Search/wazuh
Known CVEs
0
Highest CVSS
In KEV
0
Vendor
wazuh-dashboard
Connections
14 relationships
Reducing security operations complexity with Wazuh Cloud
Security teams today manage increasingly complex environments in which threats such as ransomware, advanced persistent threats, and supply chain attacks evolve rapidly. Organizations operate hybrid infrastructures spanning on-premises systems, multi-cloud platforms, containers, and Kubernetes clusters, all while navigating strict compliance requirements from frameworks including PCI DSS, HIPAA, GDPR, NIST 800-53, and CIS Benchmarks. Security operations centers (SOCs) commonly receive thousands of alerts per day, with high false-positive rates. Analysts can spend most of their time analyzing these false positives rather than investigating real threats. This contributes to burnout, delays in mean time to detect (MTTD) and mean time to respond (MTTR), and exploitable security gaps. This reality leaves organizations under-protected despite significant investments. Deployment delays mean limited visibility during critical onboarding periods. Ongoing infrastructure management diverts skilled analysts toward patching, tuning, and cluster maintenance rather than proactive threat hunting. In dynamic environments, performance degradation and costly re-architecture become the norm, while inflexible licensing models force teams to either overpay for unused features or operate without essential capabilities. This post explores some of these challenges and demonstrates how Wazuh Cloud solves them. Wazuh Cloud is a fully managed, cloud-native version of the open source Wazuh platform. It simplifies operations through automation, intelligent AI-driven analysis, and seamless scalability. By removing infrastructure overhead and enhancing detection precision, Wazuh Cloud empowers security teams to focus on what matters most: protecting critical assets in real time. Challenges in modern security operations Security teams commonly encounter several operational realities when deploying and running SIEM/XDR platforms: Extended deployment timelines: Provisioning infrastructure, rolling out agents across heterogeneous endpoints, configuring data ingestion, tuning detection rules, and integrating with existing tools can take weeks or even months. This extended onboarding period leaves critical visibility gaps during a vulnerable transition phase. Sustained maintenance demands: Self-managed environments require ongoing efforts in OS patching, indexer performance tuning, rule updates, cluster scaling, and data retention management. These tasks consume valuable analyst time that could otherwise be devoted to threat hunting and incident response. High alert volumes with limited context: In active environments, SIEMs can process millions of events and generate thousands of alerts daily. Without robust correlation and contextual enrichment, teams face substantial triage workloads, impacting MTTD and MTTR. Scaling constraints in modern infrastructures: As endpoint counts increase or organizations embrace cloud-native technologies, performance bottlenecks emerge, often necessitating costly hardware investments or architectural overhauls. Inflexible consumption models: Rigid licensing structures and tiered feature sets can lead to either overprovisioning costs or the omission of key capabilities tailored to specific needs. Organizations seek solutions that precisely align with their agent volume, data retention, and feature requirements, without rigid constraints. Support limitations: Many solutions rely on reactive, ticket-based assistance, lacking proactive platform health monitoring and specialized guidance during critical issues. These factors often result in higher operational costs and increased pressure on security teams. How Wazuh Cloud fixes these challenges Wazuh Cloud provides a managed SIEM/XDR solution designed to minimize infrastructure demands while maximizing security effectiveness: Rapid time-to-value: After quick sign-up, Wazuh supports lightweight Wazuh agent deployments across Windows, Linux, macOS, containers, and cloud workloads to achieve full visibility. Pre-configured rules and intuitive dashboards activate immediately. Key security modules such as File Integrity Monitoring (FIM) for detecting unauthorized file changes, vulnerability detection for identifying known weaknesses across systems, and Security Configuration Assessment (SCA) for evaluating compliance against industry benchmarks are all enabled automatically. This out-of-the-box setup delivers comprehensive protection without the usual lengthy configuration process. Zero-maintenance platform: Wazuh manages all backend operations, security patches, rule enhancements, threat intelligence updates, and version upgrades, delivering minimal operational impact for your team. Wazuh AI Security Analyst: This Wazuh service delivers automated AI-powered security analysis for Wazuh Cloud environments. It analyzes security alerts, vulnerability data, and endpoint activity to generate actionable insights that help organizations better understand their security posture and prioritize remediation efforts. Weekly AI-generated assessments and recommendations highlight trends, high-risk activity, and investigation priorities, reducing manual analysis, alert fatigue, and triage time while improving overall operational efficiency. Automatic scalability: Wazuh Cloud resources dynamically adjust to agent volume and data ingestion rates, reliably supporting environments from hundreds to thousands of agents without performance degradation. Flexible tiering: Select the tier that fits your current agent count, data retention, and module needs. Upgrades for extended retention or advanced analytics are straightforward, though some setting changes are applied via support workflow and may take effect on the next billing cycle. Proactive support and monitoring: Continuous health checks on clusters, agents, and ingestion pipelines, combined with direct access to Wazuh experts. How Wazuh Cloud works Wazuh Cloud is built on a robust distributed architecture optimized for managed delivery. Agent-Server model Lightweight Wazuh agents installed on endpoints collect logs, monitor file integrity, assess configurations, and detect rootkits locally. Normalized events are securely forwarded to the managed Wazuh Cloud server over an encrypted channel, reducing bandwidth usage while maintaining strong visibility across distributed and high-latency environments. Indexing and data pipeline A managed Wazuh indexer cluster handles indexing with pre-optimized shards, retention policies, and query performance. Automatic horizontal scaling prevents the degradation typical in self-managed environments. Detection engine Raw logs are parsed by decoders, then evaluated against thousands of rules organized by severity, category, and MITRE ATT&CK techniques. Advanced rule chaining across multiple data sources enables precise correlation and significantly lower false-positive rates. Wazuh AI analyst layer Wazuh AI Analyst sits above the core detection capabilities. It processes security alerts, vulnerability findings, and endpoint activity data to automatically generate weekly reports with insights, trend analysis, high-risk highlights, and prioritized remediation recommendations. This reduces the manual effort required for investigations and helps teams focus on strategic threat detection and response. Conclusion The limitations of traditional SIEMs are not merely inconveniences; they translate directly into slower detection, higher operational costs, and security gaps that adversaries exploit. Prolonged deployments mean delayed visibility. Maintenance burden means distracted teams. Alert fatigue means real threats are buried in noise. Wazuh Cloud addresses these problems by reducing the complexity of managing your security operations. A managed, cloud-native architecture handles the infrastructure, maintenance, and scalability challenges that consume security teams in self-managed environments. The built-in AI analyst reduces the cognitive load of triage, and a flexible tiering model ensures organizations pay for what they actually need. For security teams operating in dynamic, hybrid, or multi-cloud environments, the question is no longer whether a managed SIEM is viable; it is whether the cost of maintaining a traditional one is still justifiable. Wazuh Cloud makes that case straightforward. Visit Wazuh Cloud to start a free trial and experience immediate visibility and protection in your environment today. Sponsored and written by Wazuh.
bleepingcomputer.comJun 8, 2026extracted
Wazuh: PoC pubblico per lo sfruttamento della CVE-2026-30893
Wazuh: PoC pubblico per lo sfruttamento della CVE-2026-30893 Alert AL02/260512/CSIRT-ITA Sintesi Disponibile un Proof of Concept (PoC) per lo sfruttamento della CVE-2026-30893 – già sanata dal vendor – presente in Wazuh, piattaforma open-source con funzionalità Security Information and Event Management (SIEM) e Extended Detection and Response (XDR). Tipologia Arbitrary Code Execution Arbitrary File Write Prodotti e/o versioni affette Wazuh 4.4.x, versioni precedenti alla 4.14.4 Descrizione e potenziali impatti Disponibile un Proof of Concept (PoC) per lo sfruttamento della CVE-2026-30893 – già sanata dal vendor – presente in Wazuh, piattaforma open-source con funzionalità Security Information and Event Management (SIEM) e Extended Detection and Response (XDR). Tale vulnerabilità - di tipo “Path Traversal” e con score CVSS v3.1 pari a 9.0 – è dovuta alla mancanza di controlli di validazione dei percorsi di output dei file, nel contesto di un cluster Wazuh, che la funzione decompress_files() invia a os.path.join(). Un utente malintenzionato, a partire da un cluster peer, potrebbe scrivere file arbitrari al di fuori delle directory previste su tutti gli altri nodi del cluster; in particolare, sovrascrivendo i moduli Python normalmente utilizzati dai componenti di Wazuh, potrebbe verosimilmente eseguire codice arbitrario sui sistemi target. Azioni di mitigazione Ove non provveduto, si raccomanda di aggiornare tempestivamente le release vulnerabili seguendo le indicazioni del bollettino di sicurezza riportato nella sezione Riferimenti.
