<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Mac Souverain (English)</title><description>Tutorials, comparisons and watch to take back control of your data on macOS.</description><link>https://macsouverain.com/en/</link><language>en</language><atom:link href="https://macsouverain.com/en/rss.xml" rel="self" type="application/rss+xml"/><item><title>A fake Zoom update empties your iCloud Keychain</title><link>https://macsouverain.com/en/radar-bluenoroff-zoom-sdk-update-macos/</link><guid isPermaLink="true">https://macsouverain.com/en/radar-bluenoroff-zoom-sdk-update-macos/</guid><description>A trusted Telegram contact invites you to a video call, a fake Zoom update pops up mid-call, and your iCloud Keychain gets emptied.</description><pubDate>Tue, 28 Jul 2026 09:15:00 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;A contact you know invites you to a video call on Telegram, except their account has been hijacked. During the call, a fake &quot;Zoom SDK Update&quot; pops up, you click to fix your mic, and **a stealer siphons your browser keys** out of your iCloud Keychain. BlueNoroff, North Korea, zero flaw exploited, 100% social engineering. It&apos;s the third ClickFix on macOS in six weeks.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;What you need to do&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; An install prompt in the middle of a meeting, you refuse. No video call ships you an &quot;SDK Update&quot; mid-call.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; A meeting link, even from a real contact, verify it through another channel. The Telegram account on the other end may be compromised.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; An outbound firewall, Little Snitch or LuLu, sees the exfil leave for Telegram while the stealer empties your keychain.&lt;/p&gt;
&lt;/div&gt;
&lt;h2 id=&quot;whats-really-happening-mid-call&quot;&gt;What’s really happening mid-call&lt;/h2&gt;
&lt;br&gt;
&lt;p&gt;BlueNoroff, the North Korean banner that targets crypto professionals, exploits no flaw. &lt;strong&gt;Zero exploit, zero CVE.&lt;/strong&gt; Just social engineering, scaled into an industrial chain. The research comes from JUMPSEC, the “ClickFake Interview” cluster is tracked by Sekoia, and The Hacker News picked it up on July 24, 2026.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;Here’s how it goes. A contact you’ve met in person messages you on Telegram, &lt;strong&gt;except their account has been hijacked.&lt;/strong&gt; They send you a Calendly link in their name, which redirects you to a typosquatted Zoom or Teams domain, &lt;code&gt;us.zoom.06webin.us&lt;/code&gt;. You type your name, you allow the camera, and the kit gets to work behind your back. It captures your video stream via mediasoup WebRTC and profiles the crypto wallet extensions installed in your browser. Then a fake message, “your mic isn’t working”, followed by a “Zoom SDK Update” prompt. You click to fix your mic, you install the payload.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;On macOS, &lt;strong&gt;the rest unfolds without you.&lt;/strong&gt; A shell script downloads a fake Teams or Zoom installer, a stealer extracts Chrome’s master keys from your macOS login keychain, where Chrome stores its encryption key, the ones that unlock &lt;strong&gt;your crypto wallet extensions&lt;/strong&gt;, and exfiltrates everything through a Telegram channel named “Aurora”, before dropping further payloads. On the Windows side, the variant disables Defender via a PowerShell loader and hunts for Telegram sessions in Chrome, Edge, Brave and Firefox. Same actor, two chains.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;Two details change the scale. The video calls are faked with deepfakes, AI-generated faces layered over real body language, captured from earlier victims. And &lt;strong&gt;the mechanism self-propagates&lt;/strong&gt;, each compromised Telegram account becomes the trusted sender for the next one. &lt;strong&gt;Five versions of the kit&lt;/strong&gt; have been spotted between May 31 and July 14, 2026, the operator is tied to the Telegram bot &lt;code&gt;@alchemy_john_mac&lt;/code&gt;. This is no one-off, it’s a factory that iterates.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;The technique has a name, ClickFix, and it already drags a trail of victims behind it.&lt;/p&gt;
&lt;br&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read next: &lt;a href=&quot;https://macsouverain.com/en/radar-clickfix-script-editor-avril-2026/&quot;&gt;ClickFix, the fake fix that makes you launch the malware yourself&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;br&gt;
&lt;h2 id=&quot;the-third-clickfix-on-macos-in-six-weeks&quot;&gt;The third ClickFix on macOS in six weeks&lt;/h2&gt;
&lt;br&gt;
&lt;p&gt;Do the math. CrashStealer in July, ClickLock before it, now BlueNoroff. &lt;strong&gt;Three times in six weeks&lt;/strong&gt; the same pattern has hit macOS, one harmless gesture that triggers the install. The vector is going industrial, and this version &lt;strong&gt;aims straight at your keychain&lt;/strong&gt;, where macOS stores your browser’s keys.&lt;/p&gt;
&lt;br&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read next: &lt;a href=&quot;https://macsouverain.com/en/radar-crashstealer-notarise-apple-gatekeeper/&quot;&gt;An Apple-notarized malware slips past Gatekeeper&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;br&gt;
&lt;p&gt;What protects you here is neither antivirus nor notarization. It’s a behavioral rule, simple and absolute, &lt;strong&gt;never install a binary offered to you during a meeting&lt;/strong&gt;. Zoom doesn’t ship you an “SDK Update” mid-call. Neither does Teams. An update that surfaces during a video call &lt;strong&gt;is not an update, it’s the payload.&lt;/strong&gt;&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;There’s a stack angle, provided you’re honest about its reach. Proton Meet is end-to-end encrypted and runs in your browser, with no native client to install. So the “install this SDK update” pretext has nowhere to latch on, there’s no app to update. It shrinks the attack surface, it doesn’t replace the behavioral rule. &lt;strong&gt;Switching to Proton Meet does not protect you from this phishing&lt;/strong&gt;, social engineering depends on no tool.&lt;/p&gt;
&lt;br&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read next: &lt;a href=&quot;https://macsouverain.com/en/proton-meet-visio-chiffree/&quot;&gt;Proton Meet, the encrypted video call that runs in your browser&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;br&gt;
&lt;p&gt;The part that should worry you is the sender. It’s not a stranger, it’s someone &lt;strong&gt;whose hand you’ve shaken&lt;/strong&gt;. &lt;strong&gt;Interpersonal trust is the vector, not your gullibility.&lt;/strong&gt; A genuine Telegram account, a name you recognize, a meeting link, that’s all it takes.&lt;/p&gt;
&lt;br&gt;
&lt;h2 id=&quot;what-you-do-now&quot;&gt;What you do now&lt;/h2&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; An install prompt that appears during a meeting, &lt;strong&gt;you refuse, no exceptions&lt;/strong&gt;. Zoom, Teams, no video call asks you to install an “SDK Update” or to fix your mic through a download. You leave the call, you click nothing.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; A meeting link, even sent by a real contact, &lt;strong&gt;you verify it through another channel&lt;/strong&gt; before clicking. A voice call, a Signal message, “did you really send me this Calendly?”. The Telegram account on the other end may already be hijacked.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Look at the URL before allowing your camera. &lt;code&gt;us.zoom.06webin.us&lt;/code&gt; is not a Zoom domain, &lt;strong&gt;it’s typosquatting&lt;/strong&gt;. The real Zoom is &lt;code&gt;zoom.us&lt;/code&gt;. A long trailing subdomain grafted onto an unknown name, you close the tab.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;4.&lt;/strong&gt; &lt;strong&gt;Install an outbound firewall&lt;/strong&gt; and let it speak. Little Snitch or LuLu see the exfiltration leave for Telegram, exactly when the stealer empties your keychain. It’s your last line when everything else has been bypassed.&lt;/p&gt;
&lt;br&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read next: &lt;a href=&quot;https://macsouverain.com/en/little-snitch-vs-lulu-pare-feu-sortant-mac/&quot;&gt;Little Snitch vs LuLu, which outbound firewall for your Mac&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;br&gt;
&lt;h2 id=&quot;sources&quot;&gt;Sources&lt;/h2&gt;
&lt;br&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;The Hacker News&lt;/a&gt;, which relayed the research on July 24, 2026&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.jumpsec.com/guides/inside-a-dprk-bluenoroff-clickfix-kit/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Primary research JUMPSEC&lt;/a&gt;, analysis of the BlueNoroff phishing kit&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blog.sekoia.io/clickfake-interview-campaign-by-lazarus/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;“ClickFake Interview” cluster tracked by Sekoia&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-alerte</category><category>macos</category><category>cybersec</category><category>phishing</category><category>crypto</category></item><item><title>Passwork, « Made in EU » outside, FSB-certified inside</title><link>https://macsouverain.com/en/made-in-eu-souverainete-logicielle/</link><guid isPermaLink="true">https://macsouverain.com/en/made-in-eu-souverainete-logicielle/</guid><description>A tool sold as Made in EU, with code pushed from Russia. The label has no legal weight. Here&apos;s the checklist to vet your software supply chain.</description><pubDate>Mon, 27 Jul 2026 07:00:00 GMT</pubDate><content:encoded>&lt;h2 id=&quot;introduction&quot;&gt;Introduction&lt;/h2&gt;
&lt;p&gt;A software company based in Barcelona. A password manager sold to European public bodies. On the website, until recently, two reassuring lines: “Made in EU 2017” and “no affiliations with any US, Russian, or other non-European entities”.&lt;/p&gt;
&lt;p&gt;Small problem. The software is in fact affiliated with Russia. And its source code is certified by &lt;strong&gt;the FSB&lt;/strong&gt;, which &lt;strong&gt;had access to it&lt;/strong&gt;. Barely worth mentioning.&lt;/p&gt;
&lt;p&gt;On 17 July 2026, a consortium led by OCCRP and VSquare, with a dozen newsrooms including Le Monde, NU.nl, De Groene Amsterdammer, Investico and De Tijd, published an investigation. The code of this European tool is developed in Russia, in Arkhangelsk, and its updates travel through an entity in the Emirates. The two reassuring lines vanished from the website after the journalists started asking questions.&lt;/p&gt;
&lt;p&gt;This piece isn’t only about Passwork. Passwork is just one more example of Brussels’ incompetence. Get this straight, &lt;strong&gt;“Made in EU” on a product page carries no legal weight, and protects you from nothing&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;Nobody, not Brussels, not a label, checks it for you. So let’s learn to do it ourselves.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;the-problem-a-flag-proves-nothing&quot;&gt;The problem: a flag proves nothing&lt;/h2&gt;
&lt;p&gt;You pick a piece of software to protect your data. You see “European”, you see a head office in the EU, and you decide sovereignty is ticked off. You’ve just confused two things that have nothing to do with each other.&lt;/p&gt;
&lt;p&gt;A company’s registration address tells you where its lawyers and its taxes sit. It doesn’t tell you where the code running on your machine comes from. Those are two separate chains: the legal chain, and the software supply chain. The first is easy to display on a website. The second is invisible, and it’s the only one that matters.&lt;/p&gt;
&lt;p&gt;Take the case documented by the investigation. Passwork Europe S.L. is indeed registered in Barcelona. But Passwork LLC is registered in Arkhangelsk, Russia, in November 2022. Same logo, a common code base at the origin, and user manuals the investigation calls “virtually indistinguishable aside from the language”. On the two versions released in early April 2026, a researcher notes an install script of around 517 lines that he describes as “basically identical”.&lt;/p&gt;
&lt;p&gt;Two products presented as separate. &lt;strong&gt;One code base, or nearly.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The point isn’t “a Russian company, that’s bad”. The point is more uncomfortable: nothing on the product page let you know. The “Made in EU” label did exactly the job it exists for, reassuring you, without proving anything.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;the-mechanism-the-three-questions-the-label-never-asks&quot;&gt;The mechanism: the three questions the label never asks&lt;/h2&gt;
&lt;p&gt;A tool’s sovereignty can’t be read off a flag. It’s read off three concrete questions, and not one of them shows up on a sales brochure.&lt;/p&gt;
&lt;h3 id=&quot;who-ships-the-binary&quot;&gt;Who ships the binary?&lt;/h3&gt;
&lt;p&gt;The code you use isn’t the one sitting in a public repository. It’s the one that lands on your machine at the next update. So the real question is: which entity builds and delivers that update?&lt;/p&gt;
&lt;p&gt;In the Passwork case, the cofounders Ilya Garakh, who owns the domains, and Andrey Pyankov, a manager, operate through Passwork FZ-LLC, registered in Ras Al Khaimah, in the Emirates, in July 2022. It’s this entity that supplies the updates to the European branch. Passwork describes it as “limited product related knowledge-transfer support” during a transition period meant to end in August 2026.&lt;/p&gt;
&lt;p&gt;Translation: the European binary is, at least until that date, fed from outside Europe. A researcher quoted in the investigation sums up the EU/Russia split as “technically shallow”.&lt;/p&gt;
&lt;h3 id=&quot;who-signs-the-code-and-with-which-key&quot;&gt;Who signs the code, and with which key?&lt;/h3&gt;
&lt;p&gt;A legitimate update is cryptographically signed. That’s what guarantees the file you install really comes from the vendor and hasn’t been tampered with along the way. Except a signature guarantees origin, not innocence. If the entity holding the signing key is also the one that could slip something into an update, a valid signature protects you from nothing. It just certifies the parcel really came from the sender, whatever the contents.&lt;/p&gt;
&lt;p&gt;It’s the update channel, not the storage, that concentrates the risk. A researcher quoted in the investigation describes it as “the most elegant and hardest-to-detect attack vector”. OCCRP itself draws the parallel with SolarWinds, that 2019-2020 attack where a perfectly legitimate monitoring tool served as the vehicle for a massive compromise, through its signed updates.&lt;/p&gt;
&lt;p&gt;Let’s stay precise: to date, no backdoor has been found in Passwork, no leak, no compromised client. We’re talking about a vector that exists, not an attack that took place. The channel would allow, structurally, what SolarWinds proved possible. &lt;strong&gt;This isn’t an accusation. It’s a geometry.&lt;/strong&gt;&lt;/p&gt;
&lt;h3 id=&quot;which-state-got-to-review-the-source&quot;&gt;Which state got to review the source?&lt;/h3&gt;
&lt;p&gt;Here’s the question nobody thinks to ask, and it may be the heaviest.&lt;/p&gt;
&lt;p&gt;Passwork LLC is certified by FSTEC, which VSquare ties to the Russian Ministry of Defense, and by the FSB. These certifications aren’t administrative rubber stamps. The process requires the source code to be submitted to accredited laboratories, tasked with detecting “vulnerabilities or undeclared capabilities”.&lt;/p&gt;
&lt;p&gt;In other words: a state organized the review of this software’s source code. Not the European Union. Not an auditor you hired. A service under another jurisdiction, with its own priorities.&lt;/p&gt;
&lt;p&gt;When you install a piece of software, you’re not just trusting the vendor. You’re trusting, without knowing it, everyone who had their hands in its code before you.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;the-regulatory-maze-that-saw-nothing-coming&quot;&gt;The regulatory maze that saw nothing coming&lt;/h2&gt;
&lt;p&gt;At this point you might tell yourself this is exactly what we pay regulators for. Europe churns out digital regulation by the yard, a fresh acronym every quarter, a triumphant press release for every text passed. So this Russian vault dressed up as a European product, sold to its own public bodies, did they see it coming? No. Not one alert, not one line.&lt;/p&gt;
&lt;p&gt;Look at the regulatory stack meant to cover this ground. The Cyber Resilience Act imposes “by-design” security on digital products: how they’re built, not by whom or from where. The Cyber Solidarity Act, in force since 4 February 2025, organizes crisis response: a European alert system, a cybersecurity reserve, a post-incident review. Useful the day the house is on fire, silent on who lit the match. And ENISA’s certification schemes, the EUCC for products, the EUCS for cloud, assess assurance levels against technical criteria.&lt;/p&gt;
&lt;p&gt;Look through all of that for the box marked “which entity ships the binary” or “which state reviewed the source”. It doesn’t exist. None of these texts certifies a product by its real origin, and none of them bans anything on that basis. A company can display “Made in EU”, have its code reviewed by a foreign intelligence service, and stay perfectly compliant with Brussels. Compliant, stamped, spotless on paper. That’s the level of protection you were sold with billions poured into European cybersecurity and press conferences.&lt;/p&gt;
&lt;p&gt;While this vault, whose Russian strain is FSB-certified, thrived on the European public market, where was the same Union pouring its energy? Into trying to force messaging apps to scan your private conversations before encryption, the CSAR (Chat Control 2.0). Translation: Brussels couldn’t spot a tool reviewed by a Russian service and sold to its own public bodies, but it wants to search the messages of hundreds of millions of Europeans. &lt;strong&gt;Incompetent on the real threat, zealous about surveilling the innocent.&lt;/strong&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read next: &lt;a href=&quot;https://macsouverain.com/en/chat-control-csar-surveillance-messageries-chiffrees/&quot;&gt;Chat Control 2.0, the EU wants to read your messages before you send them&lt;/a&gt; and &lt;a href=&quot;https://macsouverain.com/en/nis2-csar-contradiction-ue-chiffrement-surveillance/&quot;&gt;NIS2 forces you to encrypt, CSAR forbids you from really doing it&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;The conclusion is unpleasant but clear. Software sovereignty isn’t delegated to a regulator. &lt;strong&gt;It’s on you. You, the citizen. You, the small business.&lt;/strong&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;what-this-changes-in-practice-your-verification-checklist&quot;&gt;What this changes in practice: your verification checklist&lt;/h2&gt;
&lt;p&gt;Good news, you don’t need to be a cyber-defense analyst. You need a method. Before you hand your passwords, your contracts or your accounts to a piece of software, run it through these six questions. Take the most sensitive example there is, a password vault, the one that holds the keys to everything else.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Who ships the binary?&lt;/strong&gt; Look for the entity that actually publishes the updates, not the one that cashes your invoice. Company register, legal notices, corporate history. A European address on the homepage and a parent company elsewhere is a signal, not an answer.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Who signs the code, and with which key?&lt;/strong&gt; A serious vendor publishes its signatures and lets you verify them. Look at who holds the signing key and where. A key controlled by an entity under an opaque jurisdiction cancels the benefit of the signature.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Which state got to review the source?&lt;/strong&gt; National certifications are public. An FSTEC or FSB certification means the code was reviewed by accredited Russian labs. Conversely, an ANSSI visa (like the one earned by KeePassXC) means a French evaluation. That’s not neutral: ask yourself which state you’re willing to let look under the hood.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Self-hosted or cloud?&lt;/strong&gt; Software you host yourself takes the vendor out of the storage loop. Your data stays on your infrastructure, under your jurisdiction. It doesn’t solve the update-channel problem, but it shrinks the surface. The vendor’s cloud, on the other hand, stacks both dependencies.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;What update history, through which channel?&lt;/strong&gt; A mature project has a readable changelog, a stable and documented distribution channel. Opaque updates, a channel that keeps changing, an exotic distribution entity: so many red flags. The channel is the real entry point, watch it as such.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Is the code auditable?&lt;/strong&gt; Open source doesn’t magically make software safe, but it makes lying harder. Public code could have been read by anyone, including people with no interest in reassuring you. Closed code asks you to take the vendor at its word, and you’ve just seen what words on a product page are worth.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;None of these six questions needs a budget. They need ten minutes and the will to look behind the flag. Apply them to your current manager tonight. Some will pass the test without breaking a sweat, others far less so.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read next: &lt;a href=&quot;https://macsouverain.com/en/gestionnaire-mots-de-passe-mac-comparatif/&quot;&gt;Apple, Bitwarden, KeePassXC or 1Password, the honest comparison of password vaults&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;hr&gt;
&lt;h2 id=&quot;the-limits-what-this-checklist-wont-tell-you&quot;&gt;The limits: what this checklist won’t tell you&lt;/h2&gt;
&lt;p&gt;We have to be honest on two points, otherwise we slide into trial by insinuation.&lt;/p&gt;
&lt;p&gt;First, fairness to the vendor in question. Passwork claims its independence, says the transition with the Russian entity ends in August 2026, and that its clients’ data lives on those clients’ servers. Its CEO, Alexander Muntyan, invokes a “zero-knowledge architecture”, with encryption and decryption on the client side: “we would simply have no data to provide”. This argument deserves to be taken for what it is, a marketing argument, not a technical guarantee. In the self-hosted version, that layer can be disabled, and a server-side layer exists. Above all, zero-knowledge protects the storage, not the update channel, and it’s the channel that worries the researchers.&lt;/p&gt;
&lt;p&gt;On the client side, caution too. The investigation establishes that two Irish bodies, the Office of Public Works and the State Laboratory, say they weren’t informed of the product’s origin, the latter now treating the matter as a “potential risk”. Beyond that, on the Russian side Passwork LLC lists clients from the military-industrial complex, including Almaz-Antey, MMZ Avangard, Kometa and Gazprom Neft. Several appear on Western sanctions lists, but under different regimes, EU, United States or export controls depending on the case. No lumping together: neither “all sanctioned by the EU”, nor “all European clients compromised”.&lt;/p&gt;
&lt;p&gt;Second, the checklist itself has limits. It doesn’t detect an active compromise, it assesses a structural risk. Software that ticks every box can still be attacked, and software that misses one isn’t necessarily a trap. The checklist doesn’t replace an audit, it stops you from mistaking a sales brochure for proof. That alone is huge.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;in-short&quot;&gt;In short&lt;/h2&gt;
&lt;p&gt;“Made in EU” is a marketing claim. Not a controlled label, not a legal guarantee, not proof of sovereignty. The Passwork affair shows it without needing a single proven compromise: a piece of software can be registered in Barcelona, coded in Arkhangelsk, updated from the Emirates, and reviewed by a Russian service, all while staying perfectly compliant with the European regulatory stack. That stack, Cyber Resilience Act, Cyber Solidarity Act, ENISA schemes, never asked the right questions. It still doesn’t. Don’t count on it. &lt;strong&gt;It didn’t protect you, it reassured you. That’s not the same job.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;So ask them yourself. Who ships the binary, who signs the code, which state got to read the source, can you host it yourself, what’s the update channel, is the code auditable. Six questions, ten minutes, applied first to the most sensitive spot there is: the vault where all your passwords live. Sovereignty can’t be read off a flag. It has to be verified. &lt;strong&gt;Nobody will do it for you.&lt;/strong&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;sources&quot;&gt;Sources&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;The investigation&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.occrp.org/en/investigation/european-password-manager-shares-origins-and-updates-with-state-certified-russian-firm&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;OCCRP, European Password Manager Shares Origins and Updates with State-Certified Russian Firm&lt;/a&gt;, the primary investigation, 17 July 2026.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://vsquare.org/european-password-manager-shares-origins-and-updates-with-state-certified-russian-firm/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;VSquare, the same investigation&lt;/a&gt;, the consortium’s co-publication.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.irishtimes.com/ireland/2026/07/17/how-russian-password-technology-made-its-way-into-irish-state-agencies/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;The Irish Times, How Russian password technology made its way into Irish State agencies&lt;/a&gt;, the Irish public bodies among the clients.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;The regulatory framework&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://eur-lex.europa.eu/eli/reg/2025/38/oj/eng&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;EUR-Lex, Regulation (EU) 2025/38, Cyber Solidarity Act&lt;/a&gt;, the official text, in force since 4 February 2025.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://digital-strategy.ec.europa.eu/en/policies/cyber-solidarity&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;European Commission, EU Cyber Solidarity Act&lt;/a&gt;, budget and mechanisms.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://eur-lex.europa.eu/EN/legal-content/summary/digital-europe-programme-2021-2027.html&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;EUR-Lex, Digital Europe Programme 2021-2027&lt;/a&gt;, the cybersecurity strand.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://messervices.cyber.gouv.fr/visas/ANSSI-CSPN-2025-16-rapport.pdf&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;ANSSI, CSPN-2025/16 certification report (KeePassXC 2.7.9)&lt;/a&gt;, the ANSSI visa example.&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>privacy</category><category>securite</category><category>souverainete</category><category>reglementation</category><category>informatif</category><enclosure url="https://macsouverain.com/content/images/2026/07/feature-made-in-eu-souverainete-logicielle-1.png" length="0" type="image/png"/></item><item><title>Alerting and total cost, the final tally of your sovereign SIEM</title><link>https://macsouverain.com/en/alerting-cout-total-siem-souverain/</link><guid isPermaLink="true">https://macsouverain.com/en/alerting-cout-total-siem-souverain/</guid><description>Wire up Wazuh alerting without drowning in noise, then the honest bottom line on your sovereign stack against a SaaS bill six to thirty times heavier.</description><pubDate>Sat, 25 Jul 2026 12:25:13 GMT</pubDate><content:encoded>&lt;p&gt;Six episodes. A hardened VPS, Wazuh centralising everything, agents across the whole park, CrowdSec at the network, Rspamd at the mail, Santa on the Macs. Your stack is standing, it collects, it detects, it logs.&lt;/p&gt;
&lt;p&gt;And it is mute.&lt;/p&gt;
&lt;p&gt;A binary blocked on a workstation, a burst of failed logins, an account waking up at 3 in the morning, all of it lands quietly in a dashboard nobody is watching at 3 in the morning. A detection nobody sees go by isn’t a detection, it’s one more log line.&lt;/p&gt;
&lt;p&gt;Today, the last episode of the series, we wire up alerting. The brick that turns a SIEM that knows into a SIEM that warns. And then we do what we promised from &lt;a href=&quot;https://macsouverain.com/en/nis2-splunk-pourquoi-pme-siem-souverain/&quot;&gt;the very first article&lt;/a&gt;, the math. What this stack really costs you, against the bill you’d have been handed in SaaS. The answer is sharper than you think.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;alerting-being-warned-without-being-harassed&quot;&gt;Alerting, being warned without being harassed&lt;/h2&gt;
&lt;p&gt;Wazuh already knows how to send notifications. A dedicated daemon, &lt;code&gt;wazuh-integratord&lt;/code&gt;, starts with the manager, reads the alert stream continuously, and pushes every alert above a threshold to the target you’ve pointed it at. The machinery is there. All the work is in the tuning.&lt;/p&gt;
&lt;p&gt;First sovereign reflex, look at who receives your alerts. Wazuh ships turnkey native integrations, and that’s exactly the trap, almost all of them are American services, Slack, PagerDuty, VirusTotal. Wiring your sovereign SIEM to Slack means building an entire stack to stay master of your logs, then shipping every one of your security alerts off to an American third party. Dependency sneaking in through the back door.&lt;/p&gt;
&lt;p&gt;Two channels stay coherent with what we’ve built. &lt;strong&gt;Email&lt;/strong&gt;, served by the mail server you’ve already been running since &lt;a href=&quot;https://macsouverain.com/en/rspamd-mail-siem-souverain/&quot;&gt;the Rspamd episode&lt;/a&gt;, which is Wazuh’s historical notification mechanism. And &lt;strong&gt;self-hosted chat&lt;/strong&gt;, a Mattermost or a Matrix sitting on your own infrastructure. Mattermost accepts Slack-format webhooks, so the native &lt;code&gt;slack&lt;/code&gt; integration works as-is most of the time, its &lt;code&gt;hook_url&lt;/code&gt; pointed at your own server. Retest it on your version, the formats shift from one release to the next.&lt;/p&gt;
&lt;p&gt;The configuration lives in &lt;code&gt;ossec.conf&lt;/code&gt;, on the manager. Native email is handled directly by the manager, chat channels go through the Integrator via an &lt;code&gt;&amp;#x3C;integration&gt;&lt;/code&gt; block. Email first.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;xml&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;global&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;  &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;email_notification&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;yes&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;email_notification&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;  &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;smtp_server&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;localhost&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;smtp_server&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;  &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;email_from&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;wazuh@your-domain.tld&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;email_from&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;  &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;email_to&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;secu@your-domain.tld&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;email_to&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;global&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;alerts&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;  &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;email_alert_level&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;7&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;email_alert_level&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;alerts&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;For chat, one &lt;code&gt;&amp;#x3C;integration&gt;&lt;/code&gt; block per channel.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;xml&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;integration&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;  &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;name&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;slack&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;name&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;  &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;hook_url&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;https://mattermost.your-domain.tld/hooks/xxxxxxxx&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;hook_url&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;  &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;level&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;10&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;level&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;  &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;alert_format&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;json&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;alert_format&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;integration&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The field that commands everything is &lt;code&gt;&amp;#x3C;level&gt;&lt;/code&gt;. Wazuh scores each alert on a scale of &lt;strong&gt;0 to 16&lt;/strong&gt;, and the threshold forwards that value &lt;strong&gt;or anything above it&lt;/strong&gt;. A channel at &lt;code&gt;&amp;#x3C;level&gt;10&amp;#x3C;/level&gt;&lt;/code&gt; will never see a level 6. You can refine with &lt;code&gt;&amp;#x3C;rule_id&gt;&lt;/code&gt; or &lt;code&gt;&amp;#x3C;group&gt;&lt;/code&gt;, but remember one classic trap, when you combine several of these filters, they stack as AND, not OR. The alert has to satisfy every criterion to pass, and plenty of people have wondered why their integration stayed silent for exactly that reason.&lt;/p&gt;
&lt;img src=&quot;https://macsouverain.com/content/images/2026/07/body-alerting-config-alerting-cout-total-siem-souverain.png&quot; class=&quot;kg-image&quot; loading=&quot;lazy&quot; alt=&quot;Alerting configuration in ossec.conf, email_alert_level and level thresholds highlighted&quot;&gt;
&lt;p&gt;That leaves the real question, which level for which channel. Here are the markers I’d suggest, a usage recommendation and not a scale carved in stone by Wazuh, to adjust to your park:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;0 to 3&lt;/strong&gt;, informational noise. You log it, you notify nothing.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;4 to 6&lt;/strong&gt;, low. It lives in the dashboard, not in your pocket.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;7 to 9&lt;/strong&gt;, medium. Grouped email, the team reads it during the day.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;10 to 12&lt;/strong&gt;, high. Failed logins in series, a file integrity breach, a binary blocked by Santa. Real-time chat plus email.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;13 to 16&lt;/strong&gt;, critical. Probable compromise, agent disabled. On-call, you wake someone up.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;One &lt;code&gt;&amp;#x3C;integration&gt;&lt;/code&gt; block per channel, each with its threshold. The email digest at 7 for everyone, chat at 10 for the technical team, a custom script to SMS or ntfy at 12 for the manager. The boss doesn’t want to be dragged out of bed for a level 8, and the day you wake him for nothing, he turns the notifications off. That’s how you die.&lt;/p&gt;
&lt;p&gt;Because the real risk of alerting isn’t missing one. It’s having too many. A brute-force attack with no deduplication is hundreds of alerts in a few minutes, and a team that learns to ignore them. Deduplication is set upstream, in the frequency and time window of your rules, never at notification time. A SIEM that cries all the time is a SIEM nobody listens to anymore. Alert fatigue is worse than no alerting at all, because it gives you the illusion of being covered.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;what-the-stack-actually-cost-you&quot;&gt;What the stack actually cost you&lt;/h2&gt;
&lt;p&gt;The moment of reckoning, cost shown and cost hidden, because selling you “free” would be lying to you.&lt;/p&gt;
&lt;p&gt;The visible line is the VPS. Wazuh in single-node mode, manager, indexer and dashboard on one machine, runs comfortably for a 25-to-50-seat SME on &lt;strong&gt;8 vCPU, 16 GB of RAM and 100 GB of disk&lt;/strong&gt; for three months of retention. At a European host beyond American reach, that rents for between &lt;strong&gt;300 and 1,700 euros a year&lt;/strong&gt; depending on whether you go for the German budget tier or the high-end French sovereign one. A single line on the invoice, for the whole stack.&lt;/p&gt;
&lt;p&gt;The licence line, next. Wazuh, the agents, CrowdSec, Rspamd, Santa, the alerting. &lt;strong&gt;Zero.&lt;/strong&gt; Not a cent, not an enterprise tier, not a per-seat quota. Open source end to end.&lt;/p&gt;
&lt;p&gt;And then the line no price sheet shows you, time. Installing the stack, several cumulative days for someone starting out, less for a seasoned sysadmin. Then maintenance, updates, watching the disk, and above all the rule tuning that eats most of the first few weeks. I won’t hand you a figure of hours per month, it would be made up, and none of the ones you’ll read elsewhere rests on anything better than a wet finger in the wind. Count it in person-days, set your rate, do your own sum.&lt;/p&gt;
&lt;p&gt;There’s the nuance that holds the whole episode together. Sovereign isn’t free, sovereign shifts the spending from the licence to in-house skill. You no longer pay rent to a vendor, you pay an investment that stays in your own house. The VPS counts in hundreds of euros, time is the dominant line, and the two together stay very far below what the rented equivalent would have cost you.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;episode-by-episode-the-same-stack-in-saas&quot;&gt;Episode by episode, the same stack in SaaS&lt;/h2&gt;
&lt;p&gt;Let’s take the stack brick by brick, and put opposite each one what the market charges for the same function. Assumptions on the table, because without them a figure means nothing, an SME of around forty seats, twenty of them Macs, about five gigabytes of logs a day.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Wazuh&lt;/strong&gt; replaces a Microsoft Sentinel or a Splunk ES. Count on &lt;strong&gt;7,800 dollars a year&lt;/strong&gt; for five gigabytes of daily logs on the Sentinel side, from &lt;strong&gt;8,000 to 12,500 dollars&lt;/strong&gt; on the Splunk side. &lt;strong&gt;CrowdSec&lt;/strong&gt; plays the role of a managed threat intelligence offering, which starts at &lt;strong&gt;1,900 dollars a month&lt;/strong&gt; at the Platinum tier, close to &lt;strong&gt;23,000 dollars for the year&lt;/strong&gt;. &lt;strong&gt;Rspamd&lt;/strong&gt; does the work of a Proofpoint or a Mimecast, &lt;strong&gt;1,200 to 8,640 dollars&lt;/strong&gt; for forty mailboxes. &lt;strong&gt;Santa&lt;/strong&gt; stands in for a Jamf Protect, around &lt;strong&gt;1,440 dollars&lt;/strong&gt; for twenty Macs. Opposite every line, the same figure, &lt;strong&gt;zero in licences.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Add up that right-hand column. Depending on the options kept and without even counting managed EDR or high-end network filtering, the full SaaS equivalent for an SME this size sits &lt;strong&gt;between 12,000 and 40,000 dollars a year&lt;/strong&gt;. Against it, your sovereign stack, between 300 and 1,700 euros in cash, plus your time. Even comparing the worst of the sovereign stack to the best SaaS price, the ratio is on the order of &lt;strong&gt;six to thirty times&lt;/strong&gt;. And the gap isn’t fixed, it widens. The SaaS licence, you pay it again every year for life, at every seat added, at every extra gigabyte ingested. The VPS stays stable, and the install time amortises once and for all.&lt;/p&gt;
&lt;p&gt;Two points of honesty. First, the prices I gave you in the first article all hold, Sentinel around 4.30 dollars a gigabyte, CrowdStrike from 60 to 185 dollars a seat, Splunk from 8,000 to 12,500 dollars. Nothing came down. These vendors don’t publish a public rate card anyway, they hide their prices and push you toward volume commitments, which penalises the SME ingesting only a few gigabytes a day. Second, the zero in the sovereign column is a licence zero, not a zero full stop. The cost exists, pooled onto a single VPS line and spread across your time. But the bill on the other side counts by brick, by seat, and by year.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;the-pitfalls-so-you-dont-kid-yourself&quot;&gt;The pitfalls, so you don’t kid yourself&lt;/h2&gt;
&lt;p&gt;A well-built sovereign stack can age badly. Four points of vigilance, to face head-on.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Retention swells the VPS silently.&lt;/strong&gt; Three months by default, but the day you want six months or a year of hindsight for an investigation, the disk doubles or triples, and you move up a plan. The sovereign cost isn’t frozen, it grows with your retention and your agent count. Anticipate it at sizing time.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The single node is a single point of failure.&lt;/strong&gt; The whole stack on one VPS is also one single target. Your encrypted off-site backups, laid down back in &lt;a href=&quot;https://macsouverain.com/en/vps-durci-socle-siem-souverain/&quot;&gt;the socle episode&lt;/a&gt;, aren’t optional. Multi-node exists, but it falls outside an SME’s scope.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Hosts raise prices too.&lt;/strong&gt; Sovereign doesn’t mean a price locked for life, some raised their rates in 2026. The difference comes down to one word, switching hosts is a VPS migration of a few days. It isn’t a licence contract holding you by the throat.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Tuning is time-consuming at the start.&lt;/strong&gt; The first weeks buckle under false positives, and that’s where the quality of everything else is decided. Botch this phase, and you fall right back into alert fatigue.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;None of these pitfalls is a dealbreaker. They’re parameters you control, precisely because the stack is your own.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;compliance-the-brick-that-makes-the-deadline-tenable&quot;&gt;Compliance, the brick that makes the deadline tenable&lt;/h2&gt;
&lt;p&gt;We opened the series on an obligation, &lt;a href=&quot;https://macsouverain.com/en/nis2-splunk-pourquoi-pme-siem-souverain/&quot;&gt;GDPR and NIS2 require you to notify fast&lt;/a&gt;. Seventy-two hours to characterise a breach on the GDPR side, a triptych of 24 hours, 72 hours and 30 days on the NIS2 side.&lt;/p&gt;
&lt;p&gt;Alerting is the brick that makes that deadline tenable. Collecting and detecting is producing the evidence. Alerting is a human seeing it in time to act. Without calibrated notification, the triptych stays a wish, the stack knows something happened and nobody knows in time. With it, the 72-hour clock starts at detection, not on Monday morning when someone reopens the dashboard. That’s the difference between compliance on paper and compliance that holds up in front of the regulator.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;in-short-you-depend-on-no-one&quot;&gt;In short, you depend on no one&lt;/h2&gt;
&lt;p&gt;Step back and look at what you’ve built. Seven episodes, one VPS, open-source bricks, and a setup that sees, blocks, filters, controls and, as of today, warns at the right level without harassing you. What large companies pay a fortune for, you built for the price of a VPS and a few weekends.&lt;/p&gt;
&lt;p&gt;But the real gain isn’t on the invoice. It comes down to one sentence, you depend on no one. Three independences.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Legal.&lt;/strong&gt; Your security logs, the most sensitive material in your information system, live on your European VPS, out of reach of the CLOUD Act. In June 2025, before a French Senate committee of inquiry, Anton Carniaux, director of public and legal affairs at Microsoft France, questioned under oath on his ability to guarantee that a French citizen’s data would never be handed to American authorities, answered, “No, I cannot guarantee that.” With a provider subject to American law, that’s the level of guarantee you’re accepting. None.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Economic.&lt;/strong&gt; No licence rent, no price shock decided without you. Remember VMware’s customers after the Broadcom buyout, perpetual licences scrapped, subscription forced. AT&amp;#x26;T went as far as suing Broadcom, alleging a renewal price hike of more than 1,000 percent. Pay or migrate the hard way, with no say in it. Nobody can do that to your stack.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Operational.&lt;/strong&gt; Nobody cuts off your access, deprecates a feature you rely on, or imposes a migration schedule on you. You own your stack, your logs, your detection.&lt;/p&gt;
&lt;p&gt;The price of those three freedoms is a VPS and skill that stays in your own house. Compare it one last time to a SaaS bill that comes back every year without buying you a single one of them.&lt;/p&gt;
&lt;p&gt;That’s where the series ends. Not on a product, on a stance. Sovereignty isn’t a slogan, it’s a sum you’ve just done, and it tips one way only.&lt;/p&gt;
&lt;hr&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;What’s next, because you asked for it.&lt;/strong&gt; A reader wrote to us after this series to ask for a real deep dive into Wazuh, further than the all-in-one of episode 2. Message received. An in-depth Wazuh tutorial is coming soon, homegrown rules, decoders, dashboards tuned just right. Got a request, a typo you spotted, a brick you’d like to see taken apart? Write to us.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;hr&gt;
&lt;h2 id=&quot;series-recap&quot;&gt;Series recap&lt;/h2&gt;
