home.social

#wazuh — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #wazuh, aggregated by home.social.

fetched live
  1. Как собрать базовый стек для защиты инфраструктуры на open source

    Привет, Хабр! На связи Виктор Иевлев, я руковожу отделом информационной безопасности в «Гарде». Полноценную защиту корпоративной инфраструктуры сегодня сложно представить без коммерческих средств защиты информации. Однако далеко не каждая компания может позволить себе сразу построить такой стек. Стартапы, небольшие организации, компании с ограниченным бюджетом зачастую вынуждены искать компромиссные решения и использовать open source. Я уже рассказывал в одной из статей об open source-сканерах уязвимостей. В этот раз предлагаю остановиться на защитных решениях и попробовать собрать минимальный стек на базе open source. Узнать подробности

    habr.com/ru/companies/garda/ar

    #open_source #firewall #siem #wazuh #ids #xdr #защита_информации #информационная_безопасность

  2. Как собрать базовый стек для защиты инфраструктуры на open source

    Привет, Хабр! На связи Виктор Иевлев, я руковожу отделом информационной безопасности в «Гарде». Полноценную защиту корпоративной инфраструктуры сегодня сложно представить без коммерческих средств защиты информации. Однако далеко не каждая компания может позволить себе сразу построить такой стек. Стартапы, небольшие организации, компании с ограниченным бюджетом зачастую вынуждены искать компромиссные решения и использовать open source. Я уже рассказывал в одной из статей об open source-сканерах уязвимостей. В этот раз предлагаю остановиться на защитных решениях и попробовать собрать минимальный стек на базе open source. Узнать подробности

    habr.com/ru/companies/garda/ar

    #open_source #firewall #siem #wazuh #ids #xdr #защита_информации #информационная_безопасность

  3. Как собрать базовый стек для защиты инфраструктуры на open source

    Привет, Хабр! На связи Виктор Иевлев, я руковожу отделом информационной безопасности в «Гарде». Полноценную защиту корпоративной инфраструктуры сегодня сложно представить без коммерческих средств защиты информации. Однако далеко не каждая компания может позволить себе сразу построить такой стек. Стартапы, небольшие организации, компании с ограниченным бюджетом зачастую вынуждены искать компромиссные решения и использовать open source. Я уже рассказывал в одной из статей об open source-сканерах уязвимостей. В этот раз предлагаю остановиться на защитных решениях и попробовать собрать минимальный стек на базе open source. Узнать подробности

    habr.com/ru/companies/garda/ar

    #open_source #firewall #siem #wazuh #ids #xdr #защита_информации #информационная_безопасность

  4. Ultimate Guide to #VPS #Security Hardening

    This article provides a guide to VPS security hardening.

    Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing discipline. Whether you’re hosting websites, applications, databases, or client workloads, a hardened VPS dramatically reduces the risk of compromise, data loss, downtime, and reputation ...
    Continued 👉 blog.radwebhosting.com/vps-sec #ossec #firewalld #wazuh #vpsguide #rockylinux #ufw #logwatch #netdata #prometheus #grafana

  5. Ultimate Guide to #VPS #Security Hardening

    This article provides a guide to VPS security hardening.

    Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing discipline. Whether you’re hosting websites, applications, databases, or client workloads, a hardened VPS dramatically reduces the risk of compromise, data loss, downtime, and reputation ...
    Continued 👉 blog.radwebhosting.com/vps-sec #ossec #firewalld #wazuh #vpsguide #rockylinux #ufw #logwatch #netdata #prometheus #grafana

  6. Ultimate Guide to #VPS #Security Hardening

    This article provides a guide to VPS security hardening.

    Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing discipline. Whether you’re hosting websites, applications, databases, or client workloads, a hardened VPS dramatically reduces the risk of compromise, data loss, downtime, and reputation ...
    Continued 👉 blog.radwebhosting.com/vps-sec #ossec #firewalld #wazuh #vpsguide #rockylinux #ufw #logwatch #netdata #prometheus #grafana

  7. ⚠️ #Wazuh cluster flaws enable manager takeover

    Cluster vulnerabilities can expose secrets, bypass #RBAC and chain into privileged actions or full manager compromise.
    🔗 read more: securityonline.info/...

