CVSS, EPSS, & KEV tell you what might be exploited. CrowdSec’s Live Exploit Tracker shows what’s being exploited right now. Track 700+ CVEs, prioritize patches, & block attackers with feeds you can plug into your existing stack. → www.crowdsec.net/live-exploit...
CrowdSec
@crowdsec.bsky.social
Account run by Alpacas CrowdSec is a CTI tool leveraging crowdsourced data to identify and block malevolent IPs in real time, worldwide. Join our Discord: http://discord.gg/crowdsec
MindMax put CrowdSec’s bot detection to the test and challenged ~1M suspicious clients in its first week, blocking 99%+ of non-human traffic while keeping the experience seamless for real users. Read the full success story → www.crowdsec.net/blog/mindmax... #WAF #botdetection
CrowdSec 1.8 brings bot detection to the #WAF, helping distinguish real browsers from bots that are trying to blend in. See it in action during our live webinar: 📅 October 29 🕓 4 PM CET Click Notify Me & join us → www.youtube.com/live/rHKs3yA...
🚨 CVE-2026-85706 is a critical GitLab file-read vulnerability already being exploited in the wild. CrowdSec has tracked 1,022 unique IPs sending matching requests since September 11. Read the Threat Alert article to get the analysis 👉 www.crowdsec.net/vulntracking...
CVE-2026-85706: Upgrading GitLab Won't Save Leaked Secrets
Active exploitation of CVE-2026-85706 (CVSS 10.0) exposes GitLab secrets. Upgrading blocks new requests, but exposed credentials must be rotated immediately.
crowdsec.net
Which vulnerabilities actually need your attention? Our Vulnerability & Exploitation Report uses real-world CrowdSec Network data to show how fast attackers move, what gets exploited at scale, and why CVSS alone isn’t enough. 👉 Download the report: www.crowdsec.net/vulnerabilit...
Last week, CrowdSec CEO Philippe Humeau presented at the SANS Institute Cyber Leaders event in Brussels. You can check out the prez below 👇 Want to dig into the data yourself? Check IP reputation with IPDEX: ipdex.crowdsec.net Track which IPs are exploiting which CVEs: tracker.crowdsec.net
🤖 CrowdSec 1.8’s bot detection uncovered PaperPhone, a scraping network spanning 75K IPs across 43 countries. Our first investigation found suspicious device fingerprints and a geographic footprint that isn’t quite what it seems. Read the full investigation: www.crowdsec.net/blog/the-pap...
👻 Is that a real browser… or a bot in disguise? 🤖 CrowdSec 1.8 brings #botdetection to the #WAF. Join our #CommunityOfficeHours on Oct. 29 at 4 PM CET to see it in action and explore what’s new in 1.8. 🎃 No tricks, just treats! Notify Me & save the date → www.youtube.com/live/rHKs3yA...
🚨 In this week’s #threatalert, we cover #CVE-2026-87902, a critical WordPress path traversal vulnerability that can lead to #RCE. CrowdSec has observed 30,813 unique IP addresses sending requests matching the exploitation pattern in just five days. Read more: www.crowdsec.net/vulntracking...
CrowdSec Blocklists feature a 5% daily rotation, ensuring users always benefit from fresh, up-to-date threat intelligence. To learn more about CrowdSec #Blocklists and how to integrate them with your Sophos #Firewall, watch our full video guide here: www.youtube.com/watch?v=lmqz...
CrowdSec + Suricata: do you actually need both for Linux servers? 🤔 They both detect threats, but they solve different problems. We break down where each fits, when to use them together, and why enforcement matters more than simply collecting alerts. 👉 Read more: www.crowdsec.net/blog/crowdse...
How does the attack activity affect your stack? Attack Surge helps you spot major changes, then jump into the underlying alerts to understand what’s driving the spike. Explore it in CrowdSec → docs.crowdsec.net/u/console/se... #cybersecurity #threatdetection #securityoperations
Keep your security stack in good shape🛡️ With CrowdSec Stack Health, you can: - See what needs attention - Understand what’s wrong - Get clear guidance on how to fix it - Get your stack back to good health Check it out 👉 doc.crowdsec.net/u/console/st...
🚨 This week’s Threat Alert covers CVE-2025-4427, an Ivanti EPMM authentication bypass that can lead to unauthenticated RCE when chained with CVE-2025-4428. CrowdSec has observed 865 unique IPs matching the exploitation pattern since May 2025. Read more: www.crowdsec.net/vulntracking...
