Download the latest Vulnerability & Exploitation Report

Download now

Welcome to the CrowdSec Blog

Learn more about CrowdSec, our approach to tactical intelligence, and company news.

Analyse de l’attaque de la supply chain TanStack
Announcement

Analyse de l’attaque de la supply chain TanStack

Philippe Humeau, PDG de CrowdSec, revient en détail sur l’attaque de la chaîne d’approvisionnement de 2026, depuis la fuite du code source et l’enquête technique jusqu’aux enseignements tirés.

Philippe Humeau
TanStack Supply Chain Attack Analysis
Announcement

TanStack Supply Chain Attack Analysis

CrowdSec CEO Philippe Humeau shares the full story behind the 2026 supply chain attack, from the source code leak and forensic investigation to the lessons learned.

Philippe Humeau
CrowdSec Statement: Source Code Exposure in May 2026
Announcement

CrowdSec Statement: Source Code Exposure in May 2026

CrowdSec update on a source code exposure that occurred in May 2026, including the scope, impact, investigation, and security measures taken.

The CrowdSec Team

Check out our VulnTracking Reports!

View VulnTracking Reports
How to Block Bots, Headless Browsers, and Scrapers on Nginx with CrowdSec
AI

How to Block Bots, Headless Browsers, and Scrapers on Nginx with CrowdSec

Set up open-source Nginx bot protection with CrowdSec to block scrapers, headless browsers, AI crawlers, and other unwanted automated traffic.

Thibault Koechlin
What’s New in CrowdSec 1.8: WAF Bot Detection, Kubernetes Datasource, and Performance Improvements
AI

What’s New in CrowdSec 1.8: WAF Bot Detection, Kubernetes Datasource, and Performance Improvements

Discover what’s new in CrowdSec 1.8, including WAF bot detection, a dedicated Kubernetes datasource, faster LAPI synchronization, and improved Console alerts.

Thibault Koechlin
Why You Should Write a Skill for Your Software
AI

Why You Should Write a Skill for Your Software

Learn why AI agent skills make software setup more reliable, reduce LLM guesswork, improve troubleshooting, and can even expose gaps in your documentation.

Thibault Koechlin
WAF for Traefik with CrowdSec: Virtual Patching in Docker
Integrations

WAF for Traefik with CrowdSec: Virtual Patching in Docker

Add an open-source WAF to Traefik with CrowdSec. Wire the bouncer plugin, enable virtual patching, and block real attacks, step by step in Docker.

Thibault Koechlin
Open-Source WAF for Nginx on Ubuntu with CrowdSec
Integrations

Open-Source WAF for Nginx on Ubuntu with CrowdSec

Deploy an open-source WAF for Nginx on Ubuntu with CrowdSec. Install the AppSec component, enable virtual patching, and block attacks step by step

Thibault Koechlin
CISA gives you 3 days to patch and triage. Live Exploit Tracker gives you a head start
Proactive Cybersecurity

CISA gives you 3 days to patch and triage. Live Exploit Tracker gives you a head start

CISA BOD 26-04 mandates risk-based patching driven by real exploitation evidence. Live Exploit Tracker delivers that evidence live — per CVE, per vendor.

Philippe Humeau
CrowdSec 1.7.8 Security Release: Fixes High-Severity WAF Bypass and LAPI DoS Vulnerabilities
Product Updates

CrowdSec 1.7.8 Security Release: Fixes High-Severity WAF Bypass and LAPI DoS Vulnerabilities

CrowdSec 1.7.8 fixes two security vulnerabilities: CVE-2026-44982, a high-severity WAF bypass, and CVE-2026-44981, a Local API denial-of-service issue. Upgrade now.

Sebastien Blot
Edge is the new endpoint: How to respond when edge CVEs go hot
CrowdSec

Edge is the new endpoint: How to respond when edge CVEs go hot

Edge CVEs move fast from disclosure to exploitation. Learn a practical 60-minute response framework to assess exposure, reduce risk, deploy mitigations, and communicate clearly during edge vulnerability incidents.

The CrowdSec Team
ButanGas Enhances Cybersecurity with CrowdSec to Protect LPG Distribution
Success Story

ButanGas Enhances Cybersecurity with CrowdSec to Protect LPG Distribution

ButanGas strengthens its IT security using CrowdSec’s real-time threat intelligence & blocklists, ensuring secure, uninterrupted LPG distribution across Italy.

The CrowdSec Team
crowdsec and owasp
Tutorial

Protecting Your Web Applications with OWASP CRS and CrowdSec

Deploy the OWASP Core Rule Set (CRS) with CrowdSec to detect SQL injection, XSS, and other attack patterns. Learn how to install, tune, and enable blocking.

Sebastien Blot
The future of CrowdSec support in Kubernetes
Inside CrowdSec

The future of CrowdSec support in Kubernetes

Explore CrowdSec support for Kubernetes, Ingress-NGINX deprecation, and how to migrate to Gateway API using Traefik, HAProxy, and Envoy.

Manuel Sabban
vulnerability exploits threats risk
Proactive Cybersecurity

Vulnerability 101: Understanding Security Weaknesses

Learn the difference between vulnerabilities, threats, and risks, and how understanding their lifecycle helps prevent security incidents.

Jona Azizaj
crowdsec mcp
Inside CrowdSec

CrowdSec MCP: Life Is Too Short for YAML

Learn how the CrowdSec Model Context Protocol (MCP) helps you leverage LLMs to automatically write reliable WAF rules & scenarios without writing complex YAML.

Thibault Koechlin
CrowdSec Welcomes db.gcve.eu, Strengthening Europe’s Vulnerability Intelligence, Without Losing Global Interoperability
Proactive Cybersecurity

CrowdSec Welcomes db.gcve.eu, Strengthening Europe’s Vulnerability Intelligence, Without Losing Global Interoperability

Strengthen your vulnerability workflows with db.gcve.eu: aggregated advisories, cross-source correlation, & real-time exploitation insights from CrowdSec.

Jerome Clauzade
live exploit tracker
Announcement

Introducing Live Exploit Tracker: Know What’s Exploited, Act Faster

See which CVEs are actively exploited in the wild. Live Exploit Tracker helps you prioritize faster using real attack activity, IPs, and IoCs.

Jerome Clauzade
Vulnerability Myths
Proactive Cybersecurity

5 Common Vulnerability Myths That Put Your Security At Risk

Discover 5 common cybersecurity myths that increase risk, from “we’re too small” to CVSS blind spots. Learn what really reduces exposure.

Jona Azizaj
production telemetry vs honeypots
Proactive Cybersecurity

Honeypots vs Production Telemetry: What CISOs Should Trust for Threat Intelligence

Threat intelligence isn’t equal. Learn why real-world production telemetry reveals attacker intent, and why CISOs trust it over honeypot-based intel.

Jerome Clauzade
crowdsec react2shell
Ambassador Post

React2Shell: The Overly Spicy Side of React 19. CrowdSec to the Rescue!

React2Shell (CVE-2025-55182) is a critical RCE vulnerability impacting React Server Components and Next.js. Learn how CrowdSec mitigates it fast.

Killian Prin-Abeil