    #ransomNews #cybersecurity

  8. ⚠️ #Wazuh cluster flaws enable manager takeover

    Cluster vulnerabilities can expose secrets, bypass #RBAC and chain into privileged actions or full manager compromise.
    🔗 read more: securityonline.info/...

    #ransomNews #cybersecurity

  9. ⚠️ #Wazuh cluster flaws enable manager takeover

    Cluster vulnerabilities can expose secrets, bypass #RBAC and chain into privileged actions or full manager compromise.
    🔗 read more: securityonline.info/...

    #ransomNews #cybersecurity

  10. ⚠️ #Wazuh cluster flaws enable manager takeover

    Cluster vulnerabilities can expose secrets, bypass #RBAC and chain into privileged actions or full manager compromise.
    🔗 read more: securityonline.info/...

    #ransomNews #cybersecurity

  11. ⚠️ #Wazuh cluster flaws enable manager takeover

    Cluster vulnerabilities can expose secrets, bypass #RBAC and chain into privileged actions or full manager compromise.
    🔗 read more: securityonline.info/...

    #ransomNews #cybersecurity

  12. Tired of Wazuh false positives from broad rule groups like 'syslog' or 'generic'? Query wazuh.db directly: join rules & groups tables to count per group, then tighten overly permissive ones. Works on Wazuh 4.x. #wazuh #sqlite #ValtersIT

    valtersit.com/vault/detect-ove

  13. Tired of Wazuh false positives from broad rule groups like 'syslog' or 'generic'? Query wazuh.db directly: join rules & groups tables to count per group, then tighten overly permissive ones. Works on Wazuh 4.x. #wazuh #sqlite #ValtersIT

    valtersit.com/vault/detect-ove

  14. Ultimate Guide to #VPS #Security Hardening

    This article provides a guide to VPS security hardening.

    Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing discipline. Whether you’re hosting websites, applications, databases, or client workloads, a hardened VPS dramatically reduces the risk of compromise, data loss, downtime, and reputation ...
    Continued 👉 blog.radwebhosting.com/vps-sec #ossec #rockylinux #prometheus #logwatch #firewalld #vpsguide #grafana #ufw #netdata #wazuh

  15. Ultimate Guide to #VPS #Security Hardening

    This article provides a guide to VPS security hardening.

    Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing discipline. Whether you’re hosting websites, applications, databases, or client workloads, a hardened VPS dramatically reduces the risk of compromise, data loss, downtime, and reputation ...
    Continued 👉 blog.radwebhosting.com/vps-sec #ossec #rockylinux #prometheus #logwatch #firewalld #vpsguide #grafana #ufw #netdata #wazuh

  16. Ultimate Guide to #VPS #Security Hardening

    This article provides a guide to VPS security hardening.

    Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing discipline. Whether you’re hosting websites, applications, databases, or client workloads, a hardened VPS dramatically reduces the risk of compromise, data loss, downtime, and reputation ...
    Continued 👉 blog.radwebhosting.com/vps-sec #ossec #rockylinux #prometheus #logwatch #firewalld #vpsguide #grafana #ufw #netdata #wazuh

  17. Ultimate Guide to #VPS #Security Hardening

    This article provides a guide to VPS security hardening.

    Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing discipline. Whether you’re hosting websites, applications, databases, or client workloads, a hardened VPS dramatically reduces the risk of compromise, data loss, downtime, and reputation ...
    Continued 👉 blog.radwebhosting.com/vps-sec #ossec #rockylinux #prometheus #logwatch #firewalld #vpsguide #grafana #ufw #netdata #wazuh

  18. three critical (9.1) advisories for wazuh i reported were published today. same trust assumption broken in three places: the cluster fernet key authenticates membership, and the cluster protocol then lets that peer pick filesystem paths.

