<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>hackathon.lu - The Open Source Security Software Hackathon – News</title>
    <link>https://hackathon.lu/news/</link>
    <description>Recent content in News on hackathon.lu - The Open Source Security Software Hackathon</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <lastBuildDate>Fri, 24 Apr 2026 00:00:00 +0000</lastBuildDate>
    
	  <atom:link href="https://hackathon.lu/news/index.xml" rel="self" type="application/rss+xml" />
    
    
      
        
      
    
    
    <item>
      <title>Hackathon.lu 2026: a strong year for open cybersecurity collaboration</title>
      <link>https://hackathon.lu/2026/04/24/hackathon.lu-2026-outcome/</link>
      <pubDate>Fri, 24 Apr 2026 00:00:00 +0000</pubDate>
      
      <guid>https://hackathon.lu/2026/04/24/hackathon.lu-2026-outcome/</guid>
      <description>
        
        
        &lt;p&gt;&lt;img src=&#34;https://hackathon.lu/images/hackathon.png&#34; alt=&#34;logo for hacklathon.lu&#34; loading=&#34;lazy&#34; /&gt;&lt;/p&gt;
&lt;h1&gt;Hackathon.lu 2026: a strong year for open cybersecurity collaboration&lt;/h1&gt;&lt;p&gt;&lt;a href=&#34;https://hackathon.lu/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Hackathon.lu&lt;/a&gt; 2026, held in Luxembourg on &lt;strong&gt;14–15 April 2026&lt;/strong&gt;, once again showed what makes this event special: it is not just a place to present ideas, but a place where ideas turn into code, releases, integrations, datasets, pull requests, and concrete roadmaps.&lt;/p&gt;
&lt;p&gt;Looking across the Discourse project updates, the overall picture is clear. This year’s edition produced &lt;strong&gt;more than thirty concrete project outcome threads&lt;/strong&gt;, spanning threat intelligence, malware analysis, detection engineering, vulnerability intelligence, graph exploration, forensics, and infrastructure. Some teams shipped releases on the spot. Others used the two days to validate designs, harden code, identify weaknesses, or connect previously separate tools into more useful workflows.&lt;/p&gt;
&lt;p&gt;The result is a hackathon that delivered not only new features, but also better interoperability across the open-source cybersecurity ecosystem.&lt;/p&gt;
&lt;div style=&#34;position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;&#34;&gt;
      &lt;iframe allow=&#34;accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen&#34; loading=&#34;eager&#34; referrerpolicy=&#34;strict-origin-when-cross-origin&#34; src=&#34;https://www.youtube.com/embed/GPqe-sJkyg8?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0&#34; style=&#34;position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;&#34; title=&#34;YouTube video&#34;&gt;&lt;/iframe&gt;
    &lt;/div&gt;

