#wazuh — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #wazuh, aggregated by home.social.
-
Ultimate Guide to #VPS #Security Hardening
This article provides a guide to VPS security hardening.
Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing discipline. Whether you’re hosting websites, applications, databases, or client workloads, a hardened VPS dramatically reduces the risk of compromise, data loss, downtime, and reputation ...
Continued 👉 https://blog.radwebhosting.com/vps-security-hardening/?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon.social #prometheus #rockylinux #vpsguide #ufw #firewalld #netdata #logwatch #wazuh #ossec #grafana -
Ultimate Guide to #VPS #Security Hardening
This article provides a guide to VPS security hardening.
Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing discipline. Whether you’re hosting websites, applications, databases, or client workloads, a hardened VPS dramatically reduces the risk of compromise, data loss, downtime, and reputation ...
Continued 👉 https://blog.radwebhosting.com/vps-security-hardening/?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon.social #prometheus #rockylinux #vpsguide #ufw #firewalld #netdata #logwatch #wazuh #ossec #grafana -
Ultimate Guide to #VPS #Security Hardening
This article provides a guide to VPS security hardening.
Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing discipline. Whether you’re hosting websites, applications, databases, or client workloads, a hardened VPS dramatically reduces the risk of compromise, data loss, downtime, and reputation ...
Continued 👉 https://blog.radwebhosting.com/vps-security-hardening/?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon.social #prometheus #rockylinux #vpsguide #ufw #firewalld #netdata #logwatch #wazuh #ossec #grafana -
CVE Alert: CVE-2026-74038 - Wazuh - wazuh-manager - https://www.redpacketsecurity.com/cve-alert-cve-2026-74038-wazuh-wazuh-manager/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-74038 #wazuh #wazuh-manager
-
CVE Alert: CVE-2026-74038 - Wazuh - wazuh-manager - https://www.redpacketsecurity.com/cve-alert-cve-2026-74038-wazuh-wazuh-manager/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-74038 #wazuh #wazuh-manager
-
CVE Alert: CVE-2026-74038 - Wazuh - wazuh-manager - https://www.redpacketsecurity.com/cve-alert-cve-2026-74038-wazuh-wazuh-manager/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-74038 #wazuh #wazuh-manager
-
CVE Alert: CVE-2026-74038 - Wazuh - wazuh-manager - https://www.redpacketsecurity.com/cve-alert-cve-2026-74038-wazuh-wazuh-manager/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-74038 #wazuh #wazuh-manager
-
CVE Alert: CVE-2026-74038 - Wazuh - wazuh-manager - https://www.redpacketsecurity.com/cve-alert-cve-2026-74038-wazuh-wazuh-manager/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-74038 #wazuh #wazuh-manager
-
Ultimate Guide to #VPS #Security Hardening
This article provides a guide to VPS security hardening.
Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing ...
Continued 👉 #prometheus #logwatch #firewalld #vpsguide #ufw #ossec #wazuh #rockylinux #grafana #netdata
Ultimate Guide to VPS Security... -
Wazuh без ограничений дашборда: работаем напрямую с индексами
На связи Андрей, руководитель направления Под кат →
-
Wazuh без ограничений дашборда: работаем напрямую с индексами
На связи Андрей, руководитель направления Под кат →
-
Wazuh без ограничений дашборда: работаем напрямую с индексами
На связи Андрей, руководитель направления Под кат →
-
Как собрать базовый стек для защиты инфраструктуры на open source
Привет, Хабр! На связи Виктор Иевлев, я руковожу отделом информационной безопасности в «Гарде». Полноценную защиту корпоративной инфраструктуры сегодня сложно представить без коммерческих средств защиты информации. Однако далеко не каждая компания может позволить себе сразу построить такой стек. Стартапы, небольшие организации, компании с ограниченным бюджетом зачастую вынуждены искать компромиссные решения и использовать open source. Я уже рассказывал в одной из статей об open source-сканерах уязвимостей. В этот раз предлагаю остановиться на защитных решениях и попробовать собрать минимальный стек на базе open source. Узнать подробности