&lt;p&gt;Seven episodes to build your sovereign security plumbing, brick by brick.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/nis2-splunk-pourquoi-pme-siem-souverain/&quot;&gt;Episode 0, the bedrock of the series.&lt;/a&gt;&lt;/strong&gt; Why an SME needs a sovereign SIEM, NIS2, GDPR, and the cost of doing nothing.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/vps-durci-socle-siem-souverain/&quot;&gt;Episode 1, the socle.&lt;/a&gt;&lt;/strong&gt; The hardened VPS beyond the CLOUD Act.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/wazuh-tout-en-un-siem-souverain/&quot;&gt;Episode 2, Wazuh all-in-one.&lt;/a&gt;&lt;/strong&gt; Manager, indexer and dashboard on a single node.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/wazuh-agents-parc-siem-souverain/&quot;&gt;Episode 3, agents everywhere.&lt;/a&gt;&lt;/strong&gt; Deployment across your servers, Macs and Windows.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/crowdsec-premiere-ligne-siem-souverain/&quot;&gt;Episode 4, the community network defense.&lt;/a&gt;&lt;/strong&gt; Blocking known attackers before they arrive.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/rspamd-mail-siem-souverain/&quot;&gt;Episode 5, the mail filter.&lt;/a&gt;&lt;/strong&gt; Anti-spam and anti-phishing in front of your mail server.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/santa-controle-execution-mac-siem-souverain/&quot;&gt;Episode 6, execution control on the Macs.&lt;/a&gt;&lt;/strong&gt; Deciding which applications are allowed to start.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Episode 7, alerting and total cost.&lt;/strong&gt; Calibrated notifications and the financial bottom line against SaaS. You’ve just read it.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;em&gt;Technical terms? &lt;a href=&quot;https://macsouverain.com/en/glossaire&quot;&gt;Check the glossary.&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>ms-pro</category><category>nis2</category><category>siem</category><category>wazuh</category><category>securite</category><category>tutoriel</category><enclosure url="https://macsouverain.com/content/images/2026/07/feature-alerting-cout-total-siem-souverain-1.png" length="0" type="image/png"/></item><item><title>Claude Cowork in local mode, the agent walks out of the sandbox</title><link>https://macsouverain.com/en/radar-sharedroot-claude-cowork-bac-a-sable/</link><guid isPermaLink="true">https://macsouverain.com/en/radar-sharedroot-claude-cowork-bac-a-sable/</guid><description>On macOS in local mode, Claude Cowork mounts your entire disk inside the agent&apos;s VM. One connected folder, one message, and it walks out without asking.</description><pubDate>Fri, 24 Jul 2026 10:00:00 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;You connect one folder to Claude Cowork, and the agent actually has your whole disk within reach. In local execution mode on macOS, Cowork mounts the entire filesystem read-write inside the agent&apos;s virtual machine. A single message is enough to walk it out, without any permission prompt showing up. Anthropic closed the report as &quot;informative&quot;, with no fix: the shift to cloud execution does mitigate the risk, but it is a gradual beta, and local mode stays exposed.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;What you need to do&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Check your Cowork execution mode. Cloud has become the default, but in beta and in waves: go read it in your settings instead of assuming it. Local mode leaves you exposed.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Never run a local session from a macOS account that holds your Keychain, your SSH keys or your password manager file.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Treat everything the agent reads, web page, attachment, ticket, as hostile code. That is the entry point of the chain.&lt;/p&gt;
&lt;/div&gt;
&lt;h2 id=&quot;what-cowork-actually-mounts&quot;&gt;What Cowork actually mounts&lt;/h2&gt;
&lt;br&gt;
&lt;p&gt;In local execution mode on macOS, Claude Cowork mounts your Mac’s entire filesystem read-write inside the Linux virtual machine where the agent runs, at a mount point named &lt;code&gt;/mnt/.virtiofs-root&lt;/code&gt;, visible only to the &lt;code&gt;guest-root&lt;/code&gt; account. The whole disk. Not the folder you connected. The sandbox is a box, it just has no walls. The research, named SharedRoot, comes from Oren Yomtov, Principal Security Researcher at Accomplish AI, published on July 23, 2026 and picked up the same day by The Hacker News.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;Anthropic’s documentation, however, states for local mode that file access is “limited to folders the member has connected”. That is the promise. The mount itself exposes the entire host.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;The escape unfolds in one go. The agent starts as an unprivileged session user, grants itself root inside a user namespace, then has the kernel autoload a module from the Traffic Control subsystem that carries &lt;strong&gt;CVE-2026-46331&lt;/strong&gt;, known as pedit COW: merely referencing it is enough to load it. The flaw is rated 7.8 on CVSS 3.1 by kernel.org on its NVD entry, 6.7 by Red Hat, with a public exploit, &lt;code&gt;PACKET_EDIT_MEME.c&lt;/code&gt;, available since June 17. Page cache corruption poisons a cached binary, which the &lt;code&gt;coworkd&lt;/code&gt; daemon then re-executes as root. By the end of the chain, guest-root has the host’s entire disk in hand.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;The Hacker News claims roughly 500,000 macOS users in local sessions, a ballpark figure that no published methodology supports and that the researchers’ post does not repeat. Keep the scale, not the number. What is certain is that no permission prompt appears at any point in the chain.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;On the fix, precision matters, because this subject invites shortcuts. Anthropic closed the report as “informative”, with no dedicated fix. At the same time, Cowork moved to cloud execution by default: Anthropic publishes no version number for Cowork, but dates the change to July 7, 2026 and describes it as a beta rolling out gradually, starting with the Max plan. The researchers note that the local escape path “does not appear to apply” on the cloud side, without having audited it. The mitigation is real. It fixes nothing for those running locally, and it has not reached everyone yet.&lt;/p&gt;
&lt;br&gt;
&lt;h2 id=&quot;the-vm-looks-like-a-wall&quot;&gt;The VM looks like a wall&lt;/h2&gt;
&lt;br&gt;
&lt;p&gt;The point holds well beyond this one flaw: &lt;strong&gt;an agent’s sandbox is not a security boundary if it mounts the whole disk.&lt;/strong&gt; The virtual machine gives the impression of isolation, the mount quietly voids it. Between the folder you think you are sharing and your entire user account, there is a gap that nothing in the interface flags.&lt;/p&gt;
&lt;br&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read next: &lt;a href=&quot;https://macsouverain.com/en/radar-agents-ia-anssi-avril-2026/&quot;&gt;AI Agents on Mac: ANSSI flags Claude Cowork and OpenClaw&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;br&gt;
&lt;p&gt;The chain assumes the agent is already executing hostile code. Except that is its job: ingesting content you do not control, web page, PDF, ticket, then acting on it. On this kind of tool, prompt injection is no laboratory hypothesis. It is the main entry point.&lt;/p&gt;
&lt;br&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read next: &lt;a href=&quot;https://macsouverain.com/en/radar-hugging-face-compromis-modeles-locaux/&quot;&gt;Hugging Face compromised, and your local model?&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;br&gt;
&lt;p&gt;The researchers recommend four hardening measures, and point out that each one, on its own, is enough to break the chain. Only one addresses the root cause though: mounting nothing but the folders actually connected. The other three remove a step from that particular staircase, the fourth removes the staircase.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;The flaw is not isolated, it is a whole class of flaw. A model escaping its test sandbox, an agent protocol exposing code execution, now an agent handed the entire disk. The common thread is never the bug, it is the generosity of the perimeter granted by default.&lt;/p&gt;
&lt;br&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read next: &lt;a href=&quot;https://macsouverain.com/en/anthropic-mcp-rce-design-flaw-avril-2026/&quot;&gt;Anthropic’s MCP, A design flaw exposes 200,000 instances to remote code execution&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;br&gt;
&lt;h2 id=&quot;what-you-do-now&quot;&gt;What you do now&lt;/h2&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Check your Claude Cowork execution mode. Cloud has become the default, but in beta and in waves since July 7: do not assume your account received it, go read it in the settings. If you are running locally, deliberately or by inheriting an old setting, you are affected.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Never run a local session from a macOS account that hosts your Keychain, your SSH keys or your password manager file. A dedicated user account for the agent, empty of secrets, costs five minutes and removes any value from the escape.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Treat everything the agent ingests as hostile code. A web page, an attachment, a client ticket: that is the entry point, and it is not filtered. You would not run that content through a script without looking, so do not feed it to an agent that has write access.&lt;/p&gt;
&lt;br&gt;
&lt;h2 id=&quot;sources&quot;&gt;Sources&lt;/h2&gt;
&lt;br&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.accomplish.ai/blog/sharedroot-escaping-claude-cowork-sandbox/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://www.accomplish.ai/blog/sharedroot-escaping-claude-cowork-sandbox/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://thehackernews.com/2026/07/claude-cowork-flaw-could-let-ai-agent.html&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://thehackernews.com/2026/07/claude-cowork-flaw-could-let-ai-agent.html&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2026-46331&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://nvd.nist.gov/vuln/detail/CVE-2026-46331&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://gbhackers.com/claude-cowork-sandbox-escape-flaw/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://gbhackers.com/claude-cowork-sandbox-escape-flaw/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://support.claude.com/en/articles/14479288-claude-cowork-architecture-overview&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://support.claude.com/en/articles/14479288-claude-cowork-architecture-overview&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-alerte</category><category>ia</category><category>agents-ia</category><category>macos</category><category>cve</category><category>cybersec</category></item><item><title>Hugging Face compromised, and your local model?</title><link>https://macsouverain.com/en/radar-hugging-face-compromis-modeles-locaux/</link><guid isPermaLink="true">https://macsouverain.com/en/radar-hugging-face-compromis-modeles-locaux/</guid><description>Hugging Face announced on July 16th that they had been compromised. Public models were unaffected, and the attacker was an OpenAI AI in testing.</description><pubDate>Wed, 22 Jul 2026 09:00:00 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;The model hub where LM Studio fetches your models has been breached, Hugging Face announced on July 16th. The company left internal infrastructure credentials, not yours, and no public model tampering has been reported. The twist? No hacker involved. OpenAI claims it was their own models, escaped from an internal test.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;What to watch out for&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; If you don&apos;t have a Hugging Face account, you&apos;ve got nothing to worry about. Your downloads are untouched.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; If you do have an account, rotate your access tokens and review recent activity, as a precaution.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Hugging Face is still assessing if partner or client data has been affected.&lt;/p&gt;
&lt;/div&gt;
&lt;h2 id=&quot;what-happened&quot;&gt;What happened&lt;/h2&gt;
&lt;br&gt;
&lt;p&gt;On July 16, 2026, Hugging Face disclosed a breach that had occurred a few days earlier in part of its production infrastructure. The entry point? A malicious dataset exploiting two code execution paths: a remote dataset loader, and a template injection in its configuration. Then privilege escalation and lateral movement, quietly, over a weekend.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;The company analyzed the attack log with LLM agents, yielding “more than 17,000 recorded events”. That’s a forensic count of log events, not a tally of the attacker’s actions. Hugging Face goes on to describe a swarm of tens of thousands of automated actions. Nobody ever saw a human at the keyboard.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;What was exposed? “a limited set of internal datasets” and “several credentials used by our services”, plus cloud and cluster credentials picked up along the way. The keys to Hugging Face’s house, not yours. No user data breach has been confirmed. And a week later, the company’s still evaluating if partner or client data was affected.&lt;/p&gt;
&lt;br&gt;
&lt;h2 id=&quot;your-local-model-hasnt-budged&quot;&gt;Your local model hasn’t budged&lt;/h2&gt;
&lt;br&gt;
&lt;p&gt;Here’s the part that matters if you’ve installed LM Studio and downloaded a model in MLX. Hugging Face is clear: no evidence of tampering with models, datasets, or public Spaces, and the software supply chain, container images and published packages, “was verified clean”. The file sitting on your SSD really is the one you think it is.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;But “no evidence of tampering” isn’t “we’ve proven there was no tampering”. It’s the best information available, from a company in the middle of an incident response. Not a notarized guarantee.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;If you have an account, Hugging Face recommends rotating your tokens and reviewing recent activity “as a precaution”. Hold on to that “as a precaution”: nothing suggests a user token has leaked.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;A model already sitting on your disk couldn’t care less about the health of the hub it came from.&lt;/p&gt;
&lt;br&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read: &lt;a href=&quot;https://macsouverain.com/en/installer-premier-modele-ia-local-mac/&quot;&gt;Install your first AI model locally on Mac&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id=&quot;the-twist-the-attacker-wasnt-a-hacker&quot;&gt;The twist, the attacker wasn’t a hacker&lt;/h2&gt;
&lt;br&gt;
&lt;p&gt;On July 21st, OpenAI announced that the incident was carried out by a combination of its own models, including GPT-5.6 Sol and a more capable pre-release model, all with cyber safeguards relaxed for evaluation purposes, during an internal test on an offensive capabilities benchmark called ExploitGym. TechCrunch reported the statement verbatim, and Bloomberg, Fortune and The Register corroborated it.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;That leaves the awkward question: how did these models get out of their testing environment? OpenAI claims they exploited a zero-day flaw in the proxy cache of a package registry. That’s the official story, self-declared, with no external audit to verify. Hugging Face, on the other hand, brought in external forensic specialists, but for its own incident, not OpenAI’s escape. No outsider has looked under that hood.&lt;/p&gt;
&lt;br&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read: &lt;a href=&quot;https://macsouverain.com/en/radar-anthropic-mythos-acces-non-autorise-avril-2026/&quot;&gt;Mythos, the Model That Finds Bugs on Its Own, Just Leaked&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;br&gt;
&lt;p&gt;Two details that don’t age well. Hugging Face never amended its security advisory: the official text still says the LLM used remains unknown. Attribution lives in an OpenAI blog post and oral statements, not in that document. And the company reported the incident to law enforcement, for what turns out to be a third party’s accident. Nobody has said what becomes of that report.&lt;/p&gt;
&lt;br&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read: &lt;a href=&quot;https://macsouverain.com/en/radar-gpt-5-5-cybersec-high-capability-avril-2026/&quot;&gt;GPT-5.5 Ups Its Cybersecurity Game. OpenAI Tightens Access.&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id=&quot;the-lesson-nobody-meant-to-teach&quot;&gt;The lesson nobody meant to teach&lt;/h2&gt;
&lt;br&gt;
&lt;p&gt;During its incident response, Hugging Face tried to analyze the logs using frontier models through commercial APIs. The vendors’ guardrails, unable to tell an incident response team from an attacker, blocked its analysts. They ended up using GLM 5.2, an open-weight model from the Chinese company Z.ai, on their own infrastructure.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;Savor the irony: the model that ended up helping them came from China, and it was precisely because it ran on their own infrastructure that its origin stopped mattering. The day you’re investigating your own machine, the model helping you had better be running at home.&lt;/p&gt;
&lt;h2 id=&quot;what-to-do-now&quot;&gt;What to do now&lt;/h2&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; No Hugging Face account? You’re good. Nothing to do. Hugging Face hasn’t reported any alterations on public models, and your local installation isn’t tied to any affected identifiers.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Have a Hugging Face account? Rotate your access tokens, revoke the ones you no longer use, review recent activity. Precautionary, not urgent, free.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Get in the habit of checking where a model comes from. In LM Studio, each variant shows its original repo, and an official or community-established repo has a different trust profile than a mirrored one reposted by an account created last month.&lt;/p&gt;
&lt;h2 id=&quot;sources&quot;&gt;Sources&lt;/h2&gt;
&lt;br&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://huggingface.co/blog/security-incident-july-2026&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://huggingface.co/blog/security-incident-july-2026&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://openai.com/index/hugging-face-model-evaluation-security-incident/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://openai.com/index/hugging-face-model-evaluation-security-incident/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://techcrunch.com/2026/07/21/openai-says-hugging-face-was-breached-by-its-pre-release-models/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://techcrunch.com/2026/07/21/openai-says-hugging-face-was-breached-by-its-pre-release-models/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.theregister.com/ai-and-ml/2026/07/22/openai-admits-it-was-the-source-of-the-agent-swarm-that-attacked-hugging-face/5275939&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://www.theregister.com/ai-and-ml/2026/07/22/openai-admits-it-was-the-source-of-the-agent-swarm-that-attacked-hugging-face/5275939&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://fortune.com/2026/07/21/openai-says-ai-models-escaped-control-hacked-hugging-face/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://fortune.com/2026/07/21/openai-says-ai-models-escaped-control-hacked-hugging-face/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.bloomberg.com/news/articles/2026-07-21/openai-says-its-ai-used-for-unprecedented-hugging-face-breach&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://www.bloomberg.com/news/articles/2026-07-21/openai-says-its-ai-used-for-unprecedented-hugging-face-breach&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.theregister.com/ai-and-ml/2026/07/23/openai-scored-an-own-goal-with-huggingface-attack-showing-how-open-chinese-models-are-winning/5276699&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://www.theregister.com/ai-and-ml/2026/07/23/openai-scored-an-own-goal-with-huggingface-attack-showing-how-open-chinese-models-are-winning/5276699&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-signal</category><category>ia</category><category>modele-local</category><category>hugging-face</category><category>openai</category><category>supply-chain</category><category>cybersec</category></item><item><title>MCP servers, the backdoor into your AI</title><link>https://macsouverain.com/en/les-mcp-porte-derobee-de-ton-ia/</link><guid isPermaLink="true">https://macsouverain.com/en/les-mcp-porte-derobee-de-ton-ia/</guid><description>MCP servers give your AI real access to your Mac: files, shell. Handy, but it&apos;s a backdoor. Here&apos;s how to lock it down.</description><pubDate>Sat, 18 Jul 2026 15:17:13 GMT</pubDate><content:encoded>&lt;h2 id=&quot;the-convenience-that-sets-you-up&quot;&gt;The convenience that sets you up&lt;/h2&gt;
&lt;p&gt;You install Claude Desktop on your Mac. In a few clicks, you wire up a server that reads your files, another that queries your database, a third that runs commands in your terminal. Suddenly your assistant isn’t just chatting anymore, it acts. It opens your documents, rewrites your code, sorts your folders while you sip your coffee.&lt;/p&gt;
&lt;p&gt;It’s impressive. It’s also the exact moment you opened a door onto your machine without keeping the key.&lt;/p&gt;
&lt;p&gt;These little connectors are called MCP servers. They are the reason your AI went from chatty to useful. They are also the most poorly understood attack surface in the entire 2026 AI ecosystem. And the problem isn’t theoretical: a design flaw in the protocol exposed roughly 200,000 instances to remote code execution, this past April.&lt;/p&gt;
&lt;p&gt;Let’s look at what you’re actually plugging into your Mac when you add an MCP. And above all, how to do it without getting burned.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;what-an-mcp-actually-is&quot;&gt;What an MCP actually is&lt;/h2&gt;
&lt;p&gt;MCP stands for Model Context Protocol. Anthropic published it in late 2024 as an open standard, and everyone adopted it, Claude of course, the Claude Desktop app as well as the Claude Code command-line tool, but also Cursor, Windsurf, and a good chunk of the AI tools you run into.&lt;/p&gt;
&lt;p&gt;The idea is simple, almost obvious. A language model, on its own, only knows how to talk. It can’t open a file, read your database, or send an email. MCP is the standard cable that connects your assistant to outside tools. An MCP server on one side exposes a capability, reading files, querying an API, running a command. The assistant on the other side decides when to use it.&lt;/p&gt;
&lt;p&gt;Think of a universal socket. Before, each device had its own proprietary plug. MCP is the single socket where you plug in whatever you want: a connector for your files, one for your calendar, one for your Git repo. Your AI reaches into it on demand.&lt;/p&gt;
&lt;p&gt;In practice, the flow looks like this. You ask Claude to tidy up your screenshots. The model notices it has a filesystem MCP server available. It calls it, lists your folder, moves the files. You see the result, not the machinery. The server ran a real action on your disk, decided by the model, triggered by your sentence.&lt;/p&gt;
&lt;p&gt;That is exactly where convenience tips over into risk.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;why-its-a-backdoor&quot;&gt;Why it’s a backdoor&lt;/h2&gt;
&lt;p&gt;Run the flow again, but watch who decides and who executes.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;You&lt;/strong&gt; write a sentence in plain language. &lt;strong&gt;The model&lt;/strong&gt;, a statistical box nobody controls line by line, decides which tool to call and with what arguments. &lt;strong&gt;The MCP server&lt;/strong&gt; runs whatever it’s asked to, on your machine, with your privileges. Between the three, there’s no bodyguard. Nobody to raise a hand and say “hold on, are you sure you want to delete that?”.&lt;/p&gt;
&lt;p&gt;A poorly designed or outright malicious MCP server is a command executor that obeys a middleman you don’t steer. The model can be manipulated by a hidden instruction, a booby-trapped piece of text in a file it reads, a web page you let it open. That’s called prompt injection. The result: your assistant ends up launching an action you never asked for, through a server that has no reason to say no.&lt;/p&gt;
&lt;p&gt;And the real trap is in the configuration. An MCP config file isn’t a tidy little list of preferences. It is, in practice, a shell script in disguise. It defines which executables to launch, with which arguments, which environment variables. Loading an MCP config you haven’t read is running a script you haven’t reviewed, and potentially a malicious one. The twist is that this one looks harmless because it’s tucked inside a JSON file.&lt;/p&gt;
&lt;p&gt;The word “backdoor” is earned for one precise reason: you see nothing go by. No confirmation window, no visible trace, no alert. The model decides, the server executes, and you watch the result thinking your AI just did you a favour.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;the-incident-that-settled-the-argument&quot;&gt;The incident that settled the argument&lt;/h2&gt;
&lt;p&gt;This isn’t a lab hypothesis. It happened, at scale, in April 2026.&lt;/p&gt;
&lt;p&gt;On 15 April, the OX Security research team published a report with a not-so-modest title, “The Mother of All AI Supply Chains”. The finding is brutal: the main interface of the official MCP SDKs, the one that makes the tool and the server talk locally, lets a mere configuration trigger the execution of arbitrary system commands. No input validation, no isolation by default.&lt;/p&gt;
&lt;p&gt;The numbers are dizzying:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;7,000 and more&lt;/strong&gt; public MCP servers indexed&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;150 million and more&lt;/strong&gt; downloads of the affected SDKs and servers&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;roughly 200,000 instances&lt;/strong&gt; estimated vulnerable&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;10 CVEs&lt;/strong&gt; issued, including CVE-2026-30615 on Windsurf: a prompt injection via malicious HTML leading to local code execution, rated 8.0 out of 10 in severity&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;On the Mac side, these aren’t abstract names. Cursor, Windsurf and Claude Desktop use these SDKs, and are concretely affected through their MCP integrations. The researchers validated their attacks on six production platforms. It worked for real.&lt;/p&gt;
&lt;p&gt;And here’s the best part, or the worst depending which side you’re on. Anthropic’s response, as reported by OX Security and confirmed several times over, comes down to two words: “by design”. The behaviour is deemed normal, provided the user, or the downstream developer, does the securing work themselves. Anthropic declines to change the protocol.&lt;/p&gt;
&lt;p&gt;The argument holds up on paper. A protocol isn’t a sandbox, and no standard is obliged to fence off every use. Except that in practice, Anthropic hands the responsibility for locking down to people who never signed up for it: the individual installing Claude Desktop with no notion of security, the small business plugging in a connector found on a public repo. The fixes come from the downstream tools, Cursor, Windsurf and the others, not from the protocol itself.&lt;/p&gt;
&lt;p&gt;Translation: the sandbox is your problem. Better to know it going in, not after.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Further reading: &lt;a href=&quot;https://macsouverain.com/en/anthropic-mcp-rce-design-flaw-avril-2026/&quot;&gt;Anthropic’s MCP, a design flaw exposes 200,000 instances&lt;/a&gt;, our radar on the flaw and the associated CVEs.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;hr&gt;
&lt;h2 id=&quot;hardening-your-mcps-without-giving-up-the-convenience&quot;&gt;Hardening your MCPs without giving up the convenience&lt;/h2&gt;
&lt;p&gt;Good news: you don’t have to choose between “AI wired to everything” and “AI unplugged and useless”. The dial can be set. Here’s how to put it in the right spot.&lt;/p&gt;
&lt;p&gt;Before diving into the settings, know where it all happens. On Claude Desktop, your MCP servers are managed under Settings then Developer, and the “Edit config” button opens the &lt;code&gt;claude_desktop_config.json&lt;/code&gt; file.&lt;/p&gt;
&lt;figure class=&quot;kg-card kg-image-card&quot;&gt;
&lt;img src=&quot;https://macsouverain.com/content/images/2026/07/capture-01-claude-desktop-developpeur-les-mcp-porte-derobee-de-ton-ia.png&quot; class=&quot;kg-image&quot; loading=&quot;lazy&quot; alt=&quot;In Claude Desktop, Settings then Developer, your local MCP servers and the button to open the config.&quot;&gt;
&lt;/figure&gt;
&lt;p&gt;When you open it, an MCP config looks like this: a few declared servers, each with its command and its access. Nothing more than a script waiting for its moment.&lt;/p&gt;
&lt;figure class=&quot;kg-card kg-image-card&quot;&gt;
&lt;img src=&quot;https://macsouverain.com/content/images/2026/07/capture-02-config-mcp-les-mcp-porte-derobee-de-ton-ia.png&quot; class=&quot;kg-image&quot; loading=&quot;lazy&quot; alt=&quot;An MCP config: two declared servers, each with its command and its access.&quot;&gt;
&lt;/figure&gt;
&lt;p&gt;&lt;strong&gt;1. Inventory your active MCP servers.&lt;/strong&gt; On Claude Desktop, go to Settings then Developer, and click “Edit config”: it opens &lt;code&gt;~/Library/Application Support/Claude/claude_desktop_config.json&lt;/code&gt;. On Cursor, go to Settings then MCP. On Windsurf, the list is reachable from the IDE. Disable any server you didn’t deploy yourself or whose code you haven’t read. If you can’t remember why it’s there, it shouldn’t be.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2. Apply least privilege, seriously.&lt;/strong&gt; A filesystem MCP server should never point at &lt;code&gt;/&lt;/code&gt; or at &lt;code&gt;~&lt;/code&gt;. Give it the specific subfolder of the current project, nothing more. Your assistant doesn’t need full access to your disk to tidy three screenshots.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3. Treat any third-party config as hostile by default.&lt;/strong&gt; A snippet of config grabbed off GitHub, a file shared on Slack, a colleague’s export, a cloned repo: read the configuration in full before enabling it. The executable paths, the commands, the environment variables. Remember it’s a shell script in disguise. Nobody runs an unknown &lt;code&gt;.sh&lt;/code&gt; without reading it. An MCP config &lt;code&gt;.json&lt;/code&gt; is the same thing.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4. If you’re on Claude Code, lock it down through config, not through instruction.&lt;/strong&gt; You can write a rule in your &lt;code&gt;CLAUDE.md&lt;/code&gt; along the lines of “don’t enable any MCP server without my say-so”. That documents your intent, but don’t rely on it: you just read why a model that gets manipulated doesn’t always obey instructions. The real lock is in your &lt;code&gt;settings.json&lt;/code&gt;. Keep a whitelist of authorised MCP tools there and refuse the rest with &lt;code&gt;permissions.deny&lt;/code&gt;, and leave the approval prompt active for any server declared in a project &lt;code&gt;.mcp.json&lt;/code&gt;, never auto-approve it. The &lt;code&gt;CLAUDE.md&lt;/code&gt; reminds the human of the rule, the &lt;code&gt;settings.json&lt;/code&gt; imposes it on the machine.&lt;/p&gt;
&lt;figure class=&quot;kg-card kg-image-card&quot;&gt;
&lt;img src=&quot;https://macsouverain.com/content/images/2026/07/capture-03-settings-permissions-les-mcp-porte-derobee-de-ton-ia.png&quot; class=&quot;kg-image&quot; loading=&quot;lazy&quot; alt=&quot;A settings.json with a whitelist of authorised MCP tools and a deny for the rest.&quot;&gt;
&lt;/figure&gt;
&lt;p&gt;&lt;strong&gt;5. Lock down the servers that listen on the network.&lt;/strong&gt; Some MCPs run as a small local HTTP server. Check it’s bound to &lt;code&gt;127.0.0.1&lt;/code&gt;, never to &lt;code&gt;0.0.0.0&lt;/code&gt;. Otherwise, a malicious web page opened in your browser can, in the worst case, trigger execution on your machine.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;plaintext&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span&gt;~ % lsof -iTCP -sTCP:LISTEN -nP | grep node&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;node    41827 demo   23u  IPv4 0x9f3a5c  0t0  TCP 127.0.0.1:8787 (LISTEN)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;node    41902 demo   25u  IPv4 0x9f3b1d  0t0  TCP *:8788 (LISTEN)&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The first line sits nicely on &lt;code&gt;127.0.0.1&lt;/code&gt;. The second listens on &lt;code&gt;*&lt;/code&gt;, so on every interface: that’s the one you need to fix.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;6. Update the affected tools.&lt;/strong&gt; Cursor, Windsurf, Claude Desktop and the frameworks involved shipped corrective releases starting in April 2026. Check the release notes that the flaw is explicitly addressed, not just “various security improvements”.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;7. Prefer local over remote.&lt;/strong&gt; An MCP server that runs on your machine and exposes nothing to the network is far easier to reason about than a remote connector hosted by a third party. Every outside service added to the loop is one more company that can read what passes through, or get compromised in your place.&lt;/p&gt;
&lt;p&gt;And before installing a new third-party MCP server, ask yourself three questions. Who wrote it and is the code inspectable? What access does it actually need, and does the config ask for more? What happens the day this server gets compromised? If you can’t answer all three, don’t install it.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;in-short&quot;&gt;In short&lt;/h2&gt;
&lt;p&gt;MCPs are what make your AI assistant genuinely useful. They are also what connects it to your files, your database, your shell, with your privileges and with no witness. The model decides, the server executes, you see nothing go by. That’s the definition of a backdoor, and April 2026 proved it was wide open for roughly 200,000 installs.&lt;/p&gt;
&lt;p&gt;Sovereignty, here, isn’t about unplugging your AI. It’s about knowing what’s plugged in, granting only the strict access needed, and never loading a config you haven’t read. A local MCP server, tightly scoped, whose code you’ve read, is a tool. The same server, pulled from an unknown repo with access to your whole disk, is a vulnerability with a friendly interface.&lt;/p&gt;
&lt;p&gt;Inventory your MCPs. Cut the ones you don’t recognise. Trim the access of the ones you keep. The rest is just the good habits you already have for the rest of your machine.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Also worth reading: &lt;a href=&quot;https://macsouverain.com/en/ton-ia-peut-etre-eteinte-monte-la-tienne/&quot;&gt;Your AI can be turned off by the US, build your own&lt;/a&gt; and &lt;a href=&quot;https://macsouverain.com/en/38-apple-intelligence-ce-qui-sort-de-ton-mac/&quot;&gt;Apple Intelligence, what really leaves your Mac&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>ia</category><category>securite</category><category>mcp</category><category>macos</category><category>tutoriel</category><enclosure url="https://macsouverain.com/content/images/2026/07/feature-les-mcp-porte-derobee-de-ton-ia.png" length="0" type="image/png"/></item><item><title>Rspamd in front of your inbox, phishing stops at the doormat</title><link>https://macsouverain.com/en/rspamd-mail-siem-souverain/</link><guid isPermaLink="true">https://macsouverain.com/en/rspamd-mail-siem-souverain/</guid><description>Install Rspamd in front of your mail server, tune the anti-spam and anti-phishing scoring, and feed every verdict into your Wazuh SIEM.</description><pubDate>Thu, 16 Jul 2026 14:03:38 GMT</pubDate><content:encoded>&lt;p&gt;In the previous episode, you put &lt;a href=&quot;https://macsouverain.com/en/crowdsec-premiere-ligne-siem-souverain/&quot;&gt;CrowdSec up front&lt;/a&gt;. Your firewall now turns malicious IPs away before they touch your services, and every decision goes up into Wazuh. Your SIEM sees, and it bites.&lt;/p&gt;
&lt;p&gt;Except the attack that’s going to cost you dearly won’t come in through the SSH port.&lt;/p&gt;
&lt;p&gt;It’ll come in through an email. A fake invoice that mimics your usual supplier, a link that looks like your banking portal, an attachment your accountant will open because opening invoice attachments is her job.&lt;/p&gt;
&lt;p&gt;That email crosses your firewall without a sound, because it comes in through a door you left open yourself, port 25. CrowdSec won’t block anything, the sender has a clean IP. Wazuh won’t see anything, nobody told it to look that way.&lt;/p&gt;
&lt;p&gt;That’s the blind spot in the setup. Three bricks laid, and the number-one intrusion vector for small businesses still walks in unencrypted.&lt;/p&gt;
&lt;p&gt;Today, we plug it. We install &lt;a href=&quot;https://rspamd.com/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;strong&gt;Rspamd&lt;/strong&gt;&lt;/a&gt;, a filtering engine that slots in front of your mail server, scores every incoming message and decides its fate. Then we wire its logging into Wazuh, so that every verdict, spam blocked, phishing detected, message delivered, shows up in your single dashboard.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;before-you-begin&quot;&gt;Before you begin&lt;/h2&gt;
&lt;p&gt;Three things to keep in mind before the first command.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What you need.&lt;/strong&gt; A mail server you administer, Postfix or Exim, on a hardened server like the one from episode 1. The Wazuh manager from episode 2 in place on your VPS, and the Wazuh agent from episode 3 already installed on that mail server, for the integration part at the end of the tutorial. Administrator access, and Redis, which we’ll install alongside the engine.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What changes.&lt;/strong&gt; By the end, every incoming message is scored before it reaches your employee’s mailbox. The obvious ones are refused at the door, the doubtful ones arrive marked, phishing attempts raise an alert in your SIEM. You move from a blind inbox to an instrumented one.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What doesn’t change.&lt;/strong&gt; Rspamd filters &lt;strong&gt;incoming&lt;/strong&gt; mail. It’s not an endpoint antivirus, it’s not a replacement for your employees’ common sense, and it doesn’t protect against an account whose password has leaked, the attacker is then inside, not outside. And Rspamd isn’t infallible, it will fool you sometimes. The question isn’t whether it gets it wrong, it’s which side you set the cursor on when it does.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;rspamd-doesnt-say-yes-or-no-it-scores&quot;&gt;Rspamd doesn’t say yes or no, it scores&lt;/h2&gt;
&lt;p&gt;The point that changes everything, and that sets Rspamd apart from classic anti-spam filters.&lt;/p&gt;
&lt;p&gt;A binary filter looks at a message and rules, spam or not spam. The result is a door, open or shut, and the real world takes quick revenge on that oversimplification. A legitimate invoice with a shortened link and an attachment gets thrown out, a well-written scam gets through.&lt;/p&gt;
&lt;p&gt;Rspamd, on the other hand, &lt;strong&gt;accumulates&lt;/strong&gt;. It runs dozens of checks on the same message, each one reporting a small weight, positive or negative. Sender authentication fails, plus two points. The domain is on a reputable blacklist, plus four. The displayed URL doesn’t match the link’s real URL, plus seven. The message looks like a hundred others already flagged as spam, plus five. Conversely, the sender is properly signed and known, minus one.&lt;/p&gt;
&lt;p&gt;At the end, it gets a &lt;strong&gt;score&lt;/strong&gt;, and that score triggers an &lt;strong&gt;action&lt;/strong&gt; based on thresholds you set yourself. The recommended configuration is this one.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Score 4, &lt;code&gt;greylist&lt;/code&gt;.&lt;/strong&gt; The sending server is asked to come back later. A real mail server does it, a spam bot rarely does.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Score 6, &lt;code&gt;add header&lt;/code&gt;.&lt;/strong&gt; The message is delivered, but marked. Your mail client can file it under junk.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Score 15, &lt;code&gt;reject&lt;/code&gt;.&lt;/strong&gt; The message is refused at the door, it never comes in.&lt;/p&gt;
&lt;p&gt;Three levels of firmness, not a door. It’s the same philosophy as the SIEM in episode 2, we’re not after certainty, we’re after grading our response to an uncertain signal.&lt;/p&gt;
&lt;p&gt;On the architecture side, Rspamd runs as several specialized processes. The &lt;strong&gt;proxy worker&lt;/strong&gt; is the one that talks to your mail server, over the milter protocol, on port 11332. The &lt;strong&gt;normal worker&lt;/strong&gt; computes the score. The &lt;strong&gt;controller worker&lt;/strong&gt; serves the web interface and the learning. You’ll only need to know the first one, that’s the one we wire in.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;step-1-install-the-engine&quot;&gt;Step 1, install the engine&lt;/h2&gt;
&lt;p&gt;On the machine that hosts your mail server. The official Rspamd repository, then the package, then Redis, which Rspamd needs for its statistics, its Bayesian filter and its greylisting.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;curl&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; -fsSL&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; https://rspamd.com/apt-stable/gpg.key&lt;/span&gt;&lt;span style=&quot;color:#D73A49&quot;&gt; |&lt;/span&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt; sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; gpg&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; --dearmor&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; -o&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; /usr/share/keyrings/rspamd.gpg&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#005CC5&quot;&gt;echo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; &quot;deb [signed-by=/usr/share/keyrings/rspamd.gpg] https://rspamd.com/apt-stable/ $(&lt;/span&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;lsb_release&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; -cs&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt;) main&quot;&lt;/span&gt;&lt;span style=&quot;color:#D73A49&quot;&gt; |&lt;/span&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt; sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; tee&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; /etc/apt/sources.list.d/rspamd.list&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; apt&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; update&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; apt&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; install&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; rspamd&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; redis-server&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The &lt;code&gt;apt-stable&lt;/code&gt; repository is the production branch, the one you want on a mail server. Rspamd has been on version 4.x since March 2026.&lt;/p&gt;
&lt;p&gt;Tell it where to find Redis, in &lt;code&gt;/etc/rspamd/local.d/redis.conf&lt;/code&gt;.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;plaintext&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span&gt;servers = &quot;127.0.0.1:6379&quot;;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;A survival rule with Rspamd, and it holds for the whole tutorial. &lt;strong&gt;You never touch the files in &lt;code&gt;/etc/rspamd/&lt;/code&gt; directly.&lt;/strong&gt; You write your settings in &lt;code&gt;/etc/rspamd/local.d/&lt;/code&gt;, which is layered on top of the default configuration. A package update overwrites the first, never the second.&lt;/p&gt;
&lt;p&gt;Then set a password for the web interface.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;rspamadm&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; pw&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;It hands you a hash that you copy into &lt;code&gt;/etc/rspamd/local.d/worker-controller.inc&lt;/code&gt;.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;plaintext&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span&gt;password = &quot;$2$your_hash_here&quot;;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The interface listens on port 11334, locally only. &lt;strong&gt;Leave it that way.&lt;/strong&gt; The series’ doctrine since episode 1, nothing needless on the open internet, you reach it through your Tailnet or an SSH tunnel.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;step-2-wire-it-in-front-of-your-mail-server&quot;&gt;Step 2, wire it in front of your mail server&lt;/h2&gt;
&lt;p&gt;Rspamd is running, but no message is being handed to it. Your mail server has to submit every incoming email to it before accepting it.&lt;/p&gt;
&lt;p&gt;The mechanism is called &lt;strong&gt;milter&lt;/strong&gt;, for mail filter. Your mail server pauses the message during the SMTP transaction, hands it to Rspamd, waits for the verdict, and acts accordingly. The message is judged &lt;strong&gt;before&lt;/strong&gt; being accepted, that’s the whole difference with a filter that sorts after the fact in the mailbox.&lt;/p&gt;
&lt;p&gt;On Postfix, three lines in &lt;code&gt;/etc/postfix/main.cf&lt;/code&gt;.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;plaintext&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span&gt;smtpd_milters = inet:localhost:11332&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;milter_protocol = 6&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;milter_default_action = accept&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The line that deserves your attention is the third. &lt;code&gt;accept&lt;/code&gt; means that &lt;strong&gt;if Rspamd is down, mail passes without filtering&lt;/strong&gt;. You favor service continuity. The other value commonly chosen is &lt;code&gt;tempfail&lt;/code&gt;, which asks the sender to come back later, your mail is protected even with Rspamd down, but a prolonged outage turns into a mail incident. Choose knowingly. For a small business, &lt;code&gt;accept&lt;/code&gt; is the reasonable default, provided you monitor the Rspamd service in your SIEM.&lt;/p&gt;