Ivanti EPMM CVE-2025-4427: Authentication Bypass
CVE-2025-4427 is a medium-severity Ivanti EPMM authentication bypass. CrowdSec observed 3,978 exploitation signals across 89 days.
crowdsec.net
We’ve published a deeper look at the supply chain attack that affected CrowdSec. In this article, our CEO Philippe Humeau shares an honest account of what happened, how we investigated the incident, what we found, and what we’re doing differently as a result. www.crowdsec.net/blog/tanstac...
TanStack Supply Chain Attack Analysis
CrowdSec CEO Philippe Humeau shares the full story behind the 2026 supply chain attack, from the source code leak and forensic investigation to the lessons learned.
crowdsec.net
We’re sharing a transparent update about a source code exposure that occurred in May 2026. Our investigation found that no customer data or credentials were exposed. We’ve taken precautionary steps and continue to monitor the situation. Read our full statement: www.crowdsec.net/blog/crowdse...
CrowdSec Statement: Source Code Exposure in May 2026
CrowdSec update on a source code exposure that occurred in May 2026, including the scope, impact, investigation, and security measures taken.
crowdsec.net
Copy-pasting your CrowdSec question into an LLM? Sometimes you get the answer. Sometimes you get confidently assembled gibberish. 🤖 So we gave it a better map: the CrowdSec Skill. ✨ Get the details here: www.crowdsec.net/blog/ai-agen... Because “sounds right” is not quite the same as “works.” 😏
New in CrowdSec: Alerts Explorer. See how alerts break down across your stack, group activity by source IP, then use interactive facets to jump straight into what you want to investigate. Explore it → app.crowdsec.net/alerts-v2
🚨 This week’s Threat Alert covers CVE-2026-75650 (StyleSmuggler), a critical RCE affecting Adobe Commerce & Magento. Exploited before the patch, it escalated to mass scanning, with 500+ IPs observed. Read the full analysis and protection recommendations: www.crowdsec.net/vulntracking...
🤖 robots.txt: “Please don’t crawl my site.” Bots: “lol.” Thankfully, CrowdSec 1.8 brings self-hosted bot protection: proof-of-work + browser fingerprinting to separate real browsers from scripts wearing browser costumes. Learn more 👉 www.crowdsec.net/blog/nginx-b...
🚨 In this week’s newsletter, we cover CVE-2023-54391, a critical authentication bypass affecting Proxmox VE that is seeing exploitation attempts. Read the full analysis and protect your systems 👉 www.crowdsec.net/vulntracking...
You find an unfamiliar IP in your logs. The IP alone tells you very little. The useful part is the context behind it: reputation, behavior and observed attack activity. See an IP you don't recognize? Look it up with IPDEX. 👉 ipdex.crowdsec.net #ThreatIntel #CyberSecurity #SecOps
CrowdSec 1.8 is here 🚀 🤖 Bot Detection for CrowdSec WAF ☸️ Dedicated Kubernetes datasource ⚡ Major LAPI ↔ bouncer performance improvements 🔎 Revamped Console alerts experience 🧠 Expanded CrowdSec Skill for LLMs 👇 www.crowdsec.net/blog/crowdse... #CrowdSec #CyberSecurity #OpenSource
🚨 In this week’s newsletter, we cover CVE-2026-33497, a high-severity path traversal vulnerability affecting Langflow that is seeing active exploitation. Read the full analysis and protect your systems 👉 www.crowdsec.net/vulntracking...
A compromised device can become infrastructure for the next attack. Evooo1Bot is a recent example, turning compromised edge devices into infrastructure for further malicious activity. A reminder of why recent observed behavior matters for IP reputation. 👉 www.crowdsec.net/blocklists
🚨 In this week’s newsletter, we cover CVE-2024-12847, a critical RCE vulnerability affecting NETGEAR DGN1000 routers that has become the most-attacked flaw tracked by the CrowdSec Network. Read the full analysis and protect your systems 👉 www.crowdsec.net/vulntracking...
Your AI agent is smart. But does it actually know how your software works? 🤖 We built a CrowdSec Skill to replace plausible guesses with product-specific procedures, guardrails, and verification. It even helped us find gaps in our own docs. Read the story 👇 www.crowdsec.net/blog/ai-agen...
🚨 In this week’s newsletter, we cover CVE-2026-2652, an authentication bypass vulnerability affecting MLflow that is seeing active exploitation. Read the full analysis and protect your systems 👉 www.crowdsec.net/vulntracking...
Traefik routes traffic. A WAF inspects it. Learn how to add an open-source WAF to Traefik with CrowdSec for virtual patching and real-time protection—without changing your architecture. 👇 www.crowdsec.net/blog/waf-tra... #Traefik #WAF #CyberSecurity #OpenSource