circl
CIRCL is the CERT (Computer Emergency Response Team/Computer Security Incident Response Team) for the private sector, communes and non-governmental entities in Luxembourg. The home of many open source security tools.
#infosec #cert #threatintelligence #fedi22 #incidentresponse #dfir
As we approach the end of the year, we have a small gift for everyone.
We ran a series of Rust training sessions as an introduction to the Rust programming language, and we recorded them. The videos, along with the training materials, are now available online.
Thanks to Quentin Jerome and all the participants for their contributions.
📽️ https://www.youtube.com/playlist?list=PLhSWiKucshm5vWvFCqtJePVVYgIXH6_6y
🔗 https://github.com/ngsoti/rust-training
#rust #rusttraining #programming #cybersecurity #opensource #training
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.
#cybersecurity #ivanti #vulnerabilitymanagement #vulnerability
Thanks @reverseics@infosec.exchange for the infographics and Ivanti for the continuous source of discoveries.
Rulezet v1.4.1 Core Enhancements for Filtering, Pagination, and MISP Support
🔗 Release note https://github.com/ngsoti/rulezet-core/releases/tag/v1.4.1
🔗 Online version https://rulezet.org/
#rules #threatintelligence #opensource #cti #detection #threathunting #rulezet
In 2 days @hack_lu@infosec.exchange is starting we hope to see you there. There are still some seats for the lighting talks and the call for failures. If you are already registered check your mail for the submission link and if you want to send a failure 10 minutes presentation. You can still register
don’t forget to follow @hack_lu@infosec.exchange on the #fediverse
#hacklu #conference #cybersecurity #europe #luxembourg #infosec #opensource
Checkpoint - User Authentication Bypass in VPN Remote Access and Mobile Access
Flowintel release version 2.2.1 with changes and fixes
- Markdown support in descriptions for cases, tasks, and templates
- New button to view finished tasks
- Added a safe installer version
- Multiple bug fixes and improvements
🔗 https://github.com/flowintel/flowintel/releases/tag/2.2.1
#flowintel #opensource #threatintelligence #threatintel #cybersecurity
KB4830: Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2.4465
#vulnerability #infosec #cybersecurity
🔗 https://vulnerability.circl.lu/bundle/08c1bcc5-abc2-4fd7-8a14-32dffe5c9afc
CTI-Transmute v1.0 released
An online and open source service for converting cyber threat intelligence format, built to promote interoperability and seamless data exchange.
#opensource #cti #stix #misp #openstandard
🔗 Online version https://cti-transmute.org/
🔗 Source code https://github.com/MISP/cti-transmute
CIRCL - Virtual Summer School (VSS) 2025
From 7 July to 18 July 2025, CIRCL will host a two-week online training event featuring hands-on sessions on various tools developed and maintained by CIRCL, as well as training in digital forensics and incident response (DFIR) techniques.
#opensource #dfir #training #cybersecurity #threatintelligence
@ail_project@infosec.exchange
@misp@misp-community.org
@vulnerability_lookup@social.circl.lu
@gcve@social.circl.lu
FlowIntel presentation and video is now available.
#opensource #casemanagement #cybersecurity #threatintelligence #threatintel
A vulnerability has been identified in the web-based management interface of AOS-CX switches (Hewlett Packard Enterprise (HPE)) that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable resetting the admin password.
@rafi0t@social.yoyodyne-it.eu @hacks4pancakes@infosec.exchange In that scope we operate different @misp@misp-community.org communities which can support different ISACs or security professionals willing to get intelligence, IoCs or even share intelligence or indicators. To request an access, email to info(at)circl(dot)lu
CVE-2026-27820: Buffer overflow vulnerability in Zlib::GzipReader Ruby.
https://www.ruby-lang.org/en/news/2026/03/05/buffer-overflow-zlib-cve-2026-27820/
https://vulnerability.circl.lu/vuln/CVE-2026-27820#sightings
CIRCL Virtual Summer School - VSS 2025 A Look Back at Our Successful Virtual Summer School! Videos Are Now Available.
🔗 https://www.circl.lu/pub/press/20250721/
#opensource #cybersecurity #csirt #cert #threatintelligence #dfir
TR-93 - Financial transaction fraud after system compromise.
This document outlines a malspam attack targeting businesses through fraudulent emails that exploit Remote Monitoring & Management (RMM) tools. The attackers deceive recipients into clicking a malicious link disguised as an invoice, which installs an RMM tool on their system. Since these tools are legitimate applications, they evade antivirus detection.
Flowintel release version 2.0.0 with a new UI
Flowintel is an open-source platform designed to help analysts and incident responders manage, investigate, and collaborate on cases efficiently.
🔗 https://github.com/flowintel/flowintel/releases/tag/2.0.0
A @misp@misp-community.org event (available in the CIRCL OSINT feed) has been added with the FortiOS vulnerability CVE-2022-42475 including some IoCs and detection rules.
MISP JSON file: https://www.circl.lu/doc/misp/feed-osint/e132e5f2-1a09-43e4-b2d6-8046c730616f.json
#infosec
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-3055 and CVE-2026-4368
#citrix #vulnerabilitymanagement #vulnerability
https://vulnerability.circl.lu/bundle/1ae9c3df-c65f-4755-b3a9-4d76f8c0e772
CVE-2026-31431 - crypto: algif_aead - Revert to operating out-of-place
🔗 https://vulnerability.circl.lu/vuln/CVE-2026-31431#comments
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS.
KEV confirmed.
Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management IP or SNIP with management access is enabled
TR-99 - Phishing Campaign Targeting Hotel Customers in Luxembourg