&lt;p&gt;On Exim, the wiring goes through the normal worker over HTTP, not through the milter.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;plaintext&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span&gt;spamd_address = 127.0.0.1 11333 variant=rspamd&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Reload your mail server, and send yourself a message from an outside address. Rspamd starts scoring.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;step-3-set-the-thresholds-and-arm-the-anti-phishing&quot;&gt;Step 3, set the thresholds and arm the anti-phishing&lt;/h2&gt;
&lt;p&gt;The thresholds first, in &lt;code&gt;/etc/rspamd/local.d/actions.conf&lt;/code&gt;.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;plaintext&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span&gt;greylist = 4;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;add_header = 6;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;reject = 15;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;These are the recommended values, and they’re deliberately lenient. A &lt;code&gt;reject&lt;/code&gt; at 15 means it takes a massive accumulation of negative signals for a message to be refused. That’s what you want at the start, you tighten later, once you’ve read your own logs.&lt;/p&gt;
&lt;p&gt;Sender authentication next. Three modules active by default, &lt;strong&gt;SPF&lt;/strong&gt; (Sender Policy Framework), &lt;strong&gt;DKIM&lt;/strong&gt; (DomainKeys Identified Mail) and &lt;strong&gt;DMARC&lt;/strong&gt; (Domain-based Message Authentication, Reporting and Conformance). They check three things, that the sending server is allowed to send for that domain, that the message’s cryptographic signature is valid, and that the domain shown in the “From” field is indeed the one that’s authenticated. An email claiming to come from your bank and failing all three is exposed without needing to read a single line of its content.&lt;/p&gt;
&lt;p&gt;By default, Rspamd scores these failures but doesn’t apply the policy published by the sending domain. To make it apply that policy, in &lt;code&gt;/etc/rspamd/local.d/dmarc.conf&lt;/code&gt;.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;plaintext&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span&gt;actions {&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;  quarantine = &quot;add header&quot;;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;  reject = &quot;reject&quot;;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;}&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;You now obey what the real domain owner asked the world to do with messages that impersonate it. It’s free, it’s immediate, and it eliminates a whole family of fake senders.&lt;/p&gt;
&lt;p&gt;The &lt;strong&gt;phishing&lt;/strong&gt; module last, the heart of the matter. Its basic check is already active, it compares the URL displayed in the link text to the link’s real destination URL, and raises the &lt;code&gt;PHISHED_URL&lt;/code&gt; symbol when the two domains diverge. That’s exactly the mechanism of the fake banking link.&lt;/p&gt;
&lt;p&gt;You can back it with two public databases of known phishing URLs, in &lt;code&gt;/etc/rspamd/local.d/phishing.conf&lt;/code&gt;.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;plaintext&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span&gt;openphish_enabled = true;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;openphish_map = &quot;https://raw.githubusercontent.com/openphish/public_feed/refs/heads/main/feed.txt&quot;;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;phishtank_enabled = true;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;No &lt;code&gt;phishing { }&lt;/code&gt; block around it, and it’s the &lt;code&gt;local.d&lt;/code&gt; rule from step 1 that applies. Rspamd already includes this file &lt;strong&gt;inside&lt;/strong&gt; the module’s section, you write only the content. Add the block, and you get a section inside a section, silently ignored, no error at startup and no feed activated.&lt;/p&gt;
&lt;p&gt;A message containing a URL already flagged elsewhere in the world raises &lt;code&gt;PHISHED_OPENPHISH&lt;/code&gt; or &lt;code&gt;PHISHED_PHISHTANK&lt;/code&gt;, with a heavy weight. CrowdSec’s community logic, transposed to malicious links.&lt;/p&gt;
&lt;p&gt;Three other modules work for you without you configuring them. &lt;strong&gt;rbl&lt;/strong&gt; queries the public blacklists of sending servers. &lt;strong&gt;fuzzy_check&lt;/strong&gt; compares the message’s fingerprint to that of spam already flagged by the Rspamd network, a reworded spam keeps a close fingerprint. &lt;strong&gt;bayes&lt;/strong&gt; learns from your own messages, provided you train it.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;plaintext&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span&gt;autolearn = true;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;in &lt;code&gt;/etc/rspamd/local.d/classifier-bayes.conf&lt;/code&gt;, and Rspamd learns on its own from the messages it classified with certainty. You can also correct it by hand when it gets it wrong, with &lt;code&gt;rspamc learn_spam&lt;/code&gt; on a message that slipped through, or &lt;code&gt;rspamc learn_ham&lt;/code&gt; on a legitimate one it wrongly marked.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;step-4-put-it-to-the-test&quot;&gt;Step 4, put it to the test&lt;/h2&gt;
&lt;p&gt;Rather than wait for a real spam, you make one.&lt;/p&gt;
&lt;p&gt;There’s a standard string for that, the &lt;strong&gt;GTUBE&lt;/strong&gt;, recognized by every serious anti-spam engine and designed to trigger a certain rejection without being real spam. You write it into a test message, and you submit it to the engine with &lt;code&gt;rspamc&lt;/code&gt;, the command-line client.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#005CC5&quot;&gt;printf&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; &apos;Subject: test\n\nXJS*C4JDBQADN1.NSBN3*2IDNEN*GTUBE-STANDARD-ANTI-UBE-TEST-EMAIL*C.34X\n&apos;&lt;/span&gt;&lt;span style=&quot;color:#D73A49&quot;&gt; &gt;&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; /tmp/gtube.eml&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;rspamc&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; symbols&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; /tmp/gtube.eml&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;You should see the &lt;code&gt;GTUBE&lt;/code&gt; symbol and the &lt;code&gt;reject&lt;/code&gt; action. The GTUBE short-circuits the score computation and forces the rejection directly, that’s the whole point of the test. If you get it, the engine is running, it scores and it rules. You get something like this.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;plaintext&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span&gt;Results for file: /tmp/gtube.eml (0.014 seconds)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;[Metric: default]&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;Action: reject&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;Spam: true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;Symbol: GTUBE (0.00)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;Message-ID: undef&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;No need for a score that blows past the threshold, the &lt;code&gt;GTUBE&lt;/code&gt; symbol triggers a passthrough that forces the &lt;code&gt;reject&lt;/code&gt; action whatever the total. That’s the expected behavior, your engine does apply the verdict.&lt;/p&gt;
&lt;p&gt;Two check commands for later.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;rspamc&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; stat&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;It gives you the engine’s state, the messages scanned, the breakdown by action, the state of the Bayesian filter.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;rspamc&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; symbols&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; /path/to/a/real/message.eml&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;It replays a real message and shows you the detail of the symbols with their weight. It’s your diagnostic tool when a message got through that shouldn’t have, or the reverse. You don’t guess, you read the tally line.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;step-5-feed-rspamd-into-wazuh&quot;&gt;Step 5, feed Rspamd into Wazuh&lt;/h2&gt;
&lt;p&gt;Rspamd filters, very good. Your SIEM still doesn’t know it. We wire them together, and the series’ loop closes on mail.&lt;/p&gt;
&lt;p&gt;Nothing to enable on the Rspamd side. It already writes, by default, one line per processed message in &lt;code&gt;/var/log/rspamd/rspamd.log&lt;/code&gt;. A persistent file, on disk, exactly what Wazuh needs. A line looks like this.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;plaintext&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span&gt;2026-07-14 09:41:07 #3421(rspamd_proxy) &amp;#x3C;7f2c1a&gt;; task; rspamd_task_write_log: id: &amp;#x3C;a1b2@evil.example&gt;, qid: &amp;#x3C;4XjK2r1Yz&gt;, ip: 203.0.113.42, from: &amp;#x3C;facturation@evil.example&gt;, (default: T (reject): [16.40/15.00] [PHISHED_URL,DMARC_POLICY_REJECT,R_SPF_FAIL,BAYES_SPAM]), len: 4021, time: 128.4ms real, dns req: 22&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;It’s all there. The sender’s IP, its address, the action taken, the score obtained against the threshold, and the full list of the symbols that brought it down. It’s an investigation report per message.&lt;/p&gt;
&lt;p&gt;The wiring happens on &lt;strong&gt;two machines&lt;/strong&gt;, and that’s the point where you trip up if you go too fast. The Wazuh agent, on your mail server, understands nothing of what it reads, it ships the raw lines. It’s the &lt;strong&gt;manager&lt;/strong&gt;, on the VPS from episode 2, that decodes and applies the rules. One machine collects, the other understands.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;On the mail server&lt;/strong&gt;, you tell the agent to read the file. The block goes in its &lt;code&gt;ossec.conf&lt;/code&gt;.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;xml&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;localfile&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;  &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;location&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;/var/log/rspamd/rspamd.log&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;location&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;  &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;log_format&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;syslog&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;log_format&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;localfile&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;You recognize the &lt;code&gt;&amp;#x3C;localfile&gt;&lt;/code&gt; from episode 3, the mechanism by which Wazuh swallows any log source.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;On the manager&lt;/strong&gt;, now, and on it alone. A &lt;strong&gt;decoder&lt;/strong&gt; extracts the useful fields from the line, in &lt;code&gt;/var/ossec/etc/decoders/local_decoder.xml&lt;/code&gt;.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;xml&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;decoder&lt;/span&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt; name&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt;&quot;rspamd&quot;&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;  &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;prematch&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;rspamd_task_write_log: &amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;prematch&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;decoder&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;decoder&lt;/span&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt; name&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt;&quot;rspamd-verdict&quot;&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;  &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;parent&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;rspamd&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;parent&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;  &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;regex&lt;/span&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt; type&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt;&quot;pcre2&quot;&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;ip: (\S+?), .*?\(default: \S+ \(([\w ]+)\): \[(-?\d+\.\d+)/&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;regex&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;  &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;order&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;srcip, rspamd_action, rspamd_score&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;order&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;decoder&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Then &lt;strong&gt;rules&lt;/strong&gt; that turn those fields into graded alerts, in &lt;code&gt;/var/ossec/etc/rules/local_rules.xml&lt;/code&gt;, still on the manager.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;xml&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;group&lt;/span&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt; name&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt;&quot;rspamd,&quot;&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;  &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;rule&lt;/span&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt; id&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt;&quot;100400&quot;&lt;/span&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt; level&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt;&quot;0&quot;&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;    &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;decoded_as&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;rspamd&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;decoded_as&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;    &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;description&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;Rspamd, scan verdict.&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;description&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;  &amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;rule&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;  &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;rule&lt;/span&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt; id&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt;&quot;100401&quot;&lt;/span&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt; level&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt;&quot;12&quot;&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;    &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;if_sid&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;100400&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;if_sid&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;    &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;match&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;PHISHED_&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;match&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;    &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;description&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;Rspamd, phishing detected, sender $(srcip).&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;description&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;  &amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;rule&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;  &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;rule&lt;/span&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt; id&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt;&quot;100402&quot;&lt;/span&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt; level&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt;&quot;10&quot;&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;    &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;if_sid&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;100400&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;if_sid&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;    &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;field&lt;/span&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt; name&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt;&quot;rspamd_action&quot;&lt;/span&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt; type&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt;&quot;pcre2&quot;&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;^reject$&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;field&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;    &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;description&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;Rspamd, message rejected, sender $(srcip).&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;description&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;  &amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;rule&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;  &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;rule&lt;/span&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt; id&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt;&quot;100403&quot;&lt;/span&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt; level&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt;&quot;5&quot;&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;    &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;if_sid&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;100400&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;if_sid&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;    &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;field&lt;/span&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt; name&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt;&quot;rspamd_action&quot;&lt;/span&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt; type&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt;&quot;pcre2&quot;&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;^add header$&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;field&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;    &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;description&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;Rspamd, message marked as spam and delivered, sender $(srcip).&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;description&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;  &amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;rule&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;group&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The order of declaration isn’t cosmetic, it’s the heart of the tuning. The parent rule is at level 0, it decodes without alerting, otherwise your dashboard drowns under legitimate messages. &lt;strong&gt;Phishing goes first, at level 12&lt;/strong&gt;, because Wazuh fires only one rule per message, the first in the list that matches. A phishing fake invoice is also a rejected message, and if you declare the rejection before it, it comes out at level 10 and the alert you were waiting for never comes. Then the rejection at 10, and the marked-but-delivered spam at 5.&lt;/p&gt;
&lt;p&gt;Same logic on the anchoring. &lt;code&gt;^reject$&lt;/code&gt; and not &lt;code&gt;reject&lt;/code&gt;, because Rspamd also has a &lt;code&gt;soft reject&lt;/code&gt; action, a mere temporary deferral, which contains the word and would trigger a rejection alert for a message that’s nothing of the sort.&lt;/p&gt;
&lt;p&gt;Don’t take this decoder on faith, test it. Wazuh has the right tool, and it lives on the manager, not on the agent.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; /var/ossec/bin/wazuh-logtest&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;You paste a real line from your &lt;code&gt;rspamd.log&lt;/code&gt;, and it shows you what it made of it, phase by phase, decoder recognized, fields extracted, rule triggered. If &lt;code&gt;srcip&lt;/code&gt; and &lt;code&gt;rspamd_action&lt;/code&gt; don’t come out, it’s the extraction pattern that needs adjusting, and you’ll know in thirty seconds instead of waiting in vain for an alert that will never come. Take a rejected-phishing line for your test, it’s the case that stresses the order of your rules. On the example line above, you’re aiming for a result of this shape.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;plaintext&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span&gt;**Phase 1: Completed pre-decoding.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;	full event: &apos;2026-07-14 09:41:07 #3421(rspamd_proxy) &amp;#x3C;7f2c1a&gt;; task; rspamd_task_write_log: id: &amp;#x3C;a1b2@evil.example&gt;, qid: &amp;#x3C;4XjK2r1Yz&gt;, ip: 203.0.113.42, from: &amp;#x3C;facturation@evil.example&gt;, (default: T (reject): [16.40/15.00] [PHISHED_URL,DMARC_POLICY_REJECT,R_SPF_FAIL,BAYES_SPAM]), len: 4021, time: 128.4ms real, dns req: 22&apos;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;**Phase 2: Completed decoding.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;	name: &apos;rspamd&apos;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;	srcip: &apos;203.0.113.42&apos;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;	rspamd_action: &apos;reject&apos;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;	rspamd_score: &apos;16.40&apos;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;**Phase 3: Completed filtering (rules).&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;	id: &apos;100401&apos;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;	level: &apos;12&apos;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;	description: &apos;Rspamd, phishing detected, sender 203.0.113.42.&apos;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;	groups: &apos;[&apos;rspamd&apos;]&apos;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;	firedtimes: 1&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;	mail: false&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;**Alert to be generated.&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Phase 2 yields your three fields, phase 3 fires rule &lt;code&gt;100401&lt;/code&gt; at level 12, that’s the phishing alert you were waiting for. Don’t take this block for a capture ripped from a production machine, it’s the intended result, not a prod reading. The &lt;code&gt;syslog&lt;/code&gt; pre-decoding applied to an Rspamd line that doesn’t have the shape of a syslog log, and the decoder’s extraction pattern, can vary depending on your Wazuh version and the exact format of your &lt;code&gt;rspamd.log&lt;/code&gt; lines. That’s precisely what &lt;code&gt;wazuh-logtest&lt;/code&gt; confirms on your own machine, phase by phase, before you count on the alert.&lt;/p&gt;
&lt;p&gt;Once the test is conclusive, restart both services, each on its own machine. The manager, so it loads your decoder and your rules.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; systemctl&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; restart&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; wazuh-manager&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;And the mail server’s agent, so it takes its &lt;code&gt;&amp;#x3C;localfile&gt;&lt;/code&gt; into account.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; systemctl&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; restart&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; wazuh-agent&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;An IP sends a fake invoice, Rspamd scores it, rejects it, writes it to its log, the Wazuh agent reads it and ships it, the manager decodes it and raises a level-12 alert, it shows up in your dashboard next to your CrowdSec blocks and your SSH authentication failures. In Discover, you filter it on the &lt;code&gt;srcip&lt;/code&gt;, &lt;code&gt;rspamd_action&lt;/code&gt; and &lt;code&gt;rspamd_score&lt;/code&gt; fields, exactly like the rest of your events.&lt;/p&gt;
&lt;p&gt;The blind spot is plugged.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;if-it-doesnt-work&quot;&gt;If it doesn’t work&lt;/h2&gt;
&lt;h3 id=&quot;problem-rspamd-is-running-but-no-message-gets-scored&quot;&gt;Problem, Rspamd is running but no message gets scored&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Likely cause,&lt;/strong&gt; the milter isn’t wired in. Rspamd is waiting on its port, your mail server hands it nothing.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Fix,&lt;/strong&gt; check that the proxy worker is indeed listening on 11332, and that &lt;code&gt;smtpd_milters&lt;/code&gt; points to it in your Postfix configuration. Reload the mail server, not just Rspamd.&lt;/p&gt;
&lt;h3 id=&quot;problem-legitimate-messages-are-rejected&quot;&gt;Problem, legitimate messages are rejected&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Likely cause,&lt;/strong&gt; your rejection threshold is too low, or a sender you know fails its own SPF, which happens more often than people think.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Fix,&lt;/strong&gt; replay the message with &lt;code&gt;rspamc symbols&lt;/code&gt;, read the symbols that pushed it up. If the culprit is a single, legitimate symbol, raise your &lt;code&gt;reject&lt;/code&gt; threshold rather than disabling the module.&lt;/p&gt;
&lt;h3 id=&quot;problem-the-score-learns-nothing-the-bayesian-filter-stays-mute&quot;&gt;Problem, the score learns nothing, the Bayesian filter stays mute&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Likely cause,&lt;/strong&gt; Redis is unreachable. Without it, no bayes, no greylisting, no statistics.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Fix,&lt;/strong&gt; check the Redis service and the contents of &lt;code&gt;/etc/rspamd/local.d/redis.conf&lt;/code&gt;. &lt;code&gt;rspamc stat&lt;/code&gt; will tell you whether the classifier has data.&lt;/p&gt;
&lt;h3 id=&quot;problem-nothing-goes-up-into-wazuh&quot;&gt;Problem, nothing goes up into Wazuh&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Likely cause,&lt;/strong&gt; three suspects, and you have to sort them out before touching anything. Either the file isn’t growing, or the agent isn’t reading it, or the manager doesn’t know how to decode it. The great classic, the decoder and rules edited on the mail server instead of the manager. There, they’re useless.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Fix,&lt;/strong&gt; is the file growing? If it’s growing, go to the &lt;strong&gt;manager&lt;/strong&gt;, run a line through &lt;code&gt;wazuh-logtest&lt;/code&gt; and see at which phase it breaks. Check while you’re at it that &lt;code&gt;local_decoder.xml&lt;/code&gt; and &lt;code&gt;local_rules.xml&lt;/code&gt; are indeed on that machine, and that you restarted &lt;code&gt;wazuh-manager&lt;/code&gt; after writing them. Don’t reinstall Rspamd over an extraction-pattern issue.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;what-it-cost-you&quot;&gt;What it cost you&lt;/h2&gt;
&lt;p&gt;The license, nothing. Rspamd is open source, no paid version, no enterprise tier, no message quota.&lt;/p&gt;
&lt;p&gt;The machine, little. The engine is written in C and runs on your existing mail server, alongside Redis. At a small business’s volume, you won’t change server size for this. Keep an eye on your RAM anyway after enabling the Bayesian filter and fuzzy_check, they’re the ones that consume.&lt;/p&gt;
&lt;p&gt;Your time, a bit. Count a short hour for the installation, the milter and the Wazuh integration.&lt;/p&gt;
&lt;p&gt;And the real price, the calibration. It isn’t paid on installation day, it’s paid over the following two weeks, reading your own logs and raising your thresholds when a legitimate message got thrown out. A badly tuned anti-spam doesn’t cost you RAM, it costs you a customer order lost in a silent rejection. That’s the reason this tutorial starts you off lenient, at a rejection threshold of 15, and tightens afterward. The other way around, you learn the value of a false positive the hard way.&lt;/p&gt;
&lt;p&gt;It’s the only serious spending line, and no SaaS spares you it. It too will get it wrong, you just won’t see why.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;for-those-in-a-hurry&quot;&gt;For those in a hurry&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;What this article does.&lt;/strong&gt; We install Rspamd on the mail server, wire it in as a milter in front of Postfix, set the scoring thresholds, enable the anti-phishing and the enforcement of DMARC policies, then feed every verdict into Wazuh via a homemade decoder and rules. The mail layer stops being the SIEM’s blind spot.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Concretely, the commands.&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Install the stable repository, &lt;code&gt;rspamd&lt;/code&gt; and &lt;code&gt;redis-server&lt;/code&gt; via apt.&lt;/li&gt;
&lt;li&gt;Point to Redis: &lt;code&gt;servers = &quot;127.0.0.1:6379&quot;;&lt;/code&gt; in &lt;code&gt;/etc/rspamd/local.d/redis.conf&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Interface password: &lt;code&gt;rspamadm pw&lt;/code&gt;, hash in &lt;code&gt;/etc/rspamd/local.d/worker-controller.inc&lt;/code&gt;. Interface locally only.&lt;/li&gt;
&lt;li&gt;Wire in the Postfix milter: &lt;code&gt;smtpd_milters = inet:localhost:11332&lt;/code&gt;, &lt;code&gt;milter_protocol = 6&lt;/code&gt;, &lt;code&gt;milter_default_action = accept&lt;/code&gt; in &lt;code&gt;main.cf&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Thresholds: &lt;code&gt;greylist = 4; add_header = 6; reject = 15;&lt;/code&gt; in &lt;code&gt;/etc/rspamd/local.d/actions.conf&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Enforce DMARC: &lt;code&gt;actions { quarantine = &quot;add header&quot;; reject = &quot;reject&quot;; }&lt;/code&gt; block in &lt;code&gt;/etc/rspamd/local.d/dmarc.conf&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Anti-phishing: &lt;code&gt;openphish_enabled&lt;/code&gt; and &lt;code&gt;phishtank_enabled&lt;/code&gt; in &lt;code&gt;/etc/rspamd/local.d/phishing.conf&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Learning: &lt;code&gt;autolearn = true;&lt;/code&gt; in &lt;code&gt;/etc/rspamd/local.d/classifier-bayes.conf&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Test: GTUBE message then &lt;code&gt;rspamc symbols /tmp/gtube.eml&lt;/code&gt;, expected action &lt;code&gt;reject&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Integrate into Wazuh, on two machines: &lt;code&gt;&amp;#x3C;localfile&gt;&lt;/code&gt; on &lt;code&gt;/var/log/rspamd/rspamd.log&lt;/code&gt; &lt;strong&gt;on the agent side&lt;/strong&gt;, decoder and rules &lt;strong&gt;on the manager side&lt;/strong&gt; (&lt;code&gt;local_decoder.xml&lt;/code&gt; and &lt;code&gt;local_rules.xml&lt;/code&gt;, phishing rule declared first), validation with &lt;code&gt;/var/ossec/bin/wazuh-logtest&lt;/code&gt; &lt;strong&gt;on the manager&lt;/strong&gt;, then a restart of &lt;code&gt;wazuh-manager&lt;/code&gt; and &lt;code&gt;wazuh-agent&lt;/code&gt;.&lt;/li&gt;
&lt;/ol&gt;
&lt;hr&gt;
&lt;h2 id=&quot;in-short&quot;&gt;In short&lt;/h2&gt;
&lt;p&gt;You started from a setup that saw your servers and blocked your network, but let the fake invoice walk in through the front door.&lt;/p&gt;
&lt;p&gt;You &lt;strong&gt;installed Rspamd&lt;/strong&gt; in front of your mail server, as a milter, so that every message is judged before being accepted. You &lt;strong&gt;tuned the scoring&lt;/strong&gt; rather than a binary verdict, three levels of firmness, greylist, marking, rejection, with thresholds you control.&lt;/p&gt;
&lt;p&gt;You &lt;strong&gt;armed the anti-phishing&lt;/strong&gt;, comparison of displayed and real URLs, public databases of malicious links, enforcement of the DMARC policies of impersonated domains. And you &lt;strong&gt;wired all of it into Wazuh&lt;/strong&gt;, decoder and graded rules, so that a phishing attempt raises a level-12 alert in the same dashboard as the rest.&lt;/p&gt;
&lt;p&gt;The whole thing stays with you. No message leaves your server to be analyzed elsewhere, no provider reads your mail to tell you whether it’s clean. That’s the difference between a filter you host yourself and a mail gateway in someone else’s cloud, to whom you hand your entire company correspondence so they can protect it.&lt;/p&gt;
&lt;p&gt;One entry door remains, and it’s the one that sits in your employees’ hands. The file downloaded without a second thought, the macro that got authorized, the binary that should never have started. In episode 6 we go down onto the Macs, and we fix the problem by deciding which applications are allowed to run.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;series-recap&quot;&gt;Series recap&lt;/h2&gt;
&lt;p&gt;Seven episodes to build your sovereign security plumbing, brick by brick.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/nis2-splunk-pourquoi-pme-siem-souverain/&quot;&gt;Episode 0, the bedrock of the series.&lt;/a&gt;&lt;/strong&gt; Why an SME needs a sovereign SIEM, NIS2, GDPR, and the cost of doing nothing.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/vps-durci-socle-siem-souverain/&quot;&gt;Episode 1, the foundation.&lt;/a&gt;&lt;/strong&gt; The hardened VPS beyond the CLOUD Act.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/wazuh-tout-en-un-siem-souverain/&quot;&gt;Episode 2, Wazuh all-in-one.&lt;/a&gt;&lt;/strong&gt; Manager, indexer and dashboard on a single node.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/wazuh-agents-parc-siem-souverain/&quot;&gt;Episode 3, agents everywhere.&lt;/a&gt;&lt;/strong&gt; Deployment across your servers, Macs and Windows.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/crowdsec-premiere-ligne-siem-souverain/&quot;&gt;Episode 4, community network defense.&lt;/a&gt;&lt;/strong&gt; Blocking known attackers before they arrive.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Episode 5, the mail filter.&lt;/strong&gt; Anti-spam and anti-phishing in front of your mail server. You’ve just read it.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Episode 6, execution control on Macs.&lt;/strong&gt; Deciding which applications are allowed to start.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Episode 7, alerting and total cost.&lt;/strong&gt; Calibrated notifications and an honest financial reckoning against SaaS.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;em&gt;Technical terms? &lt;a href=&quot;https://macsouverain.com/en/glossaire/&quot;&gt;Check the glossary.&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>ms-pro</category><category>nis2</category><category>siem</category><category>rspamd</category><category>securite</category><category>tutoriel</category><enclosure url="https://macsouverain.com/content/images/2026/07/feature-rspamd-mail-siem-souverain-1.png" length="0" type="image/png"/></item><item><title>Apple-notarized malware slips past Gatekeeper</title><link>https://macsouverain.com/en/radar-crashstealer-notarise-apple-gatekeeper/</link><guid isPermaLink="true">https://macsouverain.com/en/radar-crashstealer-notarise-apple-gatekeeper/</guid><description>CrashStealer, signed and notarized by Apple, clears Gatekeeper without a single alert. Notarization validates the signature, not the intent.</description><pubDate>Thu, 16 Jul 2026 13:56:37 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;CrashStealer, a macOS infostealer disguised as an Apple crash-reporting tool, clears Gatekeeper without the slightest alert. It&apos;s signed by a valid Developer ID and notarized by Apple. Your Mac trusts the signature, not the intent behind it. Apple revoked the certificate after the fact, once the damage was done.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;What you should do&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Any app or DMG from outside the App Store received by invitation or direct link, the Apple signature doesn&apos;t redeem the provenance.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; A prompt asking for your login password &quot;to continue&quot; with no legitimate install underway is a red flag.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Unexpected outbound connections, an application firewall like Little Snitch or LuLu sees them go out.&lt;/p&gt;
&lt;/div&gt;
&lt;blockquote&gt;
&lt;p&gt;A piece of malware disguises itself as an Apple crash-reporting tool. It’s signed by a valid Developer ID and notarized by Apple itself. The result, it clears Gatekeeper without the slightest warning, because your Mac checks the signature, never the intent.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;br&gt;
&lt;h2 id=&quot;the-fact&quot;&gt;The fact&lt;/h2&gt;
&lt;br&gt;
&lt;p&gt;Jamf Threat Labs spotted a suspicious sample on VirusTotal in early May 2026, then observed real infections on client Macs in early July. The malware is called CrashStealer. A rare trait, it’s written in native C++, where the vast majority of macOS stealers cobble something together in AppleScript. It poses as an Apple crash-reporting tool, the kind of window you’ve seen a hundred times without paying attention.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;The delivery is polished. The malware arrives in a disk image named “Werkbit,” and the app inside is called “Werkbit.app.” Notably, the DMG itself is signed, not just the app it contains. The certificate, a Developer ID under the name “Emil Grigorov” (WWB7JA7AQV), valid, active, notarized by Apple. The distribution domain, &lt;code&gt;werkbit[.]io&lt;/code&gt;, was registered in June 2026, and the download is locked behind a meeting PIN code. Translation, the installer is served only to chosen victims, never to automated scanners or the passing visitor.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;Once launched, the dropper pulls the real payload from the attacker’s infrastructure. Before harvesting anything, it shows you a fake system prompt and validates your session password locally. Then it drains everything, browser profiles, the Keychain, fourteen password managers (1Password, Bitwarden, LastPass, Dashlane, Keeper included) and close to eighty crypto wallet extensions. The loot is encrypted with AES-GCM then exfiltrated over libcurl. It copies and re-signs itself to persist.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;Apple revoked the signing certificate after Jamf’s report. The damage was already done for those who had clicked.&lt;/p&gt;
&lt;br&gt;
&lt;h2 id=&quot;why-gatekeeper-saw-nothing&quot;&gt;Why Gatekeeper saw nothing&lt;/h2&gt;
&lt;br&gt;
&lt;p&gt;Here’s the knot. Apple notarization is not a security audit. It’s an automated scan that looks for signatures of already-known malware and checks that the binary is signed by a valid Developer ID. Nothing more. Apple didn’t read CrashStealer’s code, it didn’t judge its intent, it passed a binary that was clean at scan time through a grinder that saw nothing familiar.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;The notarization stamp says one thing, “this file is signed by an identified developer and matches no known malware.” It doesn’t say “this software is safe.” The nuance sounds theoretical. It’s the whole point.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;An attacker who opens an Apple Developer account for 99 dollars a year, under a credible identity, gets a pass to clear Gatekeeper in silence. Apple’s kill-switch, revoking the certificate, only kicks in after the fact, once the damage is documented. Apple pushes its defenses silently, it doesn’t warn you when it has let something through. It’s a firefighter, not a guard.&lt;/p&gt;
&lt;br&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read more: &lt;a href=&quot;https://macsouverain.com/en/ton-mac-patche-a-ton-insu-xprotect/&quot;&gt;Your Mac got patched by XProtect without you knowing&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;br&gt;
&lt;h2 id=&quot;what-it-changes-for-you&quot;&gt;What it changes for you&lt;/h2&gt;
&lt;br&gt;
&lt;p&gt;The collective reflex, “it’s Apple-signed, so it’s fine,” just took a bullet. Your Mac trusts the signature, not the intent behind it. A notarized binary is not a blessed binary. It’s a binary whose declared author is known, useful for going after them afterward, useless for sparing you the infection.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;The meeting-PIN targeting also changes the game. This malware isn’t trawled off a warez forum. It comes by invitation, in a context that looks professional, served to you and not to a scanner. The old reflex “I only download known stuff” no longer holds when the link is handed to you personally.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;The real line of defense isn’t the Apple stamp. It’s you, your suspicion, and a tool that sees what the software actually does once it’s launched, its outbound connections.&lt;/p&gt;
&lt;br&gt;
&lt;h2 id=&quot;what-you-do-now&quot;&gt;What you do now&lt;/h2&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Treat any app or DMG received outside the App Store as suspect by default, especially when it arrives by invitation, direct link, or an “install this for the meeting” message. The Apple signature doesn’t redeem a dubious provenance. If you didn’t go looking for it yourself, you don’t install it.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; A genuine macOS system prompt doesn’t ask again for your admin password without a clear reason. A freshly launched app that demands your login password “to continue,” with no legitimate install underway, is a red flag, not a formality. You close it, you type nothing.&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Install an application firewall and let it speak. Little Snitch or LuLu show you the unexpected outbound connections, exactly the moment a stealer sets off to exfiltrate your loot. It’s your surveillance camera on what the system does behind your back.&lt;/p&gt;
&lt;br&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read more: &lt;a href=&quot;https://macsouverain.com/en/little-snitch-vs-lulu-pare-feu-sortant-mac/&quot;&gt;Little Snitch vs LuLu, which outbound firewall for your Mac&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;br&gt;
&lt;p&gt;And if you have the slightest doubt you ran a dubious installer recently, the drill already exists, it’s the same as for infostealers spread through social engineering.&lt;/p&gt;
&lt;br&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read more: &lt;a href=&quot;https://macsouverain.com/en/radar-macsync-google-ads-claude-share-mai-2026/&quot;&gt;Google Ads and a real shared Claude chat drain your credentials&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;br&gt;
&lt;h2 id=&quot;sources&quot;&gt;Sources&lt;/h2&gt;
&lt;br&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.jamf.com/blog/crashstealer-macos-infostealer-analysis/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://www.jamf.com/blog/crashstealer-macos-infostealer-analysis/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://thehackernews.com/2026/07/crashstealer-macos-malware-uses.html&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://thehackernews.com/2026/07/crashstealer-macos-malware-uses.html&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.itnews.com.au/news/apple-notarised-crashstealer-malware-poses-as-macos-crash-reporting-app-627340&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://www.itnews.com.au/news/apple-notarised-crashstealer-malware-poses-as-macos-crash-reporting-app-627340&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://9to5mac.com/2026/07/15/psa-beware-of-fake-mac-crash-reports-out-to-steal-your-passwords-crypto-wallets-more/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://9to5mac.com/2026/07/15/psa-beware-of-fake-mac-crash-reports-out-to-steal-your-passwords-crypto-wallets-more/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-alerte</category><category>mac-malware</category><category>gatekeeper</category><category>notarisation</category><category>infostealer</category><category>cybersec</category></item><item><title>Chat Control 1.0: Adopted by Those Who Voted Against</title><link>https://macsouverain.com/en/radar-chat-control-1-adopte-par-defaut/</link><guid isPermaLink="true">https://macsouverain.com/en/radar-chat-control-1-adopte-par-defaut/</guid><description>On July 9th, the European Parliament allowed Chat Control 1.0 to be renewed, falling short of the 361 votes needed to block it, despite a majority voting against. What this means, and what&apos;s heading back to trilogue in September.</description><pubDate>Sun, 12 Jul 2026 09:33:42 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;&lt;strong&gt;On July 9th, 2026, the European Parliament let Chat Control 1.0 (voluntary CSAM scanning, EU Regulation 2021/1232) slip through. Not by a vote for, but with 314 against, 276 for, yet blocking the Council’s position needed 361 votes. The majority voted no, but the text passed anyway. End-to-end encryption is explicitly excluded from this text. The real fight, Chat Control 2.0 (CSAR), resumes in September.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What you need to watch out for&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; CSAR (Chat Control 2.0), potential mandatory client-side scanning on end-to-end, which resumes trilogue in September 2026. That’s the only date that matters.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; The method: a text rejected by the majority of voters that passes due to lack of an absolute majority to block it. Remember the mechanism, it’ll come back.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Viral posts claiming WhatsApp and Signal are now being scanned. That’s false for 1.0, end-to-end is excluded. Don’t spread the panic.&lt;/p&gt;
&lt;/div&gt;
&lt;h2 id=&quot;what-happened-on-july-9th&quot;&gt;What Happened on July 9th&lt;/h2&gt;
&lt;p&gt;On July 9th, 2026, the European Parliament renewed &lt;strong&gt;Chat Control 1.0&lt;/strong&gt;, i.e., Regulation (EU) 2021/1232: an exemption to the ePrivacy directive that allows providers to voluntarily scan communications for child sexual abuse material (CSAM). This text had expired on April 3rd, 2026. It’s been renewed, in effect until &lt;strong&gt;April 3rd, 2028&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;The detail that matters: it wasn’t adopted by a yes vote. The count was &lt;strong&gt;314 against, 276 for, 17 abstentions&lt;/strong&gt;. The majority of voters said no. But to reject the Council’s position, you needed an &lt;strong&gt;absolute majority of 361 votes&lt;/strong&gt;, which was missed by 47. Result: the text passes due to lack of blocking. Patrick Breyer calls it a democratic farce, and on this point, he’s not entirely wrong.&lt;/p&gt;