    CVE-2026-49441: the peer-supplied metadata key in process_files_from_worker is used directly as the destination path. write etc/ossec.conf, root rce via wazuh-logcollector.

    CVE-2026-48024: same function, merged-file branch. traversal in the merged header name and in merge_type.

    CVE-2026-48162: the DAPI tmp_file field is joined to WAZUH_PATH with os.path.join and shipped back to the peer. absolute paths win, so it reads anything the wazuh user can open. grab private_key.pem, forge ES512 admin jwts offline. survives cluster key rotation, since the jwt keypair is a different scope.

    patched in 4.14.6.

    github.com/wazuh/wazuh/securit

    github.com/wazuh/wazuh/securit

    github.com/wazuh/wazuh/securit

    #Wazuh #InfoSec #CVE #SIEM #ResponsibleDisclosure #CyberSecurity

  19. three critical (9.1) advisories for wazuh i reported were published today. same trust assumption broken in three places: the cluster fernet key authenticates membership, and the cluster protocol then lets that peer pick filesystem paths.

    CVE-2026-49441: the peer-supplied metadata key in process_files_from_worker is used directly as the destination path. write etc/ossec.conf, root rce via wazuh-logcollector.

    CVE-2026-48024: same function, merged-file branch. traversal in the merged header name and in merge_type.

    CVE-2026-48162: the DAPI tmp_file field is joined to WAZUH_PATH with os.path.join and shipped back to the peer. absolute paths win, so it reads anything the wazuh user can open. grab private_key.pem, forge ES512 admin jwts offline. survives cluster key rotation, since the jwt keypair is a different scope.

    patched in 4.14.6.

    github.com/wazuh/wazuh/securit

    github.com/wazuh/wazuh/securit

    github.com/wazuh/wazuh/securit

    #Wazuh #InfoSec #CVE #SIEM #ResponsibleDisclosure #CyberSecurity

  20. three critical (9.1) advisories for wazuh i reported were published today. same trust assumption broken in three places: the cluster fernet key authenticates membership, and the cluster protocol then lets that peer pick filesystem paths.

    CVE-2026-49441: the peer-supplied metadata key in process_files_from_worker is used directly as the destination path. write etc/ossec.conf, root rce via wazuh-logcollector.

    CVE-2026-48024: same function, merged-file branch. traversal in the merged header name and in merge_type.

    CVE-2026-48162: the DAPI tmp_file field is joined to WAZUH_PATH with os.path.join and shipped back to the peer. absolute paths win, so it reads anything the wazuh user can open. grab private_key.pem, forge ES512 admin jwts offline. survives cluster key rotation, since the jwt keypair is a different scope.

    patched in 4.14.6.

    github.com/wazuh/wazuh/securit

    github.com/wazuh/wazuh/securit

    github.com/wazuh/wazuh/securit

    #Wazuh #InfoSec #CVE #SIEM #ResponsibleDisclosure #CyberSecurity

  21. three critical (9.1) advisories for wazuh i reported were published today. same trust assumption broken in three places: the cluster fernet key authenticates membership, and the cluster protocol then lets that peer pick filesystem paths.

    CVE-2026-49441: the peer-supplied metadata key in process_files_from_worker is used directly as the destination path. write etc/ossec.conf, root rce via wazuh-logcollector.

    CVE-2026-48024: same function, merged-file branch. traversal in the merged header name and in merge_type.

    CVE-2026-48162: the DAPI tmp_file field is joined to WAZUH_PATH with os.path.join and shipped back to the peer. absolute paths win, so it reads anything the wazuh user can open. grab private_key.pem, forge ES512 admin jwts offline. survives cluster key rotation, since the jwt keypair is a different scope.

    patched in 4.14.6.

    github.com/wazuh/wazuh/securit

    github.com/wazuh/wazuh/securit

    github.com/wazuh/wazuh/securit

    #Wazuh #InfoSec #CVE #SIEM #ResponsibleDisclosure #CyberSecurity

  22. three critical (9.1) advisories for wazuh i reported were published today. same trust assumption broken in three places: the cluster fernet key authenticates membership, and the cluster protocol then lets that peer pick filesystem paths.