https://habr.com/ru/companies/garda/articles/1067714/
#open_source #firewall #siem #wazuh #ids #xdr #защита_информации #информационная_безопасность
-
Как собрать базовый стек для защиты инфраструктуры на open source
Привет, Хабр! На связи Виктор Иевлев, я руковожу отделом информационной безопасности в «Гарде». Полноценную защиту корпоративной инфраструктуры сегодня сложно представить без коммерческих средств защиты информации. Однако далеко не каждая компания может позволить себе сразу построить такой стек. Стартапы, небольшие организации, компании с ограниченным бюджетом зачастую вынуждены искать компромиссные решения и использовать open source. Я уже рассказывал в одной из статей об open source-сканерах уязвимостей. В этот раз предлагаю остановиться на защитных решениях и попробовать собрать минимальный стек на базе open source. Узнать подробности
https://habr.com/ru/companies/garda/articles/1067714/
#open_source #firewall #siem #wazuh #ids #xdr #защита_информации #информационная_безопасность
-
Как собрать базовый стек для защиты инфраструктуры на open source
Привет, Хабр! На связи Виктор Иевлев, я руковожу отделом информационной безопасности в «Гарде». Полноценную защиту корпоративной инфраструктуры сегодня сложно представить без коммерческих средств защиты информации. Однако далеко не каждая компания может позволить себе сразу построить такой стек. Стартапы, небольшие организации, компании с ограниченным бюджетом зачастую вынуждены искать компромиссные решения и использовать open source. Я уже рассказывал в одной из статей об open source-сканерах уязвимостей. В этот раз предлагаю остановиться на защитных решениях и попробовать собрать минимальный стек на базе open source. Узнать подробности
https://habr.com/ru/companies/garda/articles/1067714/
#open_source #firewall #siem #wazuh #ids #xdr #защита_информации #информационная_безопасность
-
Ultimate Guide to #VPS #Security Hardening
This article provides a guide to VPS security hardening.
Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing discipline. Whether you’re hosting websites, applications, databases, or client workloads, a hardened VPS dramatically reduces the risk of compromise, data loss, downtime, and reputation ...
Continued 👉 https://blog.radwebhosting.com/vps-security-hardening/?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon.social #ossec #firewalld #wazuh #vpsguide #rockylinux #ufw #logwatch #netdata #prometheus #grafana -
Ultimate Guide to #VPS #Security Hardening
This article provides a guide to VPS security hardening.
Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing discipline. Whether you’re hosting websites, applications, databases, or client workloads, a hardened VPS dramatically reduces the risk of compromise, data loss, downtime, and reputation ...
Continued 👉 https://blog.radwebhosting.com/vps-security-hardening/?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon.social #ossec #firewalld #wazuh #vpsguide #rockylinux #ufw #logwatch #netdata #prometheus #grafana -
Ultimate Guide to #VPS #Security Hardening
This article provides a guide to VPS security hardening.
Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing discipline. Whether you’re hosting websites, applications, databases, or client workloads, a hardened VPS dramatically reduces the risk of compromise, data loss, downtime, and reputation ...
Continued 👉 https://blog.radwebhosting.com/vps-security-hardening/?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon.social #ossec #firewalld #wazuh #vpsguide #rockylinux #ufw #logwatch #netdata #prometheus #grafana -
⚠️ #Wazuh cluster flaws enable manager takeover
Cluster vulnerabilities can expose secrets, bypass #RBAC and chain into privileged actions or full manager compromise.
🔗 read more: securityonline.info/...
#ransomNews #cybersecurity -
⚠️ #Wazuh cluster flaws enable manager takeover
Cluster vulnerabilities can expose secrets, bypass #RBAC and chain into privileged actions or full manager compromise.
🔗 read more: securityonline.info/...
#ransomNews #cybersecurity -
⚠️ #Wazuh cluster flaws enable manager takeover
Cluster vulnerabilities can expose secrets, bypass #RBAC and chain into privileged actions or full manager compromise.
🔗 read more: securityonline.info/...