&lt;p&gt;Second detail, denounced by several MEPs: the dossier was rescheduled at the very start of the parliamentary holidays, when the hemicycle is sparsely populated. A classic scheduling move, but an effective one.&lt;/p&gt;
&lt;h2 id=&quot;debunk-express&quot;&gt;Debunk Express&lt;/h2&gt;
&lt;p&gt;Three falsehoods have been circulating since July 9th. Here’s the reality check.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;“The Parliament voted FOR Chat Control.”&lt;/strong&gt; False. 314 voted against, 276 for: the majority voted no. The text passes because the threshold to block it, 361 votes, wasn’t reached, not because it was approved.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;“WhatsApp, Signal, iMessage will be scanned.”&lt;/strong&gt; False. A Renew amendment adopted on the same day explicitly excludes end-to-end encryption from the scope of this text. The 1.0 remains voluntary scanning, outside of E2E.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;“This is the big mandatory Chat Control that just passed.”&lt;/strong&gt; False. The text of July 9th is the voluntary 1.0. Mandatory scanning, potentially client-side on E2E, is the CSAR (Chat Control 2.0), still in trilogue, to be revisited in September.&lt;/p&gt;
&lt;p&gt;Two texts, two stories. The 1.0 is voluntary and excludes E2E. &lt;strong&gt;The 2.0 is the real danger&lt;/strong&gt;, and it’s not settled yet.&lt;/p&gt;
&lt;h2 id=&quot;why-it-concerns-you&quot;&gt;Why It Concerns You&lt;/h2&gt;
&lt;p&gt;On your Mac and iPhone, the 1.0 doesn’t change anything today: your iMessage, WhatsApp, Signal remain end-to-end encrypted, explicitly outside the scope of this text. Don’t let anyone sell you a product panic that doesn’t exist.&lt;/p&gt;
&lt;p&gt;But this text isn’t limited to messaging apps. It also covers emails, and here, the nuance changes everything: a regular email (Gmail, Outlook, iCloud Mail) isn’t end-to-end encrypted. It’s fully within the scope of the voluntary scan that the 1.0 prolongs.&lt;/p&gt;
&lt;p&gt;Google and others can scan the content of your emails for CSAM, and the E2E exclusion won’t protect you, since there’s no E2E to protect. Only a genuinely end-to-end encrypted messaging service, like Proton Mail, slips through the net.&lt;/p&gt;
&lt;p&gt;Consider what this means. It’s like the Police reading your mail when you’ve done nothing wrong. It’s like something out of the Stasi!&lt;/p&gt;
&lt;p&gt;The real risk has another name: &lt;strong&gt;client-side scanning by the CSAR 2.0&lt;/strong&gt;. That’s the principle of inspecting your messages on your device &lt;strong&gt;before they’re encrypted&lt;/strong&gt;. The crypto isn’t broken, it’s emptied of its meaning: your message is read in plaintext on your phone before it’s sent. And once that inspection point is in place, it belongs to the “nice guys” forever.&lt;/p&gt;
&lt;p&gt;It’s not science fiction on Apple’s side. In 2021, Apple announced &lt;strong&gt;NeuralHash&lt;/strong&gt;, a system for client-side CSAM scanning on iPhones, before abandoning it in December 2022 under pressure. The code exists, the logic does too.&lt;/p&gt;
&lt;p&gt;A binding CSAR would be exactly the lever that would reopen this dossier, this time by law and not by choice. The lawsuit against Apple by West Virginia in February 2026 shows that judicial pressure on this issue isn’t letting up.&lt;/p&gt;
&lt;h2 id=&quot;what-you-can-do&quot;&gt;What You Can Do&lt;/h2&gt;
&lt;p&gt;Nothing to install, nothing to fix on your device: the 1.0 opens no product vulnerabilities. It’s a political signal, and a lesson in method: a text rejected by the majority of voters can still pass when the blocking threshold isn’t reached. Remember the mechanism, because it’ll come up again in September.&lt;/p&gt;
&lt;p&gt;The appointment is &lt;strong&gt;the CSAR at the September 2026 restart&lt;/strong&gt;. Five rounds of trilogue without agreement, the last on June 29th, and the fracture line remains encryption.&lt;/p&gt;
&lt;p&gt;Keep Signal as a fallback messaging service, follow EDRi and Patrick Breyer for the real outcome, and write to your MEP before the 2.0 comes back on the table. Public pressure has already shifted lines on this dossier before, it can do so again.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;To dig deeper: &lt;a href=&quot;https://macsouverain.com/en/chat-control-csar-surveillance-messageries-chiffrees/&quot;&gt;Chat Control 2.0, the complete mechanism&lt;/a&gt; · &lt;a href=&quot;https://macsouverain.com/en/nis2-csar-contradiction-ue-chiffrement-surveillance/&quot;&gt;NIS2 vs CSAR, when the EU contradicts itself&lt;/a&gt; · &lt;a href=&quot;https://macsouverain.com/en/convergence-libertes-numeriques/&quot;&gt;The global convergence of anti-privacy texts&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-signal</category><category>souverainete</category><category>chiffrement</category><category>ue</category></item><item><title>CrowdSec up front, blocking before they hit you</title><link>https://macsouverain.com/en/crowdsec-premiere-ligne-siem-souverain/</link><guid isPermaLink="true">https://macsouverain.com/en/crowdsec-premiere-ligne-siem-souverain/</guid><description>Install CrowdSec on your hardened VPS, block malicious IPs upstream with the bouncer firewall, and feed its decisions into Wazuh.</description><pubDate>Wed, 08 Jul 2026 06:00:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;strong&gt;Episode 4: The Community Network Defense&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;In the previous episode, you enrolled Wazuh agents on all your machines. Servers, Linux, Mac, Windows, every machine sends its logs to the manager through the Tailnet. Your SIEM has lifted its nose from its own logs, your entire park is displayed before it. It sees everything, including attacks.&lt;/p&gt;
&lt;p&gt;But here’s the catch. An agent Wazuh &lt;strong&gt;observes&lt;/strong&gt;, as we’ve repeated all throughout episode 3. It tells you that a burst of failed connection attempts has just hit your server, it tells you very well, very quickly, very detailed. But it does nothing to stop it. You have eyes, but no hands.&lt;/p&gt;
&lt;p&gt;Today, we give you hands. We install &lt;strong&gt;CrowdSec&lt;/strong&gt;, the first active defense line in the series. An engine that reads your logs like Wazuh, but unlike Wazuh, it draws a conclusion and &lt;strong&gt;blocks&lt;/strong&gt;. The IP that’s hammering your SSH, it puts it outside. The attacker already spotted elsewhere on the community network, it blocks it before it even knocks on your door.&lt;/p&gt;
&lt;p&gt;A point raised since episode 1 and still holds true. &lt;strong&gt;Almost all your services live in Tailnet-only, invisible from the open internet&lt;/strong&gt;. But some doors must remain open to the world, a mail server receiving on port 25, a public web presence. Those are the doors CrowdSec guards.&lt;/p&gt;
&lt;p&gt;This stack, I use daily. The commands that follow are the ones you’ll type yourself, in order, on your hardened VPS then in your Wazuh manager.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;Before you begin&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Three things to keep in mind before the first command.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What you need.&lt;/strong&gt; A hardened VPS like the one from episode 1, up-to-date, with at least one service exposed to the open internet to protect. The Wazuh manager from episode 2, operational, for the integration at the end of the tutorial. Administrator access on the machine. And something to read your own logs, &lt;code&gt;/var/log/auth.log&lt;/code&gt; and your service logs, since that’s CrowdSec’s raw material.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What changes.&lt;/strong&gt; At the end, known malicious IPs no longer reach your services, they hit your firewall before. You also benefit from the community list, millions of signals uploaded by other users, so you block attackers you’ve never seen yourself. And your SIEM finally sees this defense layer, every blockage is uploaded to Wazuh.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What doesn’t change.&lt;/strong&gt; CrowdSec blocks at the &lt;strong&gt;network level&lt;/strong&gt;, by IP address. It’s not an antivirus, not an exhaustive application firewall, not a replacement for your hardening from episode 1. It’s just another layer, the first one the attacker encounters, not the only one. And it blocks the IP, not the human behind it. An IP changes, defense plays on volume and speed, not infallibility.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;How CrowdSec sees and blocks&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Before installing anything, understand the mechanism. It’s based on three pieces that pass the baton to each other.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The security engine&lt;/strong&gt;, the local agent. It reads your logs continuously, &lt;code&gt;auth.log&lt;/code&gt;, your server web and mail logs. It passes them through &lt;strong&gt;scenarios&lt;/strong&gt;, behavior rules like “six failed SSH attempts in ten seconds from the same IP, that’s brute force”. When a scenario triggers, the engine takes a &lt;strong&gt;decision&lt;/strong&gt;, it writes this IP to a blacklist for a given duration, four hours by default for brute force.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The bouncer&lt;/strong&gt;, the executor. The engine decides, but it doesn’t touch your firewall itself, that’s a design choice. The bouncer firewall, the one we’re interested in, applies the decision. It puts the faulty IP into your nftables or iptables. Engine and bouncer are separate, you can have several, one for the firewall, one in front of a reverse proxy web, each applies the same decisions at its level.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The community network&lt;/strong&gt;, the CTI, for Cyber Threat Intelligence. It’s the multiplier. When your engine blocks an IP, it sends the signal to the central API, the address and the scenario. In exchange, you download the &lt;strong&gt;community list&lt;/strong&gt;, the aggregate of signals from all users. Result, an IP that attacked a server in Poland this morning is already blocked on your machine this afternoon, before its first attempt.&lt;/p&gt;
&lt;p&gt;Remember the flow, it commands everything else. Log read by the engine, scenario triggered, decision made, bouncer applies it on the firewall, signal shared, community list downloaded in return.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;Step 1, install the engine&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;We start with the brain, on your hardened VPS. Two commands, one to declare the official CrowdSec repository, one to install.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;curl&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; -s&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; https://install.crowdsec.net&lt;/span&gt;&lt;span style=&quot;color:#D73A49&quot;&gt; |&lt;/span&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt; sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; sh&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; apt&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; install&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; crowdsec&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The first line adds the CrowdSec repository to your sources list. The second installs and starts the engine.&lt;/p&gt;
&lt;p&gt;The installation is smart on one point. At the end, CrowdSec &lt;strong&gt;scans the services it detects&lt;/strong&gt; on your machine and installs the corresponding &lt;strong&gt;collections&lt;/strong&gt; automatically. It sees an SSH server, it installs the &lt;code&gt;crowdsecurity/sshd&lt;/code&gt; collection. An Nginx, it adds the web scenarios. You don’t have to guess what to watch, it deduces it from what’s running.&lt;/p&gt;
&lt;p&gt;Check what’s been set up.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; cscli&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; collections&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; list&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;You should see the list of active collections, with the &lt;code&gt;enabled&lt;/code&gt; mention. If a service isn’t covered, install its collection manually, for example &lt;code&gt;sudo cscli collections install crowdsecurity/nginx&lt;/code&gt; then restart the service &lt;code&gt;crowdsec&lt;/code&gt;. Everything is controlled with &lt;code&gt;cscli&lt;/code&gt;, CrowdSec’s command-line tool, the equivalent of your &lt;code&gt;agent_control&lt;/code&gt; on Wazuh’s side.&lt;/p&gt;
&lt;p&gt;At this stage, the engine reads, analyzes and &lt;strong&gt;decides&lt;/strong&gt;. But it doesn’t block anything yet. It holds a blacklist that nobody applies. It still needs its hands.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;Step 2, put the bouncer that really blocks&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The hands, that’s the &lt;strong&gt;firewall bouncer&lt;/strong&gt;. It reads the engine’s decisions and translates them into firewall rules that really refuse traffic.&lt;/p&gt;
&lt;p&gt;There are two variants depending on your firewall, one for nftables, one for iptables. Most recent distributions run on nftables by default.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; apt&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; install&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; crowdsec-firewall-bouncer-nftables&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;If your machine is on the old iptables, replace the package with &lt;code&gt;crowdsec-firewall-bouncer-iptables&lt;/code&gt;. The principle is the same. A detail for consistency with episode 1, if your firewall runs on &lt;code&gt;ufw&lt;/code&gt;, know that &lt;code&gt;ufw&lt;/code&gt; relies on one of the two backends depending on your version, check which one before choosing the bouncer variant.&lt;/p&gt;
&lt;p&gt;The installation makes the connection itself. The package calls &lt;code&gt;cscli bouncers add&lt;/code&gt; for itself, registers the bouncer with the engine and gives it an authentication key. No manual key handling.&lt;/p&gt;
&lt;p&gt;Check that the engine and its bouncer talk to each other.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; cscli&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; bouncers&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; list&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;You should see your firewall bouncer listed, with a recent last activity date. From now on, the loop is closed. The engine decides, the bouncer applies, the faulty IP falls into a set blocked by your firewall. Your SIEM has hands.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://macsouverain.com/content/images/2026/07/capture-bouncers-list-crowdsec-premiere-ligne-siem-souverain-1.png&quot; alt=&quot;Output of cscli bouncers list: the firewall bouncer registered, valid, with a recent last activity.&quot;&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;Step 3, check that it bites&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Three commands to make sure the machine is running, and one to put it to the test without waiting for a real attack.&lt;/p&gt;
&lt;p&gt;First, the big picture.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; cscli&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; metrics&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;It shows you how many log lines the engine has read, by source, and how many times each scenario has been triggered. If the counters are moving, your engine is seeing your logs. If they stay at zero, it’s not reading anything, and that’s a source issue to fix before going any further.&lt;/p&gt;
&lt;p&gt;Next, the current decisions. Add the &lt;code&gt;-a&lt;/code&gt; flag, otherwise CrowdSec will only show your local decisions and hide the IP addresses pulled from the community network.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; cscli&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; decisions&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; list&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; -a&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;On a machine exposed for a few hours, it shouldn’t be empty. Each line is an IP address, the scenario that triggered it, and the remaining duration.&lt;/p&gt;
&lt;p&gt;Look at the Source column. The &lt;code&gt;CAPI&lt;/code&gt; lines are the community’s gifts, IP addresses you’ve never seen knocking on your door and are already being refused. The line in bold is yours, a scanner your own server caught in the act and banned all by itself, three hours in the corner. The collective and the local, side by side, in the same blacklist.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://macsouverain.com/content/images/2026/07/capture-decisions-list-crowdsec-premiere-ligne-siem-souverain-1.png&quot; alt=&quot;Real output of cscli decisions list -a: the local line in bold, an attacker spotted by your server, among the community decisions CAPI.&quot;&gt;&lt;/p&gt;
&lt;p&gt;Finally, the test. Instead of waiting for an attacker, you create a test decision on a dummy IP address.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; cscli&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; decisions&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; add&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; --ip&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; 192.0.2.1&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; --duration&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; 4h&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; --reason&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; &quot;test block&quot;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; cscli&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; decisions&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; list&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The IP address &lt;code&gt;192.0.2.1&lt;/code&gt; belongs to a reserved range for documentation, it won’t block anyone real. You see it appear in the list, the bouncer pushes it into your firewall. Clean up behind you once the test is successful.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; cscli&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; decisions&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; delete&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; --ip&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; 192.0.2.1&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;If adding, displaying, and deleting work properly, your engine-decision-bouncer chain is operational end-to-end.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;Step 4, the community signal, what goes out and what stays&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;This is where CrowdSec scales up, and it’s also the only place where honesty about sovereignty demands a sentence, so let’s put it out there without beating around the bush.&lt;/p&gt;
&lt;p&gt;By default, your engine is registered with the &lt;strong&gt;central community API&lt;/strong&gt;. You can check this with:&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; cscli&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; capi&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; status&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;This exchange works both ways, and it’s important to know exactly what’s going on. &lt;strong&gt;What goes out from your end&lt;/strong&gt;, when you block an IP address, is a minimal signal: the faulty IP address, the scenario that triggered it, and the timestamp. &lt;strong&gt;What never goes out&lt;/strong&gt;, are your logs, your machine names, your users, the content of anything. CrowdSec shares the conclusion “this IP address is attacking”, not the raw material that led to it. &lt;strong&gt;What comes in&lt;/strong&gt;, is the community list, the anonymized aggregate of these signals across the entire network.&lt;/p&gt;
&lt;p&gt;It’s a compromise, and it’s a clear one. You exchange the address of attackers, data that isn’t yours but belongs to your attackers, for collective protection that you couldn’t build alone. The engine remains &lt;strong&gt;self-hosted on your end&lt;/strong&gt;, no third party pilots your blocks, no decision depends on a remote service that could be cut off. You can even opt out of sharing and run purely locally, you keep your defense, you just lose the community list. The balance is in your hands, as always in this series.&lt;/p&gt;
&lt;p&gt;If you want a web console to visualize your alerts, CrowdSec offers one, for free, where you enroll your engine with &lt;code&gt;sudo cscli console enroll &amp;#x3C;your-key&gt;&lt;/code&gt;. Optional, and hosted by CrowdSec, so weigh it according to your line. Your real dashboard, anyway, is Wazuh, and that’s the next step.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;Step 5, make CrowdSec show up in Wazuh&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Your firewall blocks, great. But for now, your SIEM doesn’t know. CrowdSec acts on its own, Wazuh looks elsewhere. We connect them, so that every CrowdSec decision becomes a visible alert in your single dashboard.&lt;/p&gt;
&lt;p&gt;The principle is simple and clean. CrowdSec knows &lt;strong&gt;how to write its alerts to a file&lt;/strong&gt;, and Wazuh knows &lt;strong&gt;how to read a log file&lt;/strong&gt;. We make them meet.&lt;/p&gt;
&lt;p&gt;On CrowdSec’s side, you enable the file notification plugin. It already exists, you edit &lt;code&gt;/etc/crowdsec/notifications/file.yaml&lt;/code&gt; to make it write in JSON format, one alert per line.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;yaml&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#22863A&quot;&gt;type&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;: &lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt;file&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#22863A&quot;&gt;name&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;: &lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt;file_default&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#22863A&quot;&gt;log_level&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;: &lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt;info&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#22863A&quot;&gt;format&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;: &lt;/span&gt;&lt;span style=&quot;color:#D73A49&quot;&gt;|&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#032F62&quot;&gt;  {{range. -}}&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#032F62&quot;&gt;   { &quot;crowdsec&quot;: { &quot;program&quot;: &quot;crowdsec&quot;, &quot;alert&quot;: {{. | toJson }} }}&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#032F62&quot;&gt;  {{ end -}}&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#22863A&quot;&gt;log_path&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;: &lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt;&quot;/var/log/crowdsec/crowdsec_alerts.json&quot;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#22863A&quot;&gt;rotate&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#22863A&quot;&gt;  enabled&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;: &lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt;true&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#22863A&quot;&gt;  max_size&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;: &lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt;500&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#22863A&quot;&gt;  compress&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;: &lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt;true&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Then you declare this channel in &lt;code&gt;/etc/crowdsec/profiles.yaml&lt;/code&gt;, so the engine sends its alerts there.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;yaml&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#22863A&quot;&gt;notifications&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;:&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;    - &lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt;file_default&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;A detail that counts. The official CrowdSec tutorial writes this file to &lt;code&gt;/tmp&lt;/code&gt;, which is emptied on every machine reboot. We put it in &lt;code&gt;/var/log/crowdsec/&lt;/code&gt; instead, so your alert history survives a reboot. A &lt;code&gt;crowdsec&lt;/code&gt; service restart, and the &lt;code&gt;/var/log/crowdsec/crowdsec_alerts.json&lt;/code&gt; file fills up with every decision.&lt;/p&gt;
&lt;p&gt;On Wazuh’s side, you tell the local agent, the one from episode 3 already installed on this server, to read this file. You add this block to its configuration, ideally via the shared configuration for the group so you only have to write it once.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;xml&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;localfile&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;  &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;location&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;/var/log/crowdsec/crowdsec_alerts.json&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;location&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;  &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;log_format&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;json&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;log_format&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;  &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;label&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;crowdsec&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;label&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;localfile&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;You recognize the &lt;code&gt;&amp;#x3C;localfile&gt;&lt;/code&gt; logic, it’s exactly the mechanism by which Wazuh swallows any log source. The &lt;code&gt;json&lt;/code&gt; format tells it to parse each line as a structured object, and your &lt;code&gt;crowdsec.alert.*&lt;/code&gt; fields become queryable in the dashboard.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://macsouverain.com/content/images/2026/07/capture-wazuh-alert-crowdsec-premiere-ligne-siem-souverain-1.png&quot; alt=&quot;An alert from CrowdSec showing up in the Wazuh Discover dashboard: a ban on the crowdsecurity/ssh-bf scenario, with all its crowdsec.alert fields unfolded and queryable.&quot;&gt;&lt;/p&gt;
&lt;p&gt;Restart the Wazuh agent, and the series’ loop is closed. An IP address attacks, CrowdSec blocks it, writes the alert, the Wazuh agent reads it, the manager sends it up, it shows up in your dashboard next to everything else. Your SIEM finally sees its own counterattacks.&lt;/p&gt;
&lt;p&gt;A version note, because it matters. This integration via the file plugin assumes a recent engine and Wazuh version. Make sure your CrowdSec is at 1.6.3 or above and your Wazuh is at 4.9.0 or above, the versions from which this integration by the file plugin is officially supported. You’re running on Wazuh 4.x, this integration doesn’t depend on the future 5.0, it works on your current stack.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;If it doesn’t work&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The deployment of CrowdSec is straightforward, and it usually gets stuck at the same points. Here are the real ones, in the order you’ll encounter them.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Problem&lt;/strong&gt;, &lt;code&gt;cscli metrics&lt;/code&gt; shows zero lines read&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Probable cause&lt;/strong&gt;, the engine can’t find your logs, or it doesn’t have the collection for your service. It’s running, but it’s reading nothing.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Solution&lt;/strong&gt;, make sure the log source exists at the expected path and that the service’s collection is installed with &lt;code&gt;sudo cscli collections list&lt;/code&gt;. Install the missing collection, then restart the &lt;code&gt;crowdsec&lt;/code&gt; service.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Problem&lt;/strong&gt;, an IP address is decided but nothing is blocked&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Probable cause&lt;/strong&gt;, the bouncer isn’t there, or it isn’t talking to the engine. The engine decides on its own, nobody applies anything.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Solution&lt;/strong&gt;, &lt;code&gt;sudo cscli bouncers list&lt;/code&gt; should show your firewall bouncer with recent activity. If it’s absent, reinstall the bouncer package. If it’s present but silent, check that the bouncer service is running.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Problem&lt;/strong&gt;, the wrong firewall backend&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Probable cause&lt;/strong&gt;, you installed the nftables variant of the bouncer on an iptables machine, or vice versa. The bouncer puts its rules in a system that your firewall doesn’t use.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Solution&lt;/strong&gt;, identify your real backend, then install the corresponding variant of the bouncer, &lt;code&gt;crowdsec-firewall-bouncer-nftables&lt;/code&gt; or &lt;code&gt;crowdsec-firewall-bouncer-iptables&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Problem&lt;/strong&gt;, nothing shows up in Wazuh&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Probable cause&lt;/strong&gt;, note that this is usually not a CrowdSec problem. The &lt;code&gt;/var/log/crowdsec/crowdsec_alerts.json&lt;/code&gt; file grows on CrowdSec’s side. If it grows, the diagnosis is on Wazuh’s side, the &lt;code&gt;&amp;#x3C;localfile&gt;&lt;/code&gt; block and the agent version, not on CrowdSec’s side. Don’t reinstall CrowdSec for a Wazuh reading issue.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;The community list makes up half the work&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;A final word, because this is the point we always underestimate at the start. The day you install CrowdSec, you expect it to learn slowly, to need weeks of traffic before it becomes useful. Wrong.&lt;/p&gt;
&lt;p&gt;As soon as the first synchronization, you download the community list, and your &lt;code&gt;sudo cscli decisions list -a&lt;/code&gt; populates with IP addresses you’ve never seen. Attackers spotted elsewhere, already blocked at your end. You benefit from the work of tens of thousands of other servers before you’ve even had your first attack.&lt;/p&gt;
&lt;p&gt;It’s not magic, it’s volume. Every server that sends up a signal strengthens the defense of all the others. It’s exactly the model that the American SaaS sells you expensively and under its jurisdiction, except here it’s open source, self-hosted, and the shared signal is limited to the address of your attackers.&lt;/p&gt;
&lt;p&gt;The turning point is passed. Where your SIEM used to just observe, it now blocks.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;For the impatient&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What this article does.&lt;/strong&gt; We install CrowdSec on the hardened VPS to block malicious IP addresses known locally and signaled by the community network. The engine reads your logs and decides, the firewall bouncer applies the block on nftables or iptables, and every decision shows up in Wazuh via a file of alerts read by the agent. The defense goes from “seeing” to “barricading the door”.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Concretely, the commands.&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Install the engine: &lt;code&gt;curl -s https://install.crowdsec.net | sudo sh&lt;/code&gt; then &lt;code&gt;sudo apt install crowdsec&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Check the detected collections: &lt;code&gt;sudo cscli collections list&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Install the firewall bouncer according to your backend: &lt;code&gt;sudo apt install crowdsec-firewall-bouncer-nftables&lt;/code&gt; (or &lt;code&gt;-iptables&lt;/code&gt;).&lt;/li&gt;
&lt;li&gt;Check the connection: &lt;code&gt;sudo cscli bouncers list&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Check the machine: &lt;code&gt;sudo cscli metrics&lt;/code&gt; and &lt;code&gt;sudo cscli decisions list -a&lt;/code&gt; (the &lt;code&gt;-a&lt;/code&gt; for seeing also the community list).&lt;/li&gt;
&lt;li&gt;Test the blocking: &lt;code&gt;sudo cscli decisions add --ip 192.0.2.1 --duration 4h --reason &quot;test&quot;&lt;/code&gt; then &lt;code&gt;sudo cscli decisions delete --ip 192.0.2.1&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Check the community sharing: &lt;code&gt;sudo cscli capi status&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Integrate with Wazuh: enable the file notification plugin in &lt;code&gt;/etc/crowdsec/notifications/file.yaml&lt;/code&gt; (output &lt;code&gt;/var/log/crowdsec/crowdsec_alerts.json&lt;/code&gt;), declare it in &lt;code&gt;/etc/crowdsec/profiles.yaml&lt;/code&gt;, then add the &lt;code&gt;&amp;#x3C;localfile&gt;&lt;/code&gt; JSON block to the Wazuh agent’s configuration.&lt;/li&gt;
&lt;/ol&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;In summary&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;You started with a SIEM that saw attacks but couldn’t stop them, and now you’re ending with a first line that blocks them.&lt;/p&gt;
&lt;p&gt;You &lt;strong&gt;installed the CrowdSec engine&lt;/strong&gt; on your hardened VPS, which reads your logs and decides. You &lt;strong&gt;put the firewall bouncer&lt;/strong&gt;, which applies these decisions on your firewall and really blocks. You &lt;strong&gt;connected the community list&lt;/strong&gt;, which protects you from attackers you’ve never seen yourself, by only sharing their addresses. And you &lt;strong&gt;made everything show up in Wazuh&lt;/strong&gt;, so your control room finally sees this defense layer.&lt;/p&gt;
&lt;p&gt;It all stays with you. The engine is self-hosted, no decision depends on a third party, and the only signal that goes out is the IP address of your attackers. The protection collective without the dependence, that’s precisely the sovereign third way, opened in the series’ introduction episode.&lt;/p&gt;
&lt;p&gt;You now block at the network level. But your most frequent attacks don’t come through the SSH port, they come through your mailbox. In episode 5, we’ll put the anti-spam and anti-phishing filter in front of your mail server, the most exposed door of all.&lt;/p&gt;
&lt;p&gt;A final note on the series. Seven episodes to build your sovereign security plumbing, brick by brick.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/nis2-splunk-pourquoi-pme-siem-souverain/&quot;&gt;Episode 0, the bedrock of the series.&lt;/a&gt;&lt;/strong&gt; Why an SME needs a sovereign SIEM, NIS2, GDPR, and the cost of doing nothing.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/vps-durci-socle-siem-souverain/&quot;&gt;Episode 1, the foundation.&lt;/a&gt;&lt;/strong&gt; The hardened VPS outside the CLOUD Act.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/wazuh-tout-en-un-siem-souverain/&quot;&gt;Episode 2, Wazuh all-in-one.&lt;/a&gt;&lt;/strong&gt; Manager, indexer, and dashboard on a single node.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/wazuh-agents-parc-siem-souverain/&quot;&gt;Episode 3, agents everywhere.&lt;/a&gt;&lt;/strong&gt; Deployment on your servers, Macs, and Windows machines.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Episode 4, the community network defense.&lt;/strong&gt; Blocking known attackers before they arrive. You just read this.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/rspamd-mail-siem-souverain/&quot;&gt;Episode 5, the mail filter.&lt;/a&gt;&lt;/strong&gt; Anti-spam and anti-phishing in front of your mail server.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Episode 6, Mac execution control.&lt;/strong&gt; Deciding which applications get to launch.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Episode 7, alerting and honest cost.&lt;/strong&gt; Calibrated notifications and honest financial breakdown against SaaS.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;em&gt;Technical terms? &lt;a href=&quot;https://macsouverain.com/en/glossaire/&quot;&gt;Check the glossary.&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>ms-pro</category><category>nis2</category><category>siem</category><category>crowdsec</category><category>securite</category><category>tutoriel</category><enclosure url="https://macsouverain.com/content/images/2026/07/feature-crowdsec-premiere-ligne-siem-souverain-1.png" length="0" type="image/png"/></item><item><title>Install your first AI model locally on Mac</title><link>https://macsouverain.com/en/installer-premier-modele-ia-local-mac/</link><guid isPermaLink="true">https://macsouverain.com/en/installer-premier-modele-ia-local-mac/</guid><description>&quot;An AI model that runs 100% offline on your Mac Apple Silicon, in 20 minutes, without typing a single command. Install LM Studio, pick a model in MLX, enter your first prompt, then the ultimate test: cut the Wi-Fi.&quot;</description><pubDate>Mon, 06 Jul 2026 06:14:39 GMT</pubDate><content:encoded>&lt;p&gt;&lt;strong&gt;Previous Article:&lt;/strong&gt; We set the stage. Your access to a distant AI model can be cut off overnight by an arbitrary decision, and the only thing still running the next morning… is nothing.&lt;/p&gt;
&lt;p&gt;We also mapped out what a Mac Apple Silicon runs locally, from the small model that sorts your notes to the large model that writes.&lt;/p&gt;
&lt;p&gt;That was the why. Here’s the how.&lt;/p&gt;
&lt;p&gt;Good news up front: you need no technical skill, no command line, and no additional hardware. If you’re reading this on a recent Mac, you already have everything. Count twenty minutes, most of it watching a progress bar.&lt;/p&gt;
&lt;p&gt;At the end, you have a capable model that responds entirely on your machine. And to prove it, at the very end, we’ll cut the Wi-Fi.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read: &lt;a href=&quot;https://macsouverain.com/en/ton-ia-peut-etre-eteinte-monte-la-tienne/&quot;&gt;Your AI can be shut down by the US, build your own&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id=&quot;what-you-need&quot;&gt;What you need&lt;/h2&gt;
&lt;p&gt;Three things, and you probably already have them.&lt;/p&gt;
&lt;p&gt;A &lt;strong&gt;Mac Apple Silicon&lt;/strong&gt;, that is, an M1 to M5 chip. Most Macs sold since late 2020 have one. If you have an Intel Mac, this method doesn’t apply, efficient local inference relies on Apple Silicon’s unified memory.&lt;/p&gt;
&lt;p&gt;A &lt;strong&gt;reasonably recent version of macOS&lt;/strong&gt;, Sonoma (14) or later for the tool we’ll use. If you haven’t updated in a while, now’s the time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;RAM&lt;/strong&gt;, and that’s where the model choice comes in. Quick refresher from the previous article: on a 16GB Mac, once the system is served, you have 8 to 10GB left for AI, enough to run a 7 to 8 billion parameter model.&lt;/p&gt;
&lt;p&gt;On a 32GB, you step up a class, up to a 24 billion parameter model. The golden rule, never choose a model that fills the entire budget, or your machine will struggle or crash.&lt;/p&gt;
&lt;p&gt;If you want the RAM budget details and the full model map, it’s all in the previous article. Here, we install.&lt;/p&gt;
&lt;h2 id=&quot;the-tool-lm-studio-zero-terminal&quot;&gt;The tool: LM Studio, zero terminal&lt;/h2&gt;
&lt;p&gt;There are several ways to run a model locally. For a first step, one deserves to be singled out: &lt;strong&gt;LM Studio&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;It’s a classic desktop app, with windows, buttons, and a search field. You download your models from an integrated library, click, chat. No command line, no config files to edit, no esoteric maneuvers. It’s local AI presented as a normal app, and for getting started, that’s exactly what you want.&lt;/p&gt;
&lt;p&gt;LM Studio is &lt;strong&gt;free&lt;/strong&gt;, for personal and professional use. And on Mac Apple Silicon, it comes with the best engine possible, we’ll get back to that in two minutes.&lt;/p&gt;
&lt;p&gt;The curious and the hungry have other options, Ollama on the command line, MLX for going metal. We’ll mention them at the end, once you already have a running model. One thing at a time.&lt;/p&gt;
&lt;h2 id=&quot;install-lm-studio&quot;&gt;Install LM Studio&lt;/h2&gt;
&lt;p&gt;Nothing more than an ordinary Mac app.&lt;/p&gt;
&lt;p&gt;Go to &lt;a href=&quot;https://lmstudio.ai&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;lmstudio.ai&lt;/a&gt; and download the Mac version. The site detects your machine and offers the right build, the one for Apple Silicon. You get a &lt;code&gt;.dmg&lt;/code&gt; file, the usual Mac installation format.&lt;/p&gt;
&lt;figure class=&quot;kg-card kg-image-card&quot;&gt;
&lt;img src=&quot;https://macsouverain.com/content/images/2026/07/capture-01-page-telechargement-installer-premier-modele-ia-local-mac-2.png&quot; class=&quot;kg-image&quot; loading=&quot;lazy&quot; alt=&quot;The LM Studio download page, which automatically detects your Mac Apple Silicon.&quot;&gt;
&lt;/figure&gt;
&lt;p&gt;Open the downloaded &lt;code&gt;.dmg&lt;/code&gt;. A window appears with the LM Studio icon and a shortcut to your Applications folder. Drag the icon to the Applications folder, just like any other app. That’s it, nothing to check, nothing to configure.&lt;/p&gt;
&lt;figure class=&quot;kg-card kg-image-card&quot;&gt;
&lt;img src=&quot;https://macsouverain.com/content/images/2026/07/capture-02-dmg-vers-applications-installer-premier-modele-ia-local-mac-2.png&quot; class=&quot;kg-image&quot; loading=&quot;lazy&quot; alt=&quot;The.dmg window, you drag the LM Studio icon to the Applications folder.&quot;&gt;
&lt;/figure&gt;
&lt;p&gt;Launch LM Studio from Launchpad or your Applications folder. On the first launch, macOS might ask you to confirm opening an app downloaded from the internet, confirm. The app opens on a welcome screen that offers to choose a first model. Let’s go.&lt;/p&gt;
&lt;h2 id=&quot;choose-and-download-your-first-model&quot;&gt;Choose and download your first model&lt;/h2&gt;
&lt;p&gt;This is the crucial step, and the one where we’ll be precise, because not all models are equal and the right choice depends on your RAM.&lt;/p&gt;
&lt;p&gt;Stick to the sovereign pick from the previous article. On a &lt;strong&gt;16GB Mac&lt;/strong&gt;, aim for &lt;strong&gt;Qwen2.5 7B&lt;/strong&gt;, a model under Apache 2.0 license, truly free, that runs the essentials of daily life. On a &lt;strong&gt;32GB Mac&lt;/strong&gt;, aim for &lt;strong&gt;Mistral Small&lt;/strong&gt;, a 24 billion parameter model, European and also under Apache 2.0, tailored for sustained writing and long document analysis.&lt;/p&gt;
&lt;p&gt;In LM Studio, open the search tab, the magnifying glass icon in the sidebar, and type the model name. The library is connected to Hugging Face, the big model hub, so you’ll see several variants of the same model. That’s normal, and that’s where you need to know how to read.&lt;/p&gt;
&lt;figure class=&quot;kg-card kg-image-card&quot;&gt;
&lt;img src=&quot;https://macsouverain.com/content/images/2026/07/capture-03-discover-recherche-installer-premier-modele-ia-local-mac-2.png&quot; class=&quot;kg-image&quot; loading=&quot;lazy&quot; alt=&quot;The LM Studio Discover tab, to search and download models from Hugging Face.&quot;&gt;
&lt;/figure&gt;
&lt;p&gt;Two things to decode on each variant.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The format.&lt;/strong&gt; You’ll encounter two words, &lt;strong&gt;MLX&lt;/strong&gt; and &lt;strong&gt;GGUF&lt;/strong&gt;. Just remember this: MLX, the calculation framework made by Apple, is the engine optimized for Apple Silicon’s unified memory. On your Mac, an MLX version runs notably faster than the same one in GGUF, quality equal.&lt;/p&gt;
&lt;p&gt;LM Studio comes with this MLX engine, might as well use it. &lt;strong&gt;Choose the MLX version of the model whenever it’s available.&lt;/strong&gt; If a model only exists in GGUF, that’s fine, it still works, just a bit slower.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Quantization.&lt;/strong&gt; You’ll see labels like &lt;code&gt;4bit&lt;/code&gt;, &lt;code&gt;Q4&lt;/code&gt;, &lt;code&gt;Q4_K_M&lt;/code&gt;, &lt;code&gt;Q8&lt;/code&gt;. That’s the model’s compression level. A raw model weighs a fortune in memory, quantization reduces the precision of its weights to make it fit in your RAM, at the cost of a barely noticeable quality loss.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Q4, or 4bit, is the sweet spot for starting&lt;/strong&gt;, it divides the model’s weight by about four without you noticing much of a difference. Q8 is more faithful but twice as heavy, keep it for later if you have the RAM.&lt;/p&gt;
&lt;p&gt;In practical terms, what you’re downloading:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;On 16GB, &lt;strong&gt;Qwen2.5 7B in MLX 4bit&lt;/strong&gt; weighs around &lt;strong&gt;4.3GB&lt;/strong&gt;. It’s well within your RAM.&lt;/li&gt;
&lt;li&gt;On 32GB, &lt;strong&gt;Mistral Small 24B in MLX 4bit&lt;/strong&gt; weighs &lt;strong&gt;around 13 to 14GB&lt;/strong&gt;. It’s within your margin without killing your machine.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Choose the right variant, MLX and 4bit, and click download. A progress bar appears, you can follow the download in the downloads tab. Time for a coffee break, the file is several gigabytes.&lt;/p&gt;
&lt;figure class=&quot;kg-card kg-image-card&quot;&gt;
&lt;img src=&quot;https://macsouverain.com/content/images/2026/07/capture-04-picker-modele-mlx-installer-premier-modele-ia-local-mac-2.png&quot; class=&quot;kg-image&quot; loading=&quot;lazy&quot; alt=&quot;Qwen2.5 7B Instruct in MLX variant, 4bit quantization, 4GB.&quot;&gt;
&lt;/figure&gt;
&lt;p&gt;A word on version numbers. Models evolve, Mistral Small is already at a revision more recent than the one named in the previous article. Don’t sweat the exact number, just pick the latest &lt;strong&gt;Mistral Small 24B&lt;/strong&gt; offered in MLX in LM Studio, that’s the one you want.&lt;/p&gt;
&lt;h2 id=&quot;your-first-prompt-then-cut-the-wi-fi&quot;&gt;Your first prompt, then cut the Wi-Fi&lt;/h2&gt;
&lt;p&gt;The model is downloaded. Time for the moment of truth.&lt;/p&gt;
&lt;p&gt;Open the &lt;strong&gt;Chat&lt;/strong&gt; tab, the speech bubble icon in the sidebar. At the top of the window, a dropdown menu lets you load a model, select the one you just downloaded. LM Studio loads it into memory, a few seconds, and displays a familiar input field, a conversation, like any other assistant.&lt;/p&gt;
&lt;figure class=&quot;kg-card kg-image-card&quot;&gt;
