Skip to content
You can now search across every topic, entity and event.What's new
CrowdSec
Organisation

CrowdSec

French open-source, crowdsourced cyber threat-intelligence and collaborative detection firm.

Last refreshed: 24 July 2026

Timeline for CrowdSec

#11 16 Jul

Detected in-the-wild exploitation of FortiSandbox on 17 June, a month before the KEV listing

Cybersecurity: Threats and Defences: CISA's KEV list runs a month late
View full timeline →

Background

CrowdSec's detection of Fortinet's FortiSandbox flaw a month before it reached CISA's Known Exploited Vulnerabilities catalogue underlined how FAR private threat intelligence has run ahead of the federal list. On 17 June 2026, CrowdSec logged in-the-wild exploitation of CVE-2026-39808 and shipped a detection rule the same day; CISA did not ADD the flaw to KEV until 16 July, a one-month gap.

CrowdSec is a Paris-founded cybersecurity company built around a crowdsourced model: its Security Engine shares attack signals across a global community of users, so an exploitation attempt spotted on one network can be used to block it on thousands of others. The approach positions CrowdSec as a collaborative alternative to proprietary threat feeds, pooling telemetry rather than licensing it outright.

The FortiSandbox gap illustrates a wider pattern this beat has tracked: federal defenders relying on KEV as their exploitation signal now trail private detection routinely, while CISA works through the staffing pressure already on its record.

Common Questions
What is CrowdSec?
CrowdSec is a Paris-founded cybersecurity company that runs a crowdsourced threat-intelligence engine, sharing attack signals across its global user community so an exploit seen on one network can be blocked on others.Source: Lowdown
How much earlier did CrowdSec detect the FortiSandbox flaw than CISA?
CrowdSec detected in-the-wild exploitation of CVE-2026-39808 on 17 June 2026 and shipped a detection rule that day. CISA did not ADD the flaw to its KEV catalogue until 16 July, a one-month gap.Source: Lowdown
Why does CrowdSec sometimes detect exploitation before CISA's KEV catalogue?
CrowdSec's crowdsourced model pools attack telemetry from its user community in real time, whereas CISA's KEV catalogue only lists a flaw once federal review confirms active exploitation, a slower process.Source: Lowdown