Stack Health, where we’ll cover:
• What real-world deployment data is telling us
• The most common issues & misconfigurations we’re seeing
• Live troubleshooting examples
• A sneak peek at what’s coming in v1.1, including new issue detection and improved guidance
If you’re running CrowdSec in production (or planning to), this session will be packed with practical insights you can apply immediately.
See you very soon! 🙌
What if your logs already show signs of a targeted attack, but the pattern is easy to miss? 🔎
Am I Under Attack analyzes alert activity with AI to identify suspicious surges and notify you when your infrastructure may be under threat. 🚨
Detect targeted attacks before they escalate.
The Community Blocklist blocks a lot. But the Threat Forecast Blocklist goes further:
📊 ~50% more attackers blocked
📊 1:40 prevention ratio
📊 Built from your own attack patterns
Available for the CrowdSec Console Premium plan, and still one of the most powerful ways to reduce noise before it starts.
Learn more 👉 https://crowdsec.net/blog/threat-forecast-blocklist-release
Missed our Community Office Hours? No worries, the replay is ready! 🎥
Yesterday, we took a deep dive into Stack Health and shared real-world insights straight from production deployments.
Catch the replay here 👉 https://youtu.be/knoVkVg-8Ds
Watch it on your schedule, share it with your team, and let us know what you’d like us to cover next 👇
See you at the next Office Hours!
🍯 Honeypots provide insights, but they don’t always reflect real attack activity.
Production telemetry, on the other hand, captures what’s happening across live systems.
Understanding the difference is key to better security decisions.
Read more:
https://www.crowdsec.net/blog/honeypots-vs-production-telemetry-what-cisos-should-trust
🚨 In this week’s threat alert, CrowdSec reports on CVE-2026-23744, a critical RCE in MCPJam Inspector. Exploitation attempts are rising, targeting exposed dev environments.
Learn how the vulnerability works and how to secure your systems in our latest article 👉 https://www.crowdsec.net/vulntracking-report/cve-2026-23744
🚀🎉 Big news: CrowdSec Blocklists are now available on the @Amazon Web Services (AWS) Marketplace!
✔️ Real-time, crowd-powered intelligence
✔️ Ultra-curated blocklists with 0 false positives
✔️ Stop malicious IPs, reduce SOC alerts, and prevent IAM brute force & fraud
Learn more: https://aws.amazon.com/marketplace/pp/prodview-yh6m5csuqxg6m?sr=0-3&ref_=beagle&applicationId=AWSMPContessa
New CVE? We immediately analyze exploitability, validate impact, and ship patches or virtual protections fast to shrink the exposure window.
Watch the full video to learn more 👉 https://youtube.com/live/oedE1_ycS4o
Check out #hackaday’s latest #FLOSS weekly episode featuring our CEO Philippe Humeau.
In this episode, Jonathan Bennett chats with Philippe about CrowdSec and how we created an open source Web Application Firewall that runs as a Multiplayer Firewall.
Watch to get all the details: https://hackaday.com/2026/03/04/floss-weekly-episode-865-multiplayer-firewall/

