Filter
Exclude
Time range
-
Near
Dr.Kashif Saleem retweeted
Pakistan's #NationalCERT (PKCERT) is now a Full Member of @FIRSTdotOrg (Forum of Incident Response and Security Teams), joining its growing global CSIRT network. It has strengthened Pakistanโ€™s regional and international cyber incident response collaboration.
3
11
403
See you at #FIRSTCON26 in Denver. We're looking forward to connecting with incident response professionals from around the world and exchanging perspectives on threat intelligence, DNS abuse mitigation, and Internet security. Request a meeting: join.whoisxmlapi.com/upcominโ€ฆ @FIRSTdotOrg #FIRSTConference #ThreatIntelligence #DNS #InternetSecurity
28
Jorge Gibbs retweeted
๐ŸŽค Step onto the stage at #FIRSTMX26 ๐Ÿ”—go.first.org/jv1Xh Weโ€™re looking for speakers to share practical insights, lessons learned, and emerging challenges in cybersecurity. Be part of a truly global program.
2
4
227
Heading to Denver for #FIRSTCON26 next week? Stop by the @Volexity booth to see a demo of Volcano! Weโ€™ll show you how memory analysis with Volcano uncovers advanced threat actors and helps rapidly resolve your investigations. Come find us at Booth 7 to talk threat hunting and triage workflows with our team, including @stevenadair & @attrc! @FIRSTdotOrg #DFIR #FIRSTCON
4
5
4,556
๐Ÿšจ Responsible Disclosure Notice โ€” AI-Assisted Cloud Notebook & Infrastructure Security Observations During controlled digital forensic analysis involving AI-assisted notebook environments, cloud orchestration layers, and model-integrated workflows, multiple security observations were identified relating to context isolation, credential exposure risks, unsafe execution pathways, and sensitive operational data handling. The assessment documented recurring patterns associated with: โ€ข Weak separation between user-controlled and privileged execution contexts โ€ข Cross-context data leakage risks โ€ข Access token and API credential exposure surfaces โ€ข Unsafe orchestration chaining and notebook execution behavior โ€ข Insufficient deterministic isolation in AI-connected workflows The review included notebook-style AI tooling, Jupyter-derived systems, cloud-shell infrastructure, LLM-assisted orchestration layers, and integrated development workflows. Key concerns include: Prompt-context contamination Privilege ambiguity Dynamic execution memory risks Session-linked operational exposure External API orchestration vulnerabilities These observations may have implications under: โ€ข Saudi PDPL โ€ข Privacy-by-Design principles โ€ข Zero Trust Architecture โ€ข AI governance & cloud security frameworks Recommended mitigation areas include: โœ” Deterministic privilege isolation โœ” Hardened IAM boundaries โœ” Cryptographic provenance tracking โœ” Auditable model-action logging โœ” Improved instruction/context segregation โœ” Secure-by-Design AI infrastructure controls Relevant forensic artifacts were preserved using: SHA-256 integrity validation Timestamped archival procedures Chain-of-custody documentation Controlled evidence storage practices This disclosure is submitted in good faith for coordinated remediation, defensive security improvement, and infrastructure hardening purposes. As AI systems become increasingly integrated into critical infrastructure and national operational environments, security assurances must evolve toward verifiable isolation, deterministic governance, and auditable trust boundaries. @Google @GoogleCloud @GoogleDeepMind @GeminiApp @NotebookLM @GoogleDevelopers @Android @GooglePlay @GoogleAI @GoogleWorkspace @GoogleSecurity @OpenAI @OWASPFoundation @CISAgov @FIRSTdotOrg #CyberSecurity #AISecurity #ResponsibleDisclosure #DigitalForensics #NotebookLM #Jupyter #CloudSecurity #PDPL #ZeroTrust #AIInfrastructure #BugBounty #PrivacyByDesign
1
7
7
2,528
