Alexandre Dulaunoy
Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff.
The other side is at @a@paperbay.org (photography, art and free software at large)
#infosec #opensource #threatintelligence #fedi22 #threatintel #searchable
I just released ptrclassify is a small, dependency-free Python library and CLI that infers likely IP usage from reverse-DNS PTR hostnames.
It is intentionally heuristic and multi-label. PTR naming is operator-controlled and is not authoritative evidence of how an address is actually used. The output therefore includes a confidence score, the text that matched, and the rule IDs that produced each label.
To summarize, the library is trying to guess usage (and a bit location) of an IP address based on its PTR records. It's based on a set of rules which can be updated easily.
#osint #cybersecurity #ptrclassify #opensource #dns
https://github.com/adulau/ptrclassify
module https://pypi.org/project/ptrclassify/
GCVE BCP-07, the Known Exploited Vulnerability (KEV) Assertion Format, has been updated to version 2.2. A key addition is the formalisation of the GCVE KEV Directory, a simple machine-readable directory allowing organisations to announce where their KEV catalogues and exploitation assertions are published.
We particularly encourage software and hardware vendors to publish their own KEV catalogues. Vendors are often in the best position to confirm exploitation affecting their products, and publishing this information in a machine-readable form can significantly improve vulnerability prioritisation for users, CSIRTs and vulnerability-management platforms.
For more details https://gcve.eu/2026/09/01/gcve-bcp-07-updated-a-directory-for-known-exploited-vulnerability-catalogues/
#GCVE #GNA #vulnerabilityintelligence #opensource #KEV #cybersecurity
GCVE Workshop - 22 September 2026 (14:00-18:00), Luxembourg Before The Vulnopticon Conference
We are pleased to announce a GCVE workshop on 22 September 2026, from 14:00 to 18:00, hosted at the CIRCL/LHC offices in Luxembourg, just before the VulnOpticon conference.
The workshop is free and open to everyone, but registration is required.
#cve #gcve #luxembourg #cybersecurity #vulnerabilitymanagement
Doing some statistics on the persistence of information published on security and threat intelligence blogs. A surprising number of the domains in the list below are NXDOMAIN nowadays.
Don't assume that security information and threat intelligence will remain accessible over time, especially when it is hosted by large private entities.
Some are simply mistyped, while others reflect DNS changes over time that eventually left the original URLs broken.
Stability and persistence of information is hard on Internet.
#threatintelligence #threatintel #infosec #cybersecurity
app.response.ncr.com
blog.0x3a.com
blog.anomali.com
blog.cert.societegenerale.com
blog.cylance.com
blog.deniable.org
blog.ioactive.com
blog.jpcert.or.jp
blog.kleissner.org
blog.malwareclipboard.com
blog.malwaretracker.com
blog.passivetotal.org
blog.safebit.mn
blog.team-cymru.org
blog.zimperium.com
blogs.rsa.com
cdn.securelist.com
community.saas.hpe.com
ddos.arbornetworks.com
dnsdb.isc.org
edu.arabsgate.com
info.baesystemsdetica.com
info.isightpartners.com
insider.domaintools.com
ioc.forensicartifacts.com
iranthreats.github.i
joedd.joesecurity.org
lab.anchiva.com
labs.alienvault.com
labs.lastline.com
labs.snort.org
labsblog.f-secure.com
luminosity.link
malware.sekoia.fr
morphick.net
motherboard.vice.com
ocelot.li
permalink.gmane.org
r.virscan.org
remchp.com
research.riskiq.net
resources.infosecinstitute.com
sandbox.deepviz.com
sec.sexy
securityblog.s21sec.com
securityblog.switch.ch
securitydaily.org
sub0day.com
tif.mcafee.com
wepawet.iseclab.org
www.cve.mitre.org
www.cyintanalysis.com
www.cyphort.com
www.icebrg.io
www.infosecdailynews.com
www.isightpartners.com
www.lexsi.com
www.novetta.com
www.packetmail.net
www.root9b.com
www.skycure.com
www.threatexpert.com
www.vxsecurity.sg
I spent many hours in vulnogram today and to be honest. I'm glad that a colleague started to work on a replacement called vulniverse. Still early beta but it's promising.
#opensource #vulniverse #cybersecurity #cve #gcve
work in progress https://github.com/vulnerability-lookup/vulniverse
ptrclassify is a small, dependency-free Python library and CLI that infers likely IP usage and location from reverse-DNS PTR hostnames.
Version 0.3 released including new rules and CSV tool.
Proposed changes in the CVE program CNA document
"Update 4.2.6 from SHOULD to MUST: "CNAs MUST assign different CVE IDs to separate Vulnerabilities""
🔗 https://github.com/CVEProject/cve-documents/issues/47#issuecomment-5515748024
Not sure I’m allowed to leak this yet, but the new MISP dashboard is kind of crazy.
We didn’t just refresh the old one, we rewrote it completely, and it comes with a whole set of new features and capabilities that change the game quite a bit.
What’s the difference between an API and an agent?
An API is consistent, deterministic, and scoped.
An agent is probabilistic, non-deterministic, and occasionally chaotic.
An agent adds some spice to your life.
Will you choose the boring, predictable life or the cool, chaotic one?
I’m wondering why @dnsoarc@mastodns.net is limiting potential new contributions to their project just because they are AI-assisted.
Many valuable tools support development today, including code review and security review. The copyright argument feels similar to the one behind CLAs: an unsuccessful attempt to control the origin of the code, or even the author’s ability to re-implement a specific idea with or without external tools.
https://codeberg.org/DNS-OARC#artificial-intelligence-and-large-language-model-contributions-policy