&lt;h2&gt;The big picture&lt;span class=&#34;hx-absolute -hx-mt-20&#34; id=&#34;the-big-picture&#34;&gt;&lt;/span&gt;
    &lt;a href=&#34;#the-big-picture&#34; class=&#34;subheading-anchor&#34; aria-label=&#34;Permalink for this section&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Several themes stood out across the projects:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&#34;https://misp-project.org/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;MISP&lt;/a&gt; remained a major center of gravity&lt;/strong&gt;, with work on AI-assisted workflows, graph exploration, export formats, hunts, user experience, privacy-preserving workflows, and engineering tooling.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Detection and runtime visibility improved&lt;/strong&gt;, especially around &lt;a href=&#34;https://why.kunai.rocks/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Kunai&lt;/a&gt;, Kubernetes, rootkit detection, and rule handling.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Vulnerability intelligence workflows became more connected&lt;/strong&gt;, with improvements around EPSS and forecast such as &lt;a href=&#34;https://github.com/vulnerability-lookup/TARDISsight&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;TARDISight&lt;/a&gt;, &lt;a href=&#34;https://github.com/vulnerability-lookup/TsunamiSight&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Tsunami sightings&lt;/a&gt;, CPE assignment, and &lt;a href=&#34;https://www.vulnerability-lookup.org/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Vulnerability-Lookup&lt;/a&gt; integrations.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Hackathon outcomes were not limited to shiny features&lt;/strong&gt;: documentation fixes, deployment pain points, code hardening, security assessments, and reproducibility work were all part of the story.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;That balance matters. A healthy open-source security ecosystem needs both innovation and maintenance, and Hackathon.lu 2026 delivered both.&lt;/p&gt;
&lt;h2&gt;MISP saw one of the strongest clusters of outcomes&lt;span class=&#34;hx-absolute -hx-mt-20&#34; id=&#34;misp-saw-one-of-the-strongest-clusters-of-outcomes&#34;&gt;&lt;/span&gt;
    &lt;a href=&#34;#misp-saw-one-of-the-strongest-clusters-of-outcomes&#34; class=&#34;subheading-anchor&#34; aria-label=&#34;Permalink for this section&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;A large share of the visible momentum this year came from projects around &lt;strong&gt;MISP&lt;/strong&gt; and the broader tooling orbit around it.&lt;/p&gt;
&lt;p&gt;One of the most ambitious efforts was &lt;strong&gt;AIPITCH&lt;/strong&gt;, a new round of work on a &lt;strong&gt;&lt;a href=&#34;https://discourse.ossbase.org/t/generic-misp-ai-module-architecture-considerations-second-prototype-implementation-released/1077&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;generic MISP AI module&lt;/a&gt;&lt;/strong&gt;. The team spent the hackathon defining use cases, refining architecture, and producing a second proof-of-concept implementation for combining LLM-based NLP tasks with MISP. Just as importantly, the work emphasized guardrails, testing, metadata, and tagging of AI-assisted output, which suggests a careful and practical approach rather than AI for AI’s sake.&lt;/p&gt;
&lt;p&gt;Another major milestone was the release of &lt;strong&gt;&lt;a href=&#34;https://github.com/MISP/misp-engineering-bay&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;MISP Engineering Bay v1.0&lt;/a&gt;&lt;/strong&gt;, a collection of browser-based authoring tools designed to make it easier to build and maintain MISP data structures. The first release includes an &lt;strong&gt;Object Template Creator&lt;/strong&gt; and a &lt;strong&gt;Galaxy Editor&lt;/strong&gt;, both aimed at reducing the friction of maintaining MISP’s JSON-driven ecosystem.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href=&#34;https://github.com/MISP/misp-workbench&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;MISP Workbench&lt;/a&gt;&lt;/strong&gt; also had a particularly productive hackathon. Reported outcomes included:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MITRE ATT&amp;amp;CK Pattern hunts&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;a new &lt;strong&gt;hunts heatmap&lt;/strong&gt; for coverage visualization&lt;/li&gt;
&lt;li&gt;broader work on &lt;strong&gt;TTP/MITRE hunts&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;an &lt;strong&gt;LLM-assisted query builder&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;JA4+ correlations&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;continued analyst-focused workflow improvements&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Taken together, these updates make Workbench look increasingly like a serious operational layer for large-scale indicator analysis and hunting.&lt;/p&gt;
&lt;p&gt;There was also steady progress on &lt;strong&gt;MISP workflows&lt;/strong&gt; themselves. One thread added support for &lt;strong&gt;misp-module results inside workflow roaming data&lt;/strong&gt; and introduced &lt;strong&gt;workflow environment variables for ad-hoc workflows&lt;/strong&gt;. Another used that work to prototype &lt;strong&gt;privacy-enhancing workflows&lt;/strong&gt;, specifically a **&lt;a href=&#34;https://discourse.ossbase.org/t/privacy-enhancing-technologies-in-misp-workflows/1069&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Private Set Intersection (PSI)** setup that lets separate MISP instances&lt;/a&gt; compare attribute intersections without exposing the underlying sensitive data.&lt;/p&gt;
&lt;p&gt;On the user-experience side, an &lt;strong&gt;&lt;a href=&#34;https://discourse.ossbase.org/t/audio-assistant-in-misp/1060&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Audio Assistant in MISP&lt;/a&gt;&lt;/strong&gt; explored whether event content and summaries can be delivered through speech, including local-model-backed summarization and configurable plugin settings. In parallel, a separate initiative launched &lt;strong&gt;user interviews for CTI practitioners&lt;/strong&gt;, aiming to collect real-world usage patterns and UX personas to feed future MISP development.&lt;/p&gt;