acn.gov.itMay 12, 2026extracted
⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More
Another week, another reminder that the internet is still a mess. Systems people thought were secure are being broken in simple ways, showing many still ignore basic advisories. This edition covers a mix of issues: supply chain attacks hitting CI/CD setups, long-abused IoT devices being shut down, and exploits moving quickly from disclosure to real attacks. There are also new malware tricks showing attackers are becoming more patient and creative. It’s a mix of old problems that never go away and new methods that are harder to detect. There are quiet state-backed activities, exposed data from open directories, growing mobile threats, and a steady stream of zero-days and rushed patches. Grab a coffee, and at least skim the CVE list. Some of these are the kind you don’t want to discover after the damage is done. ⚡ Threat of the Week Trivy Vulnerability Scanner Breached in for Supply Chain Attack — Attackers have backdoored the widely used open-source Trivy vulnerability scanner, injecting credential-stealing malware into official releases and GitHub Actions used by thousands of CI/CD workflows. The breach has triggered a cascade of additional supply-chain compromises stemming from impacted projects and organizations not rotating their secrets, resulting in the distribution of a self-propagating worm referred to as CanisterWorm. Trivy, developed by Aqua Security, is one of the most widely used open-source vulnerability scanners, with over 32,000 GitHub stars and more than 100 million Docker Hub downloads. The Trivy compromise is the latest in a growing pattern of attacks targeting GitHub Actions and developers in general. GitHub changed the default behavior of pull_request_target workflows in December 2025 to reduce the risk of exploitation. BAS vs Automated Pentesting: What Each Actually Covers (and Doesn't) Most teams pick one without knowing what the other misses. This guide breaks down both by use case across blue, red, and purple teams so you can see where each fits and where the gaps are. Download Now ➝ 🔔 Top News DoJ Takes Down DDoS Botnets — A cluster of IoT botnets behind some of the largest DDoS attacks ever recorded -- AISURU, Kimwolf, JackSkid, and Mossad -- were wiped as part of a broad law enforcement operation. The botnets largely spread across routers, IP cameras, and digital video recorders that are often shipped with weak credentials and rarely patched. Authorities removed the command-and-control servers used to commandeer the infected nodes. Together, operators of the four botnets had amassed more than 3 million devices, which they then sold access to other criminal hackers, who then used them to target victims with DDoS attacks to knock websites and internet services offline or mask other illicit activity. Some of these DDoS attacks were aimed at U.S. Department of Defense systems and other high-value targets. No arrests were announced, but two suspects associated with AISURU/Kimwolf are said to be based in Canada and Germany. All four botnets disrupted by the operation are variants of Mirai, which had its source code leaked in 2016 and has served as the starting point for other botnets. The U.S. Justice Department said some victims of the DDoS attacks lost hundreds of thousands of dollars through remediation expenses or ransom demands from hackers who would only stop overloading websites for a price. Google Debuts New Advanced Flow for Sideloading on Android — Google's advanced flow for Android changes how apps from unverified developers are installed, adding friction to combat scams and malware. The feature is aimed at experienced users and allows sideloading through a one-time setup. The advanced flow adds a 24-hour delay and verification steps intended to disrupt coercive pressure and give users time to make decisions. It’s designed to address scenarios where attackers pressure individuals to install unsafe software and play on the urgency of the operation to push them to bypass security warnings and disable protections before they can pause or seek help. Critical Langflow Flaw Comes Under Attack — A critical security flaw impacting Langflow has come under active exploitation within 20 hours of public disclosure, highlighting the speed at which threat actors weaponize newly published vulnerabilities. The security defect, tracked as CVE-2026-33017 (CVSS score: 9.3), is a case of missing authentication combined with code injection that could result in remote code execution. Cloud security firm Sysdig said that the attacks weaponize the vulnerability to steal sensitive data from compromised systems. "The real-world proof is definitive: threat actors exploited it in the wild within 20 hours of the advisory going public, with no public PoC code available," Aviral Srivastava, who discovered the vulnerability, told The Hacker News. "They built working exploits just from reading the advisory description. That's the hallmark of trivial exploitation when multiple independent attackers can weaponize a vulnerability from a description alone, within hours." Interlock Ransomware Exploited Cisco FMC Flaw as 0-Day — An Interlock ransomware campaign exploited a critical security flaw in Cisco Secure Firewall Management Center (FMC) Software as a zero-day well over a month before it was publicly disclosed. The vulnerability in question is CVE-2026-20131 (CVSS score: 10.0), a case of insecure deserialization of user-supplied Java byte stream, which could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary Java code as root on an affected device. "This wasn't just another vulnerability exploit; Interlock had a zero-day in their hands, giving them a week's head start to compromise organizations before defenders even knew to look," Amazon, which spotted the activity, said. Yet Another iOS Exploit Kit Comes to Light — A new watering hole attack against iPhone users has been found to deliver a previously undocumented iOS exploit kit codenamed DarkSword. While some of the attacks targeted users in Ukraine, the kit has also been put to use by two other clusters that singled out Saudi Arabian users in November 2025, as well as users in Turkey and Malaysia. It's worth noting that these exploits would not be effective on devices where Lockdown Mode is active or on the iPhone 17 with Memory Integrity Enforcement (MIE) enabled. The kit used a total of six exploits in iOS to deliver various malware families designed for surveillance and intelligence gathering. Apple has since addressed all of them. "Completely written in JavaScript, DarkSword comprises six vulnerabilities across two exploit chains that were patched in stages ending with iOS 26.3," iVerify said. "Starting in WebKit and moving down to the kernel, it achieves full iPhone compromise with elegant techniques never publicly seen before." The discovery of DarkSword makes it the second mass attack targeting iOS devices. What's more, the Russian threat actor that deployed DarkSword demonstrated poor operational security. They left the full JavaScript code unobfuscated, unprotected, and easily accessible. The findings also point to a secondary market where such exploits are being acquired by threat actors of varied motivations to actively infect unpatched iOS users on a large scale. Perseus Banking Malware Targets Android — A newly discovered Android malware is masking itself within television streaming apps in order to steal users' passwords and banking data and spy on their personal notes, researchers have found. The malware, dubbed Perseus by researchers at ThreatFabric, is being actively distributed in the wild and primarily targets users in Turkey and Italy. To infect devices, attackers disguise the malware inside apps that appear to offer IPTV services — platforms that stream television content over the internet. These apps are also widely used to stream pirated content and are often downloaded outside official marketplaces like Google Play, making users more accustomed to installing them manually and less likely to view the process as suspicious. Once installed, Perseus can monitor nearly everything a user does in real time. It uses overlay attacks — placing fake login screens over legitimate apps — and keylogging capabilities to capture credentials as they are entered. The malware's most unusual feature is its focus on personal note-taking applications. "Notes often contain sensitive information such as passwords, recovery phrases, financial details, or private thoughts, making them a valuable target for attackers," ThreatFabric said. ️🔥 Trending CVEs New vulnerabilities show up every week, and the window between disclosure and exploitation keeps getting shorter. The flaws below are this week's most critical — high-severity, widely used software, or already drawing attention from the security community. Check these first, patch what applies, and don't wait on the ones marked urgent — CVE-2026-21992 (Oracle), CVE-2026-33017 (Langflow), CVE-2026-32746 (GNU InetUtils telnetd), CVE-2026-32297, CVE-2026-32298 (Angeet ES3 KVM), CVE-2026-3888 (Ubuntu), CVE-2026-20643 (Apple WebKit), CVE-2026-4276 (LibreChat RAG API), CVE-2026-24291 aka RegPwn (Microsoft Windows), CVE-2026-21643 (Fortinet FortiClient), CVE-2026-3864 (Kubernetes), CVE-2026-32635 (Angular), CVE-2026-25769 (Wazuh), CVE-2026-3564 (ConnectWise ScreenConnect), CVE-2026-22557, CVE-2026-22558 (Ubiquiti), CVE-2025-14986 (Temporal), CVE-2026-31381, CVE-2026-31382 (Gainsight Assist), CVE-2026-26189 (Trivy), CVE-2026-4439, CVE-2026-4440, CVE-2026-4441 (Google Chrome), CVE-2026-33001, CVE-2026-33002 (Jenkins), CVE-2026-21570 (Atlassian Bamboo Center), and CVE-2026-21884 (Atlassian Crowd Data Center). 🎥 Cybersecurity Webinars Learn How to Automate Exposure Management with OpenCTI & OpenAEV → Discover how to automate continuous, threat-informed testing using open-source tools like OpenCTI and OpenAEV to validate your security controls against real attacker behavior without increasing your budget. See a live demo on how to verify your security works, identify real gaps, and integrate it into your SOC workflow at no extra cost. Identity Maturity Cracking in 2026: See the New Data + How to Catch Up Fast → Identity programs are under massive pressure in 2026 - disconnected apps, AI agents, and credential sprawl are creating real risks and audit challenges. Join this webinar for new Ponemon Institute 2026 research from over 600 leaders, showing the scale of the problem and practical steps to close gaps, reduce friction, and catch up quickly. 📰 Around the Cyber World WhatsApp Tests Usernames Instead of Phone Numbers — WhatsApp is planning to introduce usernames and unique IDs instead of phone numbers, allowing users to send messages and make voice or video calls without sharing numbers. The optional privacy feature is expected to roll out globally by June 2026, with users and businesses able to reserve unique handles. "We're excited to bring usernames to WhatsApp in the future to help people connect with new friends, groups, and businesses without having to share their phone numbers," the company said in a statement shared with The Economic Times. The feature has been under test since early January 2026. Signal introduced a similar feature in early 2024. FBI Details SE Asia Scam Centers — The U.S. Federal Bureau of Investigation (FBI) detailed its work with Thai authorities to shut down scam centers proliferating in Southeast Asia. The schemes, which primarily target retirees, small-business owners, and people seeking companionship, have been described as a blend of cyber fraud, money laundering, and human trafficking, causing billions of dollars in annual losses. These scam centers operate in a manner that's similar to how legitimate corporations do. "Recruiters advertise high-paying jobs abroad. Workers are flown to foreign countries only to discover that the positions do not exist," the FBI said. "Passports are confiscated. Armed guards patrol the grounds. Under threat of violence, workers are forced to pose as potential romantic partners or savvy investment advisers, cultivating trust with victims over weeks or months." Recent crackdowns in countries like Cambodia have freed thousands of workers from scam compounds, but the FBI warned that these breakthroughs can be temporary, as criminal networks always tend to relocate, rebrand, or shift tactics in response to law enforcement actions. APT28 Exposed Server Leaks SquirrelMail XSS Payload — A second exposed open directory discovered on a server ("203.161.50[.]145") associated with APT28 (aka Fancy Bear) has offered insights into the threat actor's espionage campaigns targeting government and military organizations across Ukraine, Romania, Bulgaria, Greece, Serbia, and North Macedonia. According to Ctrl-Alt-Intel, the directory contained command-and-control (C2) source code, scripts to steal emails, credentials, address books, and 2FA tokens from Roundcube mailboxes, telemetry logs, and exfiltrated data. The stolen data consists of 2,870 emails from government and military mailboxes, 244 sets of stolen credentials, 143 Sieve forwarding rules (to silently forward every incoming email to an attacker-controlled mailbox), and 11,527 contact email addresses. One of the newly identified tools is an XSS payload targeting the SquirrelMail webmail software, highlighting the threat actor's continued focus on leveraging XSS flaws to steal data from email inboxes. It's worth noting that the server was attributed to APT28 by the Computer Emergency Response Team of Ukraine (CERT-UA) as far back as September 2024. "Fancy Bear developed a modular, multi-platform exploitation toolkit where a victim simply opening a malicious email – with no further clicks – could result in their credentials stolen, their 2FA bypassed, emails within their mailbox exfiltrated, and a silent forwarding rule established that persists indefinitely," Ctrl-Alt-Intel said. Analysis of a Beast Ransomware Server — An analysis of an open directory on a server ("5.78.84[.]144") associated with Beast, a ransomware-as-a-service (RaaS) that's suspected to be the successor to Monster ransomware, has uncovered the various tools used by the threat actors and the different stages of their attack lifecycle. These included Advanced IP Scanner and Advanced Port Scanner to map internal networks and find open remote desktop protocol (RDP) or server message block (SMB) ports. Also identified were programs to locate sensitive files for exfiltration and flag which servers hold the most data, as well as Mimikatz, LaZagne, and Automim (for credential harvesting), AnyDesk (for persistence), PsExec (for lateral movement), and MEGASync (for data exfiltration). Beast ransomware operations paused in November 2025 and resumed in January 2026. GrapheneOS Opposes the Unified Attestation Initiative — GrapheneOS has come out strongly against Unified Attestation, stating it "serves no truly useful purpose beyond giving itself an unfair advantage while pretending it has something to do with security." The Unified Attestation initiative is an open-source, decentralized alternative to the Google Play Integrity API to provide device and app integrity checks for custom ROMs without requiring Google Play Services. "We strongly oppose the Unified