    CVE-2026-49441: the peer-supplied metadata key in process_files_from_worker is used directly as the destination path. write etc/ossec.conf, root rce via wazuh-logcollector.

    CVE-2026-48024: same function, merged-file branch. traversal in the merged header name and in merge_type.

    CVE-2026-48162: the DAPI tmp_file field is joined to WAZUH_PATH with os.path.join and shipped back to the peer. absolute paths win, so it reads anything the wazuh user can open. grab private_key.pem, forge ES512 admin jwts offline. survives cluster key rotation, since the jwt keypair is a different scope.

    patched in 4.14.6.

    github.com/wazuh/wazuh/securit

    github.com/wazuh/wazuh/securit

    github.com/wazuh/wazuh/securit

    #Wazuh #InfoSec #CVE #SIEM #ResponsibleDisclosure #CyberSecurity

  23. Ultimate Guide to #VPS #Security Hardening

    This article provides a guide to VPS security hardening.

    Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ...
    Continued 👉 #ufw #logwatch #grafana #wazuh #prometheus #rockylinux #ossec #firewalld #vpsguide #netdata

    Ultimate Guide to VPS Security...

  24. Ultimate Guide to #VPS #Security Hardening

    This article provides a guide to VPS security hardening.

    Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing discipline. Whether you’re hosting websites, applications, databases, or client workloads, a hardened VPS dramatically reduces the risk of compromise, data loss, downtime, and ...
    Continued 👉 blog.radwebhosting.com/vps-sec #ossec #rockylinux #ufw #prometheus #netdata #firewalld #logwatch #grafana #wazuh #vpsguide

  25. Ultimate Guide to #VPS #Security Hardening

    This article provides a guide to VPS security hardening.

    Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing discipline. Whether you’re hosting websites, applications, databases, or client workloads, a hardened VPS dramatically reduces the risk of compromise, data loss, downtime, and ...
    Continued 👉 blog.radwebhosting.com/vps-sec #ossec #rockylinux #ufw #prometheus #netdata #firewalld #logwatch #grafana #wazuh #vpsguide

  26. Ultimate Guide to #VPS #Security Hardening

    This article provides a guide to VPS security hardening.

    Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing discipline. Whether you’re hosting websites, applications, databases, or client workloads, a hardened VPS dramatically reduces the risk of compromise, data loss, downtime, and ...
    Continued 👉 blog.radwebhosting.com/vps-sec #ossec #rockylinux #ufw #prometheus #netdata #firewalld #logwatch #grafana #wazuh #vpsguide

  27. Ultimate Guide to #VPS #Security Hardening

    This article provides a guide to VPS security hardening.

    Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ...
    Continued 👉 #ufw #vpsguide #firewalld #grafana #wazuh #ossec #prometheus #netdata #logwatch #rockylinux

    Ultimate Guide to VPS Security...

  28. Panel auto-hospedado, gratuito y de código abierto para gestionar nuestra red LAN y NAS:
    wazuh.com/
    #wazuh

  29. Panel auto-hospedado, gratuito y de código abierto para gestionar nuestra red LAN y NAS:
    wazuh.com/
    #wazuh

  30. Panel auto-hospedado, gratuito y de código abierto para gestionar nuestra red LAN y NAS:
    wazuh.com/
    #wazuh

  31. Panel auto-hospedado, gratuito y de código abierto para gestionar nuestra red LAN y NAS:
    wazuh.com/
    #wazuh

  32. Panel auto-hospedado, gratuito y de código abierto para gestionar nuestra red LAN y NAS:
    wazuh.com/
    #wazuh

  33. Ultimate Guide to #VPS #Security Hardening

    This article provides a guide to VPS security hardening.

    Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing discipline. Whether you’re hosting websites, applications, databases, or client workloads, a hardened VPS dramatically reduces the risk of compromise, data loss, downtime, and ...
    Continued 👉 blog.radwebhosting.com/vps-sec #prometheus #vpsguide #firewalld #ossec #wazuh #rockylinux #ufw #logwatch #grafana #netdata

  34. Ultimate Guide to #VPS #Security Hardening

    This article provides a guide to VPS security hardening.

    Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing discipline. Whether you’re hosting websites, applications, databases, or client workloads, a hardened VPS dramatically reduces the risk of compromise, data loss, downtime, and ...
    Continued 👉 blog.radwebhosting.com/vps-sec #prometheus #vpsguide #firewalld #ossec #wazuh #rockylinux #ufw #logwatch #grafana #netdata

  35. Ultimate Guide to #VPS #Security Hardening

    This article provides a guide to VPS security hardening.

    Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing discipline. Whether you’re hosting websites, applications, databases, or client workloads, a hardened VPS dramatically reduces the risk of compromise, data loss, downtime, and ...
    Continued 👉 blog.radwebhosting.com/vps-sec #prometheus #vpsguide #firewalld #ossec #wazuh #rockylinux #ufw #logwatch #grafana #netdata

  36. Czy open-source wystarczy do zapewnienia zgodności z NIS2/KSC2?

    Od kwietnia 2026 roku nowelizacja ustawy o KSC jest już faktem, a tysiące podmiotów i instytucji właśnie odkrywają, że spoczywają na nich (tak naprawdę od kilku lat zapowiadane) nowe obowiązki: samoidentyfikacja, wdrożenie SZBI, raportowanie incydentów i audyty. Terminy się zbliżają, a kary, choć objęte dwuletnią karencją (art. 35 ustawy nowelizującej),...

    #Aktualności #Ksc #Nis2 #Szkolenia #Ustawa #Wazuh

    sekurak.pl/czy-open-source-wys

  37. Czy open-source wystarczy do zapewnienia zgodności z NIS2/KSC2?

    Od kwietnia 2026 roku nowelizacja ustawy o KSC jest już faktem, a tysiące podmiotów i instytucji właśnie odkrywają, że spoczywają na nich (tak naprawdę od kilku lat zapowiadane) nowe obowiązki: samoidentyfikacja, wdrożenie SZBI, raportowanie incydentów i audyty. Terminy się zbliżają, a kary, choć objęte dwuletnią karencją (art. 35 ustawy nowelizującej),...

    #Aktualności #Ksc #Nis2 #Szkolenia #Ustawa #Wazuh

    sekurak.pl/czy-open-source-wys

  38. Czy open-source wystarczy do zapewnienia zgodności z NIS2/KSC2?

    Od kwietnia 2026 roku nowelizacja ustawy o KSC jest już faktem, a tysiące podmiotów i instytucji właśnie odkrywają, że spoczywają na nich (tak naprawdę od kilku lat zapowiadane) nowe obowiązki: samoidentyfikacja, wdrożenie SZBI, raportowanie incydentów i audyty. Terminy się zbliżają, a kary, choć objęte dwuletnią karencją (art. 35 ustawy nowelizującej),...

    #Aktualności #Ksc #Nis2 #Szkolenia #Ustawa #Wazuh

    sekurak.pl/czy-open-source-wys

  39. Czy open-source wystarczy do zapewnienia zgodności z NIS2/KSC2?

    Od kwietnia 2026 roku nowelizacja ustawy o KSC jest już faktem, a tysiące podmiotów i instytucji właśnie odkrywają, że spoczywają na nich (tak naprawdę od kilku lat zapowiadane) nowe obowiązki: samoidentyfikacja, wdrożenie SZBI, raportowanie incydentów i audyty. Terminy się zbliżają, a kary, choć objęte dwuletnią karencją (art. 35 ustawy nowelizującej),...