&lt;p&gt;Finally, graph and visualization work was everywhere around the MISP ecosystem. &lt;strong&gt;&lt;a href=&#34;https://github.com/Pivotick/Pivotick&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Pivotick&lt;/a&gt;&lt;/strong&gt; became a recurring thread across multiple projects:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;experimental &lt;strong&gt;integration into MISP&lt;/strong&gt; as a replacement for the correlation graph in the Overmind theme&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;migration of &lt;a href=&#34;https://www.ail-project.org/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;AIL&lt;/a&gt; correlation and relationship graphs&lt;/strong&gt; to &lt;a href=&#34;https://github.com/Pivotick/Pivotick&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Pivotick&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;improvements to &lt;strong&gt;Pivotick UI and rendering&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;updates to &lt;strong&gt;misp-galaxy graph export&lt;/strong&gt; to support Pivotick static output and better filtering&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This recurring use of Pivotick across projects says a lot: visual exploration of CTI relationships is clearly becoming a shared priority.&lt;/p&gt;
&lt;h2&gt;Kunai work focused on real-world deployment and detection depth&lt;span class=&#34;hx-absolute -hx-mt-20&#34; id=&#34;kunai-work-focused-on-real-world-deployment-and-detection-depth&#34;&gt;&lt;/span&gt;
    &lt;a href=&#34;#kunai-work-focused-on-real-world-deployment-and-detection-depth&#34; class=&#34;subheading-anchor&#34; aria-label=&#34;Permalink for this section&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;The &lt;strong&gt;&lt;a href=&#34;https://why.kunai.rocks/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Kunai&lt;/a&gt;&lt;/strong&gt; project had one of the clearest “from lab to operations” tracks during the event.&lt;/p&gt;
&lt;p&gt;A first line of work explored &lt;strong&gt;running Kunai in Kubernetes&lt;/strong&gt;, resulting in a &lt;strong&gt;minimal proof-of-concept configuration&lt;/strong&gt; and a concrete upstream suggestion to make host UUID handling externally configurable. That was then extended by a second project: a &lt;strong&gt;Kubernetes enrichment daemon&lt;/strong&gt; that connects to the local container runtime interface and generates JSON metadata to enrich process context with container and Kubernetes information such as root PID and labels.&lt;/p&gt;
&lt;p&gt;This is exactly the kind of hackathon progression that matters: one topic uncovers a limitation, and a second topic turns that finding into an engineering response.&lt;/p&gt;
&lt;p&gt;A third Kunai thread focused on detection quality. Work on &lt;strong&gt;LinkPro eBPF rootkit analysis&lt;/strong&gt; confirmed that Kunai already detects most suspicious activity associated with the published samples, and the team assembled a &lt;strong&gt;12 GB dataset of potential eBPF malware samples&lt;/strong&gt; for further analysis and future detection improvements.&lt;/p&gt;
&lt;p&gt;On the build and deployment side, Kunai also benefited from a &lt;strong&gt;simplified Dockerfile and reduced container size&lt;/strong&gt;, with a pre-built container published for easier testing and deployment.&lt;/p&gt;
&lt;p&gt;Altogether, the Kunai outcomes show a project maturing across detection, packaging, and cloud-native operations at the same time.&lt;/p&gt;
&lt;h2&gt;Vulnerability intelligence and asset context got tighter integration&lt;span class=&#34;hx-absolute -hx-mt-20&#34; id=&#34;vulnerability-intelligence-and-asset-context-got-tighter-integration&#34;&gt;&lt;/span&gt;
    &lt;a href=&#34;#vulnerability-intelligence-and-asset-context-got-tighter-integration&#34; class=&#34;subheading-anchor&#34; aria-label=&#34;Permalink for this section&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Hackathon.lu 2026 also produced several outcomes that improved the flow between &lt;strong&gt;asset identification&lt;/strong&gt;, &lt;strong&gt;vulnerability metadata&lt;/strong&gt;, and &lt;strong&gt;shared observations&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;For &lt;strong&gt;Vulnerability-Lookup&lt;/strong&gt;, a new &lt;strong&gt;&lt;a href=&#34;https://github.com/vulnerability-lookup/vulnerability-lookup/pull/367&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;EPSS importer&lt;/a&gt;&lt;/strong&gt; was added to fetch daily EPSS data and store per-CVE metadata for later use. That is a practical step toward making exploit-likelihood context more immediately available in open vulnerability workflows.&lt;/p&gt;
&lt;p&gt;A second contribution, &lt;strong&gt;&lt;a href=&#34;https://github.com/vulnerability-lookup/TsunamiSight&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;TsunamiSight&lt;/a&gt;&lt;/strong&gt;, extracts vulnerability-related observations from &lt;strong&gt;Google Tsunami Security Scanner plugins&lt;/strong&gt; and publishes them as &lt;strong&gt;sightings&lt;/strong&gt; to a Vulnerability-Lookup instance. This is a strong example of the kind of bridge-building that hackathons are ideal for: taking useful signals that already exist elsewhere and feeding them into a broader knowledge ecosystem.&lt;/p&gt;
&lt;p&gt;Asset management also saw a useful improvement through the integration of &lt;strong&gt;&lt;a href=&#34;https://github.com/dbarzin/mercator/commit/a340fffcc2f399422a03c9e4798cff832994a830&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;CPE Guesser into Mercator&lt;/a&gt;&lt;/strong&gt;. Users can now search and assign CPE identifiers directly from Mercator’s cartography forms, making the path from component inventory to vulnerability exposure assessment more direct and less error-prone.&lt;/p&gt;
&lt;p&gt;Related work on &lt;strong&gt;&lt;a href=&#34;https://github.com/adulau/cpe-editor&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;CPE Editor&lt;/a&gt;&lt;/strong&gt; looked at how collaborative CPE editing could evolve within the &lt;a href=&#34;https://gcve.eu/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;GCVE&lt;/a&gt; context, including questions around UUID allocation, relationships between vendors and products, and metadata structure. This was more foundational than user-facing, but it points toward the longer-term problem of maintaining better shared product metadata in open ecosystems.&lt;/p&gt;
&lt;h2&gt;Releases, hardening, and maintenance were equally important outcomes&lt;span class=&#34;hx-absolute -hx-mt-20&#34; id=&#34;releases-hardening-and-maintenance-were-equally-important-outcomes&#34;&gt;&lt;/span&gt;
    &lt;a href=&#34;#releases-hardening-and-maintenance-were-equally-important-outcomes&#34; class=&#34;subheading-anchor&#34; aria-label=&#34;Permalink for this section&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;One of the healthiest signs in the Discourse activity is how much work was devoted to &lt;strong&gt;maintenance, fixes, review, and validation&lt;/strong&gt;, not just feature announcements.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href=&#34;https://github.com/MISP/bsimvis&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;BSimVis v0.1.0&lt;/a&gt;&lt;/strong&gt; was released with an API and web interface for binary similarity analysis, function diffing, tagging, filtering, and visualization. That is a tangible shipping outcome.&lt;/p&gt;