Attestation initiative and call for app developers supporting privacy, security, and freedom on mobile to avoid it," GraphenseOS said. "Companies selling phones should not be deciding which operating systems people are allowed to use for apps." VoidStealer Uses Chrome Debugger to Steal Secrets — An information stealer known as VoidStealer has observed using a novel debugger-based Application-Bound Encryption (ABE) bypass technique that leverages hardware breakpoints to extract the "v20_master_key" directly from browser memory and use it to decrypt sensitive data stored in the browser. VoidStealer is a malware-as-a-service (MaaS) infostealer that began being marketed on several dark web forums in mid-December 2025. The ABE bypass technique was introduced in version 2.0 of the stealer announced on March 13, 2026. "The bypass requires neither privilege escalation nor code injection, making it a stealthier approach compared to alternative ABE bypass methods," Gen Digital said. VoidStealer is assessed to have adopted the technique from the open-source ElevationKatz project. FBI Says it is Buying Americans' location Data — FBI director Kash Patel admitted that the agency is buying location data that can be used to track people's movements without a warrant. "We do purchase commercially available information that’s consistent with the Constitution and the laws under the Electronic Communications Privacy Act, and it has led to some valuable intelligence for us," Patel said at a hearing before the Senate Intelligence Committee. Iranian Botnet Exposed via Open Directory — An Open Directory on "185.221.239[.]162:8080" has been found to contain several payloads, including a Python-based botnet script, a compiled DDoS binary, multiple C-language denial-of-service files, and IP addresses associated with SSH credentials. "A Python script called ohhhh.py reads credentials in a host:port|username|password format and opens 500 concurrent SSH sessions, compiling and launching the bot client on each host automatically," Hunt.io said. "The exposed .bash_history captured three distinct phases of work: standing up the tunnel network, building and testing DDoS tooling against live targets, and iterative botnet development across multiple script versions." The activity has not been linked to any state-directed campaign. OpenClaw Developers Targeted in Phishing Attack — OpenClaw's combination of flexibility, local control, and a fast-growing ecosystem has made it popular among developers in a very short time. While that unprecedented adoption speed has exposed organizations to new security risks of its own (i.e., vulnerabilities and the presence of malicious skills on ClawHub and SkillsMP), threat actors are also capitalizing on the brand name and reputation to set up fake GitHub accounts for a phishing campaign that lures unsuspecting developers with promises of free $CLAW tokens and trick them into connect their cryptocurrency wallet. "The threat actor creates fake GitHub accounts, opens issue threads in attacker-controlled repositories, and tags dozens of GitHub developers," OX Security researchers Moshe Siman Tov Bustan and Nir Zadok said. "The posts claim that recipients have won $5,000 worth of CLAW tokens and can collect them by visiting a linked site and connecting their crypto wallet." The linked site ("token-claw[.]xyz") is a near-identical clone of openclaw.ai rigged with a wallet-draining "Connect your wallet" button designed to conduct cryptocurrency theft. New Campaign Targets Energy Operations Personnel in Pakistan — A targeted campaign against operations personnel at energy firms linked to projects in Pakistan has leveraged phishing emails mimicking invitations to the upcoming Pakistan Energy Exhibition & Conference (PEEC). The messages, sent from compromised accounts from a Pakistani university and a government organization, aim to deceive victims into opening PDF attachments with a fake Adobe Acrobat Reader update prompt. Clicking the update leads to the download of a ClickOnce application resource that drops the Havoc Demon C2 framework. "The redirect chain was also wrapped in geofencing and browser fingerprinting, limiting access to intended targets," Proofpoint said. "That likely reduced the exposure to automated analysis while keeping the delivery path tightly scoped." The activity has been codenamed UNK_VaporVibes. It's assessed to share overlaps with activity publicly associated with SloppyLemming. Over 373K Dark Web Sites Down — International law enforcement agencies announced the takedown of one of the largest known networks of fraudulent platforms on the dark web, uncovering hundreds of thousands of fake websites used to scam users seeking child sexual abuse content. A 10-day international operation led by German authorities and supported by Europol shut down more than 373,000 dark web domains run by a 35-year-old man based in China, who had been operating a sprawling network of fraudulent platforms since at least 2021. While the sites advertised child abuse material and cybercrime-as-a-service offerings, nothing was actually delivered after victims made a payment in Bitcoin. The fraudulent scheme netted the operator an estimated €345,000 from around 10,000 people. Authorities from 23 countries participated in the operation, and have since identified 440 customers whose purchases are now under active investigation. Malicious npm Packages Steal Secrets — Two malicious npm packages, sbx-mask and touch-adv, have been found to steal secrets from victims' computers. While one invokes the malicious code via the postinstall script, the other executes it when application code is invoked by the developer after importing it. "The evidence strongly suggests account takeover of a legitimate publisher, rather than intentional malicious activity," Sonatype said. "Hijacked publisher accounts are particularly concerning as, over time, maintainers build trust with the users of their components. Attackers aim to take advantage of that trust in order to steal valuable, or profitable, information." China to Have Its Own Post-Quantum Cryptography in 3 Years — China is reportedly planning to develop its own national post-quantum cryptography standards within the next three years, according to a report from Reuters. The U.S. finalized its first set of post-quantum cryptography standards in 2024 and is aiming to achieve full industry migration by 2035. What's Next for Tycoon2FA? — A recent law enforcement operation dismantled the infrastructure associated with the Tycoon2FA phishing-as-a-service (PhaaS) platform. However, a new analysis from Bridewell has revealed that some of the 2FA phishing CAPTCHA pages are still live. The lingering activity, the cybersecurity company noted, stems from the fact that these pages operate on a massive network of compromised third-party sites, legitimate SaaS platforms, and thousands of disposable domains. "Operators and affiliates are highly agile and will attempt to rebuild, migrate to new infrastructure, or pivot to competing PhaaS platforms," it added. "The live CAPTCHA pages we are seeing may belong to surviving criminal affiliates attempting to keep their individual campaigns breathing on secondary proxy networks." 🔧 Cybersecurity Tools MESH → It is an open-source tool from BARGHEST that enables remote mobile forensics and network monitoring over an encrypted, peer-to-peer mesh network resistant to censorship. It connects Android/iOS devices behind firewalls or CGNAT using a modified Tailscale-like protocol (no central servers needed), supports ADB wireless debugging, libimobiledevice, PCAP capture, and Suricata IDS—allowing secure, direct access for live logical acquisitions in restricted or hostile environments. enject → It is a lightweight Rust tool that protects .env secrets from AI assistants like Copilot or Claude. It replaces real values in your .env file with placeholders (e.g., en://api_key). Secrets stay encrypted in a per-project store (AES-256-GCM, master password protected). When you run enject run -- , it decrypts them only in memory at runtime, then wipes them—never leaving plaintext on disk. Open-source, macOS/Linux, perfect for safe local development. Disclaimer: For research and educational use only. Not security-audited. Review all code before use, test in isolated environments, and ensure compliance with applicable laws. Conclusion And that’s the week. The real pattern isn’t any one story; it’s the gap. The gap between a flaw and detection. Between a patch and a deployment. Between knowing and doing. Most of this week’s damage happened in that gap, and it’s not new. Before you move on: update your mobile devices, review anything touching your CI/CD pipeline, and don’t store crypto wallet recovery phrases in notes apps.
thehackernews.comMar 23, 2026extracted
Proactive strategies for cyber resilience with Wazuh
Cyber resilience involves the ability to anticipate threats, withstand active attacks, respond quickly to incidents, and recover operations with minimal disruption. Modern cyber threats continue to introduce new challenges, which is no longer a question of whether a security incident will occur, but when. Over the years, trends have shown that traditional reactive security approaches are insufficient to defend against modern cyber threats. To keep pace with constantly evolving cyber threats, organizations must adopt proactive strategies focused on cyber resilience. Wazuh, an open source security platform, provides the capabilities needed to build proactive cyber resilience. By combining SIEM and XDR capabilities, Wazuh enables organizations to detect threats early, respond to incidents effectively, and continuously adapt their defenses as threats evolve. Cyber resilience beyond prevention A resilient organization is not defined solely by its ability to prevent attacks, but by how quickly it can identify, contain, and recover from them while maintaining operations. Achieving this level of preparedness requires security platforms that provide continuous security data, real-time detection, and rapid incident response capabilities. In practical terms, cyber resilience depends on a set of core, proactive strategies that guide security operations: Visibility across your environment: Comprehensive visibility across endpoints, servers, applications, networks, and cloud workloads is essential for operational readiness. It enables security teams to understand normal behavior, confirm monitoring coverage, and ensure response readiness before incidents occur. Early threat detection: Anticipating malicious activity at an early stage helps prevent attackers from establishing persistence and reduces the overall impact of an incident. By continuously correlating security data and system events, security teams can identify threats before they develop into full-scale compromises. Rapid incident response: Coordinated and automated incident response capabilities enable organizations to contain threats swiftly, limit operational disruption, and maintain critical business functions during active cyber incidents. Recovery and continuous improvement: Cyber resilience depends on the ability to recover quickly from incidents while continuously strengthening security controls and processes. Insights gained from incidents, detections, and assessments help organizations strengthen defenses and reduce future risk. Anticipate threats and automate your incident response with a unified security platform. Gain full visibility across cloud and on-premises environments while reducing your attack surface with real-time detection and AI-powered insights. Start your journey toward cyber resilience today. Get Started with Wazuh Achieving cyber resilience with Wazuh Wazuh helps organizations put cyber resilience into practice by delivering centralized visibility, real-time threat detection, automated response, IT hygiene, and continuous assessment of security posture across IT environments. This section explores how security teams can operationalize cyber resilience strategies using Wazuh. Comprehensive visibility: The Wazuh SIEM and XDR help provide centralized visibility into workloads across virtualized, on-premises, cloud-based, and containerized environments by continuously collecting and analyzing security data. The Wazuh agent can be deployed on Linux, Windows, macOS, and other supported operating systems to collect security data, which is forwarded to the Wazuh server. Wazuh also provides syslog and agentless monitoring support for network devices and systems where agents cannot be installed, ensuring monitoring coverage and operational readiness. Detection of suspicious activity: Wazuh enables early detection by correlating security data from multiple sources, allowing security teams to identify malicious behavior in its early stages. Wazuh analyzes logs collected from various endpoints, extracts relevant information from the processed logs, and applies detection rules to match specific patterns. By leveraging its capabilities, such as log data analysis, malware detection, and File Integrity Monitoring (FIM), Wazuh can detect anomalies, file changes, and indicators of compromise across various endpoints. Security analysts can also conduct threat hunting by proactively analyzing logs, endpoint telemetry, and system behavior to identify hidden or emerging threats. Automated incident response: Wazuh provides an incident response capability that automatically responds to detected threats. Security teams can configure custom response actions, such as blocking malicious IP addresses, terminating suspicious processes, or disabling compromised user accounts. Automating response actions ensures that high-priority incidents are addressed and remediated in a timely and consistent manner. In the example below, Wazuh is used to detect and automatically remove the Cephalus ransomware executable from a monitored endpoint. Artificial Intelligence (AI): Wazuh offers a Wazuh AI analyst service, designed for Wazuh Cloud users, that provides security teams with AI-assisted analysis and insights. This service provides automated, AI-driven security analysis by combining Wazuh Cloud with advanced machine learning models. It processes security data at scale to generate actionable insights that strengthen an organization’s overall security posture. Wazuh also showcased the integration of the Claude LLM into the Wazuh dashboard in the blog post Leveraging Claude Haiku in the Wazuh dashboard for LLM-Powered insights. This integration provides contextual, summarized insights and expert-level analysis that aid incident investigation. This integration adds a chat assistant feature to the Wazuh dashboard interface, where users can analyze security data. Improved IT hygiene and security posture: Cyber resilience involves maintaining a good IT hygiene and a hardened security baseline across the environment. Addressing issues like poor patching practices and insecure configurations proactively reduces the attack surface, thereby limiting the opportunities available to attackers. Wazuh helps organizations improve IT hygiene through continuous asset visibility, vulnerability detection, and configuration assessment. The Wazuh SIEM and XDR offer vulnerability detection and security configuration assessment capabilities. The Wazuh