Hugo | DevOps | Cybersecurity
Tech Lead & DevSecOps. 🛡️ Cybersecurity | 💻 IT Tutorials | 🏴☠️ Ethical Hacking | ⚙️ Tech Reviews. Learn, secure, and explore cutting-edge IT solutions! 👇
That ZimaBoard Celeron CPU isn't weak—you're just wasting resources. Optimize Linux kernel and Docker settings for brutal homelab efficiency. #ZimaBoard #Docker #Linux
https://www.valtersit.com/guides/zima/zimaboard-home-server-setup-pushing-the-celeron-to-its-limits/
CVE-2026-47895 - Double-Free vulnerability in strongSwan EAP identity parsing. CVSS 7.5. Update to version 6.0.7 immediately. #CVE #strongSwan #infosec
Stop running separate Datadog, New Relic, and Splunk agents. Migrate to OpenTelemetry Collector with config patterns proven across 500+ host migrations. #OpenTelemetry #DevOps #Observability
Prevent BMC memory saturation by exporting raw System Event Log (SEL) records for external archival and issuing an IPMI Clear SEL request via ipmitool. #ipmi #sel #ValtersIT
https://www.valtersit.com/vault/dumping-and-clearing-system-event-log-records-to-prevent-bmc-1e81e0/
TOTOLINK: 622 CVEs, 99% unpatched. Max CVSS 9.8, top flaws: buffer overflow & command injection
Automate OpenVAS via gvm-cli over Unix sockets. Send raw XML to build CIDR targets and execute Full and Fast scan tasks.
#openvas #gvm-cli #automation
https://www.valtersit.com/vault/programmatic-headless-target-creation-and-scan-execution-via-c0f854/
CVE-2026-4703 - Critical PHP Object Injection in WS Form for WordPress leads to remote code execution via insecure deserialization. CVSS 9.8. Update now. #CVE #WordPress #infosec
Meet PCI DSS 11.5 compliance with AIDE FIM rules. Configure SHA-512 baselines to monitor system binaries, permissions, and configs on Debian, Ubuntu, and RHEL.
https://www.valtersit.com/vault/configuring-aide-file-integrity-monitoring-rules-for-pci-dss-7bcc9a/
Portabilis: 100 CVEs, 100% unpatched. Avg CVSS 4.32, max 6.3. XSS (CWE-79) leads. Trust
Deploying Encrypted DNS Internally: DoH and DoT Guide — hands-on guide for sysadmins. #dns-security #encrypted-dns #devsecops
https://www.valtersit.com/guides/networking/deploying-encrypted-dns-internally-doh-and-dot-guide/
SMB Share Enumeration with smbclient and Null Session Check
This command leverages smbclient to enumerate SMB shares on a target host, attempting a null session (no credentials) and then listing accessible shares. It works by connecting to the SMB service and
https://www.valtersit.com/vault/smb-share-enumeration-with-smbclient-and-null-session-check-3b5c2c/
Amazon: 61 CVEs tracked, avg CVSS 6.91. 42% unpatched. No KEV exploits yet, but cloud giants are prime targets. Harden your AWS configs. #AWS #cybersecurity #infosec
Brute-force LDAP with Hydra's ldap2 module via simple bind. Target port 389 (or 636 for LDAPS). Specify user DN with -l (e.g., cn=admin,dc=example,dc=com), -P for password list, -t 4 parallelism,
https://www.valtersit.com/vault/hydra-ldap-bruteforce-with-simple-bind-and-user-enumeration-51729a/
Stop guessing ciphers. Isolate SSH traffic with ssh, then add ssh.encryption_algorithms as a column to see the exact negotiated cipher. Wireshark parses SSH_MSG_KEXINIT to reveal your key exchange. Audit with confidence.
https://www.valtersit.com/vault/wireshark-display-filter-for-ssh-protocol-and-cipher-detecti-fe8312/
Parse Server: 70 CVEs, max CVSS 10. 100% unpatched. Trust Score: D. Auth bypass & SQLi risks rising (+53 in 2026). Don't trust default config
Execute NRQL queries via New Relic CLI to output real-time infrastructure resource usage data as JSON/tables directly in your CI/CD pipelines.
https://www.valtersit.com/vault/querying-infrastructure-resource-usage-via-new-relic-cli-and-23a228/
