Andras Iklody

@iglocska@infosec.exchange
501 Followers
192 Following
79 Posts
Caffeinated MISP lead dev (he/his)

Our colleague righelx did a first version of a nmap nse script to properly guess the version of SharePoint. It's still in development but it might already useful for some of you.

And maybe Microsoft is listening, to improve the mapping of CPE with their vulnerability publication...

#sharepoint #microsoft #scanning #cybersecurity

🔗 https://github.com/righel/ms-sharepoint-version-nse

GitHub - righel/ms-sharepoint-version-nse: Nmap script to detect a Microsoft SharePoint instance version.

Nmap script to detect a Microsoft SharePoint instance version. - GitHub - righel/ms-sharepoint-version-nse: Nmap script to detect a Microsoft SharePoint instance version.

GitHub

Curious about all the open source and projects developed by @circl ?

CIRCL Open Source tools powering SOC & CSIRT teams.

#opensource #cybersecurity #soc #csirt #threatintel #threatintelligence

🔗 https://hdoc.cnw.circl.lu/JJKFoeHrS9Wf28L4tAyCNg?view#

Today at the @firstdotorg conference, we’re presenting Draugnet, an open-source, lightweight submission tool designed to make sharing cyber threat intelligence easier.

With @treyka @iglocska

@misp

🔗 https://github.com/draugnet/draugnet

#misp #threatintel #anonymity #informationsharing #cybersecurity

GitHub - draugnet/draugnet

Contribute to draugnet/draugnet development by creating an account on GitHub.

GitHub
@jtk Yep, I personally cancelled a trip to the US for the same reason. Now the question is for the @firstdotorg conference in 2026 ? I assume the administration won’t change in the mean time.

I hope Wikipedia has a backup plan for their foundation. If a prosecutor wants to get rid of your Tax-Exempt Status. The next step might be the dissolution…

@wikimediafoundation

#wikipedia #wikimedia #us #freedom

🔗 https://www.thefp.com/p/trump-prosecutor-threatens-wikipedia

Exclusive: Trump’s D.C. Prosecutor Threatens Wikipedia’s Tax-Exempt Status

In a letter obtained by The Free Press, Trump appointee Ed Martin accuses the Wikimedia Foundation of violating the law. Critics say he's ‘grandstanding.’

The Free Press

Just a reminder: Vulnerability Lookup isn’t just about finding CVEs. It supports the full chain, collection from multiple sources, continuous distribution, and allocation within a coordinated vulnerability disclosure (CVD) process. 100% open source.

🔗 An online version maintained by @circl https://vulnerability.circl.lu/

🔗 https://www.vulnerability-lookup.org/

🔗 https://github.com/vulnerability-lookup/vulnerability-lookup

#opensource #cve #vulnerability #cna #cvd #cybersecurity

Vulnerability-Lookup

Vulnerability-Lookup - Fast vulnerability lookup correlation from different sources.

MISP v2.4.206 and v2.5.8 introduces new workflow modules, enhanced object relationship management and significant improvements to the event synchronisation mechanism. Key highlights include improved a reworked attribute search functionality, better handling of event reports, and various security fixes. Additionally, numerous optimizations and bug fixes enhance stability and performance.

#opensource #threatintel #misp

🔗 Release notes https://www.misp-project.org/2025/03/19/MISP.2.5.8.and.2.4.206.released.html/

MISP v2.4.206 and v2.5.8 Released - new workflow modules, improved graph object relationship management and many other improvements

MISP Threat Intelligence & Sharing

MISP Open Source Threat Intelligence Platform & Open Standards For Threat Information Sharing
GitHub - MISP/misp-docker: A production ready Dockered MISP

A production ready Dockered MISP. Contribute to MISP/misp-docker development by creating an account on GitHub.

GitHub

So, we know that X has been abusing its algorithms to push far-right content for years. The DSA procedure started in 2023, and now we’re seeing fascist content being amplified during the German elections…

We have a fundamental problem in enforcing regulations, and it's working against us.

#fascist #europe #dsa #germany

🚀 New Kunai Patch Release! 🔥

This update brings important fixes:
✅ Fix probe tripping the eBPF verifier affecting Linux v5 (only on AArch64)
✅ Improved compatibility with kernels ≥ 6.11

🔗 check it out: https://github.com/kunai-project/kunai/releases/tag/v0.5.4

#opensource #linux #threathunting #dfir

Release v0.5.4 · kunai-project/kunai

What's Changed fix(test): missing /dev/urandom by @qjerome in #175 feat: print all in replay command by @qjerome in #180 fix: aarch64 verifier kicking by @qjerome in #181 add(ci): aarch64 test cas...

GitHub
×

This 2-day physical Hackathon, held in Luxembourg on April 8th and 9th, 2025, focuses on the development of free and open-source software for cybersecurity. We aim to convene diverse developer groups to collaborate on complex programming challenges within key cybersecurity areas, such as information sharing, threat intelligence, network and system forensics, data mining, network and computer exploitation, and defense techniques.

Don’t hesitate to join us. We are open to any ideas or proposals.

@circl @misp @kunai_project @suricata @vulnerability_lookup @ail_project

https://hackathon.lu/

#hackathon #opensource #cybersecurity #threatintel #luxembourg

@adulau @circl @misp @kunai_project @suricata @vulnerability_lookup@social.circl.lu @ail_project It's physical right? We could collaborate bringing it to the attention of our Hackathon participants https://os-sci.com/event/foss-fest-2025-international-hackathon-14/register
Foss FEST 2025: International Hackathon

OpenSource Science B.V.
@adulau @circl @misp @kunai_project @suricata @vulnerability_lookup @ail_project What will be the language people use at this event? Asking for a me who has deep scars from being in Luxembourg for work 😊
@joost @adulau @circl @misp @suricata @vulnerability_lookup @ail_project english for general social interactions and/or any of (luxembourgish, german, french) depending on your interlocutor. For programming language it depends on the project you want to work on 😜
@joost English will be the primary language, but participants are welcome to use additional languages based on their preferences during interactions. I’ll update the website, it’s indeed an important point.