๐Ÿ“ข ๐ˆ๐ง๐ญ๐ซ๐จ๐๐ฎ๐œ๐ข๐ง๐  ๐ญ๐ก๐ž ๐“๐ˆ๐…๐‚๐„ ๐–๐จ๐ซ๐ค๐›๐จ๐จ๐ค ๐Ÿ๐จ๐ซ ๐Œ๐ข๐œ๐ซ๐จ๐ฌ๐จ๐Ÿ๐ญ ๐’๐ž๐ง๐ญ๐ข๐ง๐ž๐ฅ! Everyone who knows me knows how passionate I am about the ๐‚๐ฒ๐›๐ž๐ซ ๐“๐ก๐ซ๐ž๐š๐ญ ๐ˆ๐ง๐ญ๐ž๐ฅ๐ฅ๐ข๐ ๐ž๐ง๐œ๐ž (๐‚๐“๐ˆ) discipline. Back in early 2020, just before the pandemic outbreak, I had the opportunity to travel to Luxembourg for hands-on training on the @MISPProject and later on, attend two @FIRSTdotOrg CTI events in Berlin. Since then, Iโ€™ve been fortunate to work on many CTI initiatives, especially during my tenure at Alpha Bank, where my team pioneered in this area within the FSI sector. Over the years, the CTI discipline has significantly matured. With that evolution came frameworks, operational requirements, and the growing challenge of managing multiple intelligence feeds - many of which may not be relevant, actionable, or current enough to effectively protect an organization. Inspired by the TIFCE framework introduced by Sergio Albea, I built the ๐“๐ˆ๐…๐‚๐„ ๐–๐จ๐ซ๐ค๐›๐จ๐จ๐ค ๐Ÿ๐จ๐ซ ๐Œ๐ข๐œ๐ซ๐จ๐ฌ๐จ๐Ÿ๐ญ ๐’๐ž๐ง๐ญ๐ข๐ง๐ž๐ฅ. ๐Ÿ”— github.com/cyb3rmik3/KQL-thrโ€ฆ The workbook evaluates the four key pillars of the TIFCE framework: โœ… Which feeds provide unique intelligence? โœ… Which feeds are truly relevant to your environment? โœ… Which feeds correlate with confirmed malicious activity? โœ… Which feeds are fresh and actively maintained? If you are using ๐Œ๐ข๐œ๐ซ๐จ๐ฌ๐จ๐Ÿ๐ญ ๐’๐ž๐ง๐ญ๐ข๐ง๐ž๐ฅ and the ๐ƒ๐ž๐Ÿ๐ž๐ง๐๐ž๐ซ ๐—๐ƒ๐‘ stack together with multiple ๐“๐ก๐ซ๐ž๐š๐ญ ๐ˆ๐ง๐ญ๐ž๐ฅ๐ฅ๐ข๐ ๐ž๐ง๐œ๐ž feeds (MDTI, MISP etc), I encourage you to test the workbook and review the findings. Feedback and contributions are always welcome - feel free to open an Issue or submit a PR with enhancements and ideas. I know already that more visuals and some tabs with more info are needed. A huge thank you to my comrade Marios for his contributions, and to MVP brothers Sergio Albea, @BertJanCyber, and Uros Babic for their valuable preview feedback. #MicrosoftSecurity #MicrosoftSentinel #UnifiedSecOps #ThreatIntelligence #CyberThreatIntelligence #KQL #KustoQueryLanguage

3
10
43
3,260
Lโ€™ANC a organisรฉ du 18 au 20 mai une "Formation avancรฉe en Investigation Numรฉrique et Analyse Forensique Windows & Linux" en collaboration avec le @FIRSTdotOrg et le @MENIDjib.โ€จ #Cybersรฉcuritรฉ #Djibouti #DJCERT #FIRST #MDENI #ANC
2
1
4
88
New on the FIRST blog: โ€œPeak Incident Responseโ€ Read the recap from the 2026 FIRST TC hosted by CH-CERTs during #GenevaCyberWeek at:first.org/blog/20260518-Peakโ€ฆ #FIRSTdotOrg #IncidentResponse #CyberSecurity
1
1
279
Speaking to Infosecurity after VulnCon26, the CEO of @FIRSTdotOrg, discussed how AI changes how security flaws are discovered & weaponized, organizations are dealing with an unprecedented surge in vulnerabilities: infosecurity-magazine.com/inโ€ฆ
1
1
1
1,081
Pleased to meet Chris Gibson, Director of @FIRSTdotOrg, an @ITU-D Sector Member, and thank him for delivering the Cyber OSPA award recognising the @ITUโ€“@GIZ_gmbh #HerCyberTracks Initiative to @ITU HQ. I am proud to receive this recognition on behalf of @ITU and our partners, mentors, and participants as we continue to advance womenโ€™s participation in cybersecurity and ensure trust and confidence in the use of Information Communication Technologies (ICTs).
1
8
271
TeamT5 is heading to #FIRSTCON26! Born in Asia , we specialize in APT & ransomware threats across APAC, delivering local and actionable threat intelligence through ThreatVision. Letโ€™s connect and talk about intelligence-driven cyber defense. ๐Ÿš€ @FIRSTdotOrg #ThreatIntelligence #CyberSecurity #APAC #TeamT5
1
10
382
New on the @FIRSTdotOrg blog: Jonathan Andersen, CEO and Co-Founder of @webscout_io and #FIRSTCTI26 speaker, on residential proxy networks, the threat enabler hiding in critical infrastructure. A timely read alongside FIRST's NETSEC SIG. go.first.org/mfx3c #infosec
3
5
666
I will be at @FIRSTdotOrg CTI event with my colleague Janosch to give a workshop around DFIR in cloud, using cloud and more cloud (no open seats :-/). We will cover a bunch of our OpenSource tools, including @TimesketchProj and OpenRelik. Reach out if you want to have a chat.
2
84
That's a wrap on CVE/@FIRSTdotOrg #VulnCon26 & Annual CNA Summit! 500 attendees, sessions from @CISAgov, @enisa_eu, @NIST, and more, key CVE program updates new product launches. Thank you to everyone who made it possible! Read: go.first.org/WabqC #cybersecurity
2
5
758