&lt;p&gt;The &lt;strong&gt;&lt;a href=&#34;https://github.com/AbstractionsLab/idps-escape&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;IDPS-ESCAPE&lt;/a&gt; / &lt;a href=&#34;https://github.com/AbstractionsLab/satrap-dl&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;SATRAP-DL&lt;/a&gt; / &lt;a href=&#34;https://github.com/AbstractionsLab/PyFlowintel&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;PyFlowintel&lt;/a&gt;&lt;/strong&gt; cluster also reported a productive hackathon, including validation of deployment scenarios, unified configuration work, a prototype management GUI, unit tests, deployment artifact updates, and follow-up changelog entries.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href=&#34;https://github.com/adulau/ssldump/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;SSLDump&lt;/a&gt;&lt;/strong&gt; work focused on code quality and resilience: testing a proposed patch, starting a fix to neutralize control characters in output, refining OpenSSL 3 compatibility work, and integrating bounds-checking improvements identified during review.&lt;/p&gt;
&lt;p&gt;The &lt;strong&gt;&lt;a href=&#34;https://github.com/EC-DIGIT-CSIRC/ec_digit_saf_ta&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Sysdiagnose Analysis Framework (SAF)&lt;/a&gt;&lt;/strong&gt; saw issue fixes, a new case management library, and parser-related improvements, while &lt;strong&gt;AIL/MISP contribution work&lt;/strong&gt; surfaced deployment friction, resulting in documentation clarifications and discussion around removing or replacing confusing legacy installer material.&lt;/p&gt;
&lt;p&gt;Even more valuable was the explicit &lt;strong&gt;vulnerability assessment of &lt;a href=&#34;https://discourse.ossbase.org/t/dnsliar-implementing-a-whitelist/1075&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;DnsLiar&lt;/a&gt;&lt;/strong&gt;. Instead of simply adding features, one thread documented fuzzing, stress testing, logic review, and several concerns: IP leakage behavior, post-forward filtering inefficiency, lack of DNS amplification protections, and risky &lt;code&gt;unwrap&lt;/code&gt; usage in Rust. In parallel, the DnsLiar project itself started work on a &lt;strong&gt;whitelist mechanism&lt;/strong&gt; to improve reproducibility across deployments. Together, those two threads show the kind of constructive, security-minded feedback loop that a good hackathon should encourage.&lt;/p&gt;
&lt;h2&gt;Experimental ideas also moved forward&lt;span class=&#34;hx-absolute -hx-mt-20&#34; id=&#34;experimental-ideas-also-moved-forward&#34;&gt;&lt;/span&gt;
    &lt;a href=&#34;#experimental-ideas-also-moved-forward&#34; class=&#34;subheading-anchor&#34; aria-label=&#34;Permalink for this section&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Not every successful hackathon project ends in a release. Some of the most useful outcomes are prototypes, datasets, design explorations, or proof-of-concept repositories that define the next phase of work.&lt;/p&gt;
&lt;p&gt;That was the case for &lt;strong&gt;location-based document tagging&lt;/strong&gt;, where discussion around geolocation terminology and Bloom filters led to work-in-progress code in the &lt;strong&gt;&lt;a href=&#34;https://github.com/ail-project/fastopic&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;fastopic&lt;/a&gt;&lt;/strong&gt; repository.&lt;/p&gt;
&lt;p&gt;It was also visible in &lt;strong&gt;&lt;a href=&#34;https://rulezet.org/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Rulezet&lt;/a&gt;&lt;/strong&gt;, which explored how detection rules and bundles could be exported into MISP as structured objects and events, and in the &lt;strong&gt;&lt;a href=&#34;https://www.luxprovide.lu/meluxina/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Meluxina&lt;/a&gt;&lt;/strong&gt; thread, which documented practical steps and lessons around using HPC infrastructure and batch jobs for model fine-tuning.&lt;/p&gt;
&lt;p&gt;The &lt;strong&gt;Forensics Training – Bad out of Hell&lt;/strong&gt; topic similarly focused on a concrete training scenario around hidden data in FAT32 and the behavior of forensic tooling, which is exactly the sort of practitioner knowledge that benefits from collaborative experimentation.&lt;/p&gt;
&lt;p&gt;Additional work and research in the area of image correlation was initiated with the team from &lt;a href=&#34;https://www.ucd.ie/cci/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;UCD CCI&lt;/a&gt;, especially on how to enable correlation between &lt;a href=&#34;https://github.com/ail-project/lacus&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Lacus&lt;/a&gt;, &lt;a href=&#34;https://github.com/Lookyloo/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;LookyLoo&lt;/a&gt;, and &lt;a href=&#34;https://ail-project.org/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;AIL&lt;/a&gt;. Different algorithms were reviewed and gathered, which may lead to an additional publication soon.&lt;/p&gt;
&lt;h2&gt;What the 2026 edition tells us&lt;span class=&#34;hx-absolute -hx-mt-20&#34; id=&#34;what-the-2026-edition-tells-us&#34;&gt;&lt;/span&gt;
    &lt;a href=&#34;#what-the-2026-edition-tells-us&#34; class=&#34;subheading-anchor&#34; aria-label=&#34;Permalink for this section&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;The strongest conclusion from the 2026 project roundup is that &lt;strong&gt;Hackathon.lu is operating as an integration engine for open cybersecurity&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;The event is not only helping individual tools improve in isolation. It is creating connections between projects:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;MISP with AI modules, workflows, and graph tooling&lt;/li&gt;
&lt;li&gt;Kunai with Kubernetes context and malware analysis&lt;/li&gt;
&lt;li&gt;Mercator with CPE Guesser and Vulnerability-Lookup&lt;/li&gt;
&lt;li&gt;Tsunami plugins with sightings publication&lt;/li&gt;
&lt;li&gt;Privacy-enhancing techniques with operational CTI workflows&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Just as importantly, the event keeps making room for the unglamorous but essential work: fixing deployment pain, reducing container size, adding tests, reviewing architecture, documenting issues, and identifying security weaknesses before they become bigger problems.&lt;/p&gt;
&lt;p&gt;That is the real outcome of Hackathon.lu 2026. Not a single flagship announcement, but a broad, visible acceleration across a whole ecosystem of free and open-source cybersecurity tools.&lt;/p&gt;
&lt;p&gt;And that is probably the best measure of success for a hackathon like this: when the community leaves not just inspired, but with code merged, releases cut, bugs found, workflows connected, and a clearer map of what to build next.&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://www.youtube.com/watch?v=GPqe-sJkyg8&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;https://www.youtube.com/watch?v=GPqe-sJkyg8&lt;/a&gt;&lt;/p&gt;

