CrowdSec is a CTI tool leveraging crowdsourced data to identify and block malevolent IPs in real time worldwide. Join our Discord: discord.gg/crowdsec

CrowdSec Blocklists feature a 5% daily rotation, ensuring users always benefit from fresh, up-to-date threat intelligence. To learn more about CrowdSec Blocklists and how to integrate them with your @Sophos Firewall, watch our full video guide here:  piped.video/watch?v=lmqzFpHp… #firewall #threatintelligence #blocklists #cybersecurity
3
416
CrowdSec + Suricata: do you actually need both for Linux servers? 🤔 They both detect threats, but they solve different problems. We break down where each fits, when to use them together, and why enforcement matters more than simply collecting alerts. 👉 Read the full article: crowdsec.net/blog/crowdsec-v… #Linux #IDS #IPS #cybersecurity #suricata
1
1
7
552
How does the attack activity affect your stack? Attack Surge helps you spot major changes, then jump into the underlying alerts to understand what’s driving the spike. Explore it in CrowdSec → docs.crowdsec.net/u/console/… #cybersecurity #threatdetection #securityoperations
2
550
Keep your security stack in good shape🛡️ With CrowdSec Stack Health, you can: - See what needs attention - Understand what’s wrong - Get clear guidance on how to fix it - Get your stack back to good health Less time troubleshooting. More time keeping your security stack running smoothly. Check it out 👉 doc.crowdsec.net/u/console/s… #cybersecurity #securitystack #crowdsec
2
4
530
🚨 In this week’s Threat Alert, we cover CVE-2025-4427, an authentication bypass in Ivanti Endpoint Manager Mobile (EPMM) that can be chained with CVE-2025-4428 for unauthenticated remote code execution. CrowdSec has observed 865 unique IP addresses sending requests matching the exploitation pattern since May 2025. Read our latest article for the full analysis, protection recommendations, and more: crowdsec.net/vulntracking-re… Keep your network informed. Like and share this post!
5
574
We’ve published a deeper look at the supply chain attack that affected CrowdSec. In this article, our CEO Philippe Humeau shares an honest account of what happened, how we investigated the incident, what we found, and what we’re doing differently as a result. Read the full analysis here: crowdsec.net/blog/tanstack-s… We’d also like to thank @fuitesinfos for reporting the issue and reaching out to us, as well as @GitGuardian, @AikidoSecurity, and @github for their support. And, most importantly, thank you to our team for their swift and coordinated response, and to everyone in the cybersecurity community who supported us throughout.
1
5
16
5,415
On September 16, CrowdSec was informed of a source code leak involving our GitHub repository, which occurred in May 2026. Our team verified and confirmed the report. CrowdSec source code consists of two parts: a private one and another that hosts our Free Open Source Software (i.e., the Security Engine), which is public by design and therefore out of scope. The private part, though, contains the source code for our SaaS console, some AWS Cloud routines, some connectors, and automations. The news headline claiming 300 different repositories is accurate (when you include the 130+ public ones), though that number mostly reflects the code's subdivision rather than a specific volume. We do not confirm any “other file contained” or “internal development material”, since all the code is published in these repositories. The API related information is the token used by the CI/CD component itself. (see below) No client data, login/password, name, organization, or anything else was leaked, and CrowdSec doesn’t store PII or client logs; the impact is limited to CrowdSec. Our team quickly hunted for any token, credential, or sensitive leak that could enable lateral movement but found none so far. The code contained in these private repositories has value but cannot really harm CrowdSec, since our efficiency depends on our network effect and size, which code alone can't replicate. We regularly audited the SaaS source code, and its leakage shouldn’t pose an immediate threat either. Most of the leaked code has evolved significantly over those four months, but we will closely monitor for any abnormal activity. Also, using it outside of CrowdSec seems unlikely because it only interacts with our data and tools and cannot really be leveraged in another context. We will keep you updated as we continue investigating, but the Tanstack compromise is very likely to have been the leak vector (more about it cybelangel.com/blog/attaque-…), as in the case of the Mistral AI case. This component was used in our organization in May and appears to have been backdoored to extract an API key with authorization to read the private codebase. The leak was only exploitable during a short timeframe in May 2026. We nevertheless immediately rotated all required tokens & credentials to prevent further incidents. The team would like to thank @fuitesinfos for their timely, professional outreach in reporting the issue.
