#CSIRTs
Here is the European CSIRT
csirtsnetwork.eu/homepage?tab...
CSIRTs Network
csirtsnetwork.eu
April 16, 2025 at 5:27 AM
EU Cyber Resilience Act: Article 14 takes effect on 11 Sept. Manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents to CSIRTs and ENISA within set timeframes.

Here’s what it means for Element and our users.

element.io/blog/cyber-r...
Cyber Resilience Act: What changes this week and how Element is preparing
On 11 September 2026, the first substantive deadline under the Cyber Resilience Act (Regulation (EU) 2024/2847, "the CRA") will come into effect.
element.io
September 10, 2026 at 6:52 AM
CSIRTS laid the foundation for what later became OpenSOC.io (DEF CON black badge 2019!), and then Recon's Network Defense Range (NDR) which ironically would later land multiple contracts with the USAF and other military branches.

(pic of whit sitting on the retired OpenSOC/NDR mobile range rack)
May 2, 2025 at 3:46 AM
CVE改革のさなか、欧州脆弱性データベースが登場
#CybersecurityNews
www.scworld.com/news/europea...
European Vulnerability Database debuts amid CVE shakeup
The EUVD, maintained by ENISA, compiles information from the CVE program, CSIRTs and vendors.
www.scworld.com
May 16, 2025 at 8:35 AM
UPDATE: After feedback from various National CSIRTs & mail server operators (thank you!), we have identified a number of potential false positives in data being shared. We have suspended the vulnerable POP3/IMAP reports & are working on improvements before restarting reporting
January 4, 2025 at 6:51 PM
🚨 New Series Modat Magnify: Feature Findings
Kicking series off w/ Case Management ‘Device DNA’ tag. Relevant research for National & Government CSIRTs
See our findings & further research: bit.ly/3EcA5SZ 
Tag discoveries w/ #ModatMagnify #research #certs #CSIRT #cybersecurity
April 11, 2025 at 3:16 PM
We are starting regular reporting of ransomware victims (published by ransomware actors on their public data leak sites) to National CSIRTs & LE agencies subscribed to our free daily feeds - shadowserver.org/what-we-do/n...

Reports enabled as part of EU ISF MISP-LEA project: misp-lea.org
January 11, 2024 at 7:58 PM
Decomposing Memorization Reduction in Privacy-Preserving Fine-Tuning of SLMs for CSIRTs

Cristhian Kapelinski, Diego Kreutz
Decomposing Memorization Reduction in Privacy-Preserving Fine-Tuning of SLMs for CSIRTs
CSIRTs increasingly fine tune language models on vulnerability scan records, but these records expose internal network topology and create privacy risks under regulations such as GDPR and LGPD. We present the first empirical study of how DP SGD and HMAC pseudonymization interact when fine tuning sm…
arxiv.org
June 30, 2026 at 1:10 PM
You can track those here: dashboard.shadowserver.org/statistics/c...

Geo breakdown of implanted Cisco IOS XE: dashboard.shadowserver.org/statistics/c...

IP data shared daily with National CSIRTs worldwide & subscribed impacted network owners: www.shadowserver.org/what-we-do/n...
Time series · General statistics · The Shadowserver Foundation
dashboard.shadowserver.org
November 3, 2025 at 8:30 PM
El lado del mal - CloudFlare Radar: Open (Security & Network) Data para CERTs & CSIRTs www.elladodelmal.com/2025/06/clou... #OSINT #Ciberseguridad #Redes #CERT #CSIRT #SOC #CloudFlare
CloudFlare Radar: Open (Security & Network) Data para CERTs & CSIRTs
Blog personal de Chema Alonso (CDO Telefónica, 0xWord, MyPublicInbox, Singularity Hackers) sobre seguridad, hacking, hackers y Cálico Electrónico.
www.elladodelmal.com
June 29, 2025 at 7:59 AM
Data is filtered by domain ccTLD for National CSIRTs. For all other subscribers it will be filtered by the domain linked to your subscription.
November 27, 2025 at 4:38 PM
🛡️ Ab 11.09.2026 ist CERT-Bund im BSI das koordinierende #CSIRT für CRA-Meldungen in Deutschland.
📢 Es erhält Meldungen über die CRA-SRP, leitet relevante Informationen an weitere CSIRTs weiter und unterstützt so Schutzmaßnahmen.
#CybernationDeutschland #Cybernation #BSI #CyberResilienceAct #CRA
July 29, 2026 at 2:00 PM
Draugnet is a lightweight, open-source tool for anonymous cyber threat reporting. Built for the MISP ecosystem, it lets users submit and track reports — no accounts, no logins, just a simple token. Supports plain text, MISP JSON, and object templates. ideal […]