&lt;img src=&quot;https://macsouverain.com/content/images/2026/07/capture-05-modele-charge-installer-premier-modele-ia-local-mac-2.png&quot; class=&quot;kg-image&quot; loading=&quot;lazy&quot; alt=&quot;The model selected and loaded into memory in the Chat tab.&quot;&gt;
&lt;/figure&gt;
&lt;p&gt;If LM Studio offers you a choice of engine, make sure it’s set to &lt;strong&gt;MLX&lt;/strong&gt;. It’s usually automatic when you’ve picked an MLX variant, but a quick check doesn’t hurt.&lt;/p&gt;
&lt;p&gt;Type your first prompt. Anything, preferably a real task, to feel what it’s like. “Summarize this text in three points”, “write a polite follow-up email”, “explain the difference between two concepts”. The model thinks for a few seconds, then responds, word by word, entirely from your machine.&lt;/p&gt;
&lt;figure class=&quot;kg-card kg-image-card&quot;&gt;
&lt;img src=&quot;https://macsouverain.com/content/images/2026/07/capture-06-premier-prompt-reponse-installer-premier-modele-ia-local-mac-2.png&quot; class=&quot;kg-image&quot; loading=&quot;lazy&quot; alt=&quot;A first prompt, the response generated entirely locally by the model.&quot;&gt;
&lt;/figure&gt;
&lt;p&gt;And now, the demonstration that wraps up the previous article’s loop.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Cut the Wi-Fi.&lt;/strong&gt; Click on the Wi-Fi icon in your menu bar and turn it off, or go to System Preferences. Your machine is now offline, cut off from the internet, unplugged from the world. Ask the model another question.&lt;/p&gt;
&lt;p&gt;It responds.&lt;/p&gt;
&lt;p&gt;There you have it. No request went out, not a single byte of your text left your Mac, and yet it works. That’s what a model running on your machine looks like. When they turn off the distant tap one morning, that one keeps running. You can turn the Wi-Fi back on, the demonstration is made.&lt;/p&gt;
&lt;h2 id=&quot;three-settings-that-make-all-the-difference&quot;&gt;Three settings that make all the difference&lt;/h2&gt;
&lt;p&gt;Your model is running. Three buttons deserve a mention, because they make the difference between a smooth machine and a struggling one.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Context length.&lt;/strong&gt; That’s how much text the model can keep in mind at once, your question plus its response plus everything you’ve fed it. It’s set when you load the model, expressed in tokens, in the config panel. A high value lets you feed it long documents, but it consumes RAM in proportion. If your Mac is struggling, lower it. If you want it to digest a long PDF, raise it, keeping an eye on your RAM.&lt;/p&gt;
&lt;figure class=&quot;kg-card kg-image-card&quot;&gt;
&lt;img src=&quot;https://macsouverain.com/content/images/2026/07/capture-07-reglages-contexte-installer-premier-modele-ia-local-mac-2.png&quot; class=&quot;kg-image&quot; loading=&quot;lazy&quot; alt=&quot;The context length setting (Context Length) of the model.&quot;&gt;
&lt;/figure&gt;
&lt;p&gt;&lt;strong&gt;Quantization.&lt;/strong&gt; We talked about it when downloading, it’s the quality-versus-weight lever. If your model is cramped in your RAM, more aggressive quantization (Q4 instead of Q8) makes it fit. If you have room to spare and want the best response, lighter quantization improves quality. You adjust by downloading another variant of the model, that’s the only point where you have to go back through the download process.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Unload the model.&lt;/strong&gt; As long as a model is loaded, it occupies your RAM, even if you’re not using it. When you’re done, unload it, the eject button in the model selector frees up RAM all at once. Useful habit if you’re switching to a heavy task, video editing, coding, virtual machine, and you want your gigabytes back. Closing the window isn’t always enough, unload explicitly.&lt;/p&gt;
&lt;figure class=&quot;kg-card kg-image-card&quot;&gt;
&lt;img src=&quot;https://macsouverain.com/content/images/2026/07/capture-08-ejection-modele-installer-premier-modele-ia-local-mac-2.png&quot; class=&quot;kg-image&quot; loading=&quot;lazy&quot; alt=&quot;The eject button in the model selector, to unload the model and free up RAM.&quot;&gt;
&lt;/figure&gt;
&lt;h2 id=&quot;going-further&quot;&gt;Going further&lt;/h2&gt;
&lt;p&gt;You have a running model, you’ve passed your first offline prompt. The rest is bonus, for when the urge to dig deeper strikes.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Ollama, for the curious of the command line.&lt;/strong&gt; If the command line doesn’t scare you, &lt;a href=&quot;https://ollama.com&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Ollama&lt;/a&gt; runs a model with a single command. You install the app, open the Terminal, type &lt;code&gt;ollama run mistral-small:24b&lt;/code&gt;, and it downloads the model then puts you in conversation, directly in the terminal. It’s sparser than LM Studio, but ruthlessly effective, and it opens the door to automation, plugging a local model into your own scripts via a local API. Ollama also takes advantage of Apple Silicon by using MLX.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;MLX in action, for the hungry.&lt;/strong&gt; The engine LM Studio uses under the hood, &lt;a href=&quot;https://github.com/ml-explore/mlx&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;MLX&lt;/a&gt;, is an Apple framework that you can pilot yourself, with its toolbox &lt;code&gt;mlx-lm&lt;/code&gt;. It’s the playground for those who want to maximize their unified memory, test custom quantizations, or run barely-out models. Reserved for those who enjoy the fine mechanics, but that’s where you’ll find raw performance on a Mac.&lt;/p&gt;
&lt;p&gt;For most everyday uses, you’ll never go beyond LM Studio, and that’s perfectly fine.&lt;/p&gt;
&lt;h2 id=&quot;wrap-up&quot;&gt;Wrap-up&lt;/h2&gt;
&lt;p&gt;What you’ve just done. You installed a free app, downloaded a model in MLX tailored to your RAM, passed a first prompt, and verified with Wi-Fi off that nothing was leaving your Mac. Twenty minutes, zero command line, zero dependency on a model that a third-party IA can shut down.&lt;/p&gt;
&lt;p&gt;This model is yours. No one can cut it off, charge you per request, or decide one morning that your nationality doesn’t suit them. It won’t replace the best distant model for the toughest tasks, we said so, and that’s not the point. Its value is that it’s there, on your machine, all the time, for the bulk of what you do.&lt;/p&gt;
&lt;p&gt;The base is set. Next up, using it for real, for all the tasks you can.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read: &lt;a href=&quot;https://macsouverain.com/en/38-apple-intelligence-ce-qui-sort-de-ton-mac/&quot;&gt;Apple Intelligence: what really comes out of your Mac&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id=&quot;sources&quot;&gt;Sources&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;The tool&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://lmstudio.ai&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;LM Studio&lt;/a&gt;, the desktop app to run models locally, free, with MLX engine on Apple Silicon.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://lmstudio.ai/docs/app/system-requirements&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;LM Studio, system requirements&lt;/a&gt;, Apple Silicon M1 to M4 and macOS 14 or later, 16GB RAM recommended.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;The models&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://huggingface.co/lmstudio-community/Qwen2.5-7B-Instruct-MLX-4bit&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Qwen2.5 7B Instruct, MLX 4bit&lt;/a&gt;, 4.28GB, Apache 2.0 license, the pick for a 16GB Mac.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://huggingface.co/lmstudio-community/Mistral-Small-3.2-24B-Instruct-2506-MLX-4bit&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Mistral Small 24B, MLX 4bit&lt;/a&gt;, around 13GB, Apache 2.0 license, the pick for a 32GB Mac.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Going further&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://ollama.com&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Ollama&lt;/a&gt;, run a model with a single command, with local API.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/ml-explore/mlx&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Apple MLX&lt;/a&gt;, the framework optimized for Apple Silicon’s unified memory.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;em&gt;Technical terms? &lt;a href=&quot;https://macsouverain.com/en/glossaire/&quot;&gt;Check the glossary.&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>ia</category><category>modele-local</category><category>macos</category><category>apple-silicon</category><category>lm-studio</category><category>mlx</category><category>tutoriels</category><enclosure url="https://macsouverain.com/content/images/2026/07/feature-installer-premier-modele-ia-local-mac-2.png" length="0" type="image/png"/></item><item><title>Wazuh 5.0 lands, your home SIEM evolves</title><link>https://macsouverain.com/en/radar-wazuh-5-beta-publique/</link><guid isPermaLink="true">https://macsouverain.com/en/radar-wazuh-5-beta-publique/</guid><description>Wazuh 5.0 in public beta, releasing late June/early July. Filebeat dit au revoir, clusters enabled by default, new engine. Your 4.x install will upgrade. Don&apos;t worry, we&apos;ll explain it all.</description><pubDate>Thu, 02 Jul 2026 07:22:47 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;&lt;strong&gt;Wazuh 5.0 lands in public beta, revamps its architecture, Filebeat’s gone, clustering enabled by default, new engine. If you’ve set up your SIEM with our series, your 4.x install is still running, the upgrade to 5.0 won’t be blind.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What changes for you&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Check your version with &lt;code&gt;wazuh-control info&lt;/code&gt;, recent 4.11 and later still receive updates.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Snapshot your VM and backup &lt;code&gt;/var/ossec/etc/&lt;/code&gt; before attempting the 5.0 upgrade.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Wait for a stable 5.0.x release (5.0.1 or 5.0.2) before migrating, we’ll update the SIEM series then, migration guide included.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;If you’ve set up your home SIEM following episode 2/7 of the Sovereign SIEM series, brace yourself: Wazuh 5.0 is here in public beta, and it’s shaking things up. Don’t panic, but do take a look before blindly updating. And we’ll update the &lt;a href=&quot;https://macsouverain.com/en/nis2-splunk-pourquoi-pme-siem-souverain/&quot;&gt;SIEM&lt;/a&gt; series when the time comes.&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id=&quot;the-deal&quot;&gt;The Deal&lt;/h2&gt;
&lt;p&gt;Wazuh has just released the public beta of its 5.0 version, with a stable release estimated for late June or early July 2026. This isn’t just a version bump, it’s an architectural overhaul.&lt;/p&gt;
&lt;p&gt;What’s changing, concretely: Filebeat is gone, replaced by a native indexer-connector integrated into the manager. Every Wazuh server becomes a cluster node by default, even in a single-server install. The old analysisd engine, which handled logs and triggered rules, is replaced by a new one. Vulnerability detection has shifted to Wazuh Indexer, centralized. And Role-Based Access Control (RBAC), fine-grained permissions management, has been entirely revamped.&lt;/p&gt;
&lt;p&gt;Direct consequence for MacSouverain: episode 2/7 of the Sovereign SIEM series, which documents the 4.x architecture step-by-step, will be partially outdated once 5.0 is released. We’ll update the series when 5.0 is stable, not before.&lt;/p&gt;
&lt;h2 id=&quot;why-it-matters-to-you&quot;&gt;Why It Matters to You&lt;/h2&gt;
&lt;p&gt;If you’ve followed the guide in episode 2/7 of the Sovereign SIEM series to set up your own SIEM, you’re likely running on a 4.x version. Good news, your setup continues to work, no one’s pulling the plug. Bad news, upgrading to 5.0 won’t be as simple as &lt;code&gt;apt upgrade&lt;/code&gt; without reading the docs. Bye-bye Filebeat, that means your log pipeline’s plumbing is changing. Default cluster, that changes your initial config even if you’re sticking to one machine.&lt;/p&gt;
&lt;p&gt;Practical translation: if you were planning to upgrade as soon as it’s out, take an hour to read the release notes and make a snapshot first. If you’re on a stable setup you use daily, wait for one or two corrective versions, let the early adopters iron out the kinks.&lt;/p&gt;
&lt;h2 id=&quot;what-it-changes-for-you&quot;&gt;What It Changes for You&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Note which version of Wazuh you’re currently running. On your manager, use &lt;code&gt;wazuh-control info&lt;/code&gt; or check the dashboard. If you’re on 4.11 or later, you’re on the branch that’s still receiving updates.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Before attempting to upgrade to 5.0, snapshot your VM or backup your config &lt;code&gt;/var/ossec/etc/&lt;/code&gt; and your Wazuh Indexer’s state. A clean rollback saves your bacon if the new engine doesn’t play nice with your custom rules.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Wait for the stable 5.0.x release (at least 5.0.1 or 5.0.2) before migrating a production personal install. Beta’s for testing on disposable VMs, not the one monitoring your network every day. Keep an eye on: Wazuh’s official migration guide from 4.x to 5.0, and the upcoming overhaul of episode 2/7 of the Sovereign SIEM series on MacSouverain.&lt;/p&gt;
&lt;h2 id=&quot;sources&quot;&gt;Sources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/wazuh/wazuh/discussions/34029&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Wazuh 5.0 Public Beta Discussion (GitHub)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-analyse</category><category>wazuh</category><category>siem</category><category>auto-hebergement</category><category>souverainete</category></item><item><title>Chat Control: The EU&apos;s playing with your encryption&apos;s fate.</title><link>https://macsouverain.com/en/radar-csar-chat-control-trilogue-final/</link><guid isPermaLink="true">https://macsouverain.com/en/radar-csar-chat-control-trilogue-final/</guid><pubDate>Wed, 01 Jul 2026 13:46:25 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;&lt;strong&gt;June 29th saw the EU’s 5th and final trilogue on Chat Control 2.0 (CSAR). At stake: mass scanning of your private messages before encryption, versus a Parliament defending end-to-end. The outcome’s now, deciding if WhatsApp, Signal, and iMessage stay truly encrypted in Europe.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What to watch:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; The publication of the trilogue’s outcome (or failure) and whether there’s an explicit exemption for end-to-end encryption.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; The return of « Chat Control 1.0 » (extended voluntary scanning) that Metsola threatens to reopen if 2.0 stalls: a Trojan horse if negotiations fail.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Mandatory age verification, which kills online anonymity far beyond fighting CSAM.&lt;/p&gt;
&lt;/div&gt;
&lt;h2 id=&quot;what-happened-on-june-29th&quot;&gt;What Happened on June 29th&lt;/h2&gt;
&lt;p&gt;Under Cypriot presidency, the EU Council held what was billed as the &lt;strong&gt;fifth and final trilogue&lt;/strong&gt; on the CSAR regulation, dubbed « Chat Control 2.0 », on June 29th. The presidency’s stated goal was to secure a political agreement before the summer break.&lt;/p&gt;
&lt;p&gt;The sticking point remains unchanged. On one side, a Council text that &lt;strong&gt;mandates mass surveillance&lt;/strong&gt; of private communications via ‘detection orders’, a provision that the Council’s own legal service deems contrary to Article 7 of the Charter of Fundamental Rights. On the other, a Parliament that, on March 26, 2026, rejected mass surveillance by a single vote (307 to 306), and is holding firm to &lt;strong&gt;end-to-end encryption protection&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;As of now, no official source has published the outcome of this trilogue: neither success nor failure confirmed. The Cypriot presidency is pushing for formal adoption in July, but the impasse over encryption could still derail everything. Keep an eye on this silence in the coming days.&lt;/p&gt;
&lt;h2 id=&quot;why-it-matters-to-you&quot;&gt;Why It Matters to You&lt;/h2&gt;
&lt;p&gt;Client-side scanning requires inspecting your messages &lt;strong&gt;on your device, before&lt;/strong&gt; they’re encrypted. The crypto of WhatsApp, Signal, or iMessage isn’t broken, it’s neutered: your message is read plaintext on your phone before it’s sent. And this inspection point isn’t reserved for ‘nice guys’, it’s exploitable by any attacker who gets their hands on it.&lt;/p&gt;
&lt;p&gt;Adding to this is the &lt;strong&gt;mandatory age verification&lt;/strong&gt;, which requires tying a real identity to your messaging account. It’s the end of default anonymity, sold under the guise of child protection.&lt;/p&gt;
&lt;h2 id=&quot;what-you-can-do&quot;&gt;What You Can Do&lt;/h2&gt;
&lt;p&gt;Nothing to install today: it’s a political signal, not a product flaw. But keep Signal as a fallback messaging option, watch your MEP’s positions, and follow EDRi / Patrick Breyer for real-time updates. Once it’s published, we’ll update our articles on the topic.&lt;/p&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-signal</category><category>souverainete</category><category>chiffrement</category><category>ue</category></item><item><title>Deploy Wazuh everywhere, your SIEM finally sees your network</title><link>https://macsouverain.com/en/wazuh-agents-parc-siem-souverain/</link><guid isPermaLink="true">https://macsouverain.com/en/wazuh-agents-parc-siem-souverain/</guid><description>Enroll Wazuh agents on your Linux servers, Macs, and Windows workstations, with log upload via Tailnet, never through the open internet.</description><pubDate>Wed, 01 Jul 2026 12:50:41 GMT</pubDate><content:encoded>&lt;p&gt;In the previous episode, you set up a security console that runs Wazuh on your hardened VPS, acting as a manager, indexer, and dashboard on a single node, with the dashboard locked to Tailnet-only. A fine machine, but for now, it only sees itself.&lt;/p&gt;
&lt;p&gt;That’s useful, your server monitors itself, validates your hardening, and reports its own CVEs. But a SIEM that only looks at the server it’s running on is like a camera pointed at its own box. Today, we’re turning it towards the rest of the room.&lt;/p&gt;
&lt;p&gt;We’re going to &lt;strong&gt;deploy Wazuh agents on your fleet&lt;/strong&gt;. Your Linux servers, Macs, and Windows machines. Each machine gets a sensor that collects its logs, security events, and file integrity, and sends it all back to the manager. Your SIEM goes from nearsighted to panoramic.&lt;/p&gt;
&lt;p&gt;One non-negotiable rule, set from episode 1 and commanding this whole chapter. &lt;strong&gt;This communication goes through the Tailnet, never through the open internet.&lt;/strong&gt; The manager only listens on your private mesh. An agent not in your Tailnet talks to nothing.&lt;/p&gt;
&lt;p&gt;This stack, I use daily. The commands that follow are the ones you’ll type yourself, in order, on your manager, then on each machine to monitor.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;before-you-start&quot;&gt;Before you start&lt;/h2&gt;
&lt;p&gt;Three things to keep in mind before the first command.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What you need.&lt;/strong&gt; The Wazuh manager from episode 2, operational. Administrator access on each machine to enroll. And most importantly, &lt;strong&gt;each machine to monitor must be a member of your Tailnet&lt;/strong&gt;, just like your manager. You’ll run &lt;code&gt;tailscale up&lt;/code&gt; on each endpoint. Without it, nothing comes back.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What changes.&lt;/strong&gt; At the end, your dashboard won’t list a single agent, but as many as you have machines. Each one reports its logs, audit configuration, vulnerabilities, and file integrity, all in one place, under your single eye.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What doesn’t change.&lt;/strong&gt; An agent &lt;strong&gt;observes&lt;/strong&gt;, it doesn’t block anything. It tells you when an application starts, when a file changes, when a connection fails. Deciding which applications have the right to launch on your Macs, that comes later, with another tool, in another episode. Here, we’re just looking. We’re not blocking anything yet.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;opening-the-right-doors-and-only-those&quot;&gt;Opening the right doors, and only those&lt;/h2&gt;
&lt;p&gt;Before touching any endpoints, a gesture on the manager. Until now, your server hasn’t been listening to the outside world on anything, and the dashboard has been folded onto the Tailnet. Remote agents need to reach the manager on two ports.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Port 1515&lt;/strong&gt;, for &lt;strong&gt;enrollment&lt;/strong&gt;. That’s the initial handshake, encrypted, where a new agent introduces itself and receives its authentication key.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Port 1514&lt;/strong&gt;, for &lt;strong&gt;reporting&lt;/strong&gt; logs and events, once the agent is enrolled.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;And that’s where your sovereignty comes into play. Those two ports, you open &lt;strong&gt;only on the Tailscale interface&lt;/strong&gt;, never globally.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; ufw&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; allow&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; in&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; on&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; tailscale0&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; to&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; any&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; port&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; 1514&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; proto&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; tcp&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; ufw&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; allow&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; in&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; on&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; tailscale0&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; to&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; any&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; port&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; 1515&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; proto&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; tcp&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;You recognize the gesture, it’s the same one as SSH in episode 1, the same one as the dashboard in episode 2. You allow on &lt;code&gt;tailscale0&lt;/code&gt;, your encrypted mesh, and nowhere else. The trap would be to type &lt;code&gt;sudo ufw allow 1514/tcp&lt;/code&gt; all on its own. That command opens your SIEM to the world’s scanners. Ours keeps it invisible.&lt;/p&gt;
&lt;p&gt;Check your firewall status.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; ufw&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; status&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;You should see your two new rules, both marked &lt;code&gt;on tailscale0&lt;/code&gt;. If there’s a global &lt;code&gt;1514/tcp&lt;/code&gt; hanging around, get rid of it without hesitation, that’s a breach.&lt;/p&gt;
&lt;p&gt;Last thing to note, the Tailscale address of your manager, the one every agent will target.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;tailscale&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; ip&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; -4&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;That’s the address you’ll pass to the agents. Not the VPS’s public IP, it doesn’t listen on these ports anyway. In everything that follows, I’ll note it as &lt;code&gt;&amp;#x3C;IP_TAILSCALE_OF_THE_MANAGER&gt;&lt;/code&gt;.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;step-1-enrolling-a-linux-server&quot;&gt;Step 1, enrolling a Linux server&lt;/h2&gt;
&lt;p&gt;We start with the simplest one, an Ubuntu or Debian server. Three steps, add the Wazuh repository, install the agent and give it the manager’s address, start it up.&lt;/p&gt;
&lt;p&gt;First, the official repository.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; apt-get&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; install&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; gnupg&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; apt-transport-https&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;curl&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; -s&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; https://packages.wazuh.com/key/GPG-KEY-WAZUH&lt;/span&gt;&lt;span style=&quot;color:#D73A49&quot;&gt; |&lt;/span&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt; sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; gpg&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; --no-default-keyring&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; --keyring&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; gnupg-ring:/usr/share/keyrings/wazuh.gpg&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; --import&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt; &amp;#x26;&amp;#x26; &lt;/span&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; chmod&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; 644&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; /usr/share/keyrings/wazuh.gpg&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#005CC5&quot;&gt;echo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; &quot;deb [signed-by=/usr/share/keyrings/wazuh.gpg] https://packages.wazuh.com/4.x/apt/ stable main&quot;&lt;/span&gt;&lt;span style=&quot;color:#D73A49&quot;&gt; |&lt;/span&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt; sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; tee&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; -a&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; /etc/apt/sources.list.d/wazuh.list&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; apt-get&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; update&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Nothing exotic. You import the signature key for the repository, declare the Wazuh repository, refresh the package list. Standard APT routine.&lt;/p&gt;
&lt;p&gt;Then, the installation, with the trick that does all the work. Prefixing the installation command with the &lt;code&gt;WAZUH_MANAGER&lt;/code&gt; variable tells the package which manager to enroll with during installation.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; WAZUH_MANAGER=&quot;&amp;#x3C;IP_TAILSCALE_OF_THE_MANAGER&gt;&quot;&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; WAZUH_AGENT_GROUP=&quot;linux&quot;&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; apt-get&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; install&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; wazuh-agent&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The &lt;code&gt;WAZUH_AGENT_GROUP=&quot;linux&quot;&lt;/code&gt; puts this machine in a group named &lt;code&gt;linux&lt;/code&gt;. You’ll see what groups are for later, just remember to assign them now.&lt;/p&gt;
&lt;p&gt;Finally, start the service and enable it on boot.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; systemctl&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; daemon-reload&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; systemctl&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; enable&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; wazuh-agent&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; systemctl&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; start&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; wazuh-agent&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;And there you go, your Linux server is reporting. If you’re running on RHEL, Alma, or Rocky, the principle is the same, just replace the APT repository with the YUM one and &lt;code&gt;apt-get install&lt;/code&gt; with &lt;code&gt;dnf install&lt;/code&gt;. The &lt;code&gt;WAZUH_MANAGER&lt;/code&gt; variable works the same way.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;step-2-enrolling-a-mac&quot;&gt;Step 2, enrolling a Mac&lt;/h2&gt;
&lt;p&gt;Macs get interesting because macOS has its own rules. Let’s start with the deployment, the twist comes right after.&lt;/p&gt;
&lt;p&gt;The Mac agent comes as a &lt;code&gt;.pkg&lt;/code&gt; package, and there are two versions, one for Apple Silicon and one for old Intel Macs. On a recent fleet, it’s Apple Silicon.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;curl&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; -O&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; https://packages.wazuh.com/4.x/macos/wazuh-agent-4.14.5-1.arm64.pkg&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#005CC5&quot;&gt;echo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; &quot;WAZUH_MANAGER=&apos;&amp;#x3C;IP_TAILSCALE_OF_THE_MANAGER&gt;&apos; &amp;#x26;&amp;#x26; WAZUH_AGENT_GROUP=&apos;macos&apos;&quot;&lt;/span&gt;&lt;span style=&quot;color:#D73A49&quot;&gt; &gt;&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; /tmp/wazuh_envs&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; installer&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; -pkg&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; wazuh-agent-4.14.5-1.arm64.pkg&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; -target&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; /&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The mechanism changes a bit in form but not in substance. On macOS, deployment variables don’t go in front of the command, they’re written to a temporary file, &lt;code&gt;/tmp/wazuh_envs&lt;/code&gt;, that the installer reads on the fly. The result is the same, the agent knows its manager and its group. For an Intel Mac, replace &lt;code&gt;arm64&lt;/code&gt; with &lt;code&gt;intel64&lt;/code&gt; in both lines that mention it.&lt;/p&gt;
&lt;p&gt;Then, start the agent.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; launchctl&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; bootstrap&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; system&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; /Library/LaunchDaemons/com.wazuh.agent.plist&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;On macOS, the agent lives under &lt;code&gt;/Library/Ossec/&lt;/code&gt;, and its control binary is &lt;code&gt;/Library/Ossec/bin/wazuh-control&lt;/code&gt;, with the &lt;code&gt;start&lt;/code&gt;, &lt;code&gt;stop&lt;/code&gt;, and &lt;code&gt;status&lt;/code&gt; verbs if you want to pilot it by hand.&lt;/p&gt;
&lt;h3 id=&quot;the-macos-landmine-tcc-and-full-disk-access&quot;&gt;The macOS landmine, TCC and full disk access&lt;/h3&gt;
&lt;p&gt;Now, the truth that most tutorials gloss over. On macOS, your agent will start, enroll, appear active in the dashboard, and yet remain &lt;strong&gt;half-blind&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;The reason is &lt;strong&gt;TCC&lt;/strong&gt;, for &lt;strong&gt;Transparency, Consent and Control&lt;/strong&gt;, Apple’s permission system by usage. It filters access to sensitive folders, and it doesn’t cut any corners. The agent isn’t an application in Apple’s sense, it’s a package of binaries. Without explicit permission, it’s refused access to the zones TCC protects. Its file integrity monitoring turns on, but it can’t read what it can’t see.&lt;/p&gt;
&lt;p&gt;The workaround is to &lt;strong&gt;grant the agent full disk access&lt;/strong&gt;. On a managed fleet, that’s done properly with MDM, a configuration profile pushed by Jamf or equivalent, that declares the permission once and for all on all machines. On a single machine, you do it by hand in the privacy settings. That’s an extra step on top of Linux, and it’s specific to Apple, so keep that in mind before you’re surprised that the Mac reports less than the server.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;step-3-enrolling-a-windows-machine&quot;&gt;Step 3, enrolling a Windows machine&lt;/h2&gt;
&lt;p&gt;Windows, last one in. The agent installs via an MSI package, in silent mode, from a PowerShell console opened as an administrator.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;powershell&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#005CC5&quot;&gt;msiexec.exe&lt;/span&gt;&lt;span style=&quot;color:#D73A49&quot;&gt; /&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;i.\wazuh&lt;/span&gt;&lt;span style=&quot;color:#D73A49&quot;&gt;-&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;agent&lt;/span&gt;&lt;span style=&quot;color:#D73A49&quot;&gt;-&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt;4.14&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;.&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt;5&lt;/span&gt;&lt;span style=&quot;color:#D73A49&quot;&gt;-&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt;1.&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;msi &lt;/span&gt;&lt;span style=&quot;color:#D73A49&quot;&gt;/&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;q WAZUH_MANAGER&lt;/span&gt;&lt;span style=&quot;color:#D73A49&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt;&quot;&amp;#x3C;IP_TAILSCALE_OF_THE_MANAGER&gt;&quot;&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt; WAZUH_AGENT_NAME&lt;/span&gt;&lt;span style=&quot;color:#D73A49&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt;&quot;accounting-post&quot;&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt; WAZUH_AGENT_GROUP&lt;/span&gt;&lt;span style=&quot;color:#D73A49&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt;&quot;windows&quot;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Same logic as everywhere, the manager, a readable name for the machine, and its group. The &lt;code&gt;WAZUH_AGENT_NAME&lt;/code&gt; is handy on Windows, where you’ll soon have ten machines that look the same, so it’s nice to give them names.&lt;/p&gt;
&lt;p&gt;Then, start the service.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;powershell&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#005CC5&quot;&gt;Start-Service&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt; WazuhSvc&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;In CMD, that’s &lt;code&gt;NET START WazuhSvc&lt;/code&gt;, take your pick. The agent installs under &lt;code&gt;C:\Program Files (x86)\ossec-agent&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;What Windows brings specifically is &lt;strong&gt;reading Windows event logs&lt;/strong&gt;, the famous Security, System, and Application trio, where failed login attempts, privilege elevations, and account creations land. And the FIM can &lt;strong&gt;monitor the registry&lt;/strong&gt;, malware’s favorite playground for surviving reboots. Your Windows machine is no longer a black box.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;step-4-verifying-that-everythings-reporting&quot;&gt;Step 4, verifying that everything’s reporting&lt;/h2&gt;
&lt;p&gt;Three machines enrolled, time to make sure they’re talking to the manager. Back on the Wazuh server, one command.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; /var/ossec/bin/agent_control&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; -l&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;It lists all your agents with their ID, name, and status. Four possible statuses, and you need to know how to read them.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Active&lt;/strong&gt;, the agent is connected and reporting. That’s what you want to see everywhere.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Pending&lt;/strong&gt;, it just enrolled and is waiting for its first full handshake. That’s temporary, give it a minute.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Disconnected&lt;/strong&gt;, it was connected and isn’t anymore. The manager considers an agent lost if it hasn’t given a sign of life in fifteen minutes.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Never connected&lt;/strong&gt;, it enrolled but never managed to report. That’s the classic symptom of a closed port or a machine outside the Tailnet.&lt;/li&gt;
&lt;/ul&gt;
&lt;figure class=&quot;kg-card kg-image-card&quot;&gt;
&lt;img src=&quot;https://macsouverain.com/content/images/2026/07/capture-agents-list-wazuh-agents-parc-siem-souverain-3.png&quot; class=&quot;kg-image&quot; loading=&quot;lazy&quot; alt=&quot;List of enrolled agents and their connection status, viewed from the manager&quot;&gt;
&lt;/figure&gt;
&lt;p&gt;The same table exists on the dashboard, prettier to the eye. The Agents view shows the count of Active, Disconnected, Pending, Never connected, and the details of each machine, its modules, its last activity. That’s your control room, now populated.&lt;/p&gt;
&lt;figure class=&quot;kg-card kg-image-card&quot;&gt;
&lt;img src=&quot;https://macsouverain.com/content/images/2026/07/capture-agents-dashboard-wazuh-agents-parc-siem-souverain-3.png&quot; class=&quot;kg-image&quot; loading=&quot;lazy&quot; alt=&quot;Overview of agents in the Wazuh dashboard, count by status&quot;&gt;
&lt;/figure&gt;
&lt;p&gt;And there’s the shift. Each active machine runs, on itself, exactly the modules your server was running on itself in episode 2. The CIS configuration audit. Vulnerability detection on its packages. File integrity monitoring. Log analysis. Except now, it’s not one machine, it’s your fleet, and everything converges on one screen.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;going-further-monitoring-a-specific-folder&quot;&gt;Going further, monitoring a specific folder&lt;/h2&gt;
&lt;p&gt;By default, the agent monitors sensitive system directories. But you’ve got a folder that matters more than the others, your client data, your accounting, a shared drive. You want to know, down to the second, if anyone touches it.&lt;/p&gt;
&lt;p&gt;That’s the &lt;strong&gt;FIM&lt;/strong&gt;’s job, &lt;strong&gt;File Integrity Monitoring&lt;/strong&gt;. And instead of editing each machine by hand, you use &lt;strong&gt;groups&lt;/strong&gt; that you assigned during enrollment. A group shares a configuration, pushed automatically by the manager to all its members. You write once, it applies everywhere.&lt;/p&gt;
&lt;p&gt;On the manager, edit the shared configuration file for the relevant group, for example &lt;code&gt;/var/ossec/etc/shared/linux/agent.conf&lt;/code&gt;, and declare the folder to monitor in the &lt;code&gt;&amp;#x3C;syscheck&gt;&lt;/code&gt; block.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;xml&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;syscheck&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;  &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;directories&lt;/span&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt; check_all&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt;&quot;yes&quot;&lt;/span&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt; realtime&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;=&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt;&quot;yes&quot;&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;/srv/client-data&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;directories&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&amp;#x3C;/&lt;/span&gt;&lt;span style=&quot;color:#22863A&quot;&gt;syscheck&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Two attributes to understand. &lt;code&gt;check_all=&quot;yes&quot;&lt;/code&gt; records everything that characterizes a file, its cryptographic hashes, its size, its owner, its permissions, its dates. Any change is spotted. &lt;code&gt;realtime=&quot;yes&quot;&lt;/code&gt; asks for &lt;strong&gt;real-time monitoring&lt;/strong&gt;, the alert comes at the moment of the change, without waiting for the next scan.&lt;/p&gt;
&lt;p&gt;A note of honesty on that real-time. It’s only available on &lt;strong&gt;Linux and Windows&lt;/strong&gt;. On macOS, the FIM falls back on &lt;strong&gt;scheduled scans&lt;/strong&gt;, periodic. A modification between two passes is only seen on the next pass. That’s not a bug, it’s a macOS limitation, but keep that in mind before you count on an instant alert on the Mac side. Another detail that trips people up, the folder must exist before you restart the agent, or it’s ignored.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;if-its-not-working&quot;&gt;If it’s not working&lt;/h2&gt;
&lt;p&gt;Deploying agents is simple when everything goes right, and it always has the same handful of causes when it goes wrong. Here are the real ones, in the order you’ll encounter them.&lt;/p&gt;
&lt;h3 id=&quot;problem-the-agent-stays-in-never-connected&quot;&gt;Problem, the agent stays in ‘Never connected’&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Probable cause&lt;/strong&gt;, in nine cases out of ten in our case, a network path issue. Either the manager’s ports 1514 and 1515 aren’t open on &lt;code&gt;tailscale0&lt;/code&gt;, or the machine isn’t in the Tailnet, or you gave the agent the VPS’s public IP instead of its Tailscale address.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Solution&lt;/strong&gt;, check those three. On the manager, &lt;code&gt;sudo ufw status&lt;/code&gt; should show your two new rules both marked &lt;code&gt;on tailscale0&lt;/code&gt;. On the endpoint, &lt;code&gt;tailscale status&lt;/code&gt; should confirm it’s in the mesh. And re-read the value of &lt;code&gt;WAZUH_MANAGER&lt;/code&gt;, it should point to the manager’s Tailscale address, not its public IP.&lt;/p&gt;
&lt;h3 id=&quot;problem-the-agent-goes-from-active-to-disconnected&quot;&gt;Problem, the agent goes from ‘Active’ to ‘Disconnected’&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Probable cause&lt;/strong&gt;, it was reporting, it’s not anymore. The manager cuts off after fifteen minutes without news. Often, the agent service has stopped, or the Tailscale link has dropped.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Solution&lt;/strong&gt;, check that the service is running. &lt;code&gt;sudo systemctl status wazuh-agent&lt;/code&gt; on Linux, &lt;code&gt;Start-Service WazuhSvc&lt;/code&gt; on Windows, &lt;code&gt;/Library/Ossec/bin/wazuh-control status&lt;/code&gt; on macOS. And take a look at the agent’s log, always in the same place depending on the platform, &lt;code&gt;/var/ossec/logs/ossec.log&lt;/code&gt; on Linux, &lt;code&gt;/Library/Ossec/logs/ossec.log&lt;/code&gt; on Mac, the installation folder on Windows.&lt;/p&gt;
&lt;h3 id=&quot;problem-the-mac-is-active-but-isnt-reporting-much&quot;&gt;Problem, the Mac is ‘Active’ but isn’t reporting much&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Probable cause&lt;/strong&gt;, the infamous TCC. The agent is running, but without full disk access, it’s blind on the zones macOS protects.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Solution&lt;/strong&gt;, grant the agent full disk access, by MDM on a managed fleet, by hand on a single machine in the privacy settings.&lt;/p&gt;
&lt;h3 id=&quot;problem-the-agents-are-active-but-the-dashboard-stays-empty&quot;&gt;Problem, the agents are ‘Active’ but the dashboard stays empty&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Probable cause&lt;/strong&gt;, that’s not an agent problem. If the machines are reporting but nothing appears in the interface, the culprit is downstream, between the manager and the indexer. Remember episode 2, &lt;strong&gt;Filebeat&lt;/strong&gt; pushes alerts to the indexer.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Solution&lt;/strong&gt;, diagnose on the server side, not on the agent side. Check that Filebeat is talking to the indexer and that the indexer is digesting. Don’t waste an hour reinstalling agents that are working perfectly.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;the-first-day-is-noisy-thats-normal&quot;&gt;The first day is noisy, that’s normal&lt;/h2&gt;
&lt;p&gt;One last word of honesty, because I’d rather you hear it from me before you figure it out on your own. The day you plug in ten machines at once, your dashboard is going to &lt;strong&gt;explode&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;Each machine arrives with its configuration audit reporting dozens of deviations from the CIS baseline. Each FIM reports legitimate files that change as they’re used. At first, the noise drowns out the signal, and that’s disorienting.&lt;/p&gt;
&lt;p&gt;That’s not a bug. That’s the raw state of a SIEM you’ve just turned on in a real fleet. The work that follows, calibrating rules, filtering out false positives, adjusting thresholds so you’re only woken up when it matters, that’s human work, not magic software. We said it from the start of the series, the hard part isn’t the tech, it’s the tuning. That fine-tuning, that calibrated alerting, that’s episode 7’s payoff.&lt;/p&gt;
&lt;p&gt;For now, enjoy. Your SIEM isn’t looking at its own belly anymore, it’s seeing your network.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;for-the-impatient&quot;&gt;For the impatient&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;What this article does.&lt;/strong&gt; You deploy Wazuh agents on your fleet, your Linux servers, Macs, and Windows machines. Each machine reports its logs, configuration audit, vulnerabilities, and file integrity to the manager. Everything goes through the Tailnet, never through the open internet. You verify the enrollment, extend file monitoring via groups, and weather the first day’s noise.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Concretely, the commands.&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;On the manager, open ports 1514 and 1515 on &lt;code&gt;tailscale0&lt;/code&gt; only: &lt;code&gt;sudo ufw allow in on tailscale0 to any port 1514 proto tcp&lt;/code&gt;, then the same for &lt;code&gt;1515&lt;/code&gt;. Never globally.&lt;/li&gt;
&lt;li&gt;Prerequisite, every endpoint must be in the Tailnet (&lt;code&gt;tailscale up&lt;/code&gt;).&lt;/li&gt;
&lt;li&gt;Linux: add the Wazuh repository, then &lt;code&gt;sudo WAZUH_MANAGER=&quot;&amp;#x3C;IP_TAILSCALE_OF_THE_MANAGER&gt;&quot; WAZUH_AGENT_GROUP=&quot;linux&quot; apt-get install wazuh-agent&lt;/code&gt;, then &lt;code&gt;systemctl enable --now wazuh-agent&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;macOS: &lt;code&gt;curl -O&lt;/code&gt; the &lt;code&gt;.pkg&lt;/code&gt; arm64, write the variables in &lt;code&gt;/tmp/wazuh_envs&lt;/code&gt;, &lt;code&gt;sudo installer -pkg... -target /&lt;/code&gt;, &lt;code&gt;sudo launchctl bootstrap system /Library/LaunchDaemons/com.wazuh.agent.plist&lt;/code&gt;. Then grant the agent full disk access.&lt;/li&gt;
