CERT-CBRT, the operation's public radar
Recent vulnerabilities ranked by real exploitation probability, and analysis from the team that responds to incidents every day. What we learn on shift, shared., published under TLP policy.
Most likely to be exploited right now
Prioritized by exploitation probability (FIRST EPSS), not CVSS. CROC clients also get the concrete action per stack and the deployed detection before the bulletin.
Querying the public vulnerability sources…
Analysis from the shift, no marketing
What the team learns by operating: how the agents are audited, which TTPs we see in the region and how to communicate risk to the board.
Auditing the triage agent: 94% noise, 0 lost cases
The reasoning log behind every dismissal, the monthly blind sampling and how a client can review it.
Read →MFA-fatigue phishing: what we saw at three banks in the region
The full attack sequence, the signal that gives it away and the detection that cuts it.
Read →Microsoft 365 hardening guide for Dominican companies
Seven concrete controls, from conditional access to Direct Send, with the why behind each.
Read →AI in security: from copilots to agents
What to automate, what never to, and how to measure results without vanity metrics.
Read →The first 4 hours of a ransomware, told from the shift
Anonymized case: which decisions mattered and what a retainer would have changed.
Read →How to present cyber risk to the board in 4 questions
How much can we lose, what does reducing it cost, what is the return and what happens if we do nothing.
Read →The CERT-CBRT RFC 2350 profile
Formal description of the team under the RFC 2350 standard: who we are, whom we serve, under which policies we operate and how to reach us.
Version and distribution
How to reach the team
Mission, constituency and authority
Support, confidentiality and TLP
Reactive and proactive
How to report
Disclaimer: CERT-CBRT takes every precaution in preparing information, notifications, alerts and reports, but assumes no responsibility for errors or omissions, nor for damages resulting from the use of the information supplied.
Active incident?
The DFIR team responds 24/7. Containment, forensics and recovery with chain of custody.