      </description>
    </item>
    
    <item>
      <title>hackathon.lu 2026 announced</title>
      <link>https://hackathon.lu/2026/03/19/hackathon.lu-2026-announced/</link>
      <pubDate>Thu, 19 Mar 2026 00:00:00 +0000</pubDate>
      
      <guid>https://hackathon.lu/2026/03/19/hackathon.lu-2026-announced/</guid>
      <description>
        
        
        &lt;p&gt;&lt;img src=&#34;https://hackathon.lu/images/hackathon.png&#34; alt=&#34;logo for hacklathon.lu&#34; loading=&#34;lazy&#34; /&gt;&lt;/p&gt;
&lt;p&gt;The &lt;a href=&#34;https://hack.lu/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;hack.lu&lt;/a&gt; team and &lt;a href=&#34;https://www.circl.lu/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;CIRCL&lt;/a&gt; announce the new hackathon.lu 2026 event.&lt;/p&gt;
&lt;h2&gt;hackathon.lu 2026: Open Source, Security, and Collaboration — with an Open Conference Morning on 14 April&lt;span class=&#34;hx-absolute -hx-mt-20&#34; id=&#34;hackathonlu-2026-open-source-security-and-collaboration--with-an-open-conference-morning-on-14-april&#34;&gt;&lt;/span&gt;
    &lt;a href=&#34;#hackathonlu-2026-open-source-security-and-collaboration--with-an-open-conference-morning-on-14-april&#34; class=&#34;subheading-anchor&#34; aria-label=&#34;Permalink for this section&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;Luxembourg, April 2026&lt;/strong&gt; — hackathon.lu returns on &lt;strong&gt;14–15 April 2026&lt;/strong&gt;, bringing together developers, security professionals, researchers, and Open Source enthusiasts for two days of hands-on collaboration, experimentation, and knowledge sharing in the Grand Duchy of Luxembourg.&lt;/p&gt;
&lt;p&gt;Designed as a &lt;strong&gt;community-driven Open Source hackathon&lt;/strong&gt;, hackathon.lu focuses on building, improving, and challenging real-world tools and ideas — particularly in the areas of security, engineering, and interoperability. The event welcomes participants of all backgrounds, from experienced practitioners to curious newcomers.&lt;/p&gt;
&lt;h2&gt;A Conference Morning to Kick Things Off&lt;span class=&#34;hx-absolute -hx-mt-20&#34; id=&#34;a-conference-morning-to-kick-things-off&#34;&gt;&lt;/span&gt;
    &lt;a href=&#34;#a-conference-morning-to-kick-things-off&#34; class=&#34;subheading-anchor&#34; aria-label=&#34;Permalink for this section&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;To open the event, hackathon.lu will host an &lt;strong&gt;integrated conference morning&lt;/strong&gt; on &lt;strong&gt;Tuesday, 14 April 2026, from 09:00 to 12:00&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;This &lt;strong&gt;informal, breakfast-style conference&lt;/strong&gt; is &lt;strong&gt;open to the public&lt;/strong&gt; and brings together speakers from Open Source and security communities to share short, focused talks. Rather than polished product pitches, the emphasis is on &lt;strong&gt;practical experience, lessons learned, and ideas that invite collaboration&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;The conference morning is designed to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Set the tone for the hackathon&lt;/li&gt;
&lt;li&gt;Spark discussion and cross-pollination of ideas&lt;/li&gt;
&lt;li&gt;Inspire projects that participants can explore during the hackathon itself&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;From Ideas to Action&lt;span class=&#34;hx-absolute -hx-mt-20&#34; id=&#34;from-ideas-to-action&#34;&gt;&lt;/span&gt;
    &lt;a href=&#34;#from-ideas-to-action&#34; class=&#34;subheading-anchor&#34; aria-label=&#34;Permalink for this section&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Following the conference morning, registered hackathon participants will spend the remainder of &lt;strong&gt;14–15 April&lt;/strong&gt; working in small, self-organizing teams on Open Source projects, prototypes, tooling, documentation, and experiments.&lt;/p&gt;
&lt;p&gt;There is no pressure to “finish” — learning, collaboration, and shared progress are the primary goals.&lt;/p&gt;
&lt;h2&gt;Open, Inclusive, and Community-Focused&lt;span class=&#34;hx-absolute -hx-mt-20&#34; id=&#34;open-inclusive-and-community-focused&#34;&gt;&lt;/span&gt;
    &lt;a href=&#34;#open-inclusive-and-community-focused&#34; class=&#34;subheading-anchor&#34; aria-label=&#34;Permalink for this section&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;hackathon.lu is built around the values of:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Open Source and open collaboration&lt;/li&gt;
&lt;li&gt;Knowledge sharing over competition&lt;/li&gt;
&lt;li&gt;Practical, real-world engineering&lt;/li&gt;
&lt;li&gt;Building bridges between communities&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The event is closely aligned with the spirit of &lt;strong&gt;hack.lu&lt;/strong&gt;, Luxembourg’s long-standing security conference.&lt;/p&gt;
&lt;h2&gt;Registration&lt;span class=&#34;hx-absolute -hx-mt-20&#34; id=&#34;registration&#34;&gt;&lt;/span&gt;
    &lt;a href=&#34;#registration&#34; class=&#34;subheading-anchor&#34; aria-label=&#34;Permalink for this section&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Attendance for the &lt;strong&gt;conference morning&lt;/strong&gt; and participation in the &lt;strong&gt;hackathon&lt;/strong&gt; is open via registration:&lt;/p&gt;
&lt;p&gt;👉 &lt;a href=&#34;https://hackathon.lu/practical/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;https://hackathon.lu/practical/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Participation in the hackathon requires registration.&lt;br&gt;
The conference morning is open to interested members of the public.&lt;/p&gt;
&lt;p&gt;👉 Please register a talk through our CfP system: &lt;a href=&#34;https://pretalx.com/hackathon-2026/cfp&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;https://pretalx.com/hackathon-2026/cfp&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Submissions will be reviewed by a program committee, which will select the talks for the conference morning.&lt;/p&gt;
&lt;h2&gt;About hackathon.lu&lt;span class=&#34;hx-absolute -hx-mt-20&#34; id=&#34;about-hackathonlu&#34;&gt;&lt;/span&gt;
    &lt;a href=&#34;#about-hackathonlu&#34; class=&#34;subheading-anchor&#34; aria-label=&#34;Permalink for this section&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;hackathon.lu is an Open Source–focused hackathon held in Luxembourg, bringing together people who want to build, break, fix, and improve technology collaboratively. It provides a space where ideas can be discussed over coffee in the morning — and turned into code by the afternoon.&lt;/p&gt;

      </description>
    </item>
    
    <item>
      <title>Successful Outcomes from the Hackathon.lu 2025 in Luxembourg</title>
      <link>https://hackathon.lu/2025/04/11/hackathon.lu-2025-outcome/</link>
      <pubDate>Fri, 11 Apr 2025 00:00:00 +0000</pubDate>
      
      <guid>https://hackathon.lu/2025/04/11/hackathon.lu-2025-outcome/</guid>
      <description>
        
