CrowdSec's Avatar

CrowdSec

@crowdsec

Account run by Alpacas CrowdSec is a CTI tool leveraging crowdsourced data to identify and block malevolent IPs in real time, worldwide. Join our Discord: http://discord.gg/crowdsec

221
Followers
8
Following
261
Posts
12.09.2023
Joined
Posts Following

Latest posts by CrowdSec @crowdsec

Post image

πŸš€πŸŽ‰ Big news: CrowdSec Blocklists are now available on the Amazon Web Services (AWS) Marketplace!

Learn more: aws.amazon.com/marketplace/...

13.03.2026 14:36 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

New CVE? We immediately analyze exploitability, validate impact, and ship patches or virtual protections fast to shrink the exposure window.Β 

Watch the full video to learn more πŸ‘‰ youtube.com/live/oedE1_y...

#WAF #virtualpatching #CVE #cybersecurity

12.03.2026 08:35 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image Post image Post image Post image

Thousands of CVEs. But which ones are actually being exploited right now?

Live Exploit Tracker cuts through the noise by showing vulnerabilities that attackers are actively exploiting in the wild, based on real attacks observed across 1000s production systems.

πŸ‘‰ www.crowdsec.net/live-exploit...

11.03.2026 11:17 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

What if your logs already show signs of a targeted attack, but the pattern is easy to miss? πŸ”Ž

Am I Under Attack analyzes alert activity with AI to identify suspicious surges and notify you when your infrastructure may be under threat. 🚨

Read more: www.crowdsec.net/blog/am-i-un...

10.03.2026 09:23 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
CVE-2025-20281: Cisco ISE Critical RCE Under Active Exploitation CVE-2025-20281 is a critical CVSS 10.0 RCE vulnerability in Cisco Identity Services Engine (ISE). CrowdSec observes a new surge of exploitation attempts targeting exposed REST APIs

🚨 In this week’s threat alert, we dive into CVE-2025-20281, a critical Cisco Identity Services Engine (ISE) RCE vulnerability, as CrowdSec Threat Intelligence observes a new wave of exploitation attempts.

Read the full article πŸ‘‰ www.crowdsec.net/vulntracking...

09.03.2026 13:59 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
FLOSS Weekly Episode 865: Multiplayer Firewall This week Jonathan chats with Philippe Humeau about Crowdsec! That company created a Web Application Firewall as on Open Source project, and now runs it as a Multiplayer Firewall. What does that me…

Check out #hackaday’s latest #FLOSS weekly episode featuring our CEO Philippe Humeau.

In this episode, Jonathan Bennett chats with Philippe about CrowdSec and how we created an open source Web Application Firewall that runs as a Multiplayer Firewall.

hackaday.com/2026/03/04/f...

06.03.2026 12:01 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

A vulnerability is a weakness.
A threat is who can exploit it.
Risk is the likelihood Γ— impact.

Confusing them leads to bad prioritization & preventable incidents.

We break down the vulnerability lifecycle & its implications for developers & maintainers.

Read nowπŸ‘‰ www.crowdsec.net/blog/vulnera...

05.03.2026 09:06 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

The Community Blocklist blocks a lot. But the Threat Forecast Blocklist goes further:

πŸ“Š ~50% more attackers blocked
πŸ“Š 1:40 prevention ratio
πŸ“Š Built from your own attack patterns

Available for the CrowdSec Console Premium plan.

Learn more πŸ‘‰ www.crowdsec.net/blog/threat-...

04.03.2026 10:52 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

πŸ›‘Β Stop known attackers before they reach your network.

Here’s how to plugπŸ”ŒΒ  CrowdSec’s IP endpoint into Sophos Firewall and instantly benefit from global threat intelligence.

Watch the full video here: youtu.be/lmqzFpHpYyw?...Β Β 

#blocklists #ipfeeds #cybersecurity #firewall #sophos

03.03.2026 13:51 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

🚨 This week’s CrowdSec Threat Alert: CVE-2026-21859, a critical SSRF vulnerability in Mailpit, is being actively exploited to map internal networks and access sensitive infrastructure.

See more in our latest article πŸ‘‰ www.crowdsec.net/vulntracking...

02.03.2026 12:36 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Community Office Hours: Open Source HAProxy-Native Security
Community Office Hours: Open Source HAProxy-Native Security YouTube video by CrowdSec

Missed our Community Office Hours? No worries, the replay is ready! πŸŽ₯

Yesterday, we took a deep dive into Stack Health and shared real-world insights straight from production deployments.

Catch the replay here πŸ‘‰ youtu.be/knoVkVg-8Ds

27.02.2026 13:44 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Writing WAF rules shouldn’t feel like decoding ancient YAML scrolls πŸ“œ

So we built a Model Context Protocol (MCP) for CrowdSec that lets your favorite LLM generate production-ready WAF rules, with validation and feedback loops built in πŸ€–

Learn more and get started πŸ‘‰ www.crowdsec.net/blog/crowdse...

25.02.2026 09:10 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

πŸ’­ Did you know? ⟢ CrowdSec’s Live Exploit Tracker monitors 650+ CVEs actively exploited in the wild, more than half of all publicly known exploited vulnerabilities.

Learn more about the CrowdSec Live Exploit Tracker: www.crowdsec.net/live-exploit...

24.02.2026 09:51 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

🩺The Stack Health feature in the CrowdSec Console is a monitoring tool designed to help you maintain your infrastructure’s operational status and ensure it’s properly configured.

Want to learn more? Join our next #COH on February 26th at 5 PM CET.

Join here: www.youtube.com/watch?v=oedE...

20.02.2026 10:04 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Myth: CVSS scores tell the whole story

A CVSS score reflects theoretical severity, not your organization’s actual risk.

A number alone isn’t enough. Real risk depends on context.

