OpenCTI integration

OpenCTI integration

May 20th 2026 / Ambassadors
By Federico Fantini / GitHub

OpenCTI can expose shared data through different native feeds, including Live streams, TAXII collections, and CSV feeds. For this integration, I chose a TAXII collection because it exposes STIX 2.1 bundles through a standard API and provides a pagination model that is straightforward to automate.

Read more
How to Turn Wazuh Into an AI-Powered Security Assistant Using Claude

How to Turn Wazuh Into an AI-Powered Security Assistant Using Claude

May 20th 2026 / Ambassadors
By Ahmed Abdelrazek / Medium

By connecting Wazuh to Claude Desktop using MCP (Model Context Protocol), you can talk to your SIEM like you’d talk to a colleague. No complex queries. No dashboard hopping. Just ask, and get answers.

Read more
Designing Effective Monitoring with Wazuh

Designing Effective Monitoring with Wazuh

May 19th 2026 / Ambassadors
By Michael Theumert / GitHub

A common mistake in monitoring design is collecting too many metrics without understanding their purpose. More data does not mean better monitoring. It often means more noise. Effective monitoring focuses on a small number of high-value signals that clearly indicate when something is wrong.

Read more
Detecting Dirty Frag (CVE-2026-43284 and CVE-2026-43500) with Wazuh 4.14.4One week after Copy Fail (CVE-2026-31431), V4bel dropped Dirty Frag – CVE-2026-43284 and CVE-2026-43500. Same authencesn decrypt sink. Completely different code path.

Detecting Dirty Frag (CVE-2026-43284 and CVE-2026-43500) with Wazuh 4.14.4One week after Copy Fail (CVE-2026-31431), V4bel dropped Dirty Frag – CVE-2026-43284 and CVE-2026-43500. Same authencesn decrypt sink. Completely different code path.

May 19th 2026 / Ambassadors
By Kislley Rodrigues / LinkedIn

One week after Copy Fail (CVE-2026-31431), V4bel dropped Dirty Frag – CVE-2026-43284 and CVE-2026-43500. Same authencesn decrypt sink. Completely different code path.

Read more