Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Alexandre Dulaunoy

@adulau@infosec.exchange
  • Open on infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff.

The other side is at @a@paperbay.org (photography, art and free software at large)

#infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

0 Followers
0 Following
50 Posts
Joined November 06, 2022
Website:
https://www.foo.be
GitHub:
https://github.com/adulau
Matrix:
@adulau:matrix.circl.lu
ORCID:
https://orcid.org/0000-0002-5437-4652
PGP FP:
6BB5 6353 1D99 F112 4C00 8C4F 815D 4786 1ECB 73D5
Other Mastodon:
https://paperbay.org/@a

Posts

Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · 3d ago
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
From a research paper to running open-source code in just a few days. We (with @cedric@fosstodon.org) have been experimenting in Vulnerability-Lookup with the concept of Local Exploit Hazard, based on the recent research paper “Modeling Local Exploit Hazard — A Bayesian Framework for Quantifying Exploit Risk and Operational Efficiency” by Stephen Shaffer and Laura Cristiana Voicu. The idea addresses an important question in vulnerability management: Not simply “How dangerous is this vulnerability globally?” but “How much exploitation risk does this vulnerability represent in my environment?” Instead of introducing yet another static vulnerability score, the model starts from exploit likelihood such as EPSS and combines it with local security controls, CVSS attack vectors, vulnerability age and KEV policy to estimate an exploitation hazard. We implemented an experimental version in Vulnerability-Lookup and connected it directly to operational workflows. For the full details: https://www.vulnerability-lookup.org/2026/08/11/local-exploit-hazard/ #cve #gcve #vulnerabilitymanagement #vulnerability #opensource #opendata @circl@social.circl.lu
0
1
0
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · 3d ago
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
Replying to @welch@fosstodon.org
@welch@fosstodon.org Cool. If you have any question about GCVE or/and vulnerability-lookup, feel free. @jbm@infosec.exchange @nyanbinary@infosec.exchange @jgamblin@infosec.exchange @todb@infosec.exchange
0
0
0
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · 5d ago
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
Pretty cool idea from @nyanbinary@infosec.exchange - a bot to analyse fucked up references from the CVE records. @fuckeduprefs_bot@infosec.exchange Maybe we could imagine an archive bot at the same time to ensure that the references don't get lost. Just like archive.org or similar. Maybe something for @gcve@social.circl.lu to look into. #cve #vulnerability #gcve
6
1
4
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Aug 04, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
Replying to @adulau@infosec.exchange
MISP Galaxy Threat Actor Explorer v1.0.0 released https://github.com/adulau/threat-actor-explorer #cti #cybersecurity #misp #threatintelligence #threatintel @misp@misp-community.org
GitHub

GitHub - adulau/threat-actor-explorer: A Threat-Actor explorer (browser-local) from the MISP galaxy

A Threat-Actor explorer (browser-local) from the MISP galaxy dataset - adulau/threat-actor-explorer