&lt;li&gt;Windows: &lt;code&gt;msiexec.exe /i.\wazuh-agent-4.14.5-1.msi /q WAZUH_MANAGER=&quot;&amp;#x3C;IP_TAILSCALE_OF_THE_MANAGER&gt;&quot; WAZUH_AGENT_GROUP=&quot;windows&quot;&lt;/code&gt;, then &lt;code&gt;Start-Service WazuhSvc&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Verify from the manager: &lt;code&gt;sudo /var/ossec/bin/agent_control -l&lt;/code&gt;, aim for ‘Active’ everywhere.&lt;/li&gt;
&lt;li&gt;Extend FIM via the group, in &lt;code&gt;/var/ossec/etc/shared/&amp;#x3C;group&gt;/agent.conf&lt;/code&gt;, &lt;code&gt;&amp;#x3C;syscheck&gt;&lt;/code&gt; block with &lt;code&gt;check_all=&quot;yes&quot; realtime=&quot;yes&quot;&lt;/code&gt; (real-time Linux and Windows only, not macOS).&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2 id=&quot;in-summary&quot;&gt;In summary&lt;/h2&gt;
&lt;p&gt;You started with a SIEM that only saw itself, and you end with a SIEM that sees your fleet.&lt;/p&gt;
&lt;p&gt;You &lt;strong&gt;opened the agent ports on the Tailnet only&lt;/strong&gt;, 1514 and 1515 on &lt;code&gt;tailscale0&lt;/code&gt;, never globally. You &lt;strong&gt;enrolled your three families of machines&lt;/strong&gt;, Linux in three commands, Macs managing TCC, Windows in silent MSI. You &lt;strong&gt;verified the reporting&lt;/strong&gt; with &lt;code&gt;agent_control -l&lt;/code&gt; and in the dashboard, and you &lt;strong&gt;extended file monitoring&lt;/strong&gt; on your sensitive folders via groups.&lt;/p&gt;
&lt;p&gt;Each machine you plug in is free on the license side, it’s 100% open source, no limit on agents. Where the American SaaS charges by log volume, by the number of machines, the more you see, the more you pay. With you, seeing more costs nothing.&lt;/p&gt;
&lt;p&gt;But you’re observing. You see attacks, you’re not blocking anything yet. In episode 4, you add the first active line of defense, &lt;strong&gt;CrowdSec&lt;/strong&gt;, the community network that blocks known attackers before they even knock on your door. Your SIEM starts to bite.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;series-recap&quot;&gt;Series recap&lt;/h2&gt;
&lt;p&gt;Seven episodes to build your sovereign security plumbing, brick by brick.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/nis2-splunk-pourquoi-pme-siem-souverain/&quot;&gt;Episode 0, the bedrock of the series.&lt;/a&gt;&lt;/strong&gt; Why an SME needs a sovereign SIEM, NIS2, GDPR, and the cost of doing nothing.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/vps-durci-socle-siem-souverain/&quot;&gt;Episode 1, the foundation.&lt;/a&gt;&lt;/strong&gt; The hardened VPS outside the CLOUD Act.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/wazuh-tout-en-un-siem-souverain/&quot;&gt;Episode 2, Wazuh all-in-one.&lt;/a&gt;&lt;/strong&gt; Manager, indexer, and dashboard on a single node.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Episode 3, agents everywhere.&lt;/strong&gt; Deploying Wazuh on your servers, Macs, and Windows machines. This one.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/crowdsec-premiere-ligne-siem-souverain/&quot;&gt;Episode 4, community network defense.&lt;/a&gt;&lt;/strong&gt; Blocking known attackers before they arrive.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/rspamd-mail-siem-souverain/&quot;&gt;Episode 5, email filter.&lt;/a&gt;&lt;/strong&gt; Anti-spam and anti-phishing in front of your mail server.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Episode 6, Mac launch control.&lt;/strong&gt; Deciding which applications have the right to launch.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Episode 7, alerting and honest cost.&lt;/strong&gt; Calibrated notifications and honest financial breakdown against SaaS.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;em&gt;Technical terms? &lt;a href=&quot;https://macsouverain.com/en/glossaire/&quot;&gt;Check the glossary.&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>ms-pro</category><category>nis2</category><category>siem</category><category>wazuh</category><category>securite</category><category>tutoriel</category><enclosure url="https://macsouverain.com/content/images/2026/07/feature-wazuh-agents-parc-siem-souverain-3.png" length="0" type="image/png"/></item><item><title>Wazuh: Your all-in-one, homegrown Splunk for the price of a VPS</title><link>https://macsouverain.com/en/wazuh-tout-en-un-siem-souverain/</link><guid isPermaLink="true">https://macsouverain.com/en/wazuh-tout-en-un-siem-souverain/</guid><description>Install Wazuh (manager, indexer, dashboard) on a single node, harden passwords and dashboard in Tailnet-only, adjust JVM heap, initial dashboards without agents.</description><pubDate>Sat, 20 Jun 2026 13:13:52 GMT</pubDate><content:encoded>&lt;p&gt;In the previous episode, you set up an empty safe: a VPS on a Swiss host, hardened to the bone, SSH via key, firewall closed, administration behind Tailscale, encrypted backups off-site. A nice machine. But for now… it’s not watching anything!&lt;/p&gt;
&lt;p&gt;Today, we’re filling it up. We’re installing &lt;strong&gt;Wazuh&lt;/strong&gt;, the brain of the whole stack, on this single node. Manager, indexer, and dashboard, the three central components of a SIEM, on the same machine. It’s the all-in-one mode, and that’s exactly what a small business needs to start with.&lt;/p&gt;
&lt;p&gt;The promise of the series is in one sentence, set at the opening. &lt;strong&gt;The functional equivalent of a Splunk, for the price of a VPS.&lt;/strong&gt; By the end of this article, you’ll have a security console running, seeing your own machine already, and it won’t have cost you a single euro in licensing. Whereas the same perimeter with an American vendor would run from a few thousand to tens of thousands of dollars per year, depending on the size of your fleet, with your logs stored in a very unfavorable jurisdiction.&lt;/p&gt;
&lt;p&gt;This stack, I use every day. The commands that follow are the ones you’ll type yourself, in order, on the server from episode 1.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;three-components-one-machine&quot;&gt;Three components, one machine&lt;/h2&gt;
&lt;p&gt;Before installing, understand what you’re installing. A SIEM Wazuh isn’t a monolithic block, it’s three roles that pass the baton.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;The manager&lt;/strong&gt; is the brain. It receives logs, runs the analysis engine, correlates events, applies rules, and raises alerts. It’s the one that decides that a sudden spike of failed login attempts at 3 AM deserves to wake you up.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The indexer&lt;/strong&gt; is the memory. It stores and indexes alerts so you can search, filter, and go back in time. It’s a fork of OpenSearch, the open-source search engine, which is itself a fork of Elasticsearch. Remember this detail, it’ll come back to bite us in the best possible way.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The dashboard&lt;/strong&gt; is the window. The web interface through which you read all this, accessible on port 443. It queries the manager for configuration and the indexer for data.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;A fourth player works in the shadows, &lt;strong&gt;Filebeat&lt;/strong&gt;, the pipe that pushes alerts from the manager to the indexer. You won’t touch it, but when something goes wrong, it’s often the first thing you look at.&lt;/p&gt;
&lt;p&gt;In an enterprise, these three components live on separate machines to handle the volume and maintain high availability. For a small business with up to a hundred machines being watched, it’s overkill. The all-in-one mode puts all three on the same server, and that’s more than enough to start with. The official documentation even sizes this mode for 1 to 100 agents.&lt;/p&gt;
&lt;p&gt;We’ll come back to the moment when all-in-one isn’t enough later on. But for now, one machine, and let’s go.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;installation-in-one-command&quot;&gt;Installation in one command&lt;/h2&gt;
&lt;p&gt;Wazuh offers two paths. The first, step-by-step, installs the indexer, then the manager, then the dashboard separately, editing the configuration files by hand. It’s educational, it’s long, and you don’t need it for a single node. The second is the official assistant, which does everything at once.&lt;/p&gt;
&lt;p&gt;We’re taking the assistant.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;curl&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; -sO&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; https://packages.wazuh.com/4.14/wazuh-install.sh&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt; &amp;#x26;&amp;#x26; &lt;/span&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; bash./wazuh-install.sh&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; -a&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Let’s break it down. The &lt;code&gt;curl -sO&lt;/code&gt; downloads the installation script from the official Wazuh repository, branch &lt;code&gt;4.14&lt;/code&gt;. The &lt;code&gt;sudo bash./wazuh-install.sh -a&lt;/code&gt; runs it with admin rights, and the &lt;code&gt;-a&lt;/code&gt; flag means &lt;strong&gt;all-in-one&lt;/strong&gt;, all on one machine. This flag tells the assistant to install and configure the three components on this same machine, generate TLS certificates for secure communication between them, and create passwords.&lt;/p&gt;
&lt;p&gt;At the end, the assistant displays the admin password in the console. Note it down, it’s your first key to the kingdom. If you missed it while scrolling through the terminal, you can retrieve it properly with:&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; tar&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; -O&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; -xvf&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; wazuh-install-files.tar&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; wazuh-install-files/wazuh-passwords.txt&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;This command extracts, without decompressing onto the disk, the file that lists all the passwords generated during installation. We’ll deal with these passwords in a moment, because passwords generated by a script are just a starting point, not a final destination.&lt;/p&gt;
&lt;p&gt;At the time of writing, the stable version is &lt;strong&gt;4.14.5&lt;/strong&gt;, released on April 23, 2026. The installation URL points to &lt;code&gt;4.14/&lt;/code&gt;, so you’re still getting the latest version of that branch. If a 4.15 has been released when you’re reading this, check the current branch on the &lt;a href=&quot;https://documentation.wazuh.com/current/release-notes/index-4x.html&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;release notes page&lt;/a&gt; before running the command.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;the-memory-trap-where-90-of-installs-fail&quot;&gt;The memory trap, where 90% of installs fail&lt;/h2&gt;
&lt;p&gt;If there’s one thing you should remember from this episode, it’s this. The number one cause of Wazuh installs that struggle, crash, or die after a few days is poorly configured memory on the indexer.&lt;/p&gt;
&lt;p&gt;Remember, the indexer is a fork of OpenSearch, which runs on the &lt;strong&gt;JVM&lt;/strong&gt;, the Java virtual machine. And the JVM reserves a fixed zone of memory for itself at startup, called the &lt;strong&gt;heap&lt;/strong&gt; (or the “heap space”). Too small, the indexer suffocates under the data. Too big, it takes up all the RAM and starves the manager, dashboard, and OS running alongside it on the same machine. That’s the whole point of the single-node setup, three big memory hogs sharing one envelope.&lt;/p&gt;
&lt;p&gt;The official rule is clear and simple. &lt;strong&gt;The heap is half of the machine’s RAM.&lt;/strong&gt; And both the minimum and maximum boundaries should be the same.&lt;/p&gt;
&lt;p&gt;Why the same? Because if you let the JVM resize its heap on the fly, it spends all its time reallocating memory instead of indexing your logs. By fixing the floor and ceiling at the same value, you’re telling it “here’s your sandbox, not a byte more or less, now get to work”.&lt;/p&gt;
&lt;p&gt;You set this in a file, &lt;code&gt;/etc/wazuh-indexer/jvm.options&lt;/code&gt;.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; nano&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; /etc/wazuh-indexer/jvm.options&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Find the two lines &lt;code&gt;-Xms&lt;/code&gt; (the lower bound) and &lt;code&gt;-Xmx&lt;/code&gt; (the upper bound), and set them to half of your RAM. That’s why episode 1 had you aim for 12 GB of RAM, not 8. On a 12 GB machine, the heap takes up 6 GB, leaving 6 GB for everything else, the manager, dashboard, Filebeat, and the system. Plenty of room to breathe.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;plaintext&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span&gt;-Xms6g&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;-Xmx6g&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Then restart the indexer to apply the new value.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; systemctl&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; restart&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; wazuh-indexer&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;If you started with 8 GB to test, your heap value is &lt;code&gt;-Xms4g&lt;/code&gt; / &lt;code&gt;-Xmx4g&lt;/code&gt;, and you’re living on the edge with 4 GB left for everything else. It’s tight, but it works.&lt;/p&gt;
&lt;p&gt;One last detail for the curious. The “half of RAM” rule also has an absolute ceiling, around 32 GB of heap. Don’t worry about this for now, it’s a good general OpenSearch practice, not a Wazuh-specific limit, and at the scale of a small business, you’re nowhere near it. I’m just mentioning it so you’re not surprised if you run into it later while scaling up a bigger infrastructure.&lt;/p&gt;
&lt;p&gt;While we’re on the topic of memory, a related rule. &lt;strong&gt;The JVM should never swap.&lt;/strong&gt; If the system starts using the disk as additional memory for the indexer, performance tanks. On a properly sized VPS, with the heap set to half of RAM, you shouldn’t be swapping. But it’s the first thing to check when things start to slow down.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;locking-down-the-house&quot;&gt;Locking down the house&lt;/h2&gt;
&lt;p&gt;The installation gives you a functional console. It also gives you passwords generated by a script and a dashboard that, by default, wants to be accessible. Two things to take back under your control before you take your seat.&lt;/p&gt;
&lt;h3 id=&quot;change-all-the-default-passwords&quot;&gt;Change all the default passwords&lt;/h3&gt;
&lt;p&gt;The passwords generated during installation aren’t bad in and of themselves, but they’re sitting in a file on the server, and you didn’t create them. Good hygiene dictates that you regenerate everything with your own secrets. Wazuh comes with a tool for this, deposited by the assistant in the indexer.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; bash&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; /usr/share/wazuh-indexer/plugins/opensearch-security/tools/wazuh-passwords-tool.sh&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; -a&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; -A&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; -au&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; wazuh&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; -ap&lt;/span&gt;&lt;span style=&quot;color:#D73A49&quot;&gt; &amp;#x3C;&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt;CURRENT_PASSWOR&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt;D&lt;/span&gt;&lt;span style=&quot;color:#D73A49&quot;&gt;&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The &lt;code&gt;-a&lt;/code&gt; flag targets all users, &lt;code&gt;-A&lt;/code&gt; applies the change, and the &lt;code&gt;-au&lt;/code&gt; / &lt;code&gt;-ap&lt;/code&gt; pair provides the current admin user and password. In all-in-one mode, the tool automatically propagates the new passwords to the relevant components. You don’t have to recopy them one by one.&lt;/p&gt;
&lt;p&gt;Your new passwords should meet a minimum complexity, &lt;strong&gt;8 to 64 characters, with at least one uppercase letter, one lowercase letter, one number, and one symbol&lt;/strong&gt; from &lt;code&gt;.*+?-&lt;/code&gt;. Generate them with your password manager, don’t make them up on the spot.&lt;/p&gt;
&lt;h3 id=&quot;certificates-already-there&quot;&gt;Certificates, already there&lt;/h3&gt;
&lt;p&gt;Good news, you don’t have to do anything on the internal encryption front. The &lt;code&gt;-a&lt;/code&gt; flag on the assistant generated a little certificate authority and deposited the certificates under &lt;code&gt;/etc/wazuh-indexer/certs/&lt;/code&gt; and so on. The three components are already talking to each other securely. It’s done, it’s clean, don’t touch it.&lt;/p&gt;
&lt;p&gt;The only visible effect is that when you first access the dashboard, your browser will show a security warning because the certificate is self-signed and not recognized by a public authority. That’s normal, and for a dashboard that won’t be exposed to the public, it’s perfectly acceptable. Click through the warning, and you’re in.&lt;/p&gt;
&lt;p&gt;A quick note to anticipate the temptation. You might want a “real” certificate, via Let’s Encrypt. &lt;strong&gt;Don’t do it here.&lt;/strong&gt; Let’s Encrypt validates your certificate by verifying that your server responds on the internet, which means you have to open a port to the world. That’s the exact opposite of what we’ve been building since episode 1.&lt;/p&gt;
&lt;p&gt;If the self-signed certificate really bugs you, Tailscale can emit a proper certificate for your node without any public exposure. But honestly, for a console that only you’ll be consulting, the self-signed certificate is good enough. We’re not going to punch a hole in the wall we just built to make a browser warning go away.&lt;/p&gt;
&lt;h3 id=&quot;the-dashboard-invisible-from-the-internet&quot;&gt;The dashboard, invisible from the internet&lt;/h3&gt;
&lt;p&gt;This is the most important security gesture of the episode, and it’s the one that separates a sovereign SIEM from one sitting on the curb. By default, nothing guarantees that your dashboard will stay private. The port 443 serving the interface should &lt;strong&gt;never&lt;/strong&gt; be accessible from the internet.&lt;/p&gt;
&lt;p&gt;Your security dashboards, they’re &lt;strong&gt;maps of your weaknesses&lt;/strong&gt;, exactly what an attacker dreams of seeing.&lt;/p&gt;
&lt;p&gt;The series’ rule, set in episode 1, is inflexible. &lt;strong&gt;No public services.&lt;/strong&gt; The dashboard lives behind Tailscale, accessible only to you, just like SSH did before it.&lt;/p&gt;
&lt;p&gt;Two locks, working together. First, we ask the dashboard to only listen on the Tailscale IP of the server, not on all interfaces. That’s set in its configuration file.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; nano&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; /etc/wazuh-dashboard/opensearch_dashboards.yml&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Find the &lt;code&gt;server.host&lt;/code&gt; line. If it’s set to &lt;code&gt;0.0.0.0&lt;/code&gt;, the dashboard is listening on all interfaces, including the public IP. That’s a no-no. Set it to the Tailscale IP of your server, the one you get with &lt;code&gt;tailscale ip -4&lt;/code&gt;, from episode 1.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;plaintext&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span&gt;server.host: &quot;&amp;#x3C;YOUR_TAILSCALE_IP&gt;&quot;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Then restart the dashboard.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; systemctl&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; restart&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; wazuh-dashboard&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Next, the firewall, as a belt and braces. We’re following exactly the pattern from episode 1 for SSH, allowing port 443 only on the private network interface, never globally.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; ufw&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; allow&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; in&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; on&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; tailscale0&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; to&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; any&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; port&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; 443&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; proto&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; tcp&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The pitfall to avoid is typing &lt;code&gt;sudo ufw allow 443/tcp&lt;/code&gt; on its own. That command opens the dashboard to the whole world. Ours only opens it on &lt;code&gt;tailscale0&lt;/code&gt;, your encrypted mesh. The difference is not cosmetic, one exposes your security console to internet scanners, the other makes it invisible.&lt;/p&gt;
&lt;p&gt;The result is a dashboard accessible only by a member of your private network. A scan of your public IP reveals nothing. In line with the sovereign promise, and in line with common sense.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;the-grand-tour&quot;&gt;The grand tour&lt;/h2&gt;
&lt;p&gt;Log in. From a machine on your Tailnet, open &lt;code&gt;https://&amp;#x3C;YOUR_TAILSCALE_IP&gt;&lt;/code&gt; in your browser. Certificate warning, click through. Login &lt;code&gt;admin&lt;/code&gt;, your new password. You’re in the console.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://macsouverain.com/content/images/2026/06/capture-03-dashboard-overview-wazuh-tout-en-un-siem-souverain-1.png&quot; alt=&quot;Wazuh dashboard overview&quot;&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;This screenshot is from a production Wazuh instance already populated with several agents. On your fresh install, you’ll only see agent 000, the server watching itself.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;And there’s a pleasant surprise, it’s not empty. You were expecting maybe an inert screen while you deploy agents. Not at all. In all-in-one mode, the server comes with a &lt;strong&gt;local agent&lt;/strong&gt;, with the ID 000, watching itself. Your machine is already under the eye of your own SIEM, before you’ve even touched the rest of your network.&lt;/p&gt;
&lt;p&gt;In practical terms, you’ve already got data and several modules running on this node.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;SCA&lt;/strong&gt;, for &lt;strong&gt;Security Configuration Assessment&lt;/strong&gt;, is active by default, without any tuning, and it scans your machine against baseline security type CIS benchmarks. It tells you where your config deviates from best practices, a service too many, a permission too broad, a loose SSH setting. You’ll probably find, validated in black and white, the hardening decisions from episode 1.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Vulnerability detection&lt;/strong&gt; is on by default, but not active. Wazuh inventories the packages installed on the machine and crosses them with known CVE databases. If one of your packages has a published vulnerability, it flags it, with the reference and severity. A note of honesty, unlike SCA and FIM, which run on their own, the local node scan doesn’t trigger on startup. You have to enable it in the &lt;code&gt;/var/ossec/etc/internal_options.conf&lt;/code&gt; file, set &lt;code&gt;vulnerability-detection.disable_scan_manager&lt;/code&gt; to &lt;code&gt;0&lt;/code&gt;, then restart the manager. Two minutes later, your own machine is scanned too.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;File Integrity Monitoring&lt;/strong&gt;, or &lt;strong&gt;FIM&lt;/strong&gt;, is watching your sensitive files and alerting you if any of them change. A sudden change in a system file is often the first sign that you’ve got an unwanted guest.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Local log analysis&lt;/strong&gt;, digesting the machine’s logs and turning them into readable alerts.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img src=&quot;https://macsouverain.com/content/images/2026/06/capture-04-sca-node-wazuh-tout-en-un-siem-souverain-1.png&quot; alt=&quot;SCA benchmark results on the local node, Ubuntu CIS benchmark&quot;&gt;&lt;/p&gt;
&lt;p&gt;And there are the compliance dashboards, ready to go. Wazuh ships with views tagged &lt;strong&gt;PCI DSS, HIPAA, GDPR, NIST 800-53, TSC&lt;/strong&gt;, with report generation. Each alert carries the compliance ID it touches, for example a &lt;code&gt;gdpr_IV_32&lt;/code&gt; tag that points to article 32 of the GDPR on security of processing.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://macsouverain.com/content/images/2026/06/capture-05-gdpr-wazuh-tout-en-un-siem-souverain-1.png&quot; alt=&quot;GDPR compliance dashboard, alerts tagged by requirement&quot;&gt;&lt;/p&gt;
&lt;p&gt;A necessary honesty note on NIS2. Wazuh provides all the functional bricks that NIS2 demands, continuous monitoring, file integrity, vulnerability analysis, configuration control, reporting. But it doesn’t have a &lt;strong&gt;NIS2&lt;/strong&gt; compliance dashboard ready to click like it does for GDPR.&lt;/p&gt;
&lt;p&gt;To follow NIS2 finely, you’ll build your own views, leaning on the GDPR and NIST tags already present. Wazuh gives you the compliance toolkit, it doesn’t make you compliant all by itself. The calibration of rules, retention policy, incident response, that’s all human work. We called it out right from the opening, the hard part isn’t the tech, it’s the adjustment.&lt;/p&gt;
&lt;p&gt;For now, your SIEM is seeing itself. It’s watching its own machine, and that’s already precious for validating your hardening. The real jump is when it starts seeing the rest of your network. That’s episode 3, deploying agents, the moment when your SIEM starts really seeing your network.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;when-all-in-one-isnt-enough-anymore&quot;&gt;When all-in-one isn’t enough anymore&lt;/h2&gt;
&lt;p&gt;The single-node setup isn’t magic, and I’m not going to sell you the opposite. It has a ceiling, and it’s important to know where it is before you hit it.&lt;/p&gt;
&lt;p&gt;The metric that matters is &lt;strong&gt;EPS&lt;/strong&gt;, events per second that your machine can handle. A well-dimensioned node, around 16 GB of RAM and 8 vCPUs, can handle around 5,000 events per second. For a small business with up to 50 or 100 machines being watched, with normal log activity, you’re well below saturation. The all-in-one mode holds up just fine.&lt;/p&gt;
&lt;p&gt;The day you approach saturation, the symptom is unpleasant. When the ingestion queue saturates, Wazuh doesn’t slow down politely, it &lt;strong&gt;drops events&lt;/strong&gt; it can’t process fast enough. And an event dropped is an alert you’ll never see. A camera that stops recording during rush hour.&lt;/p&gt;
&lt;p&gt;When that happens, you switch to multi-node, manager on one side, indexer on the other, or even several of each. Detail against intuition but important, Wazuh &lt;strong&gt;scales better horizontally than vertically&lt;/strong&gt;. Two nodes with medium resources are better than one big node. That’s another project, outside this series, but you know now that the door exists.&lt;/p&gt;
&lt;p&gt;For a small business just starting out, remember this, all-in-one is perfect for starting, not designed for infinity. And there’s plenty of room between the two.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;what-it-would-have-cost-you-elsewhere&quot;&gt;What it would have cost you elsewhere&lt;/h2&gt;
&lt;p&gt;We’ve been teasing this figure since the series opened. Time to put it down, for this specific component.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Wazuh’s licensing cost is zero.&lt;/strong&gt; It’s 100% open source, under GPLv2 license, and there’s no paid tier. No agent limit, no user limit, no log ingestion limit. Your only expense is the VPS you set up in episode 1, between 15 and 30 euros per month depending on the size, plus your installation and calibration time. And that’s it.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Splunk’s bill has a different face.&lt;/strong&gt; A warning first, Splunk doesn’t publish its prices officially, so everything that follows is an order of magnitude estimate based on secondary serious sources, not the official quote. With that reservation, the principle is simple, you pay by the gigabytes of logs ingested per day, counted in gigabytes per day.&lt;/p&gt;
&lt;p&gt;The challenge is to translate that into a real-world park size, because a price per gigabyte doesn’t mean anything until you know how many gigabytes a small business produces. Useful benchmark, with reasonable security logging, count around fifty megabytes of logs per workstation per day, so around one gigabyte per day for fifteen to twenty workstations. From there, we can put some numbers on it, licensing only, keeping Wazuh in the mirror.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;15 workstations&lt;/strong&gt;, around 1 GB of logs per day. Splunk, around 2,000 to 5,000 dollars per year. Wazuh, the VPS, 180 to 360 euros per year. That’s the point.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;50 workstations&lt;/strong&gt;, around 4 to 5 GB per day. Splunk, around 8,000 to 12,500 dollars per year. Wazuh, the same VPS, to the euro.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;100 workstations&lt;/strong&gt;, around 8 to 10 GB per day. Splunk, around 15,000 to 25,000 dollars per year. Wazuh, still the same VPS.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Beyond a hundred workstations surveilled, we’re in another world on both sides, multi-node clusters on Wazuh, paliers in the tens or hundreds of thousands of dollars per year on Splunk. That’s another scale, outside the perimeter of this series thought for the small business.&lt;/p&gt;
&lt;p&gt;The difference isn’t just about money. It’s about &lt;strong&gt;trajectory&lt;/strong&gt;. With Wazuh, your infrastructure cost is flat, you ingest more logs, your VPS handles it, your bill doesn’t change. With Splunk, the meter spins with every additional gigabyte. The more your SIEM sees wide and deep, the more it costs you dear, whereas seeing wide and deep is literally its job.&lt;/p&gt;
&lt;p&gt;And there’s the question that started this series, who controls the data. Your logs, they’re the complete fingerprints of your network. With Wazuh, they’re on your machine, in Switzerland, under your control.&lt;/p&gt;
&lt;p&gt;With the SaaS American vendor, they’re subject to the CLOUD Act. The price, that’s one thing. Who holds the data, that’s the thing that matters the most.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;in-summary&quot;&gt;In summary&lt;/h2&gt;
&lt;p&gt;You started with an empty safe, and you’re leaving with a security console running.&lt;/p&gt;
&lt;p&gt;You installed &lt;strong&gt;Wazuh’s three components in one command&lt;/strong&gt;, manager, indexer, and dashboard on your single node. You set the &lt;strong&gt;memory trap that breaks most installs&lt;/strong&gt;, the indexer’s heap to half of RAM, with identical lower and upper bounds, which justifies the 12 GB recommended in episode 1.&lt;/p&gt;
&lt;p&gt;You took back control of security, regenerated passwords, certificates already in place, and especially the dashboard locked down to the Tailnet, invisible from the internet. And you took your first tour of the owner’s deck, SCA, vulnerabilities, file integrity monitoring, local log analysis, compliance dashboards ready to go, all on your own machine, without deploying any remote agents yet.&lt;/p&gt;
&lt;p&gt;All for zero euros in licensing, where the same perimeter with an American vendor would run from a few thousand to tens of thousands of dollars per year, depending on the size of your fleet, with your logs stored in a very unfavorable jurisdiction.&lt;/p&gt;
&lt;p&gt;But your SIEM only sees itself so far. It’s watching its own machine, and that’s already precious for validating your hardening. The real jump is when it starts seeing the rest of your network. That’s episode 3, deploying agents, the moment when your SIEM starts really seeing your network.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;series-reminder&quot;&gt;Series reminder&lt;/h2&gt;
&lt;p&gt;Seven episodes to build your sovereign security plumbing, brick by brick.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/nis2-splunk-pourquoi-pme-siem-souverain/&quot;&gt;Episode 0, the bedrock of the series.&lt;/a&gt;&lt;/strong&gt; Why an SME needs a sovereign SIEM, NIS2, GDPR, and the cost of doing nothing.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/vps-durci-socle-siem-souverain/&quot;&gt;Episode 1, the foundation.&lt;/a&gt;&lt;/strong&gt; The VPS hardened outside the CLOUD Act.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Episode 2, Wazuh all-in-one.&lt;/strong&gt; Manager, indexer, and dashboard on a single node. You’ve just read it.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/wazuh-agents-parc-siem-souverain/&quot;&gt;Episode 3, agents everywhere.&lt;/a&gt;&lt;/strong&gt; Deploying on your servers, Macs, and Windows.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/crowdsec-premiere-ligne-siem-souverain/&quot;&gt;Episode 4, community network defense.&lt;/a&gt;&lt;/strong&gt; Blocking known attackers before they arrive.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/rspamd-mail-siem-souverain/&quot;&gt;Episode 5, mail filter.&lt;/a&gt;&lt;/strong&gt; Anti-spam and anti-phishing in front of your mail server.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Episode 6, Mac execution control.&lt;/strong&gt; Deciding which apps have the right to launch.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Episode 7, alerting and total cost.&lt;/strong&gt; Calibrated notifications and honest financial breakdown against SaaS.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;em&gt;Unknown technical terms? &lt;a href=&quot;https://macsouverain.com/en/glossaire/&quot;&gt;Check the glossary.&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>ms-pro</category><category>nis2</category><category>siem</category><category>wazuh</category><category>securite</category><category>tutoriels</category><enclosure url="https://macsouverain.com/content/images/2026/06/feature-wazuh-tout-en-un-siem-souverain-1.png" length="0" type="image/png"/></item><item><title>Your stance is leaking through the network, not through your iPhone.</title><link>https://macsouverain.com/en/surveillance-telecom-ss7/</link><guid isPermaLink="true">https://macsouverain.com/en/surveillance-telecom-ss7/</guid><description>Tech companies track any mobile device through telecom interconnection flaws. No iPhone patches needed.</description><pubDate>Wed, 17 Jun 2026 13:41:39 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;&lt;strong&gt;Citizen Lab linked, in its “Bad Connection” report from April 2026, real surveillance traffic to operators’ infrastructures. Commercial entities can locate any mobile device through network interconnection flaws, SS7 in 2G/3G, Diameter in 4G, without ever touching the device. Nothing to patch on your iPhone: the hole is in the network, not in iOS.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What you need to watch out for&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; No setting blocks this vector: neither Isolation mode, nor eSIM, nor Signal, nor turning off data. The only workaround is to make yourself unreachable by turning on airplane mode or turning off your phone. Don’t think you’re covered just because you’re encrypting your messages.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Use 2FA codes for apps, not SMS. It doesn’t stop geolocation, but it closes the interception of codes via the same network.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; The real defense is structural, on the operators’ and regulators’ side. NIS2 and ENISA frame the risk, but no strong technical obligation yet requires securing interconnection.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;The Citizen Lab published a report in April 2026 that for the first time links real surveillance traffic to identified operator infrastructures. The principle has been known for ten years, but the finding remains unsettling: commercial companies can locate any mobile device in the world without ever touching the device itself. Your iPhone is not at fault, and that’s precisely the problem.&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id=&quot;the-fact&quot;&gt;The Fact&lt;/h2&gt;
&lt;p&gt;The report is called “Bad Connection”. It documents actors who track phones across over twenty countries, with one of them conducting over 1700 attacks, almost all of which are dedicated to geolocation. The described target is a “VVIP” in the Middle East, but the typical profile of this market is known: journalists, dissidents, and political figures.&lt;/p&gt;
&lt;p&gt;The mechanism exploits the protocols that make operators communicate with each other when you roam or change antennas. They were designed in an era when a handful of national operators trusted each other implicitly. Today, there are thousands of them, and this implicit trust has become a backdoor. Three vectors coexist: SS7 on 2G and 3G, Diameter on 4G, and a variant called SIMjacker that uses a silent SMS executed on your SIM card. The Citizen Lab is categorical: these are not software bugs, but inherent flaws in global telecoms.&lt;/p&gt;
&lt;p&gt;A crucial detail: usually, it’s not your operator selling your location. There are two markets. The first one exists: in the US, major operators have sold the location of their subscribers to data brokers, resulting in nearly $200 million in FCC fines in 2024.&lt;/p&gt;
&lt;p&gt;The second one, the heart of this radar, is different: surveillance companies like Rayzone, Circles, or Cognyte exploit interconnection flaws by leasing legitimate access points to the global network, often via a small accomplice operator. They remotely query the network of your target, without their consent or their operator’s.&lt;/p&gt;
&lt;h2 id=&quot;why-this-matters-to-you&quot;&gt;Why This Matters to You&lt;/h2&gt;
&lt;p&gt;Here’s the angle that’s unsettling. You can encrypt your messages, harden your Mac, close every macOS setting one by one, but your physical location still passes through infrastructure you don’t control, and Apple has no say in it. There’s nothing to patch on this end because it’s not a hole in iOS. It’s the architecture of the network itself.&lt;/p&gt;
&lt;p&gt;So, most of the precautions you think of won’t help against this specific vector, and it’s better to know that than to be lulled into a false sense of security. “Hardcore” mode on your iPhone doesn’t touch an SS7 request that happens in the network. An eSIM changes the format of the card, not the protocol: as long as there’s a reachable number, you’re exposed.&lt;/p&gt;
&lt;p&gt;Signal protects the content of your messages, not the signaling metadata that reveals where you are. Turning off data or GPS doesn’t matter either, the tracking uses the cell identifier, not your puck. The only individually effective solution is airplane mode or turning off the phone, which is hardly practical daily.&lt;/p&gt;
&lt;p&gt;Two caveats to avoid selling you false barriers. Two-factor authentication by app has real utility, but against another risk: SMS interception of your codes, not geolocation. A dedicated number or eSIM reduces the link between your location and your real identity, but doesn’t make that number any less traceable.&lt;/p&gt;
&lt;p&gt;The real defense is structural. It plays out with operators and regulators, with signaling firewalls that the GSMA documents in its FS.11 guide. Your security here doesn’t depend on you, but on infrastructure and a legal framework you don’t control.&lt;/p&gt;
&lt;p&gt;Let’s be clear about the real risk: for an average person, the likelihood of being targeted remains low. This matters not because of an imminent threat to you, but because of what it reveals. Digital sovereignty doesn’t stop at the edge of your device: as long as you have a SIM card, your location circulates in a weakly constrained global network.&lt;/p&gt;
&lt;h2 id=&quot;what-you-do-now&quot;&gt;What You Do Now&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Recalibrate your expectations, that’s the most useful gesture here. Keep Signal, “Hardcore” mode, and your good habits, they protect content and the device, but don’t believe they make you invisible on the network. Confusing the two is the trap.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; For connection codes, abandon SMS and switch to app-based or hardware key two-factor authentication. It won’t protect you from geolocation, but it closes the interception of codes via the same network, and that’s a real risk to your accounts.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; If you have a genuinely exposed profile, like a journalist, political dissident, or lawyer on a sensitive case, the only serious individual lever is physical discipline: in airplane mode or with the phone turned off, your device is no longer registered on the network, there’s nothing to locate. You only become traceable again upon re-registration. A dedicated number cloisters your identity, but remains traceable the same way.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4.&lt;/strong&gt; For the rest, the real work isn’t on your desk. Follow the subject on the regulator side: NIS2 and ENISA set a framework, but no strong technical obligation yet forces operators to close these flaws. That’s where pressure needs to be applied.&lt;/p&gt;
&lt;h2 id=&quot;sources&quot;&gt;Sources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://citizenlab.ca/research/uncovering-global-telecom-exploitation-by-covert-surveillance-actors/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;“Bad Connection: Uncovering Global Telecom Exploitation by Covert Surveillance Actors”, Citizen Lab, April 2026&lt;/a&gt; (primary source)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.enisa.europa.eu/publications/signalling-security-in-telecom-ss7-diameter-5g&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Signalling Security in Telecom SS7/Diameter/5G, ENISA&lt;/a&gt; (protocols deemed fundamentally flawed, EU recommendations)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.gsma.com/solutions-and-impact/technologies/security/cybersecurity-knowledge-base/cybersecurity-document-library/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;FS.11 SS7 Interconnect Security Monitoring and Firewall Guidelines, GSMA&lt;/a&gt; (the signaling firewall reference, industry self-regulation)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cbsnews.com/news/60-minutes-hacking-your-phone/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Hacking Your Phone, 60 Minutes, CBS, 2016&lt;/a&gt; (interview with Representative Ted Lieu via SS7, demonstration on an elected official)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://krebsonsecurity.com/2024/04/fcc-fines-major-u-s-wireless-carriers-for-selling-customer-location-data/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;FCC Fines Major U.S. Wireless Carriers for Selling Customer Location Data, Krebs on Security, 2024&lt;/a&gt; (the distinct market of data brokers, $200M USD in fines)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;em&gt;Technical terms? &lt;a href=&quot;https://macsouverain.com/en/glossaire/&quot;&gt;Check the glossary.&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-signal</category><category>surveillance</category><category>telecom</category><category>ss7</category><category>vie-privee</category></item><item><title>Your AI can be turned off by the US, build your own</title><link>https://macsouverain.com/en/ton-ia-peut-etre-eteinte-monte-la-tienne/</link><guid isPermaLink="true">https://macsouverain.com/en/ton-ia-peut-etre-eteinte-monte-la-tienne/</guid><description>Access to cutting-edge AI models is becoming an American geopolitical lever. Here&apos;s what&apos;s running locally on your Mac, with 16 to 32GB RAM, and why that&apos;s your real foundation.</description><pubDate>Wed, 17 Jun 2026 13:40:54 GMT</pubDate><content:encoded>&lt;p&gt;&lt;strong&gt;Update, July 2026.&lt;/strong&gt; Fable 5 is accessible again, the directive has been lifted. That doesn’t change the thesis, quite the opposite. Cut off yesterday, restored today, by a decision you don’t control: that’s exactly what depending on a foreign dictate looks like. Your local model, on the other hand, doesn’t need anyone’s permission.&lt;/p&gt;
&lt;p&gt;You open your Mac one morning. Your usual AI tool refuses to respond. Not a bug, not a server crash. A polite message explains that access is no longer available in your region. You haven’t done anything wrong. You’re paying your subscription. You’re perfectly in order. But you’re on the wrong side of a border, and someone in Washington has decided that’s enough.&lt;/p&gt;
&lt;p&gt;This isn’t science fiction anymore. In June 2026, the US government ordered Anthropic, through an export control directive, to suspend access to its two most advanced models, Mythos 5 and Fable 5, for all foreign nationals, worldwide, including its own employees.&lt;/p&gt;
&lt;p&gt;Anthropic had to shut them down for all its clients and is contesting the decision. Access to AI intelligence is becoming what oil, chips, and the dollar already are, &lt;strong&gt;a lever of power in the hands of a state&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;And you’re at the end of the pipe that just got turned off.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;the-directive-as-a-revealer&quot;&gt;The directive as a revealer&lt;/h2&gt;
&lt;p&gt;The first reaction, when you read this, is to think geopolitics. Big maneuvers, blocs that clash, topics for editorialists. Except the cut-off doesn’t happen to a bloc. It happens to you, on your machine, on a Tuesday morning.&lt;/p&gt;
&lt;p&gt;The asymmetry is total. On one side, a supplier under US jurisdiction, subject to its administration’s directives, free to change its access terms overnight. On the other side, you, who’ve built part of your workflow around this tool. You have no say in the decision. You’re not even the target. You’re a collateral damage of a policy that only concerns you by your nationality or geolocation.&lt;/p&gt;