vulnerability detection capability identifies known CVEs across operating systems and installed software by using vulnerability information available in the Wazuh CTI (Centralized Threat Intelligence) platform. The platform aggregates vulnerability data from various sources, including operating system vendors and public vulnerability databases. Wazuh also offers a Security Configuration Assessment (SCA) capability that evaluates systems against security standards and best practices like the Center for Internet Security (CIS) benchmarks to identify security misconfigurations and flaws. In addition, Wazuh provides out-of-the-box rulesets mapped to regulatory standards, enabling organizations to identify gaps in compliance against frameworks such as PCI DSS, GDPR, HIPAA, and NIST 800-53. By combining vulnerability detection, configuration assessment, and regulatory compliance in a single platform, Wazuh supports continuous security posture improvement and long-term cyber resilience. Continuous improvement and adaptability: Wazuh supports continuous improvement by providing rich security data, dashboards, and reporting that allow security teams to analyze trends and identify recurring weaknesses across their environment. Wazuh also enables organizations to develop custom decoders and rules tailored to their unique log sources, applications, and environments, thereby improving detection accuracy and reducing false positives. This ensures that alerts and correlations remain relevant as infrastructure and attack patterns evolve. As an open source platform, Wazuh provides organizations with the flexibility to adapt the solution to their needs rather than conforming to a fixed security model. The platform benefits from continuous enhancements driven by an active community and continuous development, enabling organizations to evolve their security capabilities and maintain long-term cyber resilience. Conclusion Cyber resilience goes beyond preventing cyberattacks or relying on isolated security controls and reactive incident handling. It requires continuous visibility, timely threat detection, coordinated incident response, and the ability to recover and adapt as threats, environments, and attack techniques evolve. Wazuh unifies threat detection, automated response, and compliance within one extensible platform. This shifts organizations from reactive defense toward sustained cyber resilience. Discover more about Wazuh by exploring their documentation and joining their growing community of professionals. Sponsored and written by Wazuh.
bleepingcomputer.comFeb 11, 2026extracted
Maintaining enterprise IT hygiene using Wazuh SIEM/XDR
Organizations face the challenge of maintaining visibility and control over their IT infrastructure. A forgotten user account, an outdated software package, an unauthorized service, or a malicious browser extension can expose vulnerabilities that threat actors are eager to exploit. Addressing these risks requires a systematic approach to maintaining the security and integrity, and overall health of every system within the organization. This is where IT hygiene becomes essential. IT hygiene is the systematic practice of maintaining consistent, secure configurations across all endpoints in an organization's infrastructure. It encompasses continuous monitoring of hardware, software, user accounts, running processes, and network configurations to ensure alignment with security policies and compliance requirements. Poor IT hygiene creates security gaps that can lead to data breaches, system compromises, and significant financial and reputational damage. Wazuh is a free, open source security platform that provides multiple capabilities, including a dedicated IT hygiene capability, file integrity monitoring, configuration assessment, vulnerability detection, and active response. This post explores how organizations can leverage Wazuh to maintain enterprise IT hygiene, examines practical use cases, and demonstrates its effectiveness in improving their security posture. IT hygiene overview IT hygiene encompasses the preventive measures organizations implement to maintain the health and security of their IT infrastructure. It reduces the risk of security incidents by ensuring systems remain properly configured, up to date, and monitored. Key aspects include: Asset visibility: Maintaining a comprehensive, up-to-date inventory of all hardware and software assets across your infrastructure. Configuration management: Ensuring systems are configured in accordance with security best practices and organizational policies. These include minimizing services, ports, and software, as well as authentication and account hardening configurations. Patch management: Regularly updating software to address known vulnerabilities. Access control: Managing user accounts and permissions to prevent unauthorized access. Monitoring and auditing: Continuously tracking system activities and configurations to detect anomalies. Without proper IT hygiene practices, organizations become vulnerable to threats such as unauthorized access, malware infections, data exfiltration, and compliance violations. Protect your systems against hidden threats. Learn how attackers use malware persistence techniques, and how Wazuh helps you detect and stop them. Learn More About Wazuh The Wazuh IT hygiene capability Wazuh introduced its IT hygiene capability in version 4.13.0, providing security teams with a centralized dashboard for monitoring system inventory across an entire infrastructure. The capability leverages the Wazuh Syscollector module to gather and aggregate data from all monitored endpoints, storing it in dedicated indices within the Wazuh indexer for querying and analysis. The Wazuh IT hygiene capability collects system inventory data, including: Hardware specifications such as CPU, memory, and storage data Operating system details and versions Installed software packages and their versions Running processes and services Network configurations and open ports User accounts and group memberships Browser extensions and their permissions This data is presented through an intuitive dashboard interface that enables security administrators to query and analyze inventory information across multiple endpoints simultaneously, eliminating the need for time-consuming manual checks. Accessing the IT hygiene dashboard Users can access inventory data through the Wazuh dashboard by navigating to Security operations > IT hygiene. The interface provides multiple tabs for different inventory categories: Each tab allows administrators to add custom filters to refine queries and select additional fields to display. This flexibility enables security teams to quickly identify configuration changes, policy violations, and security anomalies across their infrastructure. Practical use cases for enterprise IT hygiene Software patch management Maintaining consistent software versions across all endpoints is critical for security, stability, and compliance. Inconsistent package versions introduce exploitable vulnerabilities and can violate organizational patching policies. Manually verifying software versions across thousands of endpoints is impractical and error-prone. The Wazuh IT hygiene capability provides comprehensive visibility into installed packages across the entire infrastructure. Security administrators can: Identify endpoints running outdated or vulnerable software versions Detect unauthorized software installations Verify compliance with approved software catalogs For example, administrators can use the filters on the Packages tab to identify all endpoints running a specific version of a critical application or library. By applying filters on fields such as package.name and the field package.version, security teams can quickly generate a list of endpoints requiring package updates, significantly streamlining the patch management process. Browser extension management Browser extensions are an increasingly exploited attack surface, particularly in enterprise environments. Extensions with broad permissions can access sensitive data, inject malicious scripts, intercept credentials, and serve as malware vectors. Recent security incidents have involved fake ad blockers and password managers used in credential theft campaigns. The Wazuh IT hygiene capability provides complete visibility into browser extensions across all monitored endpoints, including: Extension names and versions Requested permissions (tabs, storage, webRequest, and so on.) Installation dates and sources User associations Security teams can use this information to identify unauthorized or high-risk extensions, detect extensions with excessive permissions, and enforce browser extension policies. This enables them to respond quickly to reports of malicious extensions. Identity management The Identity section of the Wazuh IT hygiene enables account auditing to ensure that user identities and permissions remain aligned with organizational policies across the entire infrastructure. Administrators can audit user information by applying the filters within the Users and Groups dashboard. The following use case demonstrates dormant account detection to identify inactive or unnecessary accounts, and privilege account verification to ensure only authorized users hold elevated permissions. Dormant account detection Dormant or abandoned user accounts pose significant security risks. These accounts, often belonging to former employees or contractors, can be exploited by attackers for unauthorized access. They represent forgotten attack vectors that may lack current security controls, such as multi-factor authentication, and thus present an entry point for attackers. The Wazuh IT hygiene capability enables organizations to identify dormant accounts systematically. Administrators can: a. Navigate to Security operations > IT Hygiene > Identity > Users. b. Filter accounts based on criteria such as: Accounts with valid login shells (indicating interactive access) Last login dates beyond organizational policies Accounts without recent activity c. Generate lists of accounts requiring review or deactivation For example, the above image shows users filtered for user.shell values such as /bin/bash or /bin/sh to identify accounts capable of interactive system access. Cross-referencing this data with the details from user.last.login field reveals dormant accounts that should be investigated or removed. Privileged account auditing Unauthorized users with administrative privileges pose a critical security risk. Accounts in the local Administrators group (Windows) or sudo group (Linux) can install software, modify system configurations, disable security controls, and access sensitive data. Even if rarely used, these accounts are valuable targets for attackers seeking to maintain persistence and escalate privileges. The Wazuh IT hygiene capability allows security teams to: Identify all users with elevated privileges across the infrastructure Verify that only authorized personnel have administrative access Detect privilege escalation attempts or policy violations Maintain compliance with access control policies Administrators can use filters in the Groups tab within the Identity section of the Wazuh IT hygiene dashboard to identify members of privileged groups. Administrators can then cross-reference these results against authorized user lists to identify accounts with unauthorized privilege assignments. Hardware resource optimization In large enterprise environments with numerous Linux and Windows endpoints, mismatched hardware specifications can lead to significant operational challenges. Servers with insufficient CPU cores or memory create performance bottlenecks that impact critical workloads, while oversized instances waste resources and drive unnecessary cloud computing costs. The Wazuh IT hygiene capability enables resource analysis across all devices, allowing administrators to: Identify endpoints that fall outside policy-defined specifications Detect underpowered systems affecting critical services Find oversized instances wasting budget Optimize cloud resource allocation Plan capacity upgrades based on actual usage patterns For example, administrators can use the filters within the Hardware tab to identify all servers with memory below a defined threshold (for example, 8GB for web servers) or systems with excessive resources that could be downsized. This data-driven approach supports both cost optimization and reliability improvements without requiring manual inspection of individual endpoints. Port and service monitoring Unnecessary open ports and unauthorized services expand the attack surface. Each open port is a potential entry point for attackers, and unauthorized services may contain vulnerabilities or misconfigurations that compromise security. The Wazuh IT hygiene capability provides comprehensive visibility into: All open network ports across endpoints Services listening on each port Process associations for running services Port states and configurations Security teams can use the filter within the Ports tab to identify endpoints with unexpected open ports or unauthorized services. For instance, database ports (3306, 5432) should not be open on workstations or web servers. They should be restricted to internal networks or specific application servers only. Best practices for implementing IT hygiene with Wazuh To maximize the benefits of Wazuh IT hygiene capabilities, organizations should follow these best practices: 1. Establish baseline inventories: Document expected configurations, approved software, authorized accounts, and standard hardware specifications for different endpoint types. Create explicit policies for software versions, user account lifecycles, browser extensions, privileged access, and hardware standards. 2. Automate alerting: Configure Wazuh to generate alerts for critical deviations such as new privileged accounts, unauthorized software installations, or suspicious browser extensions. 3. Integrate with workflows: Connect IT hygiene findings with existing ticketing systems, patch management tools, and incident response processes. 4. Maintain documentation: Keep detailed records of authorized exceptions, approved changes, and remediation actions taken in response to hygiene issues. 5. Leverage other Wazuh modules: Leverage SCA, vulnerability detection, and malware detection alongside IT hygiene for comprehensive security coverage. 6. Schedule regular reviews: Conduct periodic audits of inventory data to identify drift from baseline configurations and policy violations. 7. Train security teams: Ensure personnel understand how to effectively query and interpret IT hygiene data to identify security risks. Conclusion Maintaining IT hygiene reduces the risk of security incidents by keeping systems correctly configured, patched, and monitored. The Wazuh IT hygiene capability meets this need by providing a centralized, real-time inventory across all endpoints. Security teams can quickly spot policy violations, configuration drift, and security anomalies using holistic data on hardware, software, accounts, processes, ports, and browser extensions, enabling informed, data-driven decisions. Visit the Wazuh website or join the Wazuh community to learn more. Sponsored and written by Wazuh.
