#modsecurity
🐻 Un jour, un logiciel Libre : jour 5

Coraza : Un WAF Open Source écrit en Go, qui prend en charge l'ensemble de règles ModSecurity SecLang et est 100 % compatible avec l'ensemble de règles de base OWASP v4.
April 5, 2025 at 6:30 PM
A Go-based HTTP & OAuth Gateway and Web Application Firewall (WAF) based on ModSecurity
#golang

github.com/casbin/caswaf
GitHub - casbin/caswaf: HTTP & OAuth Gateway and Web Application Firewall (WAF) based on ModSecurity, online demo: https://door.caswaf.com
HTTP & OAuth Gateway and Web Application Firewall (WAF) based on ModSecurity, online demo: https://door.caswaf.com - casbin/caswaf
github.com
November 6, 2025 at 6:06 AM
AlmaLinux 10.3 Beta “Mauve Lion” is now available!
🔹 ModSecurity returns
🔹 Podman 6 moves container configuration out of /etc
🔹 New compiler toolsets
🔹 New language runtimes
🔹 Improved security

https://almalinux.org/blog/2026-09-10-announcing-103-beta/?utm_medium=social&utm_source=bluesky
September 14, 2026 at 6:08 PM
2024-01-25にTrustwaveからOWASPに移管。へー知らなかった。
ModSecurityについて調べた · hnakamur's blog
hnakamur.github.io
February 10, 2024 at 8:26 AM
c'est l'enfer, on a des pages qui ne doivent pas être crawlées, ça fonctionnait bien avec les moteurs de recherche, pas avec ces saloperies écrites par des guignols en vibe coding, on a passé des jours à faire du trial and error sur modsecurity jpp
November 30, 2025 at 11:52 AM
Mala praxis no avisar, tot i això jo deixaria el ModSecurity actiu i només posar l'excepció per l'OAuth com expliquen aquí ourcodeworld.com/articles/rea...
How to disable ModSecurity Rule in Plesk (Google OAuth2 redirect callback blocked by ModSecurity)
Learn how to disable the rule of ModSecurity in Plesk that prevents your Google OAuth2 redirect callback page from working properly.
ourcodeworld.com
September 18, 2024 at 7:11 AM
Later today, I'll be hosting a ModSecurity / CRS community call

luma.com/8yc1p543

We'll be talking about success metrics, WAF testing and other integration questions.
CRS Community Call · Luma
A video call where the CRS dev team gets to meet their community face-to-face. A place for information exchange and questions for both newbies and experienced…
luma.com
September 22, 2025 at 8:07 AM
CVE-2025-27110: ModSecurity Vulnerability Leaves Web Applications Exposed
CVE-2025-27110: ModSecurity Vulnerability Leaves Web Applications Exposed
Understand the implications of CVE-2025-27110 on web application security and how it may allow attacks to bypass defenses.
securityonline.info
March 1, 2025 at 7:30 AM
🔥 OWASP CRS is evolving! Introducing #CRSLang — a new YAML-based rule language replacing Seclang. Cleaner syntax, multi-engine support, bidirectional translation, and a lower barrier for new contributors.
Check it out 👉 coreruleset.org/2026...
#WAF #AppSec #OWASP #ModSecurity
February 18, 2026 at 1:43 AM
E pensar que tudo começou lá na época do modsecurity, hein? O tempo passa e as práticas são as mesmas, só mudam as ferramentas. Aprenda a base e não precisará ficar nessa corrida maluca de achar que tudo "muda" toda hora.
September 4, 2024 at 10:15 AM
we now finally have ModSecurity as a WAF for transfur.social. hopefully this helps me filter out automated spam way easier than the limited tools cloudflare gives us.

Bonus upside being able to do json-aware body text filtering for unacceptable content like CSAM hashtags and bigotry, which was […]
Original post on transfur.social
transfur.social
September 18, 2026 at 10:19 AM
🔧 ¿El error 403 te da dolores de cabeza? Descubre cómo diagnosticar si es ModSecurity o un problema de configuración y soluciona el bloqueo en tu web. Todo explicado paso a paso en nuestro nuevo post. Lee más aquí 👉 k3bone.com/blog/2024/11... #hosting #cPanel #seguridad
¿ModSecurity o un problema de configuración? Cómo diagnosticar y corregir el error 403 sin complicaciones - k3bone
¿ModSecurity o un problema de configuración? Cómo diagnosticar y corregir el error 403 sin complicaciones - k3bone - Hosting SSD en España con cPanel, LiteSpeed y WordPress
k3bone.com
November 15, 2024 at 12:21 PM
CVE-2025-39399 license-envato (CVSS Score 9.8)