3
0
3
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Aug 03, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
A standalone, browser-only HTML/JavaScript application for exploring the MISP threat-actor galaxy, UUID-based relationships across every cluster in the MISP Galaxy repository, and shared MISP Galaxy metadata. Graph rendering is performed by Pivotick. Source code: https://github.com/adulau/threat-actor-explorer/ Online (in-browser): https://foo.be/threat-actor-explorer/misp-threat-actor-explorer.html Discussions and feedback: https://discourse.ossbase.org/t/playing-with-a-threat-actor-explorer-browser-local-from-the-misp-galaxy-dataset/1118 @misp@misp-community.org #misp #cti #threatintelligence #opensource #threatactor #cybersecurity
10
1
4
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Aug 03, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
Have you seen any evidence of the famous « collect encrypt data and decrypt later » in incident response ? Until now, I haven’t. #pqc #crypto #cryptography #dfir
0
0
0
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jul 30, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
A new version of the BCP-11 "Community Contribution Fragments for Existing CVE Records" proposal has been published. https://discourse.ossbase.org/t/gcve-bcp-11-community-proposed-updates-to-existing-cve-records/1110/8#p-1495-gcve-bcp-11-community-contribution-fragments-for-existing-cve-records-1 This new version is a major refactoring of the originally proposed format. Feel free to comment, update or propose changes. An implementation will follow when the BCP-11 reach a more stable state. #gcve #cve #cybersecurity #vulnerabilitymanagement @gcve@social.circl.lu
0
0
1
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jul 29, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
Replying to @adulau@infosec.exchange
@muddle@infosec.exchange I updated the format to facilitate the use of smaller packer radio protocols. https://author-tools.ietf.org/iddiff?url1=draft-dulaunoy-rifp-00&url2=draft-dulaunoy-rifp-01&difftype=--html Thanks for the feedback.
2
0
0
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jul 29, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
Replying to @adulau@infosec.exchange
@muddle@infosec.exchange I already received question about LoRa which is pretty common for ESP32 chips. As LoRA is packet base and not IQ based, I might need to add a type for fragmented manifest over small PDU.
0
1
0
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jul 29, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
Replying to @muddle@infosec.exchange
@muddle@infosec.exchange The protocol is not two-way. It's unidirectional. Repeated frame transfer is basically the loop to send continuously the frame to ensure that a receiver get the manifest and all the frame for the image.
1
1
0
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jul 28, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
The Radio Image Framing Protocol (RIFP) 1.0 is an experimental, extensible standard for sending images over low-rate radio links. The default rifp-cpfsk-4800 profile uses binary continuous-phase FSK and can be deployed around 433.92 MHz where local regulation permits it. RIFP itself is not tied to 433 MHz or to FSK and can be used in any frequency bands. I'm still exploring various low-cost options for a device that can receive and display images on an e-ink screen in emergency areas or similar environments. :github: Python implementation https://github.com/adulau/rifp Internet-Draft https://www.ietf.org/archive/id/draft-dulaunoy-rifp-00.html #radio #fax #433mhz #opensource
56
2
47
1
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jul 27, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
Pivotick is an open-source network graph library to facilitate pivoting. Version 1.4.0 has been released and also includes a security fix. Release notes https://github.com/Pivotick/Pivotick/releases/tag/v1.4.0 Documentation https://pivotick.github.io/Pivotick/ Vulnerability fixed in 1.4.0 https://vulnerability.circl.lu/vuln/gcve-1-2026-20151 Gallery https://pivotick.github.io/Pivotick/gallery.html #opensource #infovis #graph #networkgraph #visual
6
0
5
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jul 27, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
So finally Kimi-k3 is not really open-source https://huggingface.co/moonshotai/Kimi-K3/blob/main/LICENSE I'm a bit disappointed. #kimi #ai #opensource
LICENSE · moonshotai/Kimi-K3 at main
huggingface.co

LICENSE · moonshotai/Kimi-K3 at main

We’re on a journey to advance and democratize artificial intelligence through open source and open science.

