CrowdSec

@crowdsec.bsky.social

Account run by Alpacas CrowdSec is a CTI tool leveraging crowdsourced data to identify and block malevolent IPs in real time, worldwide. Join our Discord: http://discord.gg/crowdsec

Not all #bots look like bots. 🤖 Modern bots can run real browsers, use residential IPs, and mimic legitimate traffic. CrowdSec’s #WAF Bot Detection uses fingerprinting + proof of work to identify them and stop scraping, scalping, and aggressive automation. See how it works 👇

🚨 CVE-2026-85706 is a critical GitLab file-read vulnerability already being exploited in the wild. CrowdSec has tracked 1,022 unique IPs sending matching requests since September 11. Read the Threat Alert article to get the analysis 👉 www.crowdsec.net/vulntracking...

CVE-2026-85706: Upgrading GitLab Won't Save Leaked Secrets

Active exploitation of CVE-2026-85706 (CVSS 10.0) exposes GitLab secrets. Upgrading blocks new requests, but exposed credentials must be rotated immediately.

crowdsec.net

🚨 This week’s Threat Alert covers CVE-2025-4427, an Ivanti EPMM authentication bypass that can lead to unauthenticated RCE when chained with CVE-2025-4428. CrowdSec has observed 865 unique IPs matching the exploitation pattern since May 2025. Read more: www.crowdsec.net/vulntracking...

Ivanti EPMM CVE-2025-4427: Authentication Bypass

CVE-2025-4427 is a medium-severity Ivanti EPMM authentication bypass. CrowdSec observed 3,978 exploitation signals across 89 days.

crowdsec.net

We’ve published a deeper look at the supply chain attack that affected CrowdSec. In this article, our CEO Philippe Humeau shares an honest account of what happened, how we investigated the incident, what we found, and what we’re doing differently as a result. www.crowdsec.net/blog/tanstac...

TanStack Supply Chain Attack Analysis

CrowdSec CEO Philippe Humeau shares the full story behind the 2026 supply chain attack, from the source code leak and forensic investigation to the lessons learned.

crowdsec.net

We’re sharing a transparent update about a source code exposure that occurred in May 2026. Our investigation found that no customer data or credentials were exposed. We’ve taken precautionary steps and continue to monitor the situation. Read our full statement: www.crowdsec.net/blog/crowdse...

CrowdSec Statement: Source Code Exposure in May 2026

CrowdSec update on a source code exposure that occurred in May 2026, including the scope, impact, investigation, and security measures taken.

crowdsec.net