bleepingcomputer.comDec 9, 2025extracted
Ransomware Defense Using the Wazuh Open Source Platform
Ransomware is malicious software designed to block access to a computer system or encrypt data until a ransom is paid. This cyberattack is one of the most prevalent and damaging threats in the digital landscape, affecting individuals, businesses, and critical infrastructure worldwide. A ransomware attack typically begins when the malware infiltrates a system through various vectors such as phishing emails, malicious downloads, or exploiting software vulnerabilities. Once activated, the malware encrypts files using strong cryptographic algorithms, rendering them inaccessible to the legitimate owner. The attackers then demand payment, usually in cryptocurrency like Bitcoin, in exchange for the decryption key. Modern ransomware variants have evolved beyond simple file encryption. Some employ double extortion tactics, where attackers encrypt data, exfiltrate sensitive information, and threaten to publish it publicly if the ransom is not paid. This puts pressure on victims, particularly organizations handling confidential customer data or proprietary business information. Ransomware development and propagation Understanding ransomware creation and distribution is essential for developing effective defense strategies. The ransomware lifecycle involves sophisticated development processes and diverse propagation methods that exploit technical vulnerabilities and human behavior. Ransomware development Ransomware is typically developed by cybercriminal organizations or individual threat actors with programming expertise. The creation process involves: Malware coding: Developers write malicious code using various programming languages, incorporating encryption algorithms and command-and-control communication protocols. Ransomware-as-a-Service (RaaS): Some criminal groups operate subscription-based models that provide ransomware tools to affiliates in exchange for a percentage of ransom payments. Customization and testing: Attackers test their malware against security solutions to ensure it can evade detection. Propagation methods Ransomware spreads through multiple attack vectors: Phishing emails: Malicious attachments or links that appear legitimate trick users into downloading ransomware. Exploit kits: Automated tools that scan for and exploit known vulnerabilities in applications and operating systems. Remote Desktop Protocol (RDP) attacks: Attackers gain unauthorized access through weak or compromised RDP credentials. Malicious websites and downloads: Downloads from compromised or malicious websites install ransomware with or without the user's knowledge. Supply chain attacks: Compromised trusted software or service providers can distribute ransomware to customers. Removable media: Infected USB drives and external storage devices can spread ransomware when connected to computer systems. Effects of a ransomware attack The impact of ransomware extends far beyond the immediate encryption of files. Organizations and individuals affected by ransomware experience multiple consequences that can have long-lasting repercussions on operations, finances, and reputation. Financial consequences Ransomware attacks inflict financial damage beyond file encryption. Victims may face ransom demands ranging from hundreds to millions of dollars, with no guarantee of data recovery even after payment. Additional expenses arise from incident response, forensic investigations, system restoration, and security enhancements, while regulatory non-compliance can lead to substantial legal fines and penalties for data breaches. Operational consequences Ransomware attacks cause significant operational disruption by crippling access to vital resources. Critical business data, customer information, and intellectual property may be lost or compromised, while essential services become unavailable, impacting customers, partners, and internal workflows. The resulting operational downtime often surpasses the ransom cost, as businesses can experience weeks or months of halted operations. Reputational damage Ransomware incidents often lead to lasting reputational damage as data breaches erode customer trust and confidence in an organization’s ability to safeguard sensitive information. Public disclosure of such attacks can weaken market position, strain business relationships, and create a competitive disadvantage. Preventing ransomware attacks Preventing ransomware attacks requires a multi-layered defense strategy that combines technical controls, organizational policies, and user awareness. Understanding and implementing these protective measures reduces the risk of successful ransomware infections. Technical defenses Security Information and Event Management (SIEM) and Extended Detection and Response (XDR): Implement continuous monitoring to detect and respond to suspicious activities and anomalous behavior. File integrity monitoring: Track changes to files, folders, and system configurations. This helps you identify malware behavior within your environment. Network traffic analysis: Monitor for unusual data exfiltration patterns or command-and-control communications. Regular backups: To ensure recovery without ransom, maintain frequent, automated backups of critical data stored offline or in immutable storage. Patch management: Keep operating systems, applications, and firmware up to date to remediate known vulnerabilities that ransomware exploits. Network segmentation: Isolate critical systems and limit lateral movement opportunities for attackers. Email filtering: Implement robust email security solutions to block phishing attempts and malicious attachments. Access controls: Enforce the principle of least privilege and implement strong authentication mechanisms, including multi-factor authentication. Application whitelisting: Allow only approved applications to execute in your environment, preventing unauthorized malware from running. Organizational practices Security awareness training: Educate employees about phishing tactics, social engineering, and safe computing practices. Incident response planning: Develop and regularly test comprehensive incident response procedures for ransomware scenarios. Security audits: Conduct regular vulnerability assessments and penetration testing to identify security weaknesses. Vendor risk management: Assess and monitor the security posture of third-party service providers. What Wazuh offers for ransomware protection Wazuh is a free and open source security platform that provides comprehensive capabilities for detecting, preventing, and responding to ransomware threats. It is a unified XDR (Extended Detection and Response) and SIEM (Security Information and Event Management) platform. Wazuh helps organizations build resilience against ransomware attacks through its out-of-the-box capabilities and integration with other security platforms. Threat detection and prevention Wazuh employs multiple detection mechanisms to identify ransomware activities. These include: Malware detection: Wazuh integrates with threat intelligence feeds and utilizes signature-based and anomaly-based detection methods to identify known ransomware variants. Vulnerability detection: This Wazuh capability scans systems for known vulnerabilities that ransomware commonly exploits, enabling proactive patching and reducing the likelihood of successful compromise. Log data analysis: This Wazuh capability analyzes security events collected from user endpoints, servers, cloud workloads, and network devices to detect ransomware indicators. Security configuration monitoring (SCA): The Wazuh SCA evaluates system configurations against security best practices and compliance frameworks. File integrity monitoring (FIM): This Wazuh capability monitors critical files and directories, detecting unauthorized modifications that may indicate ransomware encryption activity. Regulatory compliance monitoring: This Wazuh capability helps organizations maintain security standards and regulatory compliance requirements that deter ransomware attacks. Incident response capabilities Active response: The Wazuh Active Response capability automatically executes predefined actions when threats are detected, such as isolating infected systems, blocking malicious processes, or quarantining files. Integration with external solutions: Wazuh integrates with other security tools and platforms to improve organizations’ security posture. Use cases The following sections show some use cases of Wazuh detection and response to ransomware. Detecting and responding to DOGE Big Balls ransomware with Wazuh The DOGE Big Balls ransomware, a modified version of the FOG ransomware, combines technical exploits with psychological manipulation targeting enterprise environments. This malware variant delivers its payload through phishing campaigns or unpatched vulnerabilities. It then performs privilege escalation, reconnaissance, file encryption, and note creation on the victim's endpoint. Detection Wazuh detects the DOGE Big Balls ransomware using threat detection rules and a Wazuh Custom Database (CBD) list to match its specific pattern. CBD list containing DOGE Big Balls reconnaissance commands. net config Workstation: systeminfo: hostname: net users: ipconfig /all: route print: arp -A: netstat -ano: netsh firewall show state: netsh firewall show config: schtasks /query /fo LIST /v: tasklist /SVC: net start: DRIVERQUERY: Threat detection rules 61613 (?i)[C-Z]:.*\\\\.*.exe (?i)[C-Z]:.*.\\\\DbgLog.sys A log file $(win.eventdata.targetFilename) was created to log the output of the reconnaissance activities of the DOGE Big Balls ransomware. Suspicious activity detected. T1486 61603 etc/lists/doge-big-balls-ransomware The command $(win.eventdata.commandLine) is executed for reconnaissance activities. Suspicious activity detected. no_full_log 61613 (?i)[C-Z]:.*\\\\.*.exe (?i)[C-Z]:.*.\\\\readme.txt DOGE Big Balls ransom note $(win.eventdata.targetFilename) has been created in multiple directories. Possible DOGE Big Balls ransomware detected. T1486 100020 100021 Possible DOGE Big Balls ransomware detected. T1486 These rules flag the execution of known reconnaissance commands and detect when multiple ransom notes appear across directories. These are DOGE Big Balls ransomware IOCs that indicate file encryption and other ransomware activities. Automated response Wazuh enables ransomware detection and removal using its File Integrity Monitoring (FIM) capability and integration with YARA. In this use case, Wazuh monitors the Downloads directory in real-time. When a new or modified file appears, it triggers the active response capability to execute a YARA scan. If a file matches known YARA ransomware signatures like DOGE Big Balls, the custom active response script deletes it automatically and logs the action. Custom decoders and rules on the Wazuh server parse those logs to generate alerts showing whether the file was detected and successfully removed. Detecting Gunra ransomware with Wazuh The Gunra ransomware is typically used by private cybercriminals to extort money from its victims. It utilizes a double-extortion model that encrypts files and exfiltrates data for publication should its victim fail to pay the ransom. The Gunra ransomware spreads through Windows systems by encrypting files, appending the .ENCRT extension, and leaving ransom notes named R3ADM3.txt. It deletes shadow copies, disables backup and antivirus services to block recovery, and uses Tor networks to hide its operators. These actions make data restoration difficult and help the attackers maintain anonymity during ransom negotiations. Detection The following Wazuh rules alert when ransom notes named R3ADM3.txt appear, system components like VSS or amsi.dll are tampered with, or suspicious modules such as urlmon.dll are loaded for network activity. The rules also track attempts to delete shadow copies or disable backup and admin functions, indicating behavior typical of ransomware preparing for file encryption. Threat detection rules 61613 [^"]+\.exe [^"]*R3ADM3\.txt Possible Gunra ransomware activity detected: Multiple ransom notes dropped in $(win.eventdata.targetFilename) T1543.003 T1486 61609 C:\\\\Windows\\\\System32\\\\VSSVC\.exe C:\\\\Windows\\\\System32\\\\amsi\.dll Possible ransomware activity detected: Suspicious Volume Shadow copy Service (VSS) loaded amsi.dll for tampering and evasion attempt. T1562 T1562.001 61609 (C:\\\\Windows\\\\SystemApps\\\\Microsoft\.Windows\.AppRep\.ChxApp_cw5n1h2txyewy\\\\CHXSmartScreen\.exe) C:\\\\Windows\\\\System32\\\\urlmon\.dll Possible ransomware activity detected: Urlmon.dll was loaded, indicating network reconnaissance. T1562.001 60103 Backup Operators S-1-5-32-551 C:\\\\Windows\\\\System32\\\\VSSVC\.exe Possible Gunra ransomware activity detected: Volume Shadow copy Service (VSS) deletion attempts, gearing up to disable backups. T1562 T1562.002 60103 Administrators S-1-5-32-544 C:\\\\Windows\\\\System32\\\\VSSVC\.exe Possible Gunra ransomware activity detected: Volume Shadow copy Service (VSS) deletion shadow attempts, gearing to disable local admin accounts T1562 T1562.002 Automated response Wazuh performs automated responses to Gunra ransomware malicious file activities using its FIM capability and integration with VirusTotal. In this use case, the Wazuh File Integrity Monitoring (FIM) module monitors the Downloads folder in real-time, triggering scans whenever files are added or changed. A custom active response executable, then securely deletes any file that VirusTotal flags as a threat. Ransomware protection on Windows with Wazuh Wazuh provides ransomware protection and file recovery on monitored Windows endpoints using its command module and the Windows Volume Shadow Copy Service (VSS). This integration allows administrators to automatically take snapshots of monitored endpoints to recover files to a state before they are encrypted by malware. The following image shows successful Wazuh Active Response file recovery alerts. Conclusion Ransomware attacks pose significant financial, operational, and reputational damage. They require multi-layered defenses that combine early detection with incident response. Organizations that invest in these practices are better equipped to withstand and recover from such attacks. Wazuh provides capabilities that enable early detection and rapid response to contain ransomware attacks. It offers out-of-the-box capabilities for vulnerability detection, file integrity monitoring, log data analysis, and automated responses to prevent ransomware-caused data loss and downtime.