#ransomNews #cybersecurity -
⚠️ #Wazuh cluster flaws enable manager takeover
Cluster vulnerabilities can expose secrets, bypass #RBAC and chain into privileged actions or full manager compromise.
🔗 read more: securityonline.info/...
#ransomNews #cybersecurity -
⚠️ #Wazuh cluster flaws enable manager takeover
Cluster vulnerabilities can expose secrets, bypass #RBAC and chain into privileged actions or full manager compromise.
🔗 read more: securityonline.info/...
#ransomNews #cybersecurity -
Tired of Wazuh false positives from broad rule groups like 'syslog' or 'generic'? Query wazuh.db directly: join rules & groups tables to count per group, then tighten overly permissive ones. Works on Wazuh 4.x. #wazuh #sqlite #ValtersIT
https://www.valtersit.com/vault/detect-overly-permissive-wazuh-rule-groups-via-sqlite-query-43591c/
-
Tired of Wazuh false positives from broad rule groups like 'syslog' or 'generic'? Query wazuh.db directly: join rules & groups tables to count per group, then tighten overly permissive ones. Works on Wazuh 4.x. #wazuh #sqlite #ValtersIT
https://www.valtersit.com/vault/detect-overly-permissive-wazuh-rule-groups-via-sqlite-query-43591c/
-
Ultimate Guide to #VPS #Security Hardening
This article provides a guide to VPS security hardening.
Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing discipline. Whether you’re hosting websites, applications, databases, or client workloads, a hardened VPS dramatically reduces the risk of compromise, data loss, downtime, and reputation ...
Continued 👉 https://blog.radwebhosting.com/vps-security-hardening/?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon.raddemo.host #ossec #rockylinux #prometheus #logwatch #firewalld #vpsguide #grafana #ufw #netdata #wazuh -
Ultimate Guide to #VPS #Security Hardening
This article provides a guide to VPS security hardening.
Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing discipline. Whether you’re hosting websites, applications, databases, or client workloads, a hardened VPS dramatically reduces the risk of compromise, data loss, downtime, and reputation ...
Continued 👉 https://blog.radwebhosting.com/vps-security-hardening/?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon.raddemo.host #ossec #rockylinux #prometheus #logwatch #firewalld #vpsguide #grafana #ufw #netdata #wazuh -
Ultimate Guide to #VPS #Security Hardening
This article provides a guide to VPS security hardening.
Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing discipline. Whether you’re hosting websites, applications, databases, or client workloads, a hardened VPS dramatically reduces the risk of compromise, data loss, downtime, and reputation ...
Continued 👉 https://blog.radwebhosting.com/vps-security-hardening/?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon.raddemo.host #ossec #rockylinux #prometheus #logwatch #firewalld #vpsguide #grafana #ufw #netdata #wazuh -
Ultimate Guide to #VPS #Security Hardening
This article provides a guide to VPS security hardening.
Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing discipline. Whether you’re hosting websites, applications, databases, or client workloads, a hardened VPS dramatically reduces the risk of compromise, data loss, downtime, and reputation ...
Continued 👉 https://blog.radwebhosting.com/vps-security-hardening/?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon.raddemo.host #ossec #rockylinux #prometheus #logwatch #firewalld #vpsguide #grafana #ufw #netdata #wazuh -
three critical (9.1) advisories for wazuh i reported were published today. same trust assumption broken in three places: the cluster fernet key authenticates membership, and the cluster protocol then lets that peer pick filesystem paths.
CVE-2026-49441: the peer-supplied metadata key in process_files_from_worker is used directly as the destination path. write etc/ossec.conf, root rce via wazuh-logcollector.
CVE-2026-48024: same function, merged-file branch. traversal in the merged header name and in merge_type.