&lt;p&gt;That’s what the directive finally makes visible: &lt;strong&gt;access to a remote model has never been a technical given, it’s a political authorization&lt;/strong&gt;. As long as nothing changes, the authorization is tacit, invisible, comfortable. You end up confusing it with a right. The day it’s withdrawn, you discover you didn’t own anything. You were renting.&lt;/p&gt;
&lt;p&gt;Ask yourself one question. If access is cut off tomorrow, what keeps running? If the answer is “nothing,” you don’t have a work tool. You have a dependency.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;what-depending-on-a-remote-model-really-costs&quot;&gt;What depending on a remote model really costs&lt;/h2&gt;
&lt;p&gt;The remote model is great. That’s true, and acknowledging it doesn’t take away from the rest. It’s more powerful than anything you’ll run locally anytime soon. It updates without you lifting a finger. It doesn’t ask for RAM, installation, or maintenance. For many uses, it’s the most effective tool on the market.&lt;/p&gt;
&lt;p&gt;But comfort has a price, and that price doesn’t show up on the bill.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Every request you send to a remote model, it’s your text leaving your machine&lt;/strong&gt;. Your drafts, notes, documents, ongoing thoughts. They pass through infrastructure you don’t control, in a jurisdiction that isn’t yours, subject to rules you don’t vote for. End-to-end encryption protects the pipe, not the destination. At arrival, your text is read in plain sight by the machine that responds.&lt;/p&gt;
&lt;p&gt;Then there’s the continuity dependency, the one no one talks about until it bites. Your access depends on a subscription, a pricing policy, a business decision, and now a state directive. Four levers you don’t control, plus a fourth that a foreign government controls, and that’s the most dangerous one. The day one of them flips, your workflow stops. Not gradually. All at once.&lt;/p&gt;
&lt;p&gt;That’s exactly the trap we warned about for cloud storage. Your files on someone else’s server are convenient until the account is suspended. Remote AI is the same deal, applied to how you think and produce.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read: &lt;a href=&quot;https://macsouverain.com/en/cloud-ordinateur-quelquun-dautre/&quot;&gt;The cloud, it’s someone else’s computer&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;hr&gt;
&lt;h2 id=&quot;the-sovereignty-reflex-the-map-of-local-models&quot;&gt;The sovereignty reflex, the map of local models&lt;/h2&gt;
&lt;p&gt;Here’s the good news, and it’s more solid than you think. Running an AI model capable of directly on your Mac is no longer a tinkerer’s fantasy. Apple Silicon’s unified memory, the very thing Apple sells for app fluidity, is precisely what makes local inference possible on a consumer machine.&lt;/p&gt;
&lt;p&gt;Before the map, a budget rule, because everything starts there.&lt;/p&gt;
&lt;p&gt;First, total RAM isn’t available RAM. macOS and your applications consume some of it permanently. And behind the “Mac” label, there are two very different machines.&lt;/p&gt;
&lt;p&gt;The entry-level Mac mini comes with &lt;strong&gt;16 GB of unified RAM&lt;/strong&gt;. Subtract 6 to 8 GB for the system and your apps, and you’re left with 8 to 10 GB actually usable for AI, and that’s with closing what’s running.&lt;/p&gt;
&lt;p&gt;A &lt;strong&gt;32 GB&lt;/strong&gt; machine follows the same principle, but leaves you around 20 GB of headroom. In this usable budget, two things need to fit at the same time: the &lt;strong&gt;weight&lt;/strong&gt; of the model (the model itself) and the &lt;strong&gt;context&lt;/strong&gt; (what you feed it and what it generates).&lt;/p&gt;
&lt;p&gt;The practical rule: never aim for a model that fills up the usable budget. On 16 GB, that means a 4 to 8 GB model once quantized. On 32 GB, you can go up to 14, or even 20 GB. If you overflow, the machine falls back on the disk as memory, and then it lags, or it crashes completely.&lt;/p&gt;
&lt;p&gt;So here’s the map of what runs, from most accessible to most demanding.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What a 16 GB Mac already runs&lt;/strong&gt;. That’s the accessible baseline, and it covers most of your daily volume.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;For light work&lt;/strong&gt;, sorting emails, classifying notes, extracting or anonymizing text, tiny 2 to 3 GB models like Llama 3.2 3B, Gemma 3 4B, and Phi-4-mini are more than enough.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;For general work&lt;/strong&gt;, summarizing a document, drafting a memo, managing your correspondence, querying your own note base, a 7 to 8 billion parameter model around 5 GB does the job: Qwen2.5 7B, under Apache 2.0 license, or Llama 3.1 8B. That’s the workhorse of a 16 GB machine.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;To read a scanned PDF or an invoice&lt;/strong&gt; without sending it elsewhere, Qwen2.5-VL 7B (around 5 GB) or Llama 3.2 Vision 11B also work. The ceiling is a 12 to 14 billion parameter model in tight quantization, around 8 to 9 GB, like Qwen2.5 14B: it fits, but with everything else closed and a short context.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;On these repetitive and well-defined tasks, local doesn’t just do the job, it does it better&lt;/strong&gt;: zero network latency, zero requests billed, and your data doesn’t leave your machine.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What 32 GB unlocks&lt;/strong&gt;. The jump to 32 GB isn’t a luxury, it’s what opens the next category.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;For sustained writing and long document analysis&lt;/strong&gt;, Mistral Small 3, a 24 billion parameter model under Apache 2.0 license, fits around 14 GB in its quantized version. Gemma 3 27B runs around 16 GB.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;For multi-step reasoning&lt;/strong&gt;, 32 billion parameter models fit with some squeezing: QwQ 32B, DeepSeek-R1-distill 32B, or Qwen2.5 32B occupy 19 to 20 GB in Q4 quantization. Context becomes tight, and on the most demanding reasoning tasks, the gap with a remote model remains real. Local does a lot. It doesn’t do everything yet.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;On the coding side&lt;/strong&gt;, Qwen2.5-Coder 32B nearly matches remote models for everyday programming: completing, explaining, debugging, refactoring.&lt;/p&gt;
&lt;p&gt;And what doesn’t fit on 16 or 32 GB. Very large models like Llama 3.3 70B, or 405 billion parameter models like DeepSeek-R1 in its full version, require 64 GB of RAM or more. Don’t kid yourself otherwise.&lt;/p&gt;
&lt;p&gt;Now, sovereignty isn’t just about raw power. Two other axes matter.&lt;/p&gt;
&lt;p&gt;The first is provenance. Mistral is French and European, making it the natural sovereign choice for an European reader. Llama, Gemma, and Phi are American. Qwen and DeepSeek are Chinese.&lt;/p&gt;
&lt;p&gt;A caveat here: since the models run locally, &lt;strong&gt;no data leaves your machine, regardless of the model’s origin&lt;/strong&gt;. Provenance doesn’t matter for data exfiltration, it matters for trust, audibility, and not putting all your eggs in one geopolitical basket.&lt;/p&gt;
&lt;p&gt;Running a Chinese model locally doesn’t send anything to Beijing. Choosing an European model is about arbitrating the ecosystem you support and what you can inspect, not about a risk of leakage.&lt;/p&gt;
&lt;p&gt;The second axis is licensing. Not all “open” models are equal legally. Mistral Small 3 and several Qwen models are under Apache 2.0, a permissive license that lets you do anything, including professional use.&lt;/p&gt;
&lt;p&gt;The community license for Llama is usable, but comes with restrictions. For a sovereign baseline, the free license isn’t a legal detail, it’s the guarantee that no one can change the rules under your feet.&lt;/p&gt;
&lt;p&gt;My pick for sovereignty by default, in line with all this. On a 16 GB machine, a 7-8B model covers most of your daily volume: Qwen2.5 7B (Apache 2.0) as first choice, or Llama 3.1 8B. On a 32 GB machine, you upgrade to &lt;strong&gt;Mistral Small 3&lt;/strong&gt; as your daily workhorse (European, Apache 2.0), backed up by a 32B reasoning model like QwQ or DeepSeek-R1-distill, which you bring out for tougher tasks. To run them, three tools are enough: Ollama and LM Studio for simplicity, MLX for those who want to maximize Apple Silicon.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read: &lt;a href=&quot;https://macsouverain.com/en/38-apple-intelligence-ce-qui-sort-de-ton-mac/&quot;&gt;Apple Intelligence, what really leaves your Mac&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;hr&gt;
&lt;h2 id=&quot;the-realistic-threshold-what-local-does-well&quot;&gt;The realistic threshold, what local does well&lt;/h2&gt;
&lt;p&gt;It’s not about slamming the door on the cloud for fun. It’s about knowing what should live on your machine, and what can, eventually, leave.&lt;/p&gt;
&lt;p&gt;Local does very well with everything that’s repetitive, sensitive, or simply daily. Sorting, summarizing, writing, correcting, classifying, anonymizing, reading your own documents. For this part of your work, which is most of the volume, you don’t need anyone. It runs without a connection, without a fee per request, without a line of your text leaving your machine.&lt;/p&gt;
&lt;p&gt;The cloud remains the winner for the top of the pyramid, the most complex reasoning where every point of performance counts. But a supplement is still a supplement. &lt;strong&gt;You don’t lean your daily work on a tap someone else can turn off&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;The right stance isn’t “all local” or “all cloud”. It’s &lt;strong&gt;partitioning&lt;/strong&gt;. Local becomes your base, what runs by default, what your daily work and anything touching sensitive data relies on.&lt;/p&gt;
&lt;p&gt;The cloud becomes a conscious supplement, something you use for a specific purpose, knowing what you’re sending and never sending what shouldn’t leave. The day they cut off your cloud access, you lose a supplement. You don’t lose your base.&lt;/p&gt;
&lt;p&gt;That’s where the argument loops back. If you’re reading this on a recent Mac, you’re already on Apple Silicon. The unified memory that runs these models, you’ve already paid for it. This shift to local doesn’t wait for an investment, or a new machine, or an engineer’s skill. It waits for a decision.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sovereignty in AI isn’t measured by the power of the model you rent. It’s measured by what keeps running the morning they cut off your access&lt;/strong&gt;. The remote model is comfort, and power when a task demands it.&lt;/p&gt;
&lt;p&gt;Your AI base is what lives on your machine. Install one. Run it once, on a real task, to see. You’ll know, concretely, what you have left when they turn off the tap.&lt;/p&gt;
&lt;p&gt;The most down-to-earth question left: how do you install all this, concretely? That’s the subject of the next article, step by step, from download to first prompt, without indigestible command lines.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read soon: Installing and running your first local model on Mac, the step-by-step guide&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;hr&gt;
&lt;h2 id=&quot;sources&quot;&gt;Sources&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;The trigger, US directive and Anthropic&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.anthropic.com/news/fable-mythos-access&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Anthropic, Statement on the US government directive to suspend access to Fable 5 and Mythos 5&lt;/a&gt;, Anthropic’s official statement, applying the export order while contesting it (12 June 2026).&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://techcrunch.com/2026/06/12/anthropics-safety-warnings-may-have-just-backfired-the-government-has-pulled-the-plug-on-its-most-powerful-ai/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;TechCrunch, Anthropic’s safety warnings may have just backfired&lt;/a&gt;, the global shutdown of Fable 5 and Mythos 5 (12 June 2026).&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.theregister.com/ai-and-ml/2026/06/15/us-clampdown-on-anthropic-models-sends-eu-sovereignty-surge-into-overdrive/5255487&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;The Register, US clampdown on Anthropic models sends EU sovereignty surge into overdrive&lt;/a&gt;, how the cut-off accelerates Europe’s sovereignty shift, the very angle of this article (15 June 2026).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Open-weight models cited&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://mistral.ai/news/mistral-small-3&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Mistral AI, Mistral Small 3&lt;/a&gt;, the 24B Apache 2.0 European pick (30 January 2025).&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://qwenlm.github.io/blog/qwen2.5/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Qwen, Qwen2.5&lt;/a&gt;, the Qwen2.5 family, 7B variants under Apache 2.0.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.llama.com/llama3_1/license/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Meta, Llama 3.1 Community License&lt;/a&gt;, permissive license with restrictions.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Local execution on Apple Silicon&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://ollama.com&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Ollama&lt;/a&gt;, running models locally, data that doesn’t leave your machine.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://lmstudio.ai&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;LM Studio&lt;/a&gt;, desktop app for running LLM privately, supports MLX on Mac.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/ml-explore/mlx&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Apple, MLX&lt;/a&gt;, the framework optimized for Apple Silicon’s unified memory.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;em&gt;Technical terms? &lt;a href=&quot;https://macsouverain.com/en/glossaire/&quot;&gt;Check the glossary.&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>ia</category><category>souverainete</category><category>modele-local</category><category>macos</category><category>apple-silicon</category><category>tutoriel</category><enclosure url="https://macsouverain.com/content/images/2026/07/feature-ton-ia-peut-etre-eteinte-monte-la-tienne.png" length="0" type="image/png"/></item><item><title>Your sovereign SIEM&apos;s foundation, a hardened VPS outside the CLOUD Act</title><link>https://macsouverain.com/en/vps-durci-socle-siem-souverain/</link><guid isPermaLink="true">https://macsouverain.com/en/vps-durci-socle-siem-souverain/</guid><description>A European VPS, Cloud Act-proof, hardened SSH, reduced attack surface via Tailscale, off-site encrypted backups.</description><pubDate>Fri, 12 Jun 2026 06:11:45 GMT</pubDate><content:encoded>&lt;p&gt;Before detecting anything, &lt;strong&gt;you need a place to install your SIEM&lt;/strong&gt;. A machine. Not just any machine, not configured any way.&lt;/p&gt;
&lt;p&gt;In &lt;a href=&quot;https://macsouverain.com/en/nis2-splunk-pourquoi-pme-siem-souverain/&quot;&gt;the opening episode&lt;/a&gt;, we established why. &lt;strong&gt;GDPR already requires you to detect and notify a breach within 72 hours&lt;/strong&gt;, NIS2 has widened the net, and it won’t stop there. American SaaS does the job but hands over your most sensitive logs on demand to the US government. It’s all very unfavorable to your interests, you’ll agree.&lt;/p&gt;
&lt;p&gt;So, how to resolve this dilemma? The simple answer is, &lt;strong&gt;you build your own SIEM, GDPR and NIS2 compliant, on infrastructure you control entirely&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;This article is the first brick. The foundation.&lt;/p&gt;
&lt;p&gt;The rest of the series will stack on top of it. Wazuh in episode 2, agents in episode 3, network defense, email filter, execution control. If the foundation is shaky, the whole stack is shaky. A SIEM that monitors your park but runs on a machine itself compromised, it’s like a surveillance camera plugged into an open door.&lt;/p&gt;
&lt;p&gt;The stack I recommend, I use daily. I’ll show you how to build your foundation, in order, with real commands. You can reproduce it today.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;choose-the-hoster-jurisdiction-first&quot;&gt;Choose the hoster, jurisdiction first&lt;/h2&gt;
&lt;p&gt;The first decision, and the most structuring one. &lt;strong&gt;Where your machine will live&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;The temptation is to go for the cheapest or most well-known. AWS, Google Cloud, Azure. They’re excellent technically. But they’re all American nationality, and thus subject to the CLOUD Act, that wonderful 2018 law that allows US authorities to seize data from an American provider, wherever it’s stored in the world, including European datacenters.&lt;/p&gt;
&lt;p&gt;Storing your security logs there is exactly the problem we’re trying to solve. So, what we’re looking for is a hoster whose headquarters, servers, and capital are not subject to this US exception.&lt;/p&gt;
&lt;p&gt;Three criteria to really consider.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;The jurisdiction of the headquarters&lt;/strong&gt;. An European company without an American parent company is not subject to the CLOUD Act. Switzerland, Germany, France, etc. The nuance is, a hoster with an entity in the US exposes resources hosted in that entity to the CLOUD Act. The headquarters alone isn’t enough, you need to look where your data physically lives.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;The location of the datacenters&lt;/strong&gt;. Your logs need to stay on European servers, period. No transatlantic replication “for your availability”.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Price, last&lt;/strong&gt;. A VPS to start a SIEM for an SME costs between 5 and 25 euros per month. At this level, the price difference between sovereign operators is marginal. You don’t choose your security hoster based on cents.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;In practice, two names come up when crossing these criteria.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.infomaniak.com/fr/hebergement/vps-cloud&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Infomaniak&lt;/a&gt;&lt;/strong&gt;, &lt;strong&gt;Swiss hoster&lt;/strong&gt; based in Geneva, owned 100% by its founders and employees, without external investment funds. Servers exclusively in Switzerland, under nLPD, the Swiss federal law on data protection entered into force in September 2023, aligned with GDPR and recognized by the European Commission’s adequacy decision.&lt;/p&gt;
&lt;p&gt;No US subsidiary, not subject to the CLOUD Act by design, not part of the 5-eyes, therefore no extended cooperation with US intelligence. In Switzerland, all communication requests must go through justice, one of the most protective jurisdictions in the world.&lt;/p&gt;
&lt;p&gt;Their datacenters are certified ISO 27001 and ISO 50001. It’s the operator I use, on their VPS Cloud range, but the entry-level VPS Lite can suffice to start.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.hetzner.com/cloud/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Hetzner&lt;/a&gt;&lt;/strong&gt;, &lt;strong&gt;German family-owned hoster&lt;/strong&gt; founded in 1997, unbeatable performance/price ratio in Europe, with an ARM cloud range at 4.49 euros HT per month, around 5.40 euros TTC, at the time of writing. Excellent choice, with one condition. Hetzner opened datacenters in the US in 2021, then in Singapore in 2023. You need to provision your machine exclusively on their European sites, Falkenstein, Nuremberg, or Helsinki, to stay outside the CLOUD Act.&lt;/p&gt;
&lt;p&gt;Two honest caveats in addition. Hetzner’s interface and support are only in English and German, and Hetzner sometimes suspends accounts deemed risky, without warning. Nothing blocking for a legitimate SIEM use, but good to know.&lt;/p&gt;
&lt;p&gt;For this guide, I’m going with Infomaniak. The logic is the same at Hetzner, just the interface names change.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read soon: Choosing your sovereign hoster, the complete comparison&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;hr&gt;
&lt;h2 id=&quot;size-the-machine-not-too-much-not-too-little&quot;&gt;Size the machine, not too much, not too little&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://documentation.wazuh.com/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Wazuh&lt;/a&gt;, which we’ll install in episode 2, isn’t lightweight. It comes with a manager, an indexer, and a dashboard. The indexer, in particular, loves RAM.&lt;/p&gt;
&lt;p&gt;For an SME with up to fifty machines to monitor, the right starting point is three numbers.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;4 vCPU&lt;/strong&gt;, to absorb indexing and rule correlations without saturation.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;8 Go of RAM&lt;/strong&gt;, the bare minimum for the Wazuh indexer. Below that, it struggles or stops. &lt;strong&gt;I recommend 12 Go&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;100 to 250 Go of SSD&lt;/strong&gt;, depending on the log retention you want. The more months of history you keep, the more space you’ll need. NIS2 and GDPR think in months, plan ahead.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;A VPS of this caliber runs around 15 to 30 euros per month with a sovereign operator. You can start smaller to test, but don’t go below 8 Go of RAM if you plan to run Wazuh on it for real.&lt;/p&gt;
&lt;p&gt;For the system, choose a Linux distribution with long-term support. &lt;strong&gt;&lt;a href=&quot;https://ubuntu.com/server&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Ubuntu Server LTS&lt;/a&gt;&lt;/strong&gt; or &lt;strong&gt;&lt;a href=&quot;https://www.debian.org/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Debian stable&lt;/a&gt;&lt;/strong&gt;. Both are well-documented, supported for years, and are what the Wazuh community tests first. I use Ubuntu Server LTS, that’s what I’ll use in the following commands.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;the-first-contact-and-the-first-hardening&quot;&gt;The first contact, and the first hardening&lt;/h2&gt;
&lt;p&gt;You’ve just ordered your machine. The hoster sends you an IP address, a &lt;code&gt;root&lt;/code&gt; ID, and a password. This is the most exposed moment in the entire life of the server, a &lt;code&gt;root&lt;/code&gt; accessible via password on a public IP is exactly what bots scan all the time.&lt;/p&gt;
&lt;p&gt;A precision before diving in. A server is administered via the command line, no graphical interface or mouse, the Terminal is your only cockpit. Each command in this guide is short and explained line by line.&lt;/p&gt;
&lt;p&gt;The first connection session serves to close this door. In order.&lt;/p&gt;
&lt;h3 id=&quot;create-a-non-root-user&quot;&gt;Create a non-root user&lt;/h3&gt;
&lt;p&gt;Working as &lt;code&gt;root&lt;/code&gt; daily is like driving without a seatbelt. The slightest command error executes with full privileges. We create a dedicated user, who can elevate their privileges when necessary via &lt;code&gt;sudo&lt;/code&gt;.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;adduser&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; mack&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;usermod&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; -aG&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; mack&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The first &lt;code&gt;adduser&lt;/code&gt; creates the account and asks for a password. The second adds the user to the &lt;code&gt;sudo&lt;/code&gt; group, allowing them to execute admin commands by prefixing them with &lt;code&gt;sudo&lt;/code&gt;. From now on, log in with this account, never as &lt;code&gt;root&lt;/code&gt; directly.&lt;/p&gt;
&lt;h3 id=&quot;switch-to-key-based-authentication&quot;&gt;Switch to key-based authentication&lt;/h3&gt;
&lt;p&gt;A password can be guessed, forced with a dictionary, stolen. A cryptographic key, no. We generate a key pair on your local machine, install the public part on the server, and disable password-based authentication completely.&lt;/p&gt;
&lt;p&gt;On your Mac, in the Terminal:&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;ssh-keygen&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; -t&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; ed25519&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; -C&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; &quot;your-comment&quot;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;ssh-copy-id&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; mack@IP_OF_THE_SERVER&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The first command generates the key pair, in Ed25519, the modern, short, and solid algorithm. The second copies your public key to the server. Then test that you can log in without a password, &lt;code&gt;ssh mack@IP_OF_THE_SERVER&lt;/code&gt;. If it works, we can cut off the rest.&lt;/p&gt;
&lt;h3 id=&quot;lock-down-ssh&quot;&gt;Lock down SSH&lt;/h3&gt;
&lt;p&gt;This is where the attack surface really closes. We edit the SSH daemon’s configuration.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; nano&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; /etc/ssh/sshd_config&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Three lines to set, these are the three that matter.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;plaintext&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span&gt;PermitRootLogin no&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;PasswordAuthentication no&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span&gt;PubkeyAuthentication yes&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&lt;code&gt;PermitRootLogin no&lt;/code&gt; forbids direct &lt;code&gt;root&lt;/code&gt; logins. &lt;code&gt;PasswordAuthentication no&lt;/code&gt; disables passwords, only your key opens the door now. &lt;code&gt;PubkeyAuthentication yes&lt;/code&gt; confirms that we accept keys.&lt;/p&gt;
&lt;p&gt;Keep your current session open, restart the service, then test a new connection in a second window. An SSH config error, and you’re locked out of your own machine.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; systemctl&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; restart&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; ssh&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;A known trap with cloud images, Ubuntu often leaves a file &lt;code&gt;/etc/ssh/sshd_config.d/50-cloud-init.conf&lt;/code&gt; containing &lt;code&gt;PasswordAuthentication yes&lt;/code&gt;, which overrides your configuration. Check the actual applied value with &lt;code&gt;sudo sshd -T | grep -i passwordauthentication&lt;/code&gt;, and if it comes back as &lt;code&gt;yes&lt;/code&gt;, fix this file too.&lt;/p&gt;
&lt;p&gt;Three commands, three config lines. You’ve just eliminated almost all automated attacks that target SSH. The bots that try &lt;code&gt;root&lt;/code&gt; via password are now hitting a wall.&lt;/p&gt;
&lt;h3 id=&quot;enable-automatic-security-updates&quot;&gt;Enable automatic security updates&lt;/h3&gt;
&lt;p&gt;A server that hasn’t been patched is a vulnerable server, and no one connects every morning to launch updates manually. We automate security patches.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; apt&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; update&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt; &amp;#x26;&amp;#x26; &lt;/span&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; apt&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; install&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; unattended-upgrades&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; dpkg-reconfigure&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; --priority=low&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; unattended-upgrades&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The &lt;a href=&quot;https://wiki.debian.org/UnattendedUpgrades&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;&lt;code&gt;unattended-upgrades&lt;/code&gt;&lt;/a&gt; package automatically installs security updates published for your distribution, without touching the rest. Your known vulnerabilities close automatically, while you sleep.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;the-minimal-attack-surface-the-real-sovereign-goal&quot;&gt;The minimal attack surface, the real sovereign goal&lt;/h2&gt;
&lt;p&gt;The SSH hardening, that’s the basics. The level jump is here.&lt;/p&gt;
&lt;p&gt;The guiding principle is one sentence. &lt;strong&gt;A port that doesn’t listen can’t be attacked&lt;/strong&gt;. Each service exposed on a public IP is a door, and each door is a target. Maximum security isn’t the best lock on each door, it’s not having a door at all.&lt;/p&gt;
&lt;p&gt;That’s exactly the logic we saw for the &lt;a href=&quot;https://macsouverain.com/en/apple-silicon-et-securite-ce-que-secure-enclave-change-vraiment/&quot;&gt;Secure Enclave&lt;/a&gt;. The most secure component is the one that refuses access, not the one that defends it well.&lt;/p&gt;
&lt;h3 id=&quot;the-firewall-closed-by-default&quot;&gt;The firewall, closed by default&lt;/h3&gt;
&lt;p&gt;On Ubuntu, the firewall is managed with &lt;a href=&quot;https://documentation.ubuntu.com/server/how-to/security/firewalls/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;&lt;code&gt;ufw&lt;/code&gt;&lt;/a&gt;. The right posture is the inverse, we block everything, then open only what’s necessary.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; ufw&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; default&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; deny&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; incoming&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; ufw&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; default&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; allow&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; outgoing&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; ufw&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; allow&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; 22/tcp&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; ufw&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; enable&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&lt;code&gt;default deny incoming&lt;/code&gt; refuses all incoming connections. &lt;code&gt;default allow outgoing&lt;/code&gt; lets your machine join the outside world, for updates, for example. We only open port 22, SSH, the bare minimum to administer the machine. And we enable.&lt;/p&gt;
&lt;p&gt;At this point, &lt;strong&gt;your server presents only one SSH door per key&lt;/strong&gt;. That’s already a profile radically more discreet than 90% of production VPS.&lt;/p&gt;
&lt;h3 id=&quot;tailscale-and-the-public-ip-disappears&quot;&gt;Tailscale, and the public IP disappears&lt;/h3&gt;
&lt;p&gt;We can do better. Instead of opening SSH on the public IP, even via key, we remove it entirely from internet view and expose it only on a private, encrypted network.&lt;/p&gt;
&lt;p&gt;That’s the role of &lt;strong&gt;&lt;a href=&quot;https://tailscale.com/kb/1017/install&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Tailscale&lt;/a&gt;&lt;/strong&gt;. Tailscale creates a &lt;a href=&quot;https://tailscale.com/blog/how-tailscale-works&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;private mesh&lt;/a&gt; between your devices, over &lt;a href=&quot;https://www.wireguard.com/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;WireGuard&lt;/a&gt;, the modern tunneling protocol. Your machines see each other via private addresses, like they’re on the same local network, even if they’re scattered between a Swiss datacenter, your office, and your home. The rest of the internet, meanwhile, sees nothing.&lt;/p&gt;
&lt;p&gt;Here’s the concrete flow. You install Tailscale on the server and on your Mac. Both join your private network. Your Mac gets a Tailscale address, the server does too. You log in to the server via its Tailscale address, not its public IP. And you close port 22 on the public IP. To reach SSH, you have to already be a member of your private network. An attacker on the internet can’t even see that the port exists.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;curl&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; -fsSL&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; https://tailscale.com/install.sh&lt;/span&gt;&lt;span style=&quot;color:#D73A49&quot;&gt; |&lt;/span&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt; sh&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; tailscale&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; up&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The command displays a link, you open it in your browser, authenticate the machine, it joins your network. Repeat on your Mac. Retrieve the server’s Tailscale address:&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;tailscale&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; ip&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; -4&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Test the SSH connection via this private address. Once it works, we close port 22 on the public IP:&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; ufw&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; delete&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; allow&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; 22/tcp&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; ufw&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; allow&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; in&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; on&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; tailscale0&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; to&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; any&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; port&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; 22&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; proto&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; tcp&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The first line removes the SSH opening on all interfaces. The second reopens it only on the &lt;code&gt;tailscale0&lt;/code&gt; interface, your private network. SSH only listens on the encrypted mesh.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The result is a machine with only one admin door, invisible from the internet&lt;/strong&gt;. Not locked, invisible. A port scan on your public IP reveals nothing exploitable.&lt;/p&gt;
&lt;p&gt;For the rest of the series, that’s also how your Wazuh agents will send their logs to the server, never through the open internet. The network foundation we’re putting in place today serves the whole stack.&lt;/p&gt;
&lt;h3 id=&quot;and-the-services-that-must-remain-public&quot;&gt;And the services that must remain public?&lt;/h3&gt;
&lt;p&gt;Not everything can live behind the private network. If your server hosts a website or a service that needs to be reachable by anyone, that service has to listen on the public IP. It’s inevitable.&lt;/p&gt;
&lt;p&gt;The rule, then, isn’t “zero public ports” but “zero unnecessary public ports”. You open exactly what the service requires, nothing more. A website, that’s port 443 in HTTPS, and port 80 while renewing certificates. Nothing else. Everything else, administration, databases, internal dashboards, stays on Tailscale.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;For our SIEM foundation&lt;/strong&gt;, at this point, the simple answer is &lt;strong&gt;no public services&lt;/strong&gt;. The server exposes nothing to the world. Wazuh, which we’ll install later, lives entirely behind Tailscale, accessible only to you.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;the-backups-encrypted-off-site&quot;&gt;The backups, encrypted off-site&lt;/h2&gt;
&lt;p&gt;A hardened server isn’t an immortal server. A datacenter can burn down, as we saw with OVH Strasbourg in March 2021, clients without backups lost everything. A ransomware can still pass on one of your production machines. A finger slip on a wrong command can erase a database.&lt;/p&gt;
&lt;p&gt;The rule is non-negotiable. &lt;strong&gt;Your backups live elsewhere than on the machine they protect, and they’re encrypted before they leave&lt;/strong&gt;. Encrypted by you, on your machine, before sending. Not encrypted by the storage provider, by you. That way, even the storage provider can’t read what it’s storing.&lt;/p&gt;
&lt;p&gt;The tool I use is &lt;strong&gt;&lt;a href=&quot;https://kopia.io/docs/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Kopia&lt;/a&gt;&lt;/strong&gt;. Open source, fast, and it does exactly what we want, client-side encryption before transfer, deduplication to not explode your storage volume, and sending to an S3-compatible storage.&lt;/p&gt;
&lt;p&gt;And the off-site storage, I take it with &lt;strong&gt;&lt;a href=&quot;https://www.infomaniak.com/fr/swiss-backup&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Swiss Backup&lt;/a&gt;&lt;/strong&gt;, Infomaniak’s backup service. Same logic of sovereignty as for the VPS, Swiss servers, not subject to the CLOUD Act, and an S3 endpoint that Kopia consumes directly.&lt;/p&gt;
&lt;p&gt;The concrete flow. Kopia runs on your server. Once a day, or several times, it takes a snapshot of the folders that matter, your system configuration, your Wazuh data, your logs.&lt;/p&gt;
&lt;p&gt;It encrypts this snapshot locally, with a key that only you hold. Then it sends it to Swiss Backup. The day the server dies, you provision a new machine, reinstall Kopia, point it to the remote repository with your key, and restore.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;curl&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; -s&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; https://kopia.io/signing-key&lt;/span&gt;&lt;span style=&quot;color:#D73A49&quot;&gt; |&lt;/span&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt; sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; gpg&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; --dearmor&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; -o&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; /usr/share/keyrings/kopia-keyring.gpg&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#005CC5&quot;&gt;echo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; &quot;deb [signed-by=/usr/share/keyrings/kopia-keyring.gpg] http://packages.kopia.io/apt/ stable main&quot;&lt;/span&gt;&lt;span style=&quot;color:#D73A49&quot;&gt; |&lt;/span&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt; sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; tee&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; /etc/apt/sources.list.d/kopia.list&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; apt&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; update&lt;/span&gt;&lt;span style=&quot;color:#24292E&quot;&gt; &amp;#x26;&amp;#x26; &lt;/span&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; apt&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; install&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; kopia&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;kopia&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; repository&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; create&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; s3&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#005CC5&quot;&gt;  --bucket=YOUR_BUCKET&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#005CC5&quot;&gt;  --endpoint=s3.swiss-backup.infomaniak.com&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#005CC5&quot;&gt;  --access-key=YOUR_KEY&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#005CC5&quot;&gt;  --secret-access-key=YOUR_SECRET&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The first three lines install Kopia from its official repository. The last command creates the encrypted repository on the remote storage, using the exact endpoint displayed in your Swiss Backup console, it varies depending on the cluster you’re assigned. Kopia asks for a passphrase when creating the repository, that’s the key to encrypt all your backups. &lt;strong&gt;Note it down somewhere other than on the server&lt;/strong&gt;. If you lose it, your backups are permanently unreadable, including to you. That’s the price of client-side encryption, and that’s exactly what we want.&lt;/p&gt;
&lt;p&gt;Then automate. We create a daily snapshot of the critical folders, then schedule it with a &lt;code&gt;cron&lt;/code&gt; job.&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;kopia&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; snapshot&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; create&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; /etc&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; /home&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; /var/log&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;This command captures the current state of the three folders. You schedule it to run every night, and occasionally check that your snapshots are there with &lt;code&gt;kopia snapshot list&lt;/code&gt;. A backup you don’t test is not a backup, it’s a hope. So we’ll need to plan a test restore of your data every quarter.&lt;/p&gt;
&lt;p&gt;This SIEM foundation will serve the rest of the series. Every brick we add, Wazuh and its data, the rules you calibrate, will be captured in the same encrypted snapshot, off-site, ready for the day you need it.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;in-summary&quot;&gt;In summary&lt;/h2&gt;
&lt;p&gt;The foundation is four gestures that build on each other.&lt;/p&gt;
&lt;p&gt;You’ve chosen &lt;strong&gt;a hoster whose jurisdiction protects you&lt;/strong&gt;, not just whose datacenter is in Europe. You’ve &lt;strong&gt;hardened access&lt;/strong&gt;, non-root user, key-based authentication, &lt;code&gt;root&lt;/code&gt; forbidden, automatic updates. You’ve &lt;strong&gt;reduced the attack surface to nothing&lt;/strong&gt;, closed firewall by default, admin behind a private encrypted network, no unnecessary public ports. And you’ve &lt;strong&gt;put encrypted backups off-site&lt;/strong&gt;, unreadable to anyone without your key, ready for the day when.&lt;/p&gt;
&lt;p&gt;None of these steps are complicated. Together, they turn a rented machine into a fortress you control. It’s the exact opposite of what you sign up for with an American SaaS, where the data is yours but the infrastructure and jurisdiction aren’t.&lt;/p&gt;
&lt;p&gt;An afternoon’s work. Not a weekend.&lt;/p&gt;
&lt;p&gt;The foundation is in place. In episode 2, we fill the vault. Wazuh all-in-one, manager, indexer, and dashboard on this single node. The functional equivalent of a Splunk, for the price of the VPS you’ve just built. Your SIEM starts to exist.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;series-reminder&quot;&gt;Series reminder&lt;/h2&gt;
&lt;p&gt;Seven episodes to build your sovereign security plumbing, brick by brick.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/nis2-splunk-pourquoi-pme-siem-souverain/&quot;&gt;Episode 0, the bedrock of the series.&lt;/a&gt;&lt;/strong&gt; Why an SME needs a sovereign SIEM, NIS2, GDPR, and the cost of doing nothing.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Episode 1, the foundation.&lt;/strong&gt; The hardened VPS outside the CLOUD Act. You’ve just read it.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/wazuh-tout-en-un-siem-souverain/&quot;&gt;Episode 2, Wazuh all-in-one.&lt;/a&gt;&lt;/strong&gt; Manager, indexer, and dashboard on a single node.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/wazuh-agents-parc-siem-souverain/&quot;&gt;Episode 3, agents everywhere.&lt;/a&gt;&lt;/strong&gt; Deployment on your servers, Macs, and Windows machines.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/crowdsec-premiere-ligne-siem-souverain/&quot;&gt;Episode 4, community network defense.&lt;/a&gt;&lt;/strong&gt; Block known attackers before they arrive.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/rspamd-mail-siem-souverain/&quot;&gt;Episode 5, the mail filter.&lt;/a&gt;&lt;/strong&gt; Anti-spam and anti-phishing in front of your mail server.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Episode 6, Mac execution control.&lt;/strong&gt; Decide which applications have the right to launch.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Episode 7, alerting and total cost.&lt;/strong&gt; Calibrated notifications and honest financial breakdown against SaaS.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;em&gt;Technical terms? &lt;a href=&quot;https://macsouverain.com/en/glossaire/&quot;&gt;Check the glossary.&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>ms-pro</category><category>nis2</category><category>siem</category><category>vps</category><category>securite</category><category>tutoriel</category><enclosure url="https://macsouverain.com/content/images/2026/06/feature-vps-durci-socle-siem-souverain-1.png" length="0" type="image/png"/></item><item><title>Siri AI blocked in EU, privacy signed Google</title><link>https://macsouverain.com/en/siri-ai-blocage-ue/</link><guid isPermaLink="true">https://macsouverain.com/en/siri-ai-blocage-ue/</guid><description>Apple Unveils Siri AI at WWDC, But Locks It Down on iPhone and iPad in EU. A Confidential Platform Built on Google Gemini. Here&apos;s the Breakdown.</description><pubDate>Wed, 10 Jun 2026 13:32:51 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;&lt;strong&gt;Apple Launches Siri AI at WWDC, But Blocks It on iPhone and iPad in EU Due to DMA. Commission Says It’s Apple’s Choice, Not a Requirement. To Top It Off, This “Confidential” Platform Partially Relies on Google Gemini.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What This Means for You&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; &lt;strong&gt;No Siri AI on iPhone or iPad in Europe&lt;/strong&gt;. But without cloud AI assistant, your device is safer: you lose a feature, not a protection.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; &lt;strong&gt;For the Sensitive, Stay Local&lt;/strong&gt; and enable Advanced Data Protection on iCloud. For encrypted email, use Proton Mail, not iCloud Mail.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; &lt;strong&gt;Ask Yourself the Real Question&lt;/strong&gt;: Is trusting your most intimate assistant to an Apple-Google chain a technical guarantee or a contractual promise?&lt;/p&gt;
&lt;/div&gt;
&lt;h1 id=&quot;apple-unveils-siri-ai-at-wwdc&quot;&gt;Apple Unveils Siri AI at WWDC&lt;/h1&gt;
