ioc.exchange is one of the many independent Mastodon servers you can use to participate in the fediverse.
INDICATORS OF COMPROMISE (IOC) InfoSec Community within the Fediverse. Newbies, experts, gurus - Everyone is Welcome! Instance is supposed to be fast and secure.

Administered by:

Server stats:

1.3K
active users

#cert

3 posts3 participants0 posts today
Continued thread

I'm making a small change to the post because I forgot something very important:

"Numbers are of course important, but what matters most to me is what I wrote in the second paragraph of this text. Large telecom companies with large legal departments have reached an understanding with a public entity (CERT Polska) and are actively cooperating for the benefit of citizens. That kind of public - private collaboration is very good, because it establishes a real pathway by which the numbers can grow in the future. This is cool."

Seit 8 Jahren bin ich als Advisor im #CERT@#VDE tätig – und freue mich deshalb umso mehr darüber, dass es jetzt Deutschlands erste Root-#CNA geworden ist – herzliche Glückwünsche!

Mit dem #CVE-System werden seit über 25 Jahren Schwachstellen erfasst und mit einer eindeutigen Kennung versehen, um sie zur Mitigation zuordnen zu können. Root-CNAs haben die Aufgabe, die CVE Numbering Authorities (CNAs) zu koordinieren - eine verantwortungsvolle Position in der Cybersecurity:
heise.de/news/Security-CERT-VD

Continued thread

We saw them pulling the bodies up from the plane wreckage. The local #CERT team has Sunset Drive closed from Lighthouse Ave to Asilomar Ave.

The plane is a little ways off the beach at Arena and Sunset. I'm not sure where they were trying to get to because it's all houses there. The track on this website shows the elevation and flight path: asn.flightsafety.org/wikibase/

Did they lose power or maybe they had a control cable snap? 🤔

8080 - a short story of 4-digit number and EU regulations in pratice 🇪🇺

In Poland, the reporting mechanism via the short number 8080 enables rapid, citizen‑driven identification of smishing and cyber‑fraud attempts. Reporting a malicious message involves simply forwarding the suspicious SMS to 8080, which delivers it directly to CERT Polska for analysis [1].

Upon receipt and confirmation of malicious content, each new SMS pattern is published by CERT and within ~5 minutes, automatically fetched by all cooperating telecom providers, which then block any incoming messages matching it.

The entire system operates under the Act of 5 July 2018 on the National Cybersecurity System [2], which is the Polish implementation of the EU's NIS Directive [3] and tasks CERT with maintaining a registry of malicious SMS patterns and coordinating with telecom operators.

In 2024 alone, 746 new patterns were produced, blocking 1 475 366 fraudulent SMS before they reached users. Citizens filed 354 566 reports, of which 140 659 were classified as malicious [4].

It's difficult for me to assess whether these figures are high or low. The system may still lack sufficient patterns, and the number of blocked messages might be too small relative to the true scale of SMS communication and smishing threats... but hey, it's still better than nothing, isn't it?

Numbers are of course important, but what matters most to me is what I wrote in the second paragraph of this text. Large telecom companies with large legal departments have reached an understanding with a public entity (CERT Polska) and are actively cooperating for the benefit of citizens. That kind of public - private collaboration is very good, because it establishes a real pathway by which the numbers can grow in the future in a sustainable and enforceable way. This is pretty cool.

[1] cert.pl/baza-wiedzy/falszywe-s
[2] isap.sejm.gov.pl/isap.nsf/DocD
[3] eur-lex.europa.eu/eli/dir/2016
[4] cert.pl/uploads/docs/Raport_CP

Nabór do polskiego zespołu na ECSC 2025 już w ten weekend!

Zespół CERT Polska organizuje w najbliższy weekend (od 04.07.2025 16:00 CEST do 6.07.2025 16:00 CEST) kwalifikacje indywidualne do reprezentacji Polski, która wystąpi na corocznych ćwiczeniach organizowanych przez Europejską Agencję ds. Cyberbezpieczeństwa – European Cybersecurity Challenge. Kwalifikacje odbędą się w formie zmagań Capture The Flag w dwóch klasyfikacjach wiekowych – 5...

#Ctf #WBiegu #Cert #Ecsc

sekurak.pl/nabor-do-polskiego-

Sekurak · Nabór do polskiego zespołu na ECSC 2025 już w ten weekend!Zespół CERT Polska organizuje w najbliższy weekend (od 04.07.2025 16:00 CEST do 6.07.2025 16:00 CEST) kwalifikacje indywidualne do reprezentacji Polski, która wystąpi na corocznych ćwiczeniach organizowanych przez Europejską Agencję ds. Cyberbezpieczeństwa – European Cybersecurity Challenge. Kwalifikacje odbędą się w formie zmagań Capture The Flag w dwóch klasyfikacjach wiekowych – 5...