[Original post on infosec.exchange]
September 2, 2025 at 8:44 AM
Cyber Resilience Act: Meldepflichten für aktiv ausgenutzte Schwachstellen greifen ⏱️🛡️

Für ​Hersteller digitaler Produkte gilt seit gestern:
• 24h Frühwarnung an CSIRTs/ENISA bei bekannten Exploits
• 72h Detailmeldung zu Schweregrad & Workarounds
• Abschlussbericht 14 Tage nach Patch-Bereitstellung
September 12, 2026 at 7:46 AM
The ENISA's European Vulnerability Database (EUVD) launched officially. The dashboard provides three lists: critical vulnerabilities, exploited #vulnerabilities, and vulnerabilities coordinated by the EU's CSIRTs network. #ENISA #EUVD
euvd.enisa.europa.eu/homepage?is=...
EUVD
European Vulnerability Database
euvd.enisa.europa.eu
May 17, 2025 at 3:52 PM
UPDATE: After feedback from various National CSIRTs & mail server operators (thank you!), we have identified a number of potential false positives in data being shared. We have suspended the vulnerable POP3/IMAP reports & are working on improvements before restarting reporting
We have started notifying about hosts running POP3/IMAP services without TLS enabled, meaning usernames/passwords are not encrypted when transmitted. We see around 3.3M such cases with POP3 & a similar amount with IMAP (most overlap).

It's time to retire those services!
January 3, 2025 at 3:21 PM
...a lot of organizations fail to follow up to attacks on a "macro" level once they've been tactically addressed. If you know you're dealing with state actor or campaign X, you will engage with law enforcement, national CSIRTs, industry partners, and others differently...
February 17, 2025 at 5:59 PM
Not to keep banging the drum, but this is precisely where ISACs and their (active) public-private counterparts shine.