CVE-2026-48162: the DAPI tmp_file field is joined to WAZUH_PATH with os.path.join and shipped back to the peer. absolute paths win, so it reads anything the wazuh user can open. grab private_key.pem, forge ES512 admin jwts offline. survives cluster key rotation, since the jwt keypair is a different scope.
patched in 4.14.6.
https://github.com/wazuh/wazuh/security/advisories/GHSA-3v57-hgvj-3vj2
https://github.com/wazuh/wazuh/security/advisories/GHSA-gh4h-fx78-q8xc
https://github.com/wazuh/wazuh/security/advisories/GHSA-r6f5-h662-8ffc
#Wazuh #InfoSec #CVE #SIEM #ResponsibleDisclosure #CyberSecurity
-
three critical (9.1) advisories for wazuh i reported were published today. same trust assumption broken in three places: the cluster fernet key authenticates membership, and the cluster protocol then lets that peer pick filesystem paths.
CVE-2026-49441: the peer-supplied metadata key in process_files_from_worker is used directly as the destination path. write etc/ossec.conf, root rce via wazuh-logcollector.
CVE-2026-48024: same function, merged-file branch. traversal in the merged header name and in merge_type.
CVE-2026-48162: the DAPI tmp_file field is joined to WAZUH_PATH with os.path.join and shipped back to the peer. absolute paths win, so it reads anything the wazuh user can open. grab private_key.pem, forge ES512 admin jwts offline. survives cluster key rotation, since the jwt keypair is a different scope.
patched in 4.14.6.
https://github.com/wazuh/wazuh/security/advisories/GHSA-3v57-hgvj-3vj2
https://github.com/wazuh/wazuh/security/advisories/GHSA-gh4h-fx78-q8xc
https://github.com/wazuh/wazuh/security/advisories/GHSA-r6f5-h662-8ffc
#Wazuh #InfoSec #CVE #SIEM #ResponsibleDisclosure #CyberSecurity
-
three critical (9.1) advisories for wazuh i reported were published today. same trust assumption broken in three places: the cluster fernet key authenticates membership, and the cluster protocol then lets that peer pick filesystem paths.
CVE-2026-49441: the peer-supplied metadata key in process_files_from_worker is used directly as the destination path. write etc/ossec.conf, root rce via wazuh-logcollector.
CVE-2026-48024: same function, merged-file branch. traversal in the merged header name and in merge_type.
CVE-2026-48162: the DAPI tmp_file field is joined to WAZUH_PATH with os.path.join and shipped back to the peer. absolute paths win, so it reads anything the wazuh user can open. grab private_key.pem, forge ES512 admin jwts offline. survives cluster key rotation, since the jwt keypair is a different scope.
patched in 4.14.6.
https://github.com/wazuh/wazuh/security/advisories/GHSA-3v57-hgvj-3vj2
https://github.com/wazuh/wazuh/security/advisories/GHSA-gh4h-fx78-q8xc
https://github.com/wazuh/wazuh/security/advisories/GHSA-r6f5-h662-8ffc
#Wazuh #InfoSec #CVE #SIEM #ResponsibleDisclosure #CyberSecurity
-
three critical (9.1) advisories for wazuh i reported were published today. same trust assumption broken in three places: the cluster fernet key authenticates membership, and the cluster protocol then lets that peer pick filesystem paths.
CVE-2026-49441: the peer-supplied metadata key in process_files_from_worker is used directly as the destination path. write etc/ossec.conf, root rce via wazuh-logcollector.
CVE-2026-48024: same function, merged-file branch. traversal in the merged header name and in merge_type.
CVE-2026-48162: the DAPI tmp_file field is joined to WAZUH_PATH with os.path.join and shipped back to the peer. absolute paths win, so it reads anything the wazuh user can open. grab private_key.pem, forge ES512 admin jwts offline. survives cluster key rotation, since the jwt keypair is a different scope.
patched in 4.14.6.
https://github.com/wazuh/wazuh/security/advisories/GHSA-3v57-hgvj-3vj2
https://github.com/wazuh/wazuh/security/advisories/GHSA-gh4h-fx78-q8xc
https://github.com/wazuh/wazuh/security/advisories/GHSA-r6f5-h662-8ffc
#Wazuh #InfoSec #CVE #SIEM #ResponsibleDisclosure #CyberSecurity
-
three critical (9.1) advisories for wazuh i reported were published today. same trust assumption broken in three places: the cluster fernet key authenticates membership, and the cluster protocol then lets that peer pick filesystem paths.