3
2
3
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jul 26, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
Replying to @diffractie@glitterkitten.co.uk
@diffractie@glitterkitten.co.uk I think the major issue is the lack of authentication as these are often used for forensic investigations.
0
0
0
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jul 26, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
The GCVE Lab is an open space for experimenting with new ideas, tools, formats, and services related to the Global CVE Allocation System initiative. The lab allows the GCVE community to explore promising concepts without immediately imposing the stability, compatibility, and operational requirements expected from the core GCVE infrastructure. Open to comments/ideas. #gcve #cve #cybersecurity https://discourse.ossbase.org/t/gcve-lab-proposal/1117 https://gcve.eu @gcve@social.circl.lu @gcve@discourse.ossbase.org
0
0
0
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jul 25, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
Wireshark for the web (webasm) Open, dissect and analyse .pcap / .pcapng capture files entirely in your web browser. Online - local in your browser https://stricaud.github.io/wpcapng/ Sourc code - https://github.com/stricaud/wpcapng #nids #pcap #networkanalysis #wireshark
6
0
12
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jul 22, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
Replying to @CCC@social.bau-ha.us
@CCC@social.bau-ha.us Did we ask for same data for US citizens ?
0
1
0
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jul 17, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
Replying to @tyzbit@toot.now
@tyzbit@toot.now We are actually digging quite a lot in the topic. Academic papers claiming open source models and then you cannot get access to the original recipe is driving me nuts too. The reproducibility is usually hard to evaluate if you don’t have some H100 cards laying in your racks… but I see that more and more models are releasing details to reproduce the training steps. I remain optimism for the future while the model training will become more accessible on smaller hardware.
0
0
0
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jul 17, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
Replying to @tyzbit@toot.now
@tyzbit@toot.now There are different ones at different level of open-source but there are some which are indeed including all the training recipes including dataset and even checkpointing: https://github.com/NVIDIA-NeMo/Nemotron Nemotron is maybe one of the good example.https://github.com/allenai/olmo-core Olmo is another example. There are many more but those are actually working ones and other already reproduced the training process.
0
1
0
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jul 17, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
Replying to @flo@mi.cmbg.ws
@flo@mi.cmbg.ws This remembers me the old lobbying from Microsoft in late nineties explaining that free software and copyleft will kill the software industry. At the end, open-source/free software was a major economical driver during the past 30 years.
0
0
0
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jul 17, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
I don’t like playing the futurologist, but after seeing AI companies warn EU institutions about the supposed risks of open-weight models, I suspect some are lobbying to regain control over genuine open source and open-weight AI. Don’t fall into the trap: the greater danger lies in opaque, proprietary models, not open-source ones. #opensource #ai #cybersecurity
0
2
0
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jul 16, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
Replying to @iglocska@infosec.exchange
@iglocska@infosec.exchange Just like all the fauxpen starting with "Open" in their names. @djh@chaos.social
0
1
0
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jul 16, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
Replying to @djh@chaos.social
@djh@chaos.social The paper said open-source but on HuggingFace, it's a different story. You have to be approved to be able to look at the repository... doesn't seem very open-source.
0
1
0
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jul 15, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
Replying to @westonsteimel@hachyderm.io
@westonsteimel@hachyderm.io @darakian@fosstodon.org That’s great feedback. We will also update the FAQ about this on gcve.eu. Technically is just documenting more (than hiding the information behind a closed-door dispute process) and every users/orgs can decide which source they take. Vulnerability-lookup software stack already includes it. @gcve@social.circl.lu
2
2
0
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jul 14, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
Replying to @darakian@fosstodon.org
@darakian@fosstodon.org The model is very different. Dispute are totally fine in GCVE and we don’t need to reach a consensus or having a GNA of last resort. The information is there along with the different point of view. It’s just like git. Forking is just fine and beneficial for the system. @westonsteimel@hachyderm.io @gcve@social.circl.lu
0
1
0
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jul 14, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
Replying to @darakian@fosstodon.org
@darakian@fosstodon.org This one is a special case GNA. The GNA itself combine the proposals. But it doesn’t block other GNA to publish their point of view. There is no dispute resolution in GCVE as each GNA can publish their point of view including opposition. Via relationships https://gcve.eu/bcp/gcve-bcp-05/#potential-relationship-verbs-for-vulnerability-identifiers @westonsteimel@hachyderm.io @gcve@social.circl.lu