Unfortunately in Europe we tend to rely heavily on EU member state vertical institutions, national CSIRTs and NCSCs, without the messy business of active tactical cooperation.
February 17, 2025 at 6:39 PM
FYI - 'The EU Agency for Cybersecurity switched on the Cyber Resilience Act‘s Single Reporting Platform on 11 September 2026'
www.helpnetsecurity.com/2026/09/14/e... #ENISA #CRA #VulnerabilityReporting
ENISA launched the CRA Single Reporting Platform for actively exploited vulnerabilities - Help Net Security
The CRA Single Reporting Platform is live, and manufacturers now have 24 hours to report actively exploited vulnerabilities to EU CSIRTs.
www.helpnetsecurity.com
September 14, 2026 at 5:42 PM
We only share raw IP data with National CSIRTs for their respective countries and network owners for their network/constituency only. These are available by (free) subscription at www.shadowserver.org/what-we-do/n...
November 14, 2023 at 2:08 PM
Europe Strengthens Cyber Defense as ENISA Becomes CVE Root #cybersecurity #infosec
Europe Strengthens Cyber Defense as ENISA Becomes CVE Root
The European Union Agency for Cybersecurity (ENISA) has taken a major step forward in advancing vulnerability management across Europe by becoming a CVE Root within the global Common Vulnerabilities and Exposures (CVE) Program. This designation makes ENISA a central point of contact for national and EU authorities, members of the EU CSIRTs Network, and other partners under its mandate.  Previously acting as a Common Vulnerability and Exposure (CVE) Numbering Authority (CNA), ENISA has been authorized since January 2024 to assign CVE Identifiers (CVE IDs) and publish CVE Records for vulnerabilities discovered by or reported to EU CSIRTs. The move to CVE Root status expands the agency’s responsibilities and strengthens the coordination of vulnerability management efforts throughout the EU.  ENISA’s Executive Director, Juhan Lepassaar, emphasized the importance of this milestone: “By becoming a Root, ENISA moves a step further to improve the development and capacity of the Agency to support vulnerability management in the EU. With the new responsibilities, ENISA extends its support to the CSIRTs network and to all its partners to further enhance the EU's ability to manage and coordinate cybersecurity vulnerabilities and improve digital security across the Union.”  This development aligns with wider EU investments in coordinated vulnerability disclosure, the European Vulnerability Database (EUVD), and responsibilities outlined in the Cyber Resilience Act (CRA). Under the CRA, ENISA will guide manufacturers on compliance, assist in applying the new cybersecurity framework, and contribute to the development of the Single Reporting Platform for vulnerability notifications.  Understanding the CVE Program and ENISA’s Expanded Mandate  Founded in 1999, the CVE Program serves as a global system for identifying and cataloging publicly disclosed vulnerabilities. CVE IDs and accompanying records allow developers, organizations, and cybersecurity professionals to understand and address security flaws quickly. As a key figure in this ecosystem, ENISA now plays an expanded role in supporting the identification, onboarding, and oversight of CNAs that fall within its scope.  As a CVE Root, ENISA will help enforce CVE Program guidelines, refine procedures for assigning and managing CVE IDs, and maintain its registry services to support the vulnerability coordination work of EU CSIRTs. It will also act as a central contact point for cooperative partners under its mandate.  ENISA will join the CVE Program Council of Roots, the coordinating body responsible for overseeing operational alignment among Root organizations. Internationally, Roots include MITRE, CISA, Google, Red Hat, and Japan’s JPCERT/CC. Within the EU, INCIBE-CERT, Thales Group, and CERT@VDE are existing Roots, now accompanied by ENISA.  Transition Plans for Existing CNAs  ENISA’s new Root scope applies to organizations within its mandate, and eligible CNAs interested in transitioning under ENISA’s Root may do so voluntarily. The CVE Program will collaborate closely with each organization to support a smooth and phased transition. This approach ensures that CNAs can align the change with their operational requirements while maintaining continuity in their vulnerability management processes.  By becoming a CVE Root, ENISA deepens its involvement in coordinated vulnerability management across the EU. The agency’s expanded duties will help enhance the accuracy and timeliness of CVE Records, improve cross-border coordination, and support responsible vulnerability disclosure practices. These advances contribute directly to reducing fragmentation across Member States and creating a more unified European cybersecurity ecosystem.  ENISA also plays a pivotal role in several strategic EU cybersecurity initiatives. It operates the European Vulnerability Database (EUVD), developed under the NIS2 Directive and now fully operational. Additionally, the agency is developing the Single Reporting Platform (SRP) under the Cyber Resilience Act to facilitate mandatory reporting of actively exploited vulnerabilities by manufacturers starting in September 2026.  Conclusion   As secretariat of the EU CSIRTs Network, ENISA plays a key role in coordinating vulnerability disclosure across Member States and guiding CVD policies, reinforcing Europe’s cybersecurity resilience. Its new CVE Root status further strengthens its capacity in vulnerability management and cross-border coordination.  Complementing these efforts, Cyble offers AI-driven threat intelligence and real-time monitoring, enabling European enterprises to detect, investigate, and mitigate emerging cyber threats. Request a personalized demo from Cyble today to enhance your organization’s cyber resilience. 
thecyberexpress.com
November 23, 2025 at 3:44 AM
Free vulnerable IP data shared daily with 201 National CSIRTs (covering 175 countries & territories) & 10000+ other subscribed organizations worldwide in www.shadowserver.org/what-we-do/n...
CRITICAL: Vulnerable HTTP Report | The Shadowserver Foundation
DESCRIPTION LAST UPDATED: 2025-12-05 DEFAULT SEVERITY LEVEL: CRITICAL This report identifies hosts that have the Hypertext Transfer Protocol (HTTP) service running on some port that may have a vulnera...
www.shadowserver.org
December 9, 2025 at 4:24 PM
2/2

The MoU will support deeper engagement with NOGs, Peering Forums, CERTs/CSIRTs, SIGs, national IGFs and NRENs — communities building local capability and resilience.

Read more on the blog: apnic.foundation/empowering-d...

#DigitalInclusion #Internet
Empowering digital growth: A new era of collaboration for the Asia Pacific - APNIC Foundation
The APNIC Foundation and APNIC have entered into a strategic Memorandum of Understanding (MoU) to harmonise support for the regional Internet community, prioritising sustainable development and local ...
apnic.foundation
June 23, 2026 at 7:07 AM