CVE-2026-49441: the peer-supplied metadata key in process_files_from_worker is used directly as the destination path. write etc/ossec.conf, root rce via wazuh-logcollector.
CVE-2026-48024: same function, merged-file branch. traversal in the merged header name and in merge_type.
CVE-2026-48162: the DAPI tmp_file field is joined to WAZUH_PATH with os.path.join and shipped back to the peer. absolute paths win, so it reads anything the wazuh user can open. grab private_key.pem, forge ES512 admin jwts offline. survives cluster key rotation, since the jwt keypair is a different scope.
patched in 4.14.6.
https://github.com/wazuh/wazuh/security/advisories/GHSA-3v57-hgvj-3vj2
https://github.com/wazuh/wazuh/security/advisories/GHSA-gh4h-fx78-q8xc
https://github.com/wazuh/wazuh/security/advisories/GHSA-r6f5-h662-8ffc
#Wazuh #InfoSec #CVE #SIEM #ResponsibleDisclosure #CyberSecurity
-
Ultimate Guide to #VPS #Security Hardening
This article provides a guide to VPS security hardening.
Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ...
Continued 👉 #ufw #logwatch #grafana #wazuh #prometheus #rockylinux #ossec #firewalld #vpsguide #netdata
Ultimate Guide to VPS Security... -
Ultimate Guide to #VPS #Security Hardening
This article provides a guide to VPS security hardening.
Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing discipline. Whether you’re hosting websites, applications, databases, or client workloads, a hardened VPS dramatically reduces the risk of compromise, data loss, downtime, and ...
Continued 👉 https://blog.radwebhosting.com/vps-security-hardening/?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon.social #ossec #rockylinux #ufw #prometheus #netdata #firewalld #logwatch #grafana #wazuh #vpsguide -
Ultimate Guide to #VPS #Security Hardening
This article provides a guide to VPS security hardening.
Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing discipline. Whether you’re hosting websites, applications, databases, or client workloads, a hardened VPS dramatically reduces the risk of compromise, data loss, downtime, and ...
Continued 👉 https://blog.radwebhosting.com/vps-security-hardening/?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon.social #ossec #rockylinux #ufw #prometheus #netdata #firewalld #logwatch #grafana #wazuh #vpsguide -
Ultimate Guide to #VPS #Security Hardening
This article provides a guide to VPS security hardening.
Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ongoing discipline. Whether you’re hosting websites, applications, databases, or client workloads, a hardened VPS dramatically reduces the risk of compromise, data loss, downtime, and ...
Continued 👉 https://blog.radwebhosting.com/vps-security-hardening/?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon.social #ossec #rockylinux #ufw #prometheus #netdata #firewalld #logwatch #grafana #wazuh #vpsguide -
Wazuh (open-source XDR & SIEM) in v4.14.7 released
-
Wazuh (open-source XDR & SIEM) in v4.14.7 released
-
Wazuh (open-source XDR & SIEM) in v4.14.7 released
-
Wazuh (open-source XDR & SIEM) in v4.14.7 released
-
Ultimate Guide to #VPS #Security Hardening
This article provides a guide to VPS security hardening.
Securing a Virtual Private Server (VPS) is not a one-time task—it’s an ...
Continued 👉 #ufw #vpsguide #firewalld #grafana #wazuh #ossec #prometheus #netdata #logwatch #rockylinux
Ultimate Guide to VPS Security... -
Panel auto-hospedado, gratuito y de código abierto para gestionar nuestra red LAN y NAS:
https://wazuh.com/
#wazuh -
Panel auto-hospedado, gratuito y de código abierto para gestionar nuestra red LAN y NAS:
https://wazuh.com/
#wazuh -
Panel auto-hospedado, gratuito y de código abierto para gestionar nuestra red LAN y NAS:
https://wazuh.com/
#wazuh -
Panel auto-hospedado, gratuito y de código abierto para gestionar nuestra red LAN y NAS:
https://wazuh.com/
#wazuh -
Panel auto-hospedado, gratuito y de código abierto para gestionar nuestra red LAN y NAS:
https://wazuh.com/
#wazuh