thehackernews.comNov 4, 2025extracted
The role of Artificial Intelligence in today’s cybersecurity landscape
Artificial Intelligence (AI) refers to computer programs designed to perform tasks that typically require human intelligence. These include learning, problem-solving, decision-making, and perception. AI systems use big data and algorithms to analyze information, adapt their behavior, and achieve goals without constant human oversight. The rapid improvements in AI capabilities enable advanced attacks by malicious actors. Attackers no longer rely solely on manual intrusion attempts. They harness automation, AI-driven malware, and Living off the Land (LOTL) tactics that blend with legitimate activity. Organizations must adopt equally advanced technologies to defend against this new threat landscape. In modern security operations, AI is indispensable. It applies not only to anomaly detection but also to log correlation, malware classification, phishing detection, and threat intelligence. The key advantage lies in speed and scale. AI can process millions of events across distributed environments and highlight suspicious activity in minutes, something human analysts could never achieve. Challenges with traditional detection methods Traditional detection methods are effective against known threats but often struggle with scale and adaptability. Security teams face these challenges: Alert fatigue: Security Operations Centers (SOCs) often drown in thousands of daily alerts. Most are false positives or low priority, but analysts must review them. The repetitive nature of this work creates alert fatigue, where genuine threats are overlooked or not properly treated due to the overwhelming noise. This directly contributes to analyst burnout and increases Mean Time to Detect (MTTD). Rapid exploitation of vulnerabilities: When new vulnerabilities are disclosed, threat actors can weaponize them within days or even hours. Proof of Concept (PoC) exploits are quickly shared across forums and integrated into botnets or ransomware kits. Organizations relying on manual patch cycles or traditional vulnerability scanners are left exposed, often for weeks. This gives attackers a significant advantage. Evasion through legitimate processes: Modern adversaries increasingly hide their activity by leveraging existing tools and methods in the target environment. This includes Living off the Land (LOTL) techniques such as abusing and exploiting trusted applications, system services, or even security tools to mask malicious behavior. Because these processes are also used daily by administrators and business applications, distinguishing between routine operations and malicious use is highly challenging. As a result, signature-based defenses often fail. Overwhelming data volumes: Large enterprises can generate petabytes of logs across endpoints, servers, applications, and cloud services. Even with powerful indexing and search engines, correlating this data in real-time is nearly impossible with static rule sets. This data overload leads to blind spots where attackers can hide. Advanced phishing campaigns: Phishing remains the most common initial attack vector for malware and credential theft. With generative AI, adversaries craft compelling emails free of grammatical errors and inconsistencies. To the human eye, these attacks are nearly indistinguishable from genuine communications. Insider threats and account compromise: Insiders with malicious intent or compromised user accounts often operate within the boundaries of normal access rights. Their activities blend in with legitimate business processes, making them difficult to detect without establishing a historical baseline of behavior. Zero-day and unknown threats: Signature-based security tools depend on known patterns of malicious activity. Zero-day exploits and polymorphic malware bypass these defenses by constantly changing their code or leveraging new techniques. As a result, defenders are always a step behind. How Artificial Intelligence helps address these challenges With the scale of today’s cyber threats laid out, it is easier to see where AI makes its mark. The benefits of AI are not abstract or futuristic; they directly counter the pain points security teams face daily. From reducing alert fatigue to automating compliance, AI introduces speed, accuracy, and scalability into areas where human analysts are often overwhelmed. AI addresses these challenges in some ways: Noise reduction and prioritization: Machine learning algorithms can filter repetitive alerts, correlate related events, and prioritize incidents that pose the most significant risk. By reducing false positives, AI allows analysts to focus their energy on high-value alerts instead of sifting through endless noise. Vulnerability prioritization: AI-driven vulnerability management platforms go beyond identifying missing patches. They assess exploitability in the wild, exposure within the organization’s environment, and the potential business impact. This enables IT teams to focus remediation efforts where they are most critical, effectively reducing the window of opportunity for attackers. Behavioral analysis of legitimate process activity: AI goes beyond static signatures by learning what “normal” looks like for legitimate tools and processes in a given environment. AI can establish baselines for typical usage patterns, such as when, how often, and under what context these processes are executed. Continuously analyzing deviations from these baselines highlights suspicious activity that might otherwise be dismissed as routine IT operations. This helps uncover stealthy activities that blend into everyday operations. Scalable data processing: Unlike traditional systems that struggle with heavy log volumes, AI models can ingest and analyze massive amounts of structured and unstructured data in real-time. This provides defenders with actionable insights across entire infrastructures, eliminating blind spots. Advanced insider threat detection: AI-powered User and Entity Behavior Analytics (UEBA) continuously learn the habits of employees and systems. Suspicious activities, such as unusual login times, accessing atypical data sets, or abnormal privilege escalations, are automatically flagged, allowing proactive detection of insider threats. Phishing detection through NLP: Natural language processing (NLP) models can detect malicious intent in email content, even when the message looks professional. With header analysis and sender reputation scoring, AI tools identify phishing attempts that would otherwise slip past traditional filters. Automated incident response: AI-enhanced SOAR (Security Orchestration, Automation, and Response) platforms can recommend or automatically execute actions such as isolating compromised endpoints or blocking malicious IP addresses. This reduces mean time to respond (MTTR) from hours to minutes. How Wazuh is adopting Artificial Intelligence for stronger cyber defense Wazuh is a free and open source security platform that unifies XDR and SIEM capabilities. It protects workloads across on-premises, virtualized, containerized, and cloud-based environments. Wazuh integrates AI capabilities in multiple features to improve detection, investigation, and situational awareness. Below are some ways Wazuh uses AI to make cybersecurity defenses more innovative and responsive. AI-Generated insights from security data Security platforms collect massive amounts of data, alerts, vulnerability scans, and endpoint logs, but analysts often lack the time to extract patterns or summarize trends. Valuable context is buried in dashboards, reports, and raw telemetry. Without distilled insights, decision-making slows down and threats might slip by unnoticed. Wazuh showcased the integration of Claude 3.5 Haiku through AWS Bedrock into its dashboard in the blog post Leveraging Claude Haiku in the Wazuh dashboard for LLM-Powered insights. The integration requires enabling AI assistant plugins and configuring AWS IAM credentials. Once connected, Claude provides contextual answers, not just raw log snippets. This bridges the gap between alerts and action by embedding expert knowledge directly into the monitoring workflow. This integration adds a chat assistant feature to the Wazuh dashboard interface, where users can query the system in natural language. The following are examples of how AI can turn raw security data into actionable insights: Guided vulnerability response Prompt example: “What do I do when I see a vulnerability alert?” Vulnerability alerts can be overwhelming, especially without clear remediation guidance. AI-generated insights provide context on the alert severity, potential impact, and recommended response steps, enabling security teams to act quickly and effectively. Automated configuration guidance Prompt example: “How do I configure active responses for brute-force attempts?” Instead of digging through documentation, analysts can query the AI directly for configuration steps. The assistant responds with practical, actionable guidance on setting up automated countermeasures such as blocking IP addresses or isolating endpoints, streamlining the deployment of active defenses. Running service vulnerability profiling and contextual audit Network audits often reveal many open ports and services across endpoints. Knowing that a port is open is only part of the picture. Security teams must understand what services are running, whether they have known vulnerabilities, and how they might be exploited. Without this context, open services can become weak spots, especially if they are running outdated software or exposed to the internet unnecessarily. The Nmap and ChatGPT security auditing with Wazuh blog post shows how integrating Nmap scans with ChatGPT allows analysts to uncover more than just “what is open”. Wazuh can run periodic Nmap scans through its command monitoring modules, collecting outputs of open ports and the corresponding service versions. This data is then sent to ChatGPT (via API), which returns enriched information about each open service, including potential vulnerabilities and remediation guidance. This results in analysts gaining guided assistance when interpreting alerts or planning remediation. By reducing the time spent cross-referencing documentation, the AI assistant helps security teams respond more quickly and confidently. AI-Enhanced threat hunting Threat hunting is essential for detecting stealthy attacks that bypass signatures and rules. However, doing so manually across millions of logs is resource-intensive and requires expert analysts. Leveraging artificial intelligence for threat hunting in Wazuh blog post shows how Wazuh uses Llama 3 (via Ollama) with vector embeddings and Facebook AI Similarity Search (FAISS) to search archived logs semantically. Instead of relying on keyword matches, analysts can query in natural language, and the system retrieves contextually relevant results. The following are examples of how AI can assist security teams in uncovering hidden threats: Intrusion detection Prompt example: “Identify SSH brute-force attempts last week.” Brute-force attacks often blend into the noise of authentication logs, making them difficult to catch with static searches. With AI-enhanced hunting, analysts can query logs in natural language and quickly retrieve events showing repeated failed login attempts, highlighting intrusion attempts that might otherwise be overlooked. Data exfiltration monitoring Prompt example: “Check for signs of data exfiltration.” Detecting unauthorized data transfers requires analyzing large volumes of network and system logs. AI-powered hunting enables analysts to search semantically across historical data, surfacing anomalies such as unusual file transfers or suspicious outbound connections that could indicate exfiltration attempts. This approach allows Wazuh to uncover threats that might otherwise remain hidden while enabling retrospective investigations. By embedding conversational AI into hunting workflows, Wazuh gives analysts an efficient way to ask more profound, more flexible questions of their data. Wazuh AI analyst service As more workloads and infrastructure move to the Cloud, security teams deal with increasingly distributed environments, larger attack surfaces, and massive system data volumes. Traditional approaches to monitoring and response can struggle to keep pace with this scale and complexity. This is where the Wazuh AI analyst becomes particularly relevant. Designed for Wazuh Cloud users, Wazuh AI analyst is an emerging feature that gives security teams a conversational investigation partner. While still in its early stages, it aims to augment security teams by providing alerts summaries, contextual enrichment, and next-step guidance. This service provides automated, AI-driven security analysis by combining Wazuh Cloud with advanced machine learning models. It processes security data at scale to generate actionable insights that strengthen an organization’s overall security posture. By embedding AI into Wazuh Cloud, organizations gain a scalable security ally that grows with their infrastructure and strengthens their ability to respond to threats. Conclusion The cybersecurity landscape is shifting rapidly. Defenders cannot afford to remain static with attackers adopting automation, stealth, and AI-driven tactics to outpace traditional defenses. Artificial intelligence is no longer optional in digitized environments; it is becoming an essential layer of modern cyber defense. By reducing noise, uncovering hidden threats, and accelerating response, AI empowers security teams to stay ahead of adversaries. AI is not replacing human expertise; it is augmenting it. Human analysts bring critical thinking, creativity, and context that machines cannot replicate. AI, on the other hand, delivers unmatched speed, scalability, and consistency. Together, they create a layered defense that matches the sophistication of modern threats. Wazuh demonstrates this shift in practice. AI-enhanced threat hunting, intelligent insights, and the emerging Wazuh AI Analyst for cloud users show how AI can be integrated into workflows that ensure defenders can handle the growing complexity of cyber attacks. Discover more about Wazuh by exploring their documentation and joining their growing community of professionals. Sponsored and written by Wazuh.
