🪟 Windows TippsThe Gemini desktop app is now available for Windows(11.09.2026 um 17:06 Uhr)
⚠️ Malware / Trojaner / VirenWindows 11 just dropped the tool ransomware abused, Microsoft says don’t restore WMIC(10.09.2026 um 20:11 Uhr)
⚠️ Malware / Trojaner / VirenVorsicht: Android-Malware verschlüsselt Ihre Handys und nimmt heimlich Fotos auf(11.09.2026 um 09:35 Uhr)
🕵️ SicherheitslückenMicrosoft geht endlich eines der nervigsten Probleme von Windows 11 an(11.09.2026 um 11:58 Uhr)
💾 IT Security ToolsSysinternals Suite(11.09.2026 um 12:00 Uhr)
🕵️ SicherheitslückenDefender 0-Day ShieldBreak (CVE-2026-69414) nicht sauber gepatcht - BornCity(11.09.2026 um 12:52 Uhr)
🔧 AI Nachrichten Stealing AI Reasoning Traces(08.09.2026 um 12:20 Uhr)
🪟 Windows TippsThe Gemini desktop app is now available for Windows(11.09.2026 um 17:06 Uhr)
⚠️ Malware / Trojaner / VirenWindows 11 just dropped the tool ransomware abused, Microsoft says don’t restore WMIC(10.09.2026 um 20:11 Uhr)
⚠️ Malware / Trojaner / VirenVorsicht: Android-Malware verschlüsselt Ihre Handys und nimmt heimlich Fotos auf(11.09.2026 um 09:35 Uhr)
🕵️ SicherheitslückenMicrosoft geht endlich eines der nervigsten Probleme von Windows 11 an(11.09.2026 um 11:58 Uhr)
💾 IT Security ToolsSysinternals Suite(11.09.2026 um 12:00 Uhr)
🕵️ SicherheitslückenDefender 0-Day ShieldBreak (CVE-2026-69414) nicht sauber gepatcht - BornCity(11.09.2026 um 12:52 Uhr)
🔧 AI Nachrichten Stealing AI Reasoning Traces(08.09.2026 um 12:20 Uhr)

💾 IT Security Tools 🕛 vor 14 Std. 4 Min Lesezeit SECURITY-FEED
0

GitHub Release: wazuh/wazuh v4.14.8-rc1 (11.09.2026)

↗ Quelle (GitHub · wazuh/wazuh)
🗣️ Stimme:
GitHub Release: wazuh/wazuh v4.14.8-rc1 (11.09.2026)
Avatar
$ git clone https://github.com/wazuh/wazuh.git

What's Changed



  • Bump 4.14.8 branch by

  • Multi SCA, Decoder and Rule fixes by

  • Maintain crypto_method on keystore rebuild by

  • Merge 4.14.7 into 4.14.8 by

  • Fix RBAC permission bypass in GET /security/actions and /security/resources by

  • Validate destination paths when uploading list, rule, and decoder files by

  • Prevent cluster worker from overwriting protected master files by

  • Improve access control on the agent active-configuration endpoint by

  • Fix typo in SCA rules by

  • Prevent race condition in Windows RSA key container initialization (randombytes) by

  • Limit node expansion in yaml2json by

  • Reorder revoke-token from API integration test by

  • Fix benchmark test_cluster_error_logs test by

  • Correct EnableMulticast expected value in Windows LLMNR checks by

  • Prevent spurious CRITICAL (1211) queue error during rootcheck/FIM shutdown on WPK upgrade by

  • Add sshd-session/sshd-auth to default macOS ULS query by

  • Remove multiple warning messages for each unathorized shared policy by

  • Fix typo in SCA rules by

  • Fix analysisd deadlock on AR send when the queue is not drained by

  • Disable OpenSSL runtime CPU probing in Python daemon wrappers by

  • Expose audit_uid, audit_gid and effective_uid in eBPF whodata provider by

  • Reject upgrade commands from the agent channel in wazuh-analysisd by

  • initializeContext thread-safe with std::call_once by

  • Validate destination paths when deleting rule and decoder files by

  • Use DisplayName and python.exe version for Microsoft Store packages by

  • Fix analysisd flaky test by

  • Update MITRE mapping in Microsoft Graph rules by

  • Validate read path in CDB list file retrieval by

  • Merge 4.14.7 into 4.14.8 by

  • Fix flaky content manager component tests caused by a race in the fake server startup by

  • Discard_regex values containing a space break argument parsing by

  • Decouple authd use_password invalid test from the manager restart return code by

  • Prevent empty string version from being stored for agents by

  • Prevent exiting Wazuh-DB worker when oversized message arrives. by

  • Classify SCA policy remoteness by activation source, not file path by

  • Reject undersized legacy-format agent messages in wazuh-remoted by

  • Remove WMI dependancy when installing msi packages by

  • Remove startup deprecation warning from agent_upgrade by

  • Improve login attempt limiting under concurrent requests by

  • Fix out-of-bounds write when generating FIM alerts in wazuh-analysisd by

  • Enforce password validation for empty passwords in update_user by

  • Enforce token revocation for run_as (authorization-context) API sessions by

  • Fix wildcard matching in the installed-files check by

  • Prevent orphaned S3 artifacts and false-positive collisions in AWS integration tests [4.14.8] by

  • Report macOS 26 and 27 release codenames by

  • Validate CDB list paths in list-retrieval and delete cluster callables by

  • Skip 4.x CI checks on draft pull requests by

  • Fix remote-command configuration validation by

  • Revert agent workflows to GitHub runners 4x by

  • Perpended string "data." in field names removed from FortiAuth rules and decoders by

  • Remove stale EC2-timing exclusion in syscollector-rtr by

  • Validate read paths in group configuration and daemon stats retrieval by

  • Suppress StarletteDeprecationWarning for cluster_control and all framework CLI tools by

  • Move the 4.14.8 server workflows to GitHub-hosted runners and add sccache compilation caching by

  • Avoid holding exec_sock_mutex while connecting to the exec queue by

  • AWS integration tests: isolate concurrent runs on the shared bucket with a per-run S3 namespace (GITHUB_RUN_ID) [4.14.8] by

  • Remove avoidable copies, double lookups and pessimizing moves in agent-side hot paths by

  • Bump 4.14.8 branch by


Full Changelog: v4.14.7...v4.14.8-rc1

Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf github.com.
↗ Original-Artikel auf github.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Stealing AI Reasoning Traces
1 Quelle
AIs as Modern Genies
1 Quelle
Bitcoin: KI-Hacker räumen Millionen ab! Wird Künstliche Intelligenz zum Problem? - ftd.de