0
1
0
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jul 13, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
Replying to @westonsteimel@hachyderm.io
@westonsteimel@hachyderm.io Thanks for contributing too. It’s an early draft to be implemented in the gcve open source toolset. Ideas and feedback more than welcome! @gcve@social.circl.lu
1
1
0
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jul 12, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
Replying to @hrbrmstr@mastodon.social
@hrbrmstr@mastodon.social and they forget 70% of other vulnerabilities thinking only CVE exists 🫣 We still kindly accept nice PR on vulnerability-lookup and we won’t be killed by a VC 😇 https://vulnerability.circl.lu/ https://github.com/vulnerability-lookup/vulnerability-lookup
0
0
0
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jul 11, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
Replying to on social.gompa.me
@neal@social.gompa.me All is documented as BCP including IDs allocation https://gcve.eu/bcp/ If you have any question feel free. @bernardq@ehlo.exim.org
0
0
0
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jul 08, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
We are exploring some ambitious ideas around reducing external dependencies and relying more on our own libraries across MISP and related tooling. Over the past year, we have been working on a replacement network graph library for the new MISP interface and things are getting really interesting. Pivotick is already used in around ten open-source tools, including CTI Transmute, AIL Project, and Rulezet. It has also recently been integrated into the new MISP UI, OverMind. The library is, of course, open source and comes with extensive documentation, including AI-parseable documentation to make integration easier. We have just released Pivotick v1.2.0. https://pivotick.github.io/Pivotick/ https://github.com/Pivotick/Pivotick #infovis #cybersecurity #opensource
0
0
0
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jul 08, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
We started rulezet project after identifying a clear gap in open source tooling for detection rules management: the ability to operate synchronised instances while still allowing each organisation to maintain its own autonomous rule repository. Rulezet addresses this need as an open source platform for managing, sharing, and synchronising detection rules. Each organisation can run its own standalone instance and decide independently which other instances, communities, or repositories it wants to synchronise with. The latest release reached a significant milestone to make it more operational for other DFIR tools. Online version: https://rulezet.org/ Release notes: https://github.com/rulezet/rulezet-core/releases/tag/1.6.1 #dfir #opensource #cybersecurity
0
0
0
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jul 05, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
Replying to @bzg@floss.social
@bzg@floss.social @zacchiro@mastodon.xyz You might be interested in vulnerability-lookup https://github.com/vulnerability-lookup/vulnerability-lookup which is much more advanced and complete for the global vulnerability ecosystem. @oh2fih@infosec.exchange
1
0
0
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jul 05, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
Looking at the current distributed.net statistics on the current RC5-72 brute force, this actually puts some key-size discussions into perspective. #cryptography #crypto #symmetric #cybersecurity
0
1
0
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jul 05, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
We just released cve-search v6.0.1 - it is a security and maintenance release. All users are strongly encouraged to upgrade. Thanks to @oh2fih@infosec.exchange for the remediation fix and release support. Thanks to George Chen for the report about the security vulnerability. #cve #gcve #cybersecurity 🔗 https://github.com/cve-search/cve-search/releases/tag/v6.0.1
4
1
7
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jul 02, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
Replying to @vickyjo@mastodon.social
@vickyjo@mastodon.social I ran workshops on this topic in the early 2000s, yet the mistake of creating a custom license remains surprisingly common. It would be useful to document the most frequent pitfalls and explain how they can harm a community, reduce adoption, and ultimately weaken a new open-source project. @passthesaltcon@infosec.exchange
0
0
0
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jul 02, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
An idea for next year workshop @passthesaltcon@infosec.exchange - open source license for developers? It could be a nice opportunity because it seems to be a never ending learning process. #opensource
3
0
1
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jul 02, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
@aristot73@infosec.exchange I'm not into this kind of sport. But here, it might be different ;-) Should we expect the harbor of Antwerp to be bombed soon. @bert_hubert@mastodon.nl
0
0
0
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jun 21, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
« Once an organisation accepts that the difficult software will be bought elsewhere, internal teams slowly lose the habit of building. Procurement becomes a substitute for strategy. Legal review becomes a substitute for leadership. Risk management becomes a substitute for execution. » https://foo.be/2026/06/Sovereignty-Is-Engineered-Not-Procured.html #sovereignty #europe #opensource
9
0
9
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jun 04, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange

What’s the difference between an API and an agent?

An API is consistent, deterministic, and scoped.
An agent is probabilistic, non-deterministic, and occasionally chaotic.

An agent adds some spice to your life.

Will you choose the boring, predictable life or the cool, chaotic one?

#ai #ia

infosec.exchange

Infosec Exchange

9
4
5
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jun 03, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange
Replying to @iglocska@infosec.exchange
@iglocska@infosec.exchange Sorry but we cannot hide this any longer. @misp@misp-community.org
0
0
0
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · Jun 03, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange

Not sure I’m allowed to leak this yet, but the new MISP dashboard is kind of crazy.

We didn’t just refresh the old one, we rewrote it completely, and it comes with a whole set of new features and capabilities that change the game quite a bit.

#misp #cti #dashboard #opensource

@misp@misp-community.org

infosec.exchange

Infosec Exchange

20
6
20
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · May 31, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange

I’m wondering why @dnsoarc@mastodns.net is limiting potential new contributions to their project just because they are AI-assisted.

Many valuable tools support development today, including code review and security review. The copyright argument feels similar to the one behind CLAs: an unsuccessful attempt to control the origin of the code, or even the author’s ability to re-implement a specific idea with or without external tools.

#ai #opensource #copyright

https://codeberg.org/DNS-OARC#artificial-intelligence-and-large-language-model-contributions-policy

0
3
2
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · May 30, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange

IETF I-D updated - Programming Methodology Framework aka PMF

This update includes "Swearwords and Software Engineering"

#update #computerscience #methodology #programming

🔗 https://datatracker.ietf.org/doc/draft-dulaunoy-programming-methodology-framework/

2
1
3
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · May 29, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange

The synthetic exercise world format now includes a nice map.

So no one can blame us when you conduct an exercise: everything is fictional ;-) Yes, we’ve had cases like this during threat intelligence exercises.

All Synthetic Exercise World - Self-contained fictional world dataset for cyber exercises and standards documents are available at https://github.com/MISP/Synthetic-Exercise-World-Format

#cti #cyberexercise #exercise #threatintelligence #opensource

11
0
7
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · May 28, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange

I still don’t understand standards committees composed of people who have never implemented software. They design a standard without ever confronting the realities of implementation, then wonder why no one adopts it.

#openstandard #standard

6
1
3
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · May 27, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange

Yesterday, in our very warm office, an interesting discussion emerged: there was no dedicated taxonomy for evaluating Cyber Threat Intelligence (CTI) in MISP.

So, we created one called: cti-evaluation

🔗 https://www.misp-project.org/taxonomies.html#_cti_evaluation

My colleagues Théo Geffe and Christian Studer then took it one step further by implementing it in CTI-transmute.

From discussion to a first implementation and tests in less than 48 hours, not too bad! Feedback on the taxonomy is more than welcome. And you can already test it live on cti-transmute.org

🔗 https://cti-transmute.org/convert/detail/93

#cti #misp #cybersecurity #threatintelligence #opensource #threatintel

@misp@misp-community.org
@circl@social.circl.lu

10
0
7
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · May 13, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange

This release includes a major new feature: a graph visualisation for the MISP standard and STIX format, making it easier to explore, understand, and present CTI data structures directly from JSON.

CTI Transmute is an online service available at cti-transmute.org and also an open source project available on GitHub.

The FIRST CTI 2026 conference in Munich was a great source of feedback for this release. Many of the improvements and new features introduced in v1.2 came directly from discussions, demonstrations, and feedback gathered during the event. Thank you to everyone who tested, commented, challenged ideas, and shared practical use cases.

#cti #stix #misp #standard #interoperability #cybersecurity

🔗 Release notes CTI Transmute https://github.com/MISP/cti-transmute
🔗 Release notes misp-stix https://github.com/MISP/misp-stix/releases/tag/2026.5.13

4
0
5
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · May 10, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange

The Synthetic Exercise World Format provides fictional countries, companies, sectors, and threat actors with structured metadata for neutral CTI examples, exercises, interoperability tests, and standards documentation without referencing real-world sensitive entities.

I just released version 1.0.

#cti #opensource #misp #cybersecurity #threatintelligence #threatintel

🔗 GitHub - https://github.com/MISP/Synthetic-Exercise-World-Format

21
0
15
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · May 08, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange

This kernel vulnerability looks interesting to look at.

crypto: caam - fix overflow on long hmac keys

VLAI Severity -> High (confidence: 0.9638)

https://vulnerability.circl.lu/vuln/CVE-2026-43330

#kernel #cybersecurity

0
0
1
0
Open post
adulau
Alexandre Dulaunoy @adulau@infosec.exchange · May 07, 2026
Alexandre Dulaunoy
@adulau@infosec.exchange

Enjoy when humans are using machines in unexpected ways. I break stuff and I do stuff. The other side is at @a (photography, art and free software at large) #infosec #opensource #threatintelligence #fedi22 #threatintel #searchable

infosec.exchange

I’m still completely lost with logic of JA4+ patent licensing and actual incompatibility with the copyleft-license. So it seems to be a patent-based license and really risky to implement if you want to keep your actual software open source.

Did someone explore alternatives to avoid this? and especially other format which are open source friendly?

#ja4 #ja3 #jarm #cti #opensource #patent #cti
#threatintel #cybersecurity

🔗 https://github.com/FoxIO-LLC/ja4/blob/main/License%20FAQ.md

8
2
7
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 20:52:27 UTC