        
        &lt;p&gt;&lt;img src=&#34;https://hackathon.lu/images/hackathon.png&#34; alt=&#34;logo for hacklathon.lu&#34; loading=&#34;lazy&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Press Release: Successful Outcomes from the Hackathon.lu 2025 in Luxembourg&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Luxembourg, April 9, 2025&lt;/em&gt; – The Hackathon 2025, held from April 8 to 9, has successfully brought together a global community of more than 50 cybersecurity experts, developers, and innovators, all working toward advancing the realm of free and open-source software (FOSS) in cybersecurity. Hosted in Luxembourg, the hackathon focused on building cutting-edge tools and improving existing systems to enhance security in a rapidly evolving digital world.&lt;/p&gt;
&lt;p&gt;Organized as part of the renowned &lt;em&gt;hack.lu&lt;/em&gt; event series, Hackathon 2025 saw remarkable collaboration across teams, resulting in the successful implementation of several key software updates, tools, and features. The event underscored the power of open-source technology in driving advancements in cybersecurity, and participants demonstrated the vital role of innovation in strengthening digital defenses.&lt;/p&gt;
&lt;p&gt;We would like to thank all the participants who contributed their time and creativity to make this hackathon a success, as well as our sponsors, POST Luxembourg and Conostix, for providing the infrastructure support.&lt;/p&gt;
&lt;p&gt;Looking ahead, the &lt;em&gt;hackathon.lu&lt;/em&gt; team is already planning the next edition of the event, scheduled for April 2026. As a reminder, the &lt;em&gt;hack.lu&lt;/em&gt; security conference—one of Europe’s leading cybersecurity events—will take place from October 21-24, 2025, at the Alvisse Parc Hotel in Dommeldange, Luxembourg. Early bird tickets are still available for a few more days at &lt;a href=&#34;https://2025.hack.lu/info/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;https://2025.hack.lu/info/&lt;/a&gt;. Additionally, the &lt;em&gt;hack.lu&lt;/em&gt; Call for Papers (CFP) is open, and cybersecurity experts are encouraged to submit their proposals at &lt;a href=&#34;https://pretalx.com/hack-lu-2025/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;https://pretalx.com/hack-lu-2025/&lt;/a&gt;. For those looking to support the event, there are still a few sponsoring opportunities available at &lt;a href=&#34;https://2025.hack.lu/sponsoring/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;https://2025.hack.lu/sponsoring/&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://hackathon.lu/images/hackathon2025-1.jpg&#34; alt=&#34;hackathon.lu 2025&#34; loading=&#34;lazy&#34; /&gt;
&lt;img src=&#34;https://hackathon.lu/images/hackathon2025-2.jpg&#34; alt=&#34;hackathon.lu 2025&#34; loading=&#34;lazy&#34; /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Highlights of the Successful Projects and Contribution:&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;MISP Fleet Commander Release&lt;/strong&gt;&lt;br&gt;
The MISP Fleet Commander, a new management interface for MISP instances, was launched with the goal of streamlining the operational management for security analysts. This tool significantly reduces the complexities involved in maintaining multiple MISP instances, thus improving overall efficiency in threat intelligence sharing.&lt;br&gt;
&lt;a href=&#34;https://discourse.ossbase.org/t/misp-fleet-commander/85&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Read more on Discourse&lt;/a&gt; | &lt;a href=&#34;https://github.com/MISP/misp-fleet-commander&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;GitHub Repository&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Lacus v1.13.1&lt;/strong&gt;&lt;br&gt;
Lacus, a data analysis platform, saw an impressive update with version 1.13.1. The new release enhances the tool&amp;rsquo;s capabilities in managing and processing large sets of security data, providing users with more efficient and comprehensive data analysis.&lt;br&gt;
&lt;a href=&#34;https://discourse.ossbase.org/t/lacus-v1131-release/85&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Read more on Discourse&lt;/a&gt; | &lt;a href=&#34;https://github.com/ail-project/LacusCore/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;GitHub Repository&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Lookyloo v1.28.1&lt;/strong&gt;&lt;br&gt;
Lookyloo, a tool for visualizing web infrastructure, was upgraded to version 1.28.1, introducing new functionalities that provide deeper insights into web structures. This tool aids cybersecurity professionals in mapping out potential vulnerabilities in web applications, ensuring proactive security measures are in place.&lt;br&gt;
&lt;a href=&#34;https://discourse.ossbase.org/t/lookyloo-v1281-release/85&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Read more on Discourse&lt;/a&gt; | &lt;a href=&#34;https://github.com/Lookyloo/Lookyloo&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;GitHub Repository&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Flowintel Enhancements&lt;/strong&gt;&lt;br&gt;
Flowintel, a platform for network traffic analysis, received vital improvements, making it more effective at detecting and analyzing cyber threats in real time. These enhancements bolster the tool’s capabilities in identifying unusual patterns in network data and provide better insights for responding to incidents.&lt;br&gt;
&lt;a href=&#34;https://discourse.ossbase.org/t/docker-fix-for-flowintel/78&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Read more on Discourse&lt;/a&gt; | &lt;a href=&#34;https://github.com/Flowintel/flowintel&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;GitHub Repository&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Kunai-Sandbox v0.1.4 Release&lt;/strong&gt;&lt;br&gt;
The Kunai-Sandbox, a malware analysis tool, introduced new updates aimed at improving the efficiency of malware detection and analysis. This release brings enhanced sandboxing capabilities, providing a more secure environment for analyzing suspicious files and activities.&lt;br&gt;
&lt;a href=&#34;https://discourse.ossbase.org/t/kunai-sandbox-v014/85&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Read more on Discourse&lt;/a&gt; | &lt;a href=&#34;https://github.com/kunai-project/sandbox&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;GitHub Repository&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Pykunai v0.1.5&lt;/strong&gt;&lt;br&gt;
Pykunai, a tool designed to improve security operations and integration with Kunai, received a new update with version 0.1.5, which focuses on enhancing the tool’s functionality for cybersecurity professionals. This update streamlines several processes, making threat identification and response faster and more effective.&lt;br&gt;
&lt;a href=&#34;https://discourse.ossbase.org/t/pykunai-v015/85&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Read more on Discourse&lt;/a&gt; | &lt;a href=&#34;https://github.com/kunai-project/pykunai&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;GitHub Repository&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Vulnerability-Lookup Enhancements&lt;/strong&gt;&lt;br&gt;
The Vulnerability-Lookup platform received key updates that enhance its ability to manage and identify vulnerabilities across various systems. These improvements ensure that security teams have timely and accurate information when responding to potential security threats.&lt;br&gt;
&lt;a href=&#34;https://discourse.ossbase.org/t/vulnerability-lookup-improvements/85&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Read more on Discourse&lt;/a&gt; | &lt;a href=&#34;https://github.com/vulnerability-lookup/vulnerability-lookup&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;GitHub Repository&lt;/a&gt; | &lt;a href=&#34;https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v2.8.0&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Release v2.8.0 including hackathon.lu contribution&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;New MISP object summariser-output added in MISP&lt;/strong&gt;&lt;br&gt;
In the objective to extend AI-support in MISP, a new &lt;code&gt;summariser-output&lt;/code&gt; object template has been added. During the hackathon, a new pipeline to support RSS gathering and AI-summarisation was developed.
&lt;a href=&#34;https://discourse.ossbase.org/t/new-misp-object-summariser-output-added-in-misp/67&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Read more on Discourse&lt;/a&gt; | &lt;a href=&#34;https://github.com/MISP/misp-objects/commit/052a2d6b0d8b2ccd02499e4324939131393fec99&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;GitHub Repository&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Virgil v0.1.0 Launch&lt;/strong&gt;&lt;br&gt;
The introduction of Virgil, a new security analysis tool, marked a significant milestone in the hackathon. Designed to enhance the analysis capabilities of security professionals, Virgil promises to become an essential tool in the fight against cybercrime.&lt;br&gt;
&lt;a href=&#34;https://discourse.ossbase.org/t/virgil-v010-release/85&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Read more on Discourse&lt;/a&gt; | &lt;a href=&#34;https://github.com/Yoyodyne-IT/Virgil&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;GitHub Repository&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;MISP OpenAPI Documentation&lt;/strong&gt;&lt;br&gt;
Another key accomplishment was the development of an improved comprehensive documentation for MISP’s collections endpoints. This new documentation aims to make it easier for users to implement MISP’s powerful features, fostering wider adoption of the platform across the cybersecurity community. Various updates were done on the OpenAPI specification.&lt;br&gt;
