Skip to content
You can now search across every topic, entity and event.What's new
CrowdSec
Organisation

CrowdSec

French open-source, crowdsourced cyber threat-intelligence and collaborative detection firm.

CrowdSec is a French crowdsourced threat-intelligence firm that spotted active exploitation of a FortiSandbox flaw on 17 June 2026, a month before CISA added it to its KEV catalogue.

Last refreshed: 3 August 2026 · Appears in 1 active topic

Timeline for CrowdSec

#12 28 Jul

Mentioned in: KEV patch clocks fell to three days

Cybersecurity: Threats and Defences
#12 28 Jul
#11 16 Jul

Detected in-the-wild exploitation of FortiSandbox on 17 June, a month before the KEV listing

Cybersecurity: Threats and Defences: CISA's KEV list runs a month late
View full timeline →

Background

CrowdSec is a French cyber threat-intelligence firm built on a crowdsourced, collaborative detection model: participating organisations share attack signals observed on their own networks, which CrowdSec aggregates to build a shared, real-time picture of active exploitation.

That model lets it often observe live exploitation before it is reflected in official government vulnerability catalogues, which typically depend on formal verification and coordination steps that take longer to complete.

Its network draws on telemetry contributed by participating organisations of many sizes, including some too small to run dedicated threat-intelligence operations of their own, which is part of why crowdsourced platforms like CrowdSec can sometimes spot live exploitation before centralised official catalogues formally list it.

Key Issues
Detection lag

CrowdSec caught the flaw a month early

CrowdSec detected hackers actively exploiting a flaw in Fortinet's FortiSandbox appliance, CVE-2026-39808, on 17 June 2026. CISA did not ADD that flaw to its official KEV catalogue until 16 July, leaving a month during which CrowdSec's own telemetry was ahead of the US government's public list.

The gap illustrates the role crowdsourced detection plays alongside official catalogues: organisations relying solely on KEV listing as a patch trigger had no signal on FortiSandbox for that entire month, even as exploitation was already under way.

Common Questions
What is CrowdSec?
CrowdSec is a Paris-founded cybersecurity company that runs a crowdsourced threat-intelligence engine, sharing attack signals across its global user community so an exploit seen on one network can be blocked on others.Source: Lowdown
How much earlier did CrowdSec detect the FortiSandbox flaw than CISA?
CrowdSec detected in-the-wild exploitation of CVE-2026-39808 on 17 June 2026 and shipped a detection rule that day. CISA did not ADD the flaw to its KEV catalogue until 16 July, a one-month gap.Source: Lowdown
Why does CrowdSec sometimes detect exploitation before CISA's KEV catalogue?
CrowdSec's crowdsourced model pools attack telemetry from its user community in real time, whereas CISA's KEV catalogue only lists a flaw once federal review confirms active exploitation, a slower process.Source: Lowdown