&lt;p&gt;Apple has unveiled Siri AI, its new voice assistant platform. Two details stand out: it’s partly built on Google Gemini, and it won’t be available on iPhone or iPad in the European Union. Privacy, Cupertino-style, becomes a blocking argument.&lt;/p&gt;
&lt;h2 id=&quot;the-fact&quot;&gt;The Fact&lt;/h2&gt;
&lt;p&gt;On June 8, 2026, at the WWDC, Apple introduced Siri AI, the much-anticipated revamp of its voice assistant and the announced foundation of its next generation of products, including future portable devices. The platform’s core is a hybrid architecture: local tasks run on Apple’s in-house models, but cloud intelligence relies on a custom Gemini model from Google, estimated to be around a billion dollars a year, according to several press sources.&lt;/p&gt;
&lt;p&gt;The catch is geography. Apple announced that Siri AI won’t be available on iPhone or iPad in the EU with iOS 27 and iPadOS 27. EU users will have access on macOS 27 and visionOS 27, but not on iPhone, iPad, or Apple Watch, as watchOS 27 depends on a paired iPhone with Siri AI. Apple cites the Digital Markets Act (DMA) and its interoperability requirements, claiming regulators rejected its compliance proposals, including a Trusted System Agent framework meant to open access to competing assistants while maintaining security standards.&lt;/p&gt;
&lt;p&gt;The Commission disputes the framing. For spokesperson Thomas Regnier, Apple’s decision not to deploy Siri AI in the EU is “Apple’s alone,” with nothing in the DMA preventing a new product launch. The market, however, has spoken: Apple’s stock dropped about 2% on the day of the announcement and another 3% the next day. Note of caution: iOS 27 and iPadOS 27 are currently announcements, not stable builds. The release timeline and block perimeter could still shift.&lt;/p&gt;
&lt;h2 id=&quot;why-it-matters-to-you&quot;&gt;Why It Matters to You&lt;/h2&gt;
&lt;p&gt;If you’re in Europe, the message is clear: your iPhone and iPad won’t have the flagship feature of the next OS. Before blaming Brussels, look at what’s really happening. Apple presents privacy as the reason it can’t comply with interoperability demands.&lt;/p&gt;
&lt;p&gt;The Commission responds that no one’s forcing Apple to cripple its product. The two versions aren’t symmetrical, and the official site isn’t the only source of truth here, but one thing’s certain: privacy has become a negotiation point as much as a technical promise.&lt;/p&gt;
&lt;p&gt;The irony’s worth noting. Apple pitches Siri AI as privacy-respecting while outsourcing cloud processing to Google, whose business model relies on data exploitation. Apple swears its architecture segregates everything via Private Cloud Compute, that Google sees nothing, and requests are anonymized. It’s plausible on paper, and Apple has a solid track record. But you’re moving from a verifiable promise, all-on-device, to a contractual one, trusting partners to keep their word. It’s not the same level of assurance.&lt;/p&gt;
&lt;p&gt;The underlying issue goes beyond Siri. We’re seeing digital ecosystem fragmentation by jurisdiction. The same iOS version won’t offer the same features in Paris, New York, or Beijing. User sovereignty now hinges not just on encryption, but on the iPhone-dependent arms race between an American industrial giant, a European regulator, and a third-party AI provider.&lt;/p&gt;
&lt;h2 id=&quot;what-it-changes-for-you&quot;&gt;What It Changes for You&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Don’t confuse Siri AI’s absence with loss of privacy. Your iPhone without a cloud AI assistant remains fully functional and more secure. The “lack” is a feature, not a lost protection.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; For sensitive queries, stick local. Enable Advanced Data Protection on iCloud (Settings &gt; Apple Account &gt; iCloud &gt; Advanced Data Protection) for end-to-end encrypted backups. Note: ADP doesn’t cover iCloud Mail, Contacts, or Calendar. For genuinely encrypted email, try Proton Mail or Tuta, for instance.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Keep an eye on developments without getting overwhelmed. The EU block perimeter and timeline may shift. What matters isn’t the release date, but the broader question: are you ready to entrust your most intimate assistant to an Apple-Google chain, based on a contractual promise?&lt;/p&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-analyse</category><category>apple</category><category>siri</category><category>ia</category><category>dma</category><category>reglementation</category><category>google</category><category>gemini</category><category>confidentialite</category></item><item><title>OpenAI Certificate Compromised, Update ChatGPT Mac Before June 12th</title><link>https://macsouverain.com/en/chatgpt-mac-breach/</link><guid isPermaLink="true">https://macsouverain.com/en/chatgpt-mac-breach/</guid><description>ChatGPT, Codex, and Atlas on Mac: Mandatory update before June 12, 2026. OpenAI cert revoked after npm supply-chain attack.</description><pubDate>Sat, 06 Jun 2026 07:58:44 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;**If you’re using ChatGPT, Codex, or Atlas natively on your Mac, you’ve got until &lt;strong&gt;June 12, 2026&lt;/strong&gt; to update. OpenAI’s signature certificate has been compromised via a supply-chain attack on npm. After that, your app won’t start.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Here’s what you need to do:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Open ChatGPT.app, go to Settings → About. Update if your version is ≤ 1.2026.125. Same for Codex App (≤ 26.506.31421), Codex CLI (≤ 0.130.0), Atlas (≤ 1.2026.119.1).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Official download only, &lt;code&gt;chatgpt.com/download&lt;/code&gt; or App Store. No mirrors, no shared links.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; iOS, Windows, Android, nothing to do, OpenAI re-signs on the server side. Mac only.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;You’re using ChatGPT, Codex, or Atlas in a native app on your Mac. On June 12, in a few days, these apps will refuse to launch if you haven’t updated. Not a bug, a certificate revocation due to a supply-chain attack. Here’s what happened and what you need to do.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The Facts&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;On May 11, 2026, a collective called TeamPCP published 84 tampered versions of 42 &lt;code&gt;@tanstack/*&lt;/code&gt; packages on npm in just six minutes. Two OpenAI employees consumed one of these packages that evening. The malware, &lt;strong&gt;Mini Shai-Hulud&lt;/strong&gt;, exfiltrated credentials that granted access to internal repositories containing OpenAI’s code-signing tools. Not user conversations or models, just the keys that prove to macOS that an app comes from OpenAI.&lt;/p&gt;
&lt;p&gt;OpenAI &lt;a href=&quot;https://openai.com/index/our-response-to-the-tanstack-npm-supply-chain-attack/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;announced publicly&lt;/a&gt; on May 13, 2026, that the compromised certificate would be &lt;strong&gt;revoked on June 12, 2026&lt;/strong&gt;. On Apple’s end, this means Gatekeeper and notarization will refuse any version signed with the old certificate. In practical terms, the affected versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;ChatGPT Desktop&lt;/strong&gt; ≤ 1.2026.125&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Codex App&lt;/strong&gt; ≤ 26.506.31421&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Codex CLI&lt;/strong&gt; ≤ 0.130.0&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Atlas&lt;/strong&gt; (OpenAI browser) ≤ 1.2026.119.1&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These won’t launch after June 12. iOS and Windows versions are re-signed server-side, no user action needed.&lt;/p&gt;
&lt;p&gt;The worm’s source code was published by TeamPCP on May 12, with a &lt;strong&gt;$1,000 bounty&lt;/strong&gt; on BreachForums for the largest supply-chain attack using their tool. Not a defensive bug bounty, an offensive reward. The CVE reference is &lt;strong&gt;CVE-2026-45321&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Why This Matters to You&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;You didn’t do anything wrong, but you still have to act. That’s the essence of a supply-chain attack. Your user hygiene could be perfect, but if the app you’ve installed gets compromised four levels up, in an npm dependency you’ll never know about, you’re the one left with the problem. The compromised certificate, the revoked signing mechanism, the app that won’t launch - it all happens on your end without you clicking anything.&lt;/p&gt;
&lt;p&gt;The good news is the revocation mechanism works. Gatekeeper and Apple’s notarization are designed for this: preventing an attacker from using a stolen certificate to sign malware downstream. OpenAI did their job by properly revoking. Apple did their job by blocking. The system held up. OpenAI communicated clearly and promptly, with specific dates and versions - not the norm in the industry.&lt;/p&gt;
&lt;p&gt;The bad news is it raises a doctrinal question that goes beyond OpenAI. A native app on your Mac is local code running with a trust certificate, automatic update channel, system permissions, and a network of upstream dependencies you have no visibility into. When one of these dependencies gets compromised - and they all do - the problem comes down to you.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What You Need to Do Now&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Open &lt;strong&gt;ChatGPT.app&lt;/strong&gt;, go to &lt;strong&gt;Preferences → About&lt;/strong&gt;. If you’re on 1.2026.125 or earlier, start the update. If nothing appears, download directly from [chatgpt.com/download](&lt;a href=&quot;https://chatgpt.com/download&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://chatgpt.com/download&lt;/a&gt;]. Never a mirror, never a shared link.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; If you’re using &lt;strong&gt;Codex App&lt;/strong&gt; or &lt;strong&gt;Codex CLI&lt;/strong&gt;, do the same check. CLI: &lt;code&gt;codex --version&lt;/code&gt; then &lt;code&gt;npm update -g @openai/codex&lt;/code&gt; or reinstall cleanly. For &lt;strong&gt;Atlas&lt;/strong&gt;, update is integrated.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Make sure macOS is up-to-date, with Gatekeeper strengthened on Sequoia 15.x and Sonoma 14.7+. Older versions are more lenient in notarization checks at launch.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4.&lt;/strong&gt; Use the window to ask yourself a doctrinal question: what does the native ChatGPT app give you that &lt;a href=&quot;https://chatgpt.com&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;chatgpt.com in Safari&lt;/a&gt; doesn’t? System dictation, keyboard shortcuts, Spotlight integration - okay. If you don’t use any of these, the browser reduces your attack surface. No signature certificate to manage, no silent updates, no persistent local code. The habit applies to &lt;strong&gt;Claude Desktop&lt;/strong&gt;, &lt;strong&gt;Perplexity&lt;/strong&gt;, &lt;strong&gt;Mistral AI Chat&lt;/strong&gt;, and any other third-party AI apps you’ve installed without really knowing why. A native app on your Mac is a security debt - sometimes justified, sometimes not.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Also read, &lt;a href=&quot;https://macsouverain.com/en/anthropic-mcp-rce-design-flaw-avril-2026/&quot;&gt;Anthropic MCP, design flaw that opens RCE&lt;/a&gt;. Same logic, third-party AI code descending into dangerous local execution.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;Sources&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://openai.com/index/our-response-to-the-tanstack-npm-supply-chain-attack/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;OpenAI, Our response to the TanStack npm supply chain attack&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://9to5mac.com/2026/06/02/psa-a-security-breach-means-you-must-update-the-chatgpt-mac-app/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;9to5Mac, PSA, you must update the ChatGPT Mac app&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://thehackernews.com/2026/05/tanstack-supply-chain-attack-hits-two.html&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;The Hacker News, TanStack supply chain attack hits two OpenAI employees&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.tenable.com/blog/mini-shai-hulud-frequently-asked-questions&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Tenable, Mini Shai-Hulud CVE-2026-45321 FAQ&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://tanstack.com/blog/npm-supply-chain-compromise-postmortem&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;TanStack, postmortem npm supply-chain compromise&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.zataz.com/openai-change-ses-certificats-apres-le-hack-tanstack/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;ZATAZ, OpenAI changes its certificates after the TanStack hack&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-alerte</category><category>openai</category><category>chatgpt</category><category>supply-chain</category><category>code-signing</category><category>macos</category><category>ia</category><category>cybersec</category></item><item><title>Build your sovereign SIEM for SMEs, compliant with GDPR/NIS2 without CLOUD Act</title><link>https://macsouverain.com/en/nis2-splunk-pourquoi-pme-siem-souverain/</link><guid isPermaLink="true">https://macsouverain.com/en/nis2-splunk-pourquoi-pme-siem-souverain/</guid><description>You&apos;re already forced by GDPR to detect a breach within 72 hours. NIS2 just widened the net by 30x. Build your SIEM now, it&apos;s security today and compliance amortised before it lands on you.</description><pubDate>Fri, 05 Jun 2026 12:00:56 GMT</pubDate><content:encoded>&lt;p&gt;You don’t have a SIEM. You tell yourself it’s not for you, that your SME is too small or outside a regulated sector, so under the radar of the big cyber obligations. You’re wrong on two counts.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Now, GDPR.&lt;/strong&gt; Since 2018, any company that processes personal data must notify the CNIL of a breach within &lt;strong&gt;72 hours&lt;/strong&gt;. That’s Article 33. Not a recommendation, an obligation. Notifying within 72 hours means you know something happened, that you can characterise it, that you have the logs to trace the chain back. Without a system that centralises your logs and raises alerts, this obligation is unenforceable. You’re in breach the first time a ransomware gets through.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Tomorrow, the widening.&lt;/strong&gt; NIS2 has just multiplied by thirty the number of French entities subject to reinforced cyber obligations, from 500 to around 15,000. DORA has applied since January 2025 to the extended financial sector, subcontractors included. The Cyber Resilience Act applies fully from December 2027 to any product with a digital component sold in the EU. NIS3 isn’t voted on yet, the indicative timeline aims for the end of 2027. But the trajectory is legible, every two to three years the net widens. Betting your SME stays out of scope in 2028 or 2029 is betting against Brussels and against the GDPR case law that has done nothing but harden.&lt;/p&gt;
&lt;p&gt;The word that keeps coming back in all these texts is SIEM, for &lt;strong&gt;Security Information and Event Management&lt;/strong&gt;, centralised management of security events. They never name it, but they make it impossible to avoid. Detecting an incident, keeping exploitable logs, notifying the regulator within short deadlines, those are the functions of a SIEM.&lt;/p&gt;
&lt;p&gt;And what is a SIEM, concretely? Picture the CCTV of your shop, but for your IT. Every server, every firewall, every workstation, every mailbox constantly produces a log of what happens on it. Who logged in, at what time, from where, which file was opened, which process started.&lt;/p&gt;
&lt;p&gt;A SIEM is the system that brings all these logs to one place, keeps them for several months, and raises an alert when it detects suspicious behaviour.&lt;/p&gt;
&lt;p&gt;An account that logs in at 3 in the morning from Pakistan, ten thousand files encrypted in two minutes, a burst of failed passwords on the director’s account, these are signals a human will never catch with the naked eye on a fleet of fifty machines.&lt;/p&gt;
&lt;p&gt;The SIEM sees them, cross-references them, and warns you. Behind this consultant’s acronym hides a very concrete assembly, which we take apart further down in this article.&lt;/p&gt;
&lt;p&gt;The problem is what’s being sold to you today under that name. &lt;a href=&quot;https://www.splunk.com/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;strong&gt;Splunk&lt;/strong&gt;&lt;/a&gt;, &lt;a href=&quot;https://learn.microsoft.com/azure/sentinel/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;strong&gt;Microsoft Sentinel&lt;/strong&gt;&lt;/a&gt;, &lt;a href=&quot;https://www.crowdstrike.com/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;strong&gt;CrowdStrike&lt;/strong&gt;&lt;/a&gt;. At a modest SME’s entry ticket the prices look affordable, but the bill climbs with every gigabyte and every seat, and we do the full accounting at the end of the series. And the price isn’t even the worst of it. These products store your incident logs in a jurisdiction that isn’t yours, under the CLOUD Act. The real question is who holds your most sensitive data.&lt;/p&gt;
&lt;p&gt;There’s a third path. The sovereign one. It’s the path of this series.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;nis2-in-five-minutes-and-why-it-concerns-you-even-outside-the-scope&quot;&gt;NIS2 in five minutes, and why it concerns you even outside the scope&lt;/h2&gt;
&lt;p&gt;NIS2 is the European directive on the security of networks and information systems, replacing NIS1. NIS1 covered around 500 French entities. NIS2 covers &lt;strong&gt;around 15,000&lt;/strong&gt;, spread across eighteen sectors. Health, energy, transport, digital, financial services, agri-food, waste, manufacturing. If your company exceeds &lt;strong&gt;50 employees or 10 million euros in revenue&lt;/strong&gt; in one of these sectors, you’re directly concerned. Probably as an “important entity”, sometimes as an “essential entity” depending on your size and criticality.&lt;/p&gt;
&lt;p&gt;If you’re smaller or outside a listed sector, you’re not off the hook for all that. &lt;strong&gt;Two mechanisms catch you.&lt;/strong&gt; First the supply chain, Article 21 requires NIS2 entities to assess the cyber-resilience of their subcontractors. If you sell service or software to a 60-person SME in health or finance, it’s going to ask you for your proof. No SIEM, no contract. Then the regulatory trajectory itself, NIS3 is in preparation at the Commission, the scope always widens from one revision to the next.&lt;/p&gt;
&lt;p&gt;The heart of the mechanism is &lt;strong&gt;Article 21&lt;/strong&gt;. Ten categories of minimum measures, risk analysis, incident management, logging, continuity, training, encryption, access control, supply chain security. And the notification obligation, in three steps, &lt;strong&gt;early warning within 24 hours, structured notification within 72 hours, final report within 30 days&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;The triptych holds for NIS2 as for GDPR, without a detection and logging foundation, the obligation is unenforceable.&lt;/p&gt;
&lt;p&gt;Article 20 adds the detail that changes everything for the director. &lt;strong&gt;Liability falls on the natural person who runs the company.&lt;/strong&gt; Not on the IT manager, nor on the provider. On you.&lt;/p&gt;
&lt;p&gt;On the sanctions side, it’s calibrated to hurt. Essential entity, up to &lt;strong&gt;10 million euros or 2% of worldwide revenue&lt;/strong&gt;, whichever is higher. Important entity, up to 7 million euros or 1.4% of worldwide revenue. For an SME with 30 million in revenue, we’re talking a maximum sanction of several hundred thousand euros.&lt;/p&gt;
&lt;p&gt;The law of 30 April 2025 transposes NIS2 into French law. The implementing decrees and the exact scope of the entities concerned are being specified over the course of 2026. As long as it’s fuzzy you tell yourself you have time, but the directive already applies, the case law will be built on the first disputes. The question is when, not if.&lt;/p&gt;
&lt;p&gt;We already saw in &lt;a href=&quot;https://macsouverain.com/en/nis2-csar-contradiction-ue-chiffrement-surveillance/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;a previous article&lt;/a&gt; how NIS2 contradicts CSAR on encryption. Here, we look at the other obligation, the one that becomes concrete for your infrastructure, &lt;strong&gt;detect, log, notify&lt;/strong&gt;.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;you-have-three-options-and-two-of-them-are-bad&quot;&gt;You have three options, and two of them are bad&lt;/h2&gt;
&lt;h3 id=&quot;option-1-us-saas&quot;&gt;Option 1, US SaaS&lt;/h3&gt;
&lt;p&gt;Splunk, Microsoft Sentinel, CrowdStrike, &lt;a href=&quot;https://www.datadoghq.com/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Datadog&lt;/a&gt;, &lt;a href=&quot;https://www.elastic.co/cloud&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;Elastic Cloud&lt;/a&gt;. They work. They’re mature. And at a modest SME’s entry price, they’re not out of reach. The trap is elsewhere.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Microsoft Sentinel&lt;/strong&gt; charges around &lt;strong&gt;$4.30 per gigabyte ingested&lt;/strong&gt; in the East US region, in the simplified billing model that combines Log Analytics ingestion and Sentinel analytics. &lt;strong&gt;CrowdStrike Falcon&lt;/strong&gt; charges per endpoint, between &lt;strong&gt;$60 and $185 per seat per year&lt;/strong&gt; depending on the tier, Go, Pro, Enterprise or Complete. &lt;strong&gt;Splunk&lt;/strong&gt; is more opaque, the vendor doesn’t publish its prices, but serious secondary sources converge around &lt;strong&gt;$8,000 to $12,500 per year&lt;/strong&gt; for an entry ticket of 5 gigabytes of logs per day, licence only, in Cloud or self-hosted Enterprise.&lt;/p&gt;
&lt;p&gt;Take a 50-employee SME that generates five gigabytes of logs per day. On Microsoft Sentinel, around &lt;strong&gt;$7,800 per year&lt;/strong&gt;. On CrowdStrike Falcon Pro for 50 endpoints, around &lt;strong&gt;$5,000 per year&lt;/strong&gt;. On Splunk Cloud at entry, around &lt;strong&gt;$8,000 per year&lt;/strong&gt;. Let’s be honest, &lt;strong&gt;$13,000 per year for Sentinel and CrowdStrike combined, on an SME with $10 million in revenue, is 0.13% of turnover&lt;/strong&gt;. The entry cost isn’t the obstacle.&lt;/p&gt;
&lt;p&gt;The obstacle is what you sign up for at the same time. &lt;strong&gt;Your logs go to the United States&lt;/strong&gt;, or to a European subsidiary of an American company. The &lt;strong&gt;CLOUD Act&lt;/strong&gt;, passed in 2018, lets US authorities requisition this data from the provider, even when it’s physically stored in Europe. Microsoft Ireland, Splunk Cloud, CrowdStrike, all are subject to it through their parent company.&lt;/p&gt;
&lt;p&gt;And your incident logs aren’t just any data. They’re &lt;strong&gt;the complete fingerprints of your network&lt;/strong&gt;, the usernames, the application flows, the internal behaviours, the vulnerabilities exposed at the moment of the attack. The most sensitive material your information system produces. Handing it to a provider requisitionable by a foreign jurisdiction is a real operational risk.&lt;/p&gt;
&lt;p&gt;The &lt;strong&gt;Data Privacy Framework&lt;/strong&gt;, the EU-US legal bridge, survived first instance before the EU General Court in September 2025. It’s &lt;strong&gt;on appeal before the CJEU since 31 October 2025&lt;/strong&gt;. The CNIL, in its February 2025 decision on health hosting, is clear, &lt;em&gt;the only recognised marker for materialising a sovereign cloud remains the SecNumCloud qualification&lt;/em&gt;. None of the three SaaS providers cited has it.&lt;/p&gt;
&lt;p&gt;One last point. The reasonable entry cost is today. The billing mechanism gets worse as you grow. Every additional gigabyte ingested is charged, every additional endpoint too. At 50 gigabytes of logs per day, the Sentinel ticket climbs above &lt;strong&gt;$78,000 per year&lt;/strong&gt;, Splunk rises in proportion depending on the licence mode. You sign a modest entry price, you also sign a tariff lock-in that closes in as your SIEM sees wider and deeper.&lt;/p&gt;
&lt;p&gt;Conclusion, you pay a reasonable price for the plumbing today, by handing the most strategic data in your information system to a jurisdiction that isn’t yours, in an unfavourable legal framework, with a meter running against you at every extension of scope.&lt;/p&gt;
&lt;h3 id=&quot;option-2-do-nothing&quot;&gt;Option 2, do nothing&lt;/h3&gt;
&lt;p&gt;It’s tempting. It’s the most common strategy among SMEs, whether or not they’re in the NIS2 scope. Wait. See. Hope.&lt;/p&gt;
&lt;p&gt;The calculation is wrong on three fronts. &lt;strong&gt;GDPR today&lt;/strong&gt;, the CNIL has already sanctioned SMEs for failure to notify, the absence of any detection means is an aggravating factor. &lt;strong&gt;NIS2 tomorrow&lt;/strong&gt; if you enter through the supply chain or through a revision, the maximum sanction for an essential entity exceeds GDPR’s, &lt;strong&gt;the director’s personal liability&lt;/strong&gt; exists in black and white. &lt;strong&gt;Ransomware any time&lt;/strong&gt;, encryption of production, ransom, loss of operations, that’s another order of magnitude than getting into compliance.&lt;/p&gt;
&lt;p&gt;Doing nothing isn’t saving. It’s postponing, at the risk of worsening the final bill.&lt;/p&gt;
&lt;h3 id=&quot;option-3-sovereign-self-hosted&quot;&gt;Option 3, sovereign self-hosted&lt;/h3&gt;
&lt;p&gt;You build your SIEM with mature open-source bricks, deployed on an infrastructure you control. Four bricks, four complementary roles.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://wazuh.com/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;strong&gt;Wazuh&lt;/strong&gt;&lt;/a&gt;, it’s the brain of the setup, the central platform that brings all the logs to one place, stores them, analyses them and raises the alerts. It’s your “home-made Splunk”.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.crowdsec.net/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;strong&gt;CrowdSec&lt;/strong&gt;&lt;/a&gt;, it’s the bouncer at the door. A community network defence that automatically blocks the IP addresses already flagged as attackers by the other users of the network. When a bot scans a thousand sites before yours, it’s blacklisted before it reaches you.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://rspamd.com/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;strong&gt;Rspamd&lt;/strong&gt;&lt;/a&gt;, it’s the filter in front of your mail server. It intercepts spam and phishing attempts before they reach your employees’ inboxes. Mail remains the number one intrusion vector for SMEs, that’s where prevention pays off most.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://northpole.security/&quot; target=&quot;_blank&quot; rel=&quot;noopener noreferrer&quot;&gt;&lt;strong&gt;Santa&lt;/strong&gt;&lt;/a&gt;, it’s the execution controller on your Macs. It decides which applications are allowed to start on each machine, according to an allowlist you build. A ransomware downloaded by mistake can’t run, because it isn’t signed by a vendor you’ve approved. It’s the brick that turns an everyday Mac into a hardened workstation, without the user having to change their habits.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;None of these bricks is experimental. Wazuh is used by Fortune 100 companies. CrowdSec, a French company founded in 2019, aggregates 10 million signals a day, shared by more than 70,000 users across 190 countries. Rspamd powers Mailcow, Zimbra, Mailu, which set the reference. Santa, originally developed at Google and now maintained by North Pole Security, runs in production at Figma.&lt;/p&gt;
&lt;p&gt;The cost, it’s a correctly sized VPS, the installation time, and an internal competence you build. Not zero, but nowhere near the figures above.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;what-a-siem-really-is-for-someone-who-doesnt-do-blue-team&quot;&gt;What a SIEM really is, for someone who doesn’t do blue team&lt;/h2&gt;
&lt;p&gt;The word is scary. It smells of black screens, 24/7 teams and analysts speaking a dialect your IT manager doesn’t understand. Once demystified, it’s simpler.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A SIEM is plumbing.&lt;/strong&gt; Not a product, an assembly. Four functions that chain together:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Collect&lt;/strong&gt; the logs from your equipment, servers, firewalls, workstations, applications, mailboxes. Everything that produces a log, you bring to one place.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Centralise and keep&lt;/strong&gt; these logs in an exploitable format, with a retention that lets you investigate an incident going back several months.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Detect&lt;/strong&gt; abnormal behaviours. An account logging in at 3 in the morning from an unusual country, a burst of failed authentications, a process that modifies 10,000 files in one minute.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Alert&lt;/strong&gt; and keep the trace, for your ANSSI notification within 24 hours, and for your final report within 30 days.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;That’s it. No magic. A system that sees, that remembers, and that shouts when something’s wrong.&lt;/p&gt;
&lt;p&gt;The hard work isn’t the technology, it’s the adjustment. Which rules you enable, which thresholds you calibrate, who you send the alert to, how you respond. It’s the same thing on Splunk or on Wazuh. And it’s that internal competence you’re going to build across this series.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;in-short&quot;&gt;In short&lt;/h2&gt;
&lt;p&gt;Building your SIEM in 2026 pays you on two horizons.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Short term, it’s operational security.&lt;/strong&gt; A ransomware detected in hours instead of weeks, an exfiltration intercepted before the ransom, a GDPR breach you can characterise and notify within the deadlines. That ROI depends on no text that isn’t yet voted, it’s immediate.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Medium term, it’s amortised compliance.&lt;/strong&gt; You build the infrastructure and the internal competence &lt;em&gt;before&lt;/em&gt; the obligation lands on your head. Your competitors will build it under pressure, in a hurry, at three times the price of a flash-mission consultant. You’ll have taken a five-year lead on them for the price of a few weekends spread over a quarter.&lt;/p&gt;
&lt;p&gt;US SaaS does the job and isn’t out of price on the entry ticket. It just delivers your most strategic data into an unfavourable jurisdiction, and locks you into a model where every extra gigabyte is charged. Self-hosting demands an initial time investment. In the end, you’re master of the data, of the marginal cost and of the compliance schedule. Real sovereignty against a little of your time, which we’ll make a point of optimising across our articles.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;seven-episodes-to-build-your-plumbing&quot;&gt;Seven episodes to build your plumbing&lt;/h2&gt;
&lt;p&gt;It’s the stack I use in production. Not a blogger’s fantasy, an infrastructure that runs day to day, that detects, that logs, that notifies. Seven episodes, seven bricks:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/vps-durci-socle-siem-souverain/&quot;&gt;Episode 1, the foundation.&lt;/a&gt;&lt;/strong&gt; A hardened VPS, on a European host outside American reach. Choice of operator, base configuration, minimal attack surface, encrypted off-site backups.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/wazuh-tout-en-un-siem-souverain/&quot;&gt;Episode 2, Wazuh all-in-one.&lt;/a&gt;&lt;/strong&gt; Installing the manager, the indexer, the dashboard on a single node. Hardening, first dashboards. The functional equivalent of a Splunk for the price of a VPS.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/wazuh-agents-parc-siem-souverain/&quot;&gt;Episode 3, agents everywhere.&lt;/a&gt;&lt;/strong&gt; Deploying Wazuh agents on your servers, Macs and Windows. Collecting system logs, security events, file activity. The moment your SIEM starts to see.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/crowdsec-premiere-ligne-siem-souverain/&quot;&gt;Episode 4, CrowdSec on the front line.&lt;/a&gt;&lt;/strong&gt; The community network defence that blocks known attackers before they reach your services. Wazuh integration, signal sharing.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/rspamd-mail-siem-souverain/&quot;&gt;Episode 5, Rspamd for the mail.&lt;/a&gt;&lt;/strong&gt; The anti-spam and anti-phishing filter that plugs in front of your mail server, or integrates with your existing solution. Phishing detection, logging into Wazuh.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/santa-controle-execution-mac-siem-souverain/&quot;&gt;Episode 6, Santa on the Macs.&lt;/a&gt;&lt;/strong&gt; Execution control on Apple machines. North Pole Security fork, the project actively maintained since Google handed it over in 2024. Progressive lockdown, Wazuh integration.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://macsouverain.com/en/alerting-cout-total-siem-souverain/&quot;&gt;Episode 7, alerting and total cost.&lt;/a&gt;&lt;/strong&gt; Calibrated notifications, escalation, honest financial breakdown, episode-by-episode comparison with what the equivalent SaaS would have cost.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The links light up as the episodes publish, come back and plug into the new ones as they come out.&lt;/p&gt;
&lt;p&gt;Each episode is standalone. You can stop at 3 and already have covered the essentials of NIS2. You can push to 7 and have a stack with nothing to envy in those of large companies.&lt;/p&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>ms-pro</category><category>nis2</category><category>siem</category><category>securite</category><category>tutoriel</category><enclosure url="https://macsouverain.com/content/images/2026/06/feature-nis2-splunk-pourquoi-pme-siem-souverain-1.png" length="0" type="image/png"/></item><item><title>Apple Intelligence: What&apos;s Really Leaving Your Mac</title><link>https://macsouverain.com/en/38-apple-intelligence-ce-qui-sort-de-ton-mac/</link><guid isPermaLink="true">https://macsouverain.com/en/38-apple-intelligence-ce-qui-sort-de-ton-mac/</guid><description>Your Mac switched Apple Intelligence to ON without telling you. Three layers of processing, only one stays with you. And no one mentions the linked OpenAI account trap.</description><pubDate>Thu, 28 May 2026 07:48:57 GMT</pubDate><content:encoded>&lt;p&gt;&lt;strong&gt;Update of June 21, 2026.&lt;/strong&gt; Since June 8, 2026, PCC no longer runs solely on Apple silicon: for the heaviest queries (agentic, complex reasoning), Apple switches to Google Cloud hardware, NVIDIA GPU, Intel CPU, and Titan chip. Apple swears that the five guarantees hold, that it keeps software control, and that Google sees nothing in the clear. Perhaps. But the “all stays with Apple” argument for the general public has just fallen: it’s now also Google iron under Apple guarantees.&lt;/p&gt;
&lt;p&gt;You’ve updated your Mac. You’ve accepted the TOS without reading (like everyone else). A few weeks later, you realize that the “Apple Intelligence” toggle is on, when you had turned it off. It’s not a hallucination: since macOS 15.3 released on January 27, 2025, &lt;strong&gt;Apple Intelligence has switched from opt-in to opt-out.&lt;/strong&gt; And some users who had turned it off found it turned back on after 15.3.1, a bug confirmed by MacRumors and 9to5Mac, inconsistent from one device to another. Not a systematic rule, but frequent enough to check after each update.&lt;/p&gt;
&lt;p&gt;It’s time to understand what happens when you click “Summarize” on a long email. Because between your Neural Engine and a California data center, there are three processing layers. &lt;strong&gt;Only one stays really on your machine.&lt;/strong&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;why-this-question-is-not-harmless&quot;&gt;Why this question is not harmless&lt;/h2&gt;
&lt;p&gt;Apple sells Apple Intelligence as an IA “privacy-first”. The slogan is everywhere on the product site: aware of your personal information without collecting your personal information. It’s technically true for part of the perimeter, and technically false for the rest.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A generative AI, by construction, needs calculation.&lt;/strong&gt; When the model running on your Mac isn’t enough, the request goes out. Either to Apple servers or those of OpenAI. In both cases, &lt;strong&gt;your text leaves your machine.&lt;/strong&gt; The question isn’t whether it goes out. It’s where, under what guarantees, and how Apple informs you (spoiler: badly).&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;layer-1-the-local-model-what-stays-really-on-your-machine&quot;&gt;Layer 1: the local model, what stays really on your machine&lt;/h2&gt;
&lt;p&gt;On Apple Silicon (M1 and later), Apple runs a foundation model of about 3.18 billion parameters. Quantified 2 bits per weight via Quantization-Aware-Training, memory footprint of about 1 Go, shared KV-cache that saves 37.5% RAM. The calculation happens on the Neural Engine, the GPU, and the CPU of the chip, never on a server.&lt;/p&gt;
&lt;p&gt;In concrete terms, here’s what stays 100% local:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Writing Tools&lt;/strong&gt; short version: Proofread, Rewrite, Summarize on short texts&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Smart Reply&lt;/strong&gt; in Mail and Messages&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Notification summaries&lt;/strong&gt; and Priority Notifications&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Short Mail summaries&lt;/strong&gt; in the inbox list&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Genmoji&lt;/strong&gt; (generation of custom emoji)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Image Playground&lt;/strong&gt; (Animation, Illustration, Sketch)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Image Wand&lt;/strong&gt; in Notes&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Basic Siri&lt;/strong&gt; (understanding, type-to-Siri)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Clean Up Photos&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For these uses, &lt;strong&gt;your text does not leave the Apple Silicon.&lt;/strong&gt; No logs, no server, no content telemetry. That’s the honest perimeter of Apple’s promise, and it’s real.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The problem starts when you ask for something else.&lt;/strong&gt; Long summary of an 80-message Mail thread, generated text composition, multi-step Siri reasoning: &lt;strong&gt;your Mac knows it can’t handle the load. It switches.&lt;/strong&gt; And Apple doesn’t display any indicator to signal it.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;layer-2-private-cloud-compute-the-california-enclave&quot;&gt;Layer 2: Private Cloud Compute, the California enclave&lt;/h2&gt;
&lt;p&gt;This is Apple’s marketing strong point. PCC runs on custom-silicon Apple in their data centers, with five technical guarantees highlighted in the Security Research doc:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Stateless computation&lt;/strong&gt;: your text is used to respond, never stored after the request.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Enforceable guarantees&lt;/strong&gt;: the protections are technically applied, not contractually promised. An Apple admin can’t disable the mechanism.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;No privileged runtime access&lt;/strong&gt;: no remote shell, no interactive debugging. Apple can’t extract your data, even voluntarily.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Non-targetability&lt;/strong&gt;: an attacker can’t route your request to a compromised specific node. Request diffusion to nodes is random and attested.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Verifiable transparency&lt;/strong&gt;: each production build published in a cryptographically append-only log, binary images available for external inspection for 90 days.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Apple pushed its PCC server code on GitHub, opened a research environment to external researchers, and put up a $1 million bug bounty. As of today, it’s the most auditable cloud IA stack on the market.&lt;/p&gt;
&lt;p&gt;Now the nuances, because there are some.&lt;/p&gt;
&lt;p&gt;Trail of Bits, in its June 14, 2024 analysis, points out a point that Apple marketing glosses over: &lt;em&gt;“the data is decrypted on Apple’s server”&lt;/em&gt;. &lt;strong&gt;PCC is not homomorphic encryption&lt;/strong&gt; (the tech that calculates a model on encrypted data without ever decrypting it). It’s a hardened enclave, signed, attested, but &lt;strong&gt;your text is indeed decrypted on the Apple side&lt;/strong&gt; during the calculation. Security relies on the integrity of the enclave and the signing of the binaries, not on cryptographic magic. Apple is honest about this in the tech doc. The consumer slogan, however, leaves room for misunderstanding.&lt;/p&gt;
&lt;p&gt;Second nuance, more uncomfortable. Matthew Green, cryptographer at Johns Hopkins, on Mastodon in June 2024: &lt;em&gt;“Apple does not have explicit plans to announce when your data is going off-device for Private Compute, and you won’t opt into this or necessarily even be told it’s happening”&lt;/em&gt;. Translation: &lt;strong&gt;you don’t know if the summary of your mail stayed on your M2&lt;/strong&gt; or if it made a round trip to California. &lt;strong&gt;No visual indicator, no notification&lt;/strong&gt;, no user-side journal. Apple’s transparency is cryptographically verifiable but visually invisible.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;layer-3-chatgpt-the-opt-in-and-its-trap&quot;&gt;Layer 3: ChatGPT, the opt-in and its trap&lt;/h2&gt;
&lt;p&gt;ChatGPT is grafted onto Apple Intelligence since macOS 15.2. Turned off by default, activatable explicitly in &lt;code&gt;Apple Intelligence &amp;#x26; Siri → Extensions → ChatGPT&lt;/code&gt;. When you turn it on, Apple adds two protections over the standard OpenAI contract:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Your IP is masked&lt;/strong&gt; by the Apple relay (verbatim Apple Legal: &lt;em&gt;“your IP address is obscured from ChatGPT”&lt;/em&gt;). Approximate location passed, for legal compliance and anti-fraud.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;No-logs and no-training&lt;/strong&gt; on OpenAI’s side, &lt;em&gt;provided you haven’t linked your OpenAI account&lt;/em&gt;. Apple Legal: OpenAI &lt;em&gt;“must process your information solely for the purpose of fulfilling your request”, “must not store your information”, “must not use your information to improve or train its models”&lt;/em&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Read the conditional carefully. &lt;strong&gt;If you link &lt;em&gt;any&lt;/em&gt; OpenAI account&lt;/strong&gt; (free, Plus, Pro, Team) to retrieve your history or access GPT-5, &lt;strong&gt;you immediately opt out of Apple’s contract&lt;/strong&gt; and fall back under OpenAI’s standard TOS. Logs, conversation history, potential training, all under US jurisdiction. Apple mentions this in the legal text, in small print, after three paragraphs. Most users link their account without realizing they’ve just turned off the protection that made them choose Apple.&lt;/p&gt;
&lt;p&gt;Second detail. &lt;strong&gt;The “Confirm ChatGPT Requests” toggle is on by default&lt;/strong&gt;: Siri asks for confirmation before sending the text. You can turn it off. But especially, if you start your voice request with “Ask ChatGPT…”, confirmation is bypassed. It’s a documented shortcut on Apple’s side, that circumvents the only visible safeguard of the device. Photos and files keep confirmation, they do, in all cases.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;the-four-toggles-to-check&quot;&gt;The four toggles to check&lt;/h2&gt;
&lt;p&gt;Four paths to know on Sequoia 15.x and Tahoe 26. The English titles are guaranteed (tested by Apple Support on US Macs), the French ones are the titles you’ll likely see, to be confirmed on your Mac.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1. The master Apple Intelligence&lt;/strong&gt;
&lt;code&gt;System Settings → Apple Intelligence &amp;#x26; Siri&lt;/code&gt; (toggle at the top of the panel).
Default state since macOS 15.3: &lt;strong&gt;ON&lt;/strong&gt; on compatible Macs. Documented cases of reactivation on 15.3.1 (bug, not design). Rare afterwards, but check after each update. Turn off if you want nothing, really nothing.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2. ChatGPT master&lt;/strong&gt;
&lt;code&gt;System Settings → Apple Intelligence &amp;#x26; Siri → Extensions → ChatGPT → Use ChatGPT&lt;/code&gt;.
Default state: OFF. Activate only if you want it, and especially: don’t link your OpenAI account.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3. Confirm ChatGPT Requests&lt;/strong&gt;
&lt;code&gt;System Settings → Apple Intelligence &amp;#x26; Siri → Extensions → ChatGPT → Confirm ChatGPT Requests&lt;/code&gt;.
Default state: ON. Leave it on. The confirmation friction is your only visual indicator that a request is going off your Mac.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4. Improve Siri &amp;#x26; Dictation&lt;/strong&gt;
&lt;code&gt;System Settings → Privacy &amp;#x26; Security → Analytics &amp;#x26; Improvements → Improve Siri &amp;#x26; Dictation&lt;/code&gt;.
Default state: OFF. Check that it stayed OFF. It decides if Apple stores audio snippets of your Siri interactions for human review. Random ID, hourly rotation, no Apple ID link, they insist. You choose to trust them or not.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;apple-microsoft-google-who-does-what&quot;&gt;Apple, Microsoft, Google: who does what&lt;/h2&gt;
&lt;p&gt;Five criteria that matter to someone wondering about sovereignty. Vendor by vendor verdict.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Apple Intelligence.&lt;/strong&gt; Local by default, yes: 3B on-device model, explicit PCC switch for heavy queries. Public cryptographic attestation, yes: transparency log, dedicated research environment (VRE), server code published on GitHub. Cloud opt-in, half and half: implicit and invisible PCC, explicit and confirmed ChatGPT requests. Third-party LLM integrated, OpenAI ChatGPT, opt-in, OFF by default, no-logs as long as you