&lt;a href=&#34;https://discourse.ossbase.org/t/misp-openapi-docs/85&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Read more on Discourse&lt;/a&gt; | &lt;a href=&#34;https://github.com/MISP/misp-openapi&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;GitHub Repository&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;MISP MCP: Natural Language Interface&lt;/strong&gt;&lt;br&gt;
A groundbreaking development was the integration of natural language processing (NLP) into MISP via the MISP MCP (MISP Cloud Platform). This feature allows users to interact with MISP using natural language, enabling non-technical stakeholders to query and manage cybersecurity data more easily.&lt;br&gt;
&lt;a href=&#34;https://discourse.ossbase.org/t/misp-mcp-interact-with-misp-through-natural-language/85&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Read more on Discourse&lt;/a&gt; | &lt;a href=&#34;https://github.com/Eacus/misp-mcp&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;GitHub Repository&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Flowintel Docker Fix&lt;/strong&gt;&lt;br&gt;
Flowintel also saw a crucial update, resolving Docker compatibility issues, ensuring that the platform runs seamlessly in containerized environments. This fix allows users to deploy Flowintel in a more flexible and scalable manner.&lt;br&gt;
&lt;a href=&#34;https://discourse.ossbase.org/t/docker-fix-for-flowintel/78&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Read more on Discourse&lt;/a&gt; | &lt;a href=&#34;https://github.com/Flowintel/flowintel&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;GitHub Repository&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Sysdiagnose Submissions&lt;/strong&gt;&lt;br&gt;
A new tool was introduced for automating the submission of sysdiagnostic information from mobile phone, improving incident response by enabling faster troubleshooting of system issues and providing richer context to cybersecurity teams.&lt;br&gt;
&lt;a href=&#34;https://discourse.ossbase.org/t/sysdiagnose-submissions/76&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Read more on Discourse&lt;/a&gt; | &lt;a href=&#34;https://github.com/EC-DIGIT-CSIRC/sysdiagnose&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;GitHub Repository&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;AIL Geospatial Analyst Module&lt;/strong&gt;&lt;br&gt;
The AIL (Analysis Information Leak) platform introduced a new Geospatial Analyst module, enhancing the ability to map and analyze geographic information within cybersecurity operations. This addition greatly improves the visualization of threats and incidents based on location.&lt;br&gt;
&lt;a href=&#34;https://discourse.ossbase.org/t/ail-geospatial-analyst-module-available/75&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Read more on Discourse&lt;/a&gt; | &lt;a href=&#34;https://github.com/ail-project/ail-framework/pull/269&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;GitHub Repository&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;MISP Lite OpenSearch Integration&lt;/strong&gt;&lt;br&gt;
A notable update was the integration of MISP Lite with OpenSearch, enabling faster and more efficient querying of threat intelligence data. This improvement strengthens MISP Lite’s role in smaller-scale security environments that rely on performance and scalability.&lt;br&gt;
&lt;a href=&#34;https://discourse.ossbase.org/t/misp-lite-opensearch-integration/72&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Read more on Discourse&lt;/a&gt; | &lt;a href=&#34;https://github.com/flowintel/misp-lite&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;GitHub Repository&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Embedded Device Feed for MISP&lt;/strong&gt;&lt;br&gt;
A new feed was added to MISP specifically for tracking vulnerabilities in embedded devices. This feed aims to address the growing concerns around Internet of Things (IoT) security by providing timely and relevant intelligence on potential threats.&lt;br&gt;
&lt;a href=&#34;https://discourse.ossbase.org/t/add-new-feed-for-embedded-devices/63&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Read more on Discourse&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;ADBox Algorithmic Multiplexing&lt;/strong&gt;&lt;br&gt;
ADBox, a tool for Active Directory auditing, received a major update with the addition of algorithmic multiplexing, improving its ability to process and analyze large datasets. This enhancement makes ADBox more efficient at detecting malicious activities in complex networks.&lt;br&gt;
&lt;a href=&#34;https://discourse.ossbase.org/t/task-algorithmic-multiplexing-adding-a-new-ad-implementation-to-adbox/57&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Read more on Discourse&lt;/a&gt; | &lt;a href=&#34;https://github.com/AbstractionsLab/idps-escape&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;GitHub Repository&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Suricata Rules Generation Enhancement for MISP&lt;/strong&gt;&lt;br&gt;
MISP’s capabilities were further improved with an update focused on generating better &lt;a href=&#34;https://suricata.io/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Suricata&lt;/a&gt; rules. This change allows MISP users to produce more accurate and effective rules for intrusion detection systems, strengthening network defenses.&lt;br&gt;
&lt;a href=&#34;https://discourse.ossbase.org/t/updating-misp-for-generation-of-better-suricata-rules/56&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Read more on Discourse&lt;/a&gt; | &lt;a href=&#34;https://github.com/MISP/MISP/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;GitHub Repository&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Certificate Transparency Support in Cocktailparty&lt;/strong&gt;&lt;br&gt;
Cocktailparty, a tool for streaming cybersecurity data feed, added support for certificate transparency, enabling more efficient detection of certificate-related threats. This update will help teams stay ahead of potential security risks linked to certificate mismanagement.&lt;br&gt;
&lt;a href=&#34;https://discourse.ossbase.org/t/support-of-certificate-transparency-in-cocktailparty/83&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Read more on Discourse&lt;/a&gt; | &lt;a href=&#34;https://github.com/flowintel/cocktailparty&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;GitHub Repository&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Codeclarity Sends Sightings to Vulnerability Lookup&lt;/strong&gt;&lt;br&gt;
&lt;a href=&#34;https://github.com/CodeClarityCE&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Codeclarity&lt;/a&gt;, a platform for vulnerability analysis, introduced a new feature that automatically sends sightings to the Vulnerability Lookup platform. This integration allows teams to rapidly identify and respond to potential security threats by correlating findings with an updated vulnerability database.&lt;br&gt;
&lt;a href=&#34;https://discourse.ossbase.org/t/codeclarity-sends-sightings-to-vulnerability-lookup/81&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Read more on Discourse&lt;/a&gt; | &lt;a href=&#34;https://github.com/CodeClarityCE&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;GitHub Repository&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Replacement of Redis with Valkey in AIL Project&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;As many projects aim to maintain a fully open-source stack, a proposal has been made to replace Redis with Valkey in the AIL project.&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://github.com/ail-project/ail-framework/pull/268&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Pull-request&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;LexiLang language detection improved in AIL Project&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Pull request was made during the hackathon.lu for the LexiLang project (used by the AIL Project) introduces the following changes: To improve language detection, it includes a major cleanup and refinement of language dictionaries to reduce false positives.
It also enhances accuracy by removing ambiguous or low-quality entries from the dictionaries.
This is a significant improvement for AIL, enabling better language detection with fewer false positives.&lt;/p&gt;
&lt;p&gt;For more details: &lt;a href=&#34;https://github.com/LibreTranslate/LexiLang/pull/17&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;LexiLang improvement&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;Summary:&lt;/strong&gt;
The Hackathon 2025 in Luxembourg showcased an impressive array of innovative open-source cybersecurity tools and updates, developed in just two days by a global community of experts. Participants collaborated intensively to create impactful solutions, enhancing threat intelligence sharing, vulnerability detection, and network security. The event highlighted the power of open-source collaboration in driving rapid advancements in the cybersecurity field.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Looking Ahead:&lt;/strong&gt;
The Hackathon 2025 demonstrates the power of collaboration, community-driven development, and open-source technology in advancing cybersecurity. With these new tools and updates, cybersecurity professionals are better equipped to combat the growing range of cyber threats in today’s interconnected world. The event has successfully illustrated the critical role of innovation in keeping digital infrastructures safe and resilient.&lt;/p&gt;
&lt;p&gt;Participants, organizers, and contributors from around the world are already looking forward to future editions of the hackathon, where they can continue to push the boundaries of cybersecurity and build stronger defenses for global digital ecosystems.&lt;/p&gt;
&lt;p&gt;For more information about the Hackathon 2025 and the projects developed, please visit &lt;a href=&#34;https://hackathon.lu&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;hackathon.lu&lt;/a&gt;.&lt;/p&gt;

