756 Followers
14 Following
554 Posts
Improving Security Together
Websitehttps://www.first.org
πŸ”οΈπŸŒž Denver is warming up… and so is the registration deadline. Standard registration closes April 30, before rates climb higher than Mile High. Grab your badge, mark your trail, and meet us out West. #FIRSTCON26 πŸ”—https://go.first.org/zBBwJ
Registration Options / 38th Annual FIRST Conference

38th Annual FIRST Conference - Denver (US), June 14-19, 2026.

FIRST β€” Forum of Incident Response and Security Teams
πŸ€ πŸ”οΈ Last call on the frontier!
Headin’ to Denver for #FIRSTCON26? Book your hotel by Friday, May 15th, 2026, to snag the discounted rateβ€”miss that deadline and the deal rides off into the sunset. Don’t get caught without a bunk. Saddle up and book now! πŸ¨βœ¨πŸ”— https://go.first.org/55i80
Conference Venue and Accommodations / 38th Annual FIRST Conference

38th Annual FIRST Conference - Denver (US), June 14-19, 2026.

FIRST β€” Forum of Incident Response and Security Teams

πŸŽ‰ #FIRSTCTI26 is officially a wrap, and it's the people who made it. Three days of workshops, plenary sessions, and hands-on training across the CTI landscape in Munich, Germany.

Sessions were led by practitioners and researchers from Google, AWS, the European Commission CSOC, ENISA, CIRCL, CERT-In, Intel 471, BlackRock, Deloitte, NTT DATA, Expel, and dozens more.

Highlights:
βœ… From Signal to Action was the dominant theme β€” practitioners tackled the gap between data and defensive action, building CTI pipelines under resource constraints and automating enrichment to cut through noise
βœ… AI took center stage as a double-edged force β€” sessions explored how LLMs and RAG architectures can multiply analyst capacity, while also confronting poisoned OSINT, compromised pipelines, and adversarial manipulation of AI-assisted analysis
βœ… New capabilities and partnerships were announced: Silobreaker unveiled agentic AI to speed up analyst research; CTM360 launched its AI-powered external CTEM platform; and Venation announced a partnership with UK-based POKKIT to deliver plain-English and Dutch cyber resilience guidance to smaller EMEA organizations

TLP:CLEAR sessions were live-streamed and are available now on FIRST's YouTube Channel.

A huge thank you to everyone who attended, presented, sponsored, and supported this event.

See you at the next one!

πŸ“– Read more: https://go.first.org/zqJyk

#CyberDefense #cybersecurity #infosec

FIRST Concludes Sold-Out 2026 Cyber Threat Intelligence Conference in Munich

Global practitioners gathered to advance AI-driven CTI, detection engineering, and threat intelligence standards

FIRST β€” Forum of Incident Response and Security Teams

The CVE funding disruption exposed a single point of failure in the infrastructure that underpins global vulnerability management. In this Help Net Security interview, ENISA's Nuno Rodrigues Carvalho, #VulnCon26 speaker, breaks down what needs to change.

πŸ“– Read more: https://go.first.org/bSrxK

#CyberDefense #cybersecurity #CVE

Coordinated vulnerability disclosure is now an EU obligation, but cultural change takes time - Help Net Security

ENISA's Nuno Carvalho on CVE program risks, EU regulatory enforcement, and building a distributed vulnerability disclosure ecosystem.

Help Net Security
Servus from #FIRSTCTI26! πŸ₯¨
Day 2 is live with top‑notch Cyber Threat Intelligence. Our #TLPCLEAR sessions are streamed on YouTube - no Lederhosen required πŸ˜‰
πŸ‘‰ https://www.youtube.com/watch?v=DMAqEP2Kqgs
#CTI #InfoSec
FIRST

9 likes. "2026 FIRST CTI Conference - Day 2 Plenary Sessions - Live Stream"

YouTube
Day 3 begins with gratitude for this community and the work happening here in Munich. One more day of insights, connection, and shared purpose. 🀝 #FIRSTCTI26 #cyberthreatintelligence #threatintel πŸ”—https://go.first.org/1OpsO
2026 Cyber Threat Intelligence Conference | #FIRSTCTI26

FIRST β€” Forum of Incident Response and Security Teams

New on the FIRST blog: Jenn Gile, Co-Founder of OpenSourceMalware and #VulnCon26 speaker, on why malicious open source packages don't fit the traditional vulnerability intelligence model.

The response motion looks familiar. A malicious package appears in a public registry, a record lands in OSV, tools fire an alert, and someone opens a ticket. But the data and the playbook don't actually match the threat.

πŸ” Vulnerabilities are passive. They wait to be exploited.
⚑ Malicious packages are active. They execute on install.
πŸ”§ Vulnerabilities have a fixed version.
🚫 Malicious packages ARE the latest version.

That mismatch leaves three investigative gaps vulnerability databases weren't built to fill:

πŸ“¦ Payload: what the malware did and which files were affected.
πŸ‘€ Threat actor: C2 infrastructure and accounts reused across campaigns.
πŸ”— Campaign: how one package connects to broader activity.

Case in point: the axios account takeover on March 30, 2026. OSV surfaces three IOCs. The campaign has at least nine, two of them shared with other malicious assets.

Jenn's argument: malicious packages need their own intelligence track, built around a different set of questions.

πŸ“– Read more: https://go.first.org/BwFfv

#cybersecurity #infosec #VulnerabilityManagement

Malicious Packages Don't Fit the Vulnerability Intelligence Model

Malicious open source packages and software vulnerabilities may look alike on the surface, but they demand entirely different response playbooks. Treating a malicious npm or PyPI package like a CVE leaves critical questions unanswered: what did it execute, where did it phone home, and what campaign is it part of? Purpose-built malicious package intelligence infrastructure is needed to answer those questions.

FIRST β€” Forum of Incident Response and Security Teams
Guten Morgen from Munich! β˜•
#FIRSTCTI26 is LIVE and #CyberThreatIntelligence is flowing!
πŸ”πŸ’₯ Jump into the TLP:CLEAR sessions streaming right now on YouTube:
πŸ‘‰ https://www.youtube.com/watch?v=-9GbyvoktXc
Prost to great CTI! 🍻
#FIRSTCTI26 #CyberThreatIntelligence #CTI #Infosec #Munich
2026 FIRST CTI Conference - Day 1 Plenary Sessions - Live Stream

YouTube
Day 2 begins with the same energy and curiosity that makes this CTI community so strong. Looking forward to another full day of shared insights and meaningful dialogue. 🀝✨ #FIRSTCTI26 #cyberthreatintelligence #threatintel πŸ”—https://go.first.org/1OpsO
2026 Cyber Threat Intelligence Conference | #FIRSTCTI26

FIRST β€” Forum of Incident Response and Security Teams
Day 1 of the FIRST Cyber Threat Intelligence Conference is officially underway here in #Munich. We’re kicking off three days of insights, collaboration, and forward‑thinking discussions shaping the future of CTI. πŸ›‘οΈβœ¨ #FIRSTCTI26 #cyberthreatintelligence #threatintel πŸ”—https://go.first.org/1OpsO
2026 Cyber Threat Intelligence Conference | #FIRSTCTI26

FIRST β€” Forum of Incident Response and Security Teams