bleepingcomputer.comOct 6, 2025extracted
Defending against malware persistence techniques with Wazuh
Malware persistence techniques enable attackers to maintain access to compromised endpoints despite system reboots, credential changes, or other disruptions. Common methods include altering configurations, injecting startup code, and hijacking legitimate processes. These approaches ensure the malware or attacker remains active, allowing malicious activities to continue without the need for re-exploitation. In this article, we will examine the nature of malware persistence techniques, their impact, and strategies for defending against them. Common malware persistence techniques The MITRE ATT&CK framework catalogs a range of techniques used by threat actors to maintain persistence. Below are examples of malware persistence techniques from the framework that allow attackers to sustain long-term access to compromised endpoints: T1053 – Scheduled Task/Job Adversaries abuse task scheduling features to run malicious code repeatedly or at set intervals. Built-in utilities such as Task Scheduler (Windows), cron (Linux), and launchd (macOS) can execute programs or scripts at specified times or in response to certain events. T1037 – Boot or Logon Initialization Scripts Attackers configure scripts to execute during system boot or user logon, ensuring persistence or privilege escalation. On Linux, mechanisms like rc.local, init.d, or systemd are commonly used to launch malicious code at startup. T1543 – Create or Modify System Process System-level processes such as Windows services, Linux daemons, or macOS launchd agents run automatically in the background. Threat actors can install or modify these processes to execute malicious payloads on startup or during system operation. T1136 – Create Account Adversaries may create new local, domain, or cloud user accounts on compromised systems to maintain access. With sufficient privileges, these accounts can be used for ongoing access without requiring persistent remote access tools. T1098 - Account Manipulation Account manipulation enables attackers to maintain or elevate access by modifying credentials, changing group memberships, or bypassing security policies. For example, adding an SSH key to ~/.ssh/authorized_keys enables persistent remote access without needing a password. Impact of malware persistence techniques Malware persistence techniques are designed to ensure attackers maintain long-term access to compromised systems. Below, we explore some impacts of malware persistence techniques. Extended dwell time Malware persistence techniques enable attackers to remain in a compromised environment for a prolonged period without requiring re-exploitation. This extended presence, often lasting weeks or months, gives them time to explore the network, escalate privileges, and plan their next moves carefully before detection. Remediation evasion Even after initial removal, attackers can regain access using persistence mechanisms such as scheduled tasks, malicious services, or unauthorized user accounts. This makes cleanup efforts ineffective unless all persistence mechanisms are identified and removed. Data exfiltration Persistent access is often used in Advanced Persistent Threats (APTs), where attackers gradually exfiltrate data over an extended period to maintain long-term infiltration and exploitation. This allows sensitive information, such as credentials or business data, to be stolen over time. Deployment of additional malware With continuous access, attackers can introduce additional malicious tools, including ransomware, backdoors, or remote access trojans. This can further compromise the system or expand the attack surface across the network. Compromised regulatory compliance Malware persistence techniques enable attackers to maintain unauthorized access to systems over an extended period. This long-term access can lead to violations of regulatory standards, such as GDPR, HIPAA, and PCI DSS, which require strict data protection, system integrity, and breach notification. Protect your systems against hidden threats. Learn how attackers use malware persistence techniques, and how Wazuh helps you detect and stop them. Learn More About Wazuh How to defend against malware persistence techniques Defending against persistence techniques requires a layered approach that combines detection, prevention, and incident response. Below are some key defense strategies: 1. Patch management: Several persistence techniques exploit known vulnerabilities in operating systems, applications, or drivers. By regularly applying patches to these components, you can significantly reduce the available attack surface. 2. File Integrity Monitoring (FIM): FIM helps detect unauthorized changes to critical files, such as startup scripts, scheduled task configurations, registry keys, or application binaries. By monitoring these sensitive files, you can identify when attackers attempt to gain persistence. 3. User account monitoring: Persistence often involves creating new user accounts, modifying existing ones, or escalating privileges. Continuous monitoring of account creation, deletion, and permission changes can reveal suspicious behavior. 4. Harden system configurations: Securing baseline configurations reduces the risk of attackers abusing system features for persistence. This includes disabling unused services, enforcing strong password policies, limiting administrative privileges, and using group policies to restrict autorun behavior. 5. Threat hunting: Conducting proactive threat hunts allows security teams to detect hidden persistence mechanisms that evade automated tools. This includes searching for suspicious behavior, such as unusual process executions, scheduled tasks, or long-dormant malware. 6. Endpoint security: Deploying robust endpoint protection tools such as XDR enables real-time monitoring of activity and blocks known persistence behaviors. Modern endpoint tools can detect and automatically respond to indicators like registry changes, service installations, and unauthorized script execution. How Wazuh defends against malware persistence techniques Wazuh is a free and open source enterprise-ready security solution that provides unified SIEM and XDR protection across several workloads. It provides a centralized view for threat detection and security monitoring across virtualized, on-premises, cloud-based, and containerized environments. Wazuh offers several capabilities to defend against malware persistence techniques. These capabilities include, but are not limited to: Active response File Integrity Monitoring (FIM) Security and Configuration Assessment (SCA) Log data analysis Vulnerability detection Active response The Wazuh Active Response module enables security teams to automate response actions based on predefined triggers, helping them efficiently manage security incidents. Automation ensures that high-priority events are addressed promptly and consistently. Wazuh provides several built-in response scripts that can perform actions such as blocking malicious network traffic or removing infected files from monitored endpoints. In the example below, the Active Response module disables a Linux account that has been targeted by brute-force login attempts. File Integrity Monitoring (FIM) The Wazuh FIM module monitors files and directories, generating alerts when a user or process creates, modifies, or deletes monitored files. It builds a baseline by scanning and storing checksums and file attributes. When a user or process changes a file, the module compares its checksum and attributes with the baseline and triggers an alert if a mismatch is detected. The blog post Detecting Common Linux Persistence Techniques with Wazuh highlights how the Wazuh FIM module detects malware persistence on Linux endpoints. We use the FIM module to monitor changes to systemd services and timers on a monitored endpoint. Since systemd manages services and startup tasks, monitoring its configuration files is important for detecting unauthorized changes. Security and Configuration Assessment (SCA) System hardening reduces the attack surface by eliminating misconfigurations and unnecessary components. The Wazuh SCA module helps improve system hardening by scanning monitored endpoints to detect misconfigurations and recommending remediation actions. It uses policy files to check system settings, files, processes, and registry entries. For example, the Wazuh SCA can assess whether it is necessary to change password policies, remove unnecessary software, disable unnecessary services, or audit the network configurations. In Figure 3 below, the Wazuh SCA scan result shows failed because the public key authentication for SSH is not enabled. Log data analysis Wazuh provides visibility into your IT infrastructure by collecting, analyzing, and storing logs from endpoints, network devices, and applications. The Wazuh agent, running on a monitored endpoint, collects and forwards system and application logs to the Wazuh server for analysis. Log data analysis enables threat detection, performance monitoring, troubleshooting, compliance auditing, and the identification of anomalous activities. In Detecting Windows persistence techniques with Wazuh, the Wazuh agent collects logs from a Windows endpoint and forwards them to the Wazuh server for analysis. This helps identify signs of malware persistence, such as unauthorized account creation, changes to startup folders or registry keys, and modifications to services. Figure 4 below illustrates the detection of a modification to a Windows service. Vulnerability detection The Wazuh Vulnerability Detection module identifies vulnerabilities in the operating system and installed applications by correlating software inventory with known vulnerability data in the Wazuh CTI platform. It generates alerts displayed on the Wazuh dashboard, giving a clear view of vulnerabilities across all monitored endpoints. This helps security teams take proactive measures to reduce risk and strengthen system defenses before exploitation occurs. The vulnerability detection dashboard in Figure 5 below highlights the package name, OS, agent, vulnerability ID, and severity of detected vulnerabilities. Conclusion Malware persistence techniques enable attackers to maintain long-term access to compromised systems, posing significant risks to organizational security. Defending against these techniques requires a multi-layered approach that combines proactive measures, such as system hardening, FIM, regular patching, threat hunting, and user monitoring. Wazuh enhances threat defense by providing several capabilities to detect and respond to suspicious activity across monitored endpoints, including malware persistence techniques. It enables security teams to monitor for unauthorized changes, scheduled tasks, unusual processes, account modifications, and other indicators of compromise. Start using Wazuh today to strengthen your organization's defense strategy. You can also join their community for professional support. Sponsored and written by Wazuh.