      </description>
    </item>
    
    <item>
      <title>hackathon.lu 2025 announced</title>
      <link>https://hackathon.lu/2024/12/24/hackathon.lu-2025-announced/</link>
      <pubDate>Tue, 24 Dec 2024 00:00:00 +0000</pubDate>
      
      <guid>https://hackathon.lu/2024/12/24/hackathon.lu-2025-announced/</guid>
      <description>
        
        
        &lt;p&gt;&lt;img src=&#34;https://hackathon.lu/images/hackathon.png&#34; alt=&#34;logo for hacklathon.lu&#34; loading=&#34;lazy&#34; /&gt;&lt;/p&gt;
&lt;p&gt;The &lt;a href=&#34;https://hack.lu/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;hack.lu&lt;/a&gt; team and &lt;a href=&#34;https://www.circl.lu/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;CIRCL&lt;/a&gt; announce the new hackathon.lu 2025 event.&lt;/p&gt;
&lt;p&gt;This 2-day physical Hackathon, held in Luxembourg on April 8th and 9th, 2025, focuses on the development of free and open-source software for cybersecurity. We aim to convene diverse developer groups to collaborate on complex programming challenges within key cybersecurity areas, such as information sharing, threat intelligence, network and system forensics, data mining, network and computer exploitation, and defense techniques. The hackathon&amp;rsquo;s objectives include improving existing open-source security &lt;a href=&#34;https://hackathon.lu/projects/&#34; &gt;projects&lt;/a&gt;, enhancing interoperability and integration between different security tools, and driving the creation of innovative new solutions.&lt;/p&gt;
&lt;p&gt;The hackathon will emphasize tackling complex challenges, whether by enhancing existing projects or creating new ones, with a focus on how in-person collaboration and interaction can help overcome specific obstacles. We encourage activities both before and after the hackathon to maximize productivity and ensure the event is a catalyst for impactful progress. We aim to foster collaboration with both existing and new projects while building stronger trust within collaborative groups.&lt;/p&gt;
&lt;p&gt;Many &lt;a href=&#34;https://hackathon.lu/projects/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;open-source security projects&lt;/a&gt; will be at the hackathon, including the MISP Project, AIL Project, Kunai, Flowintel, Lacus, Lookyloo, Pandora, Vulnerability-Lookup, OISF and Suricata. If you&amp;rsquo;d like to join us or propose a specific project for the hackathon, feel free to &lt;a href=&#34;https://hackathon.lu/practical/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;get in touch&lt;/a&gt;!&lt;/p&gt;
&lt;p&gt;Ready to join? Register here: &lt;a href=&#34;https://hackathon.lu/practical/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;https://hackathon.lu/practical/&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If you&amp;rsquo;re leading a project, we encourage you to submit your proposal. We&amp;rsquo;re enthusiastic about expanding our project list for the hackathon.&lt;/p&gt;

      </description>
    </item>
    
  </channel>
</rss>