    #Aktualności #Ksc #Nis2 #Szkolenia #Ustawa #Wazuh

    sekurak.pl/czy-open-source-wys

  40. Czy open-source wystarczy do zapewnienia zgodności z NIS2/KSC2?

    Od kwietnia 2026 roku nowelizacja ustawy o KSC jest już faktem, a tysiące podmiotów i instytucji właśnie odkrywają, że spoczywają na nich (tak naprawdę od kilku lat zapowiadane) nowe obowiązki: samoidentyfikacja, wdrożenie SZBI, raportowanie incydentów i audyty. Terminy się zbliżają, a kary, choć objęte dwuletnią karencją (art. 35 ustawy nowelizującej),...

    #Aktualności #Ksc #Nis2 #Szkolenia #Ustawa #Wazuh

    sekurak.pl/czy-open-source-wys

  41. Ultimate Guide to #VPS #Security Hardening

    This article provides a guide to VPS security hardening.

    Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ...
    Continued 👉 #ufw #grafana #logwatch #vpsguide #wazuh #netdata #ossec #firewalld #rockylinux #prometheus

    Ultimate Guide to VPS Security...

  42. Ultimate Guide to #VPS #Security Hardening

    This article provides a guide to VPS security hardening.

    Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing discipline. Whether you’re hosting websites, applications, databases, or client workloads, a hardened VPS dramatically reduces the risk of compromise, data loss, downtime, and ...
    Continued 👉 blog.radwebhosting.com/vps-sec #ossec #netdata #logwatch #grafana #vpsguide #wazuh #prometheus #ufw #firewalld #rockylinux

  43. Ultimate Guide to #VPS #Security Hardening

    This article provides a guide to VPS security hardening.

    Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing discipline. Whether you’re hosting websites, applications, databases, or client workloads, a hardened VPS dramatically reduces the risk of compromise, data loss, downtime, and ...
    Continued 👉 blog.radwebhosting.com/vps-sec #ossec #netdata #logwatch #grafana #vpsguide #wazuh #prometheus #ufw #firewalld #rockylinux

  44. Ultimate Guide to #VPS #Security Hardening

    This article provides a guide to VPS security hardening.

    Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing discipline. Whether you’re hosting websites, applications, databases, or client workloads, a hardened VPS dramatically reduces the risk of compromise, data loss, downtime, and ...
    Continued 👉 blog.radwebhosting.com/vps-sec #ossec #netdata #logwatch #grafana #vpsguide #wazuh #prometheus #ufw #firewalld #rockylinux

  45. Ultimate Guide to #VPS #Security Hardening

    This article provides a guide to VPS security hardening.

    Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing discipline. Whether you’re hosting websites, applications, databases, or client workloads, a hardened VPS dramatically reduces the risk of compromise, data loss, downtime, and ...
    Continued 👉 blog.radwebhosting.com/vps-sec #ossec #netdata #logwatch #grafana #vpsguide #wazuh #prometheus #ufw #firewalld #rockylinux

  46. From now on all #CVe #CVEAlert additional to #yara #Sigma and #Suricate rules will have #Splunk #Wazuh rules all for FREE no tracking no registration, no payments! #cybersecurity #devsecops #devops #infosec #redteam #blueteam #github #gitlab #git #developers #developer info source and follow for more updates as there will be more EX: valtersit.com/cve/CVE-2026-973

  47. SIEMs are overpriced black boxes. Wazuh is open-source, customizable, and actually useful for threat hunting. No fluff, just configs that work in production. #Wazuh #Security #DevOps

    valtersit.com/guides/security/

  48. SIEMs are overpriced black boxes. Wazuh is open-source, customizable, and actually useful for threat hunting. No fluff, just configs that work in production. #Wazuh #Security #DevOps

    valtersit.com/guides/security/

  49. SIEMs are overpriced black boxes. Wazuh is open-source, customizable, and actually useful for threat hunting. No fluff, just configs that work in production. #Wazuh #Security #DevOps

    valtersit.com/guides/security/