2
8
18
2,243
Copy-pasting your CrowdSec question into an LLM? Sometimes you get the answer. Sometimes you get confidently assembled gibberish. 🤖 So we gave it a better map: the CrowdSec Skill. ✨ It uses our own docs to give you clear, structured guidance that LLMs can actually follow.  Because “sounds right” is not quite the same as “works.” 😏 Get the details: crowdsec.net/blog/ai-agent-s…
1
7
721
New in CrowdSec: Alerts Explorer. See how alerts break down across your stack, group activity by source IP, then use interactive facets to jump straight into what you want to investigate. Explore it → app.crowdsec.net/alerts-v2
2
6
530
🚨 In this week’s Threat Alert article, we cover CVE-2026-75650 (#StyleSmuggler), a critical RCE vulnerability affecting Adobe Commerce & Magento that was exploited before the patch was released. In just days, exploitation escalated to mass scanning, with 500+ IPs observed targeting vulnerable stores. We break down how the attack works, why residential IPs make traditional IP blocklists less effective, and what defenders can do to protect their Magento stores. Read the article for the full analysis and protection recommendations: crowdsec.net/vulntracking-re… Be sure to like and share this post to keep your network informed. #CVE202675650 #cybersecurity #CVE #threatalert
4
519
🤖 robots.txt: “Please don’t crawl my site.” Bots: “lol.” Thankfully, CrowdSec 1.8 brings self-hosted bot protection: proof-of-work + browser fingerprinting to separate real browsers from scripts wearing browser costumes.  No CAPTCHA. No black-box scoring. No per-request cloud bill. Just rules you can actually see and control. 👀 Read our latest article for all the details 👉crowdsec.net/blog/nginx-bot-…  #cybersecurity #botprotection #opensource
5
444
🚨 In this week’s newsletter, we cover CVE-2023-54391, a critical authentication bypass affecting Proxmox VE that is seeing exploitation attempts. We break down how attackers can bypass password verification with a single unauthenticated request and what defenders should do next. Read the full analysis and protect your systems 👉 crowdsec.net/vulntracking-re…
3
679
🔎 You find an unfamiliar IP in your logs. The IP alone tells you very little. The useful part is the context behind it: reputation, behavior and observed attack activity. See an IP you don't recognize? Look it up with IPDEX. 👉 ipdex.crowdsec.net #ThreatIntel #CyberSecurity #SecOps
6
584
CrowdSec 1.8 is here 🚀 🤖 Bot Detection for CrowdSec WAF ☸️ Dedicated Kubernetes datasource ⚡ Major LAPI ↔ bouncer performance improvements 🔎 Revamped Console alerts experience 🧠 Expanded CrowdSec Skill for LLMs See everything we’ve been cooking 👇 crowdsec.net/blog/crowdsec-1… #CrowdSec #CyberSecurity #OpenSource
4
11
714
🚨 In this week’s newsletter, we cover CVE-2026-33497, a high-severity path traversal vulnerability affecting Langflow that is seeing active exploitation. We break down how attackers can steal the key used to sign login tokens with a single unauthenticated request and what defenders should do next. Read the full analysis and protect your systems 👉 crowdsec.net/vulntracking-re…
2
552
A compromised device can become infrastructure for the next attack. Evooo1Bot is a recent example, turning compromised edge devices into infrastructure for further malicious activity. A reminder of why recent observed behavior matters for IP reputation. 👉 crowdsec.net/blocklists #CyberSecurity #ThreatIntel #Botnet
4
461