bleepingcomputer.comAug 25, 2025extracted
Wazuh for Regulatory Compliance
Organizations handling various forms of sensitive data or personally identifiable information (PII) require adherence to regulatory compliance standards and frameworks. These compliance standards also apply to organizations operating in regulated sectors such as healthcare, finance, government contracting, or education. Some of these standards and frameworks include, but are not limited to: Payment Card Industry Data Security Standard (PCI DSS) General Data Protection Regulation (GDPR) Health Insurance Portability and Accountability Act (HIPAA) National Institute of Standards and Technology Special Publication framework (NIST SP 800-53) Trust Services Criteria (TSC) Cybersecurity Maturity Model Certification (CMMC) Reasons for meeting compliance requirements Below are some reasons for meeting compliance requirements: To protect businesses and organizations from cybersecurity risks, threats, and data breaches. To develop efficient organizational processes that aid in attaining business licensing. To avoid financial risk, losses, and fines due to data breaches or non-compliance with regulatory requirements. How to meet regulatory compliance requirements Regulatory compliance standards and frameworks can be implemented by adhering to the following points: Regular review of current regulatory compliance standards and frameworks applicable to your organization. Designating a specialist to be in charge of the compliance process. This specialist may be the organization's compliance officer. Sensitizing employees and relevant third parties to compliance standards and the need to stay compliant. This sensitization may include training and tabletop exercises on the applicable compliance frameworks. Performing regular internal audits of systems and processes to ensure compliance with the relevant regulatory requirements. Using platforms to monitor and enforce compliance. An example of such a platform is Wazuh. Wazuh SIEM/XDR Wazuh is an open source security platform that provides unified Extended Detection and Response (XDR) and Security Information and Event Management (SIEM) protection for endpoints and cloud workloads. It unifies historically separate functions into a single agent and platform architecture. Wazuh offers various capabilities, including threat detection and response, vulnerability detection, file integrity monitoring, container security, system inventory, and security configuration assessment. These capabilities are aided by visualizations that show various metrics and your organization's compliance with specific standards. Wazuh can help you track and implement regulatory compliance standards and frameworks by providing the following: Out-of-the-box modules that support compliance frameworks and standards. Compliance events visualization. Alerts classification by compliance requirements. Updated regulatory compliance documentation. Out-of-the-box modules that support compliance frameworks and standards Wazuh includes default dashboards, modules, and rulesets associated with specific compliance standards and regulatory frameworks. These include dashboards for PCI DSS, GDPR, HIPAA, NIST SP 800-53, and TSC frameworks. The section below shows examples of such applications of these modules. Log analysis You can configure Wazuh to suit your peculiar organizational requirements, such as monitoring for sensitive information. This is achievable using the Wazuh log data analysis and File Integrity Monitoring (FIM) modules. An example of such can be seen in the post conducting primary account number scan with Wazuh. The post shows you how to detect exposed primary account numbers (PAN) within a monitored endpoint. You can utilize such capabilities to identify sensitive information and improve your organization's security posture. Active response for incident handling Wazuh includes the Active Response module for automating incident responses. This module allows you to set a preferred response when an alert is triggered. You can also develop custom active response scripts tailored to your environment's use cases. The example below shows an active response that disables a user account upon detecting multiple failed user login attempts. Compliance events visualization Wazuh provides dedicated dashboards to monitor and track events relevant to compliance requirements. These dashboards offer a quick view of recent compliance events, the timeline of alerts generated, the agents on which the alerts occur, and the alert volumes by agents. The image below shows the visualization dashboard for NIST SP 800-53 requirements: Alerts classification by compliance requirements The Wazuh compliance dashboard offers a “Controls” section that shows applicable compliance requirements. This dashboard also shows alerts generated for each requirement and the event details that generated the alert. This dashboard provides visibility into the requirements and helps direct the efforts of the compliance specialist and internal auditors to stay current with regulatory compliance standards. Updated regulatory compliance documentation One way to stay compliant is to regularly review and stay updated with the regulatory compliance frameworks applicable to your organization. Wazuh supports this by providing an information section for each requirement. This section contains a description of the requirement and related alerts. The information on the Wazuh dashboard is updated with the latest compliance standards and frameworks versions. This information will give the compliance team a quick overview of the impact of the alerts being generated. Conclusion Adherence to regulatory compliance is key for businesses and organizations. These compliance standards and frameworks guide companies in protecting and securing themselves. Various supporting platforms can be used to ensure compliance with regulatory standards and frameworks. Wazuh is one such platform. It provides threat detection, response, and visibility on the compliance status of your endpoints.
thehackernews.comAug 18, 2025extracted
Documenti d’identità italiani in vendita online, rubati agli hotel: l’allarme
Il Cert-Agid ha recentemente segnalato un allarmante caso di data breach che coinvolge tre strutture alberghiere italiane. Tra giugno e luglio 2025, un attore malevolo noto come “mydocs” ha compromesso i sistemi di queste strutture, sottraendo quasi 200 mila di scansioni ad alta risoluzione di documenti d’identità, tra passaporti e carte d’identità, utilizzati dai clienti durante il check-in. Il materiale è stato poi messo in vendita su un forum underground, confermando una tendenza già osservata in precedenti episodi. Il rischio infatti è quello legato allo smishing a tema Inps. Sul problema indaga anche il Garante Privacy, dato che il data breach è anche una violazione della privacy e gli hotel sono obbligati a segnalare l’avvenuto. Indice degli argomenti Dopo il susseguirsi di post criminali, sul medesimo forum underground, il threat actor “mydocs” ha finora messo in vendita oltre 168mila documenti di identità di cittadini (non solo italiani), esfiltrati da 12 strutture alberghiere italiane (come da ultimo aggiornamento CERT-AGID). Dalle nostre analisi OSINT effettuate, sulla base delle dichiarazioni dell’attore criminale nelle sue “aste online”, possiamo finalmente quantificare questo danno ed esprimerne i dettagli, almeno per le rivendicazioni note e delle quali siamo entrati in visione. Questo riepilogo mette in luce l’enorme quantità di scansioni e dati, custoditi nel tempo dalle strutture, con un totale di 168.600 documenti d’identità trafugati e attualmente in giro per il mondo criminale. Sono l’Hotel Ca’ dei Conti di Venezia, con circa 38 mila documenti rubati, e Casa Dorita di Cervia (RA), con circa 2.300 documenti. Il Borghese Contemporary Hotel di Roma ha subito la perdita di circa 7.600 documenti, mentre l’Hotel Rocca di Cassino (FR) ne ha circa 1.700. A Milano, l’Hotel Sanpi ha visto sottratti circa 5.600 documenti e l’Hotel Mediolanum circa 22.200. Il Savoia Resort di Bardonecchia (TO) è stato colpito con circa 22.100 documenti sottratti, mentre l’Astoria Suite Hotel di Rimini ne ha registrati circa 20.800. Infine, l’Hotel Continentale di Trieste ha subito il furto di circa 17mila documenti. Ci sono anche l’hotel Regina Elisabella (Ischia), con 30 mila documenti, Hotel Ercolini e Savi (3.600) a Montecatini Terme. Dinamica dell’attacco agli hotel e implicazioni tecniche L’attaccante ha sfruttato vulnerabilità nei sistemi di gestione degli hotel, probabilmente legate a credenziali deboli, software non aggiornati o configurazioni errate dei database. Sebbene i dettagli tecnici specifici non siano stati divulgati, è plausibile che l’accesso sia avvenuto tramite: SQL injection su portali di check-in non adeguatamente protetti; Credenziali esposte su server FTP o cloud storage mal configurati; Phishing mirato contro il personale amministrativo. Un esempio di possibile IOC (Indicator of Compromise) rilevabile nei log dell’infrastruttura alberghiera potrebbe essere: POST /checkin_form.php HTTP/1.1 User-Agent: Mozilla/5.0 (compatible; mydocs-scraper/1.0) Payload: ' OR 1=1 -- Rischi per le vittime e riutilizzo illecito I documenti rubati sono un bersaglio ambito per attività fraudolente. Gli attori malevoli potrebbero utilizzarli per creare falsi d’identità, aprire linee di credito o condurre attacchi di social engineering ai danni di vittime, loro familiari o colleghi (scrive il Cert-Agid). Un caso emblematico è l’uso di questi dati per bypassare sistemi di autenticazione a due fattori (2FA) che si basano su documenti d’identità caricati digitalmente. Ricordiamo il caso precedentemente osservato di furto di documenti mediante attacchi di tipo smishing a tema INPS, particolarmente attivo nel mese di marzo 2025. Misure di mitigazione per organizzazioni e cittadini Per prevenire simili incidenti, le strutture ricettive dovrebbero: Crittografare i documenti archiviati, utilizzando standard come AES-256; Limitare l’accesso ai dati sensibili con politiche di least privilege; Monitorare tentativi di accesso anomali, ad esempio con tool come Wazuh o Elastic SIEM. Chiunque abbia soggiornato in un hotel italiano nei mesi interessati dovrebbe verificare la presenza di attività sospette, come richieste di credito non autorizzate. È inoltre consigliabile attivare servizi di allerta per nuovi conti aperti a proprio nome, offerti da agenzie come Cifas o il Crif. Questo episodio sottolinea l’importanza di un approccio proattivo alla cybersecurity, sia per le aziende che per i singoli individui. La collaborazione con autorità come il Cert-Agid e la Polizia Postale è cruciale per identificare e neutralizzare rapidamente queste minacce. Al primo sentore di anomalia, non esitate a ingaggiare una segnalazione. E’ possibile utilizzare il portale dedicato del Commissariato di PS.
cybersecurity360.itAug 7, 2025extracted