πŸ‘‰ Discover the other common vulnerability myths: www.crowdsec.net/blog/5-commo...

19.02.2026 14:30 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Here at CrowdSec, we split intelligence into 2 layers πŸ‘‡

πŸ”Ž CTI gives you context.
πŸ›‘ TTI enforces.

Read our article to learn more about how CTI + TTI built on production telemetry changes the game: www.crowdsec.net/blog/honeypo...

18.02.2026 13:01 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

πŸ—“οΈ Save the date for this month’s Community Office Hours: Feb 26 at 5 PM CET

Join us for a focused session on CrowdSec Stack Health.

πŸ‘‰ Get all the details here: www.youtube.com/watch?v=oedE...

17.02.2026 13:44 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Dify Under Attack: Unfixed CVE-2025-56520 Exploited in the Wild CVE-2025-56520 is actively exploited in Dify, exposing AI platforms to SSRF-driven reconnaissance, internal scanning, and potential credential theft.

🚨 This week’s CrowdSec Threat Alert: CVE-2025-56520, an actively exploited SSRF vulnerability in Dify, is enabling reconnaissance and internal network probing across exposed AI platforms.

Learn more πŸ‘‰ www.crowdsec.net/vulntracking...

16.02.2026 14:17 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
CrowdSec Suricata Integration with Thibault Koechlin
CrowdSec Suricata Integration with Thibault Koechlin YouTube video by OISF-Suricata

πŸŽ₯ Missed our webinar with #Suricata? The replay is live!

CrowdSec CTO Thibault Koechlin breaks down the CrowdSec + Suricata integration, from parsing logs to blocking malicious IPs, with a live demo to show it in action.

πŸ‘‰ Watch now: www.youtube.com/watch?v=af_K...

13.02.2026 09:42 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Web applications are a prime target for attackers, and the threat is only growing.Β 

But what if you could block over 75% of malicious traffic before it even reaches your server, with just a few commands?Β 

Learn more πŸ‘‰ www.crowdsec.net/blog/strengt...

12.02.2026 07:39 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Europe gets a boost in vulnerability intelligence! πŸš€

db.gcve.eu is now live, an open, European-operated advisory database. CrowdSec complements it with real-world exploit data via our Live Exploit Tracker.

Defenders deserve actionable signals, not just scores.

πŸ‘‰ www.crowdsec.net/blog/crowdse...

11.02.2026 09:00 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

CrowdSec TCP protection helps MSPs & hosters stop mass attacks automatically, using shared threat intelligence, not manual rules.

Watch the full video here to learn more: www.youtube.com/watch?v=knoV...

10.02.2026 09:38 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
CVE-2026-1281 in Ivanti EPMM: Confirmed In-the-Wild Exploitation CVE-2026-1281 is an actively exploited RCE vulnerability in Ivanti EPMM. Learn how to detect, mitigate, and protect your infrastructure.

🚨 This week’s CrowdSec Threat Alert: CVE-2026-1281, a pre-auth RCE in Ivanti EPMM, is actively exploited in the wild, putting Enterprise Mobile Management at risk worldwide.

Discover all the details in our latest article πŸ‘‰ www.crowdsec.net/vulntracking...

09.02.2026 12:46 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Install the CrowdSec WAF in Just 4 Minutes
Install the CrowdSec WAF in Just 4 Minutes YouTube video by CrowdSec

⏳Secure your web apps in just 4 minutes!

Follow this tutorial & unlock its full potential:

βœ… Traditional WAF protection enhanced with advanced CrowdSec behavioral detection
βœ… Effortless virtual patching
βœ… Full compatibility with your existing ModSecurity rules

πŸŽ₯ www.youtube.com/watch?v=LyNf...

06.02.2026 09:29 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

πŸŽ‰Introducing Live Exploit Tracker, the latest addition to CrowdSec’s security arsenal.

L.E.T. delivers ground-truth threat intelligence based on real attacks observed across hundreds of thousands of production systems worldwide.

Learn more & get started today β†’ www.crowdsec.net/blog/introdu...

05.02.2026 09:41 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

It’s been a minute since we last shined a light on CrowdSec Academy, so here’s your reminder πŸ‘‹

You can learn the fundamentals of cybersecurity and master CrowdSec’s open-source Security Engine, completely free.

πŸŽ“ Start learning now β†’ academy.crowdsec.net/home

04.02.2026 10:19 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

✨ The CrowdSec Console Premium free trial is now 30 days πŸ“…, giving you more time to evaluate advanced features in real conditions properly.

Learn more β†’ doc.crowdsec.net/u/console/pr...

03.02.2026 11:53 πŸ‘ 0 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

🚨 This week’s CrowdSec Threat Alert article highlights CVE-2025-68645 (LFI) and CVE-2022-27926 (XSS), actively exploited in the wild against Zimbra Collaboration servers.

Explore attack details, threat trends, and mitigation steps in the article πŸ‘‰ www.crowdsec.net/vulntracking...

02.02.2026 13:47 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

We’re proud to be included in the VulnCheck State of Exploitation 2026 report and recognized for CrowdSec’s growth as a leading source in first reporting KEVs throughout 2025.

Big thanks to @vulncheck.bsky.social for the recognition.

πŸ‘‰ Read the full article:
www.vulncheck.com/blog/state-o...

30.01.2026 09:39 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Open Source HAProxy-Native Security
Open Source HAProxy-Native Security YouTube video by CrowdSec

Watch the full Open Source HAProxy-Native Security webinar replay over on YouTube: youtu.be/knoVkVg-8Ds

Dive into SPOA, SPOE, and SPOP, how they fit into the traffic flow, and how CrowdSec collects signals and enforces decisions using HAProxy’s native integrations.

29.01.2026 10:26 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0