#WordPress plugin #vulnerability #cybersecurity #wordpressfirewall #hacking #wpsecurity #atomicedge #cybersecurity #malware #vulnerabilityresearch #cve #redteam #proofofconcept
CVE-2025-39399 – license-envato Proof of Concept - Atomic Edge
CVE-2025-39399 vulnerability in license-envato WordPress plugin. Proof of concept, ModSecurity rule, and patched version analysis by Atomic Edge.
atomicedge.io
September 22, 2026 at 9:00 AM
My 12 Apache / ModSecurity / OWASP CRS tutorials receive about 8k unique visitors per month.

www.netnea.com/cms/apache-t...
Apache / ModSecurity Tutorials – Welcome to netnea
www.netnea.com
December 1, 2024 at 6:58 PM
⚙️ SSD-Powered cPanel Web Hosting – Up to 25x Faster
blog.radwebhosting.com
September 14, 2026 at 4:30 AM
La que m'ha liat el proveïdor de hosting activant unilateralment ModSecurity al servidor amb els webs que tenen aplicacions Oauth de Google no té nom. La mare que els va parir!
September 18, 2024 at 7:06 AM
Defensive Linux Security Tools 🛡
🕸 WAFs
- ModSecurity
- Curiefense
- BunkerWeb
- Coraza
December 24, 2025 at 6:58 PM
New WAFFLED Attack Exploits AWS, Azure, Cloud Armor, Cloudflare, and ModSecurity WAFs
New WAFFLED Attack Exploits AWS, Azure, Cloud Armor, Cloudflare, and ModSecurity WAFs
cybersecuritynews.com
July 18, 2025 at 9:20 AM
CVE-2023-41954 wp-user-avatar (CVSS Score 7.3)

#WordPress plugin #vulnerability #cybersecurity #wordpressfirewall #hacking #wpsecurity #atomicedge #cybersecurity #malware #vulnerabilityresearch #cve #redteam #proofofconcept
CVE-2023-41954 – wp-user-avatar Proof of Concept - Atomic Edge
CVE-2023-41954 vulnerability in wp-user-avatar WordPress plugin. Proof of concept, ModSecurity rule, and patched version analysis by Atomic Edge.
atomicedge.io
September 21, 2026 at 7:07 PM
CVE-2023-44150 wp-user-avatar (CVSS Score 5.3)

#WordPress plugin #vulnerability #cybersecurity #wordpressfirewall #hacking #wpsecurity #atomicedge #cybersecurity #malware #vulnerabilityresearch #cve #redteam #proofofconcept
CVE-2023-44150 – wp-user-avatar Proof of Concept - Atomic Edge
CVE-2023-44150 vulnerability in wp-user-avatar WordPress plugin. Proof of concept, ModSecurity rule, and patched version analysis by Atomic Edge.
atomicedge.io
September 21, 2026 at 6:07 PM
정말 지긋지긋하지만, SSH 무차별 대입을 진압하니까 xmlrpc.php(워드프레스 API 엔드포인트)에 대한 무차별 공격이 이어지고 있어 오늘도 방화벽이 잠잠할 날이 없습니다. 처음에는 ModSecurity WAF를 로그만 남기는 상태로 상태를 볼 생각이었으나 같은 패턴의 공격이 너무 늘어서 차단을 켭니다. 이에 따라, 오탐으로 만에 하나 열려야 되는 페이지가 안열리는 등, 한마디로 사이트가 망가질 수 있습니다. 시각과 IP 앞 6자리를 알려주시면 최대한 고쳐보겠습니다. 미리 감사드립니다.
August 2, 2025 at 2:52 PM
Installer et configurer ModSecurity (le WAF de l'OWASP) et bloquer efficacement les attaques (XSS, injection SQL, etc.).

#nginx #ModSecurity #WAF #SécuritéWeb #Linux #Tuto #CultureLinux
💥 NGINX + ModSecurity : détection & blocage des attaques 🚀
YouTube video by CultureLinux
www.youtube.com
October 28, 2025 at 4:03 PM
CVE-2024-11083 wp-user-avatar (CVSS Score 5.3)

#WordPress plugin #vulnerability #cybersecurity #wordpressfirewall #hacking #wpsecurity #atomicedge #cybersecurity #malware #vulnerabilityresearch #cve #redteam #proofofconcept
CVE-2024-11083 – wp-user-avatar Proof of Concept - Atomic Edge
CVE-2024-11083 vulnerability in wp-user-avatar WordPress plugin. Proof of concept, ModSecurity rule, and patched version analysis by Atomic Edge.
atomicedge.io
September 21, 2026 at 5:07 PM