home.social

#wazuh — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #wazuh, aggregated by home.social.

  1. Ultimate Guide to #VPS #Security Hardening

    This article provides a guide to VPS security hardening.

    Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing discipline. Whether you’re hosting websites, applications, databases, or client workloads, a hardened VPS dramatically reduces the risk of compromise, data loss, downtime, and reputation ...
    Continued 👉 blog.radwebhosting.com/vps-sec #grafana #vpsguide #prometheus #firewalld #netdata #logwatch #ossec #wazuh #ufw #rockylinux

  2. Ultimate Guide to #VPS #Security Hardening

    This article provides a guide to VPS security hardening.

    Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing discipline. Whether you’re hosting websites, applications, databases, or client workloads, a hardened VPS dramatically reduces the risk of compromise, data loss, downtime, and reputation ...
    Continued 👉 blog.radwebhosting.com/vps-sec #grafana #vpsguide #prometheus #firewalld #netdata #logwatch #ossec #wazuh #ufw #rockylinux

  3. Ultimate Guide to #VPS #Security Hardening

    This article provides a guide to VPS security hardening.

    Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing discipline. Whether you’re hosting websites, applications, databases, or client workloads, a hardened VPS dramatically reduces the risk of compromise, data loss, downtime, and reputation ...
    Continued 👉 blog.radwebhosting.com/vps-sec #grafana #vpsguide #prometheus #firewalld #netdata #logwatch #ossec #wazuh #ufw #rockylinux

  4. three critical (9.1) advisories for wazuh i reported were published today. same trust assumption broken in three places: the cluster fernet key authenticates membership, and the cluster protocol then lets that peer pick filesystem paths.

    CVE-2026-49441: the peer-supplied metadata key in process_files_from_worker is used directly as the destination path. write etc/ossec.conf, root rce via wazuh-logcollector.

    CVE-2026-48024: same function, merged-file branch. traversal in the merged header name and in merge_type.

    CVE-2026-48162: the DAPI tmp_file field is joined to WAZUH_PATH with os.path.join and shipped back to the peer. absolute paths win, so it reads anything the wazuh user can open. grab private_key.pem, forge ES512 admin jwts offline. survives cluster key rotation, since the jwt keypair is a different scope.

    patched in 4.14.6.

    github.com/wazuh/wazuh/securit

    github.com/wazuh/wazuh/securit

    github.com/wazuh/wazuh/securit

    #Wazuh #InfoSec #CVE #SIEM #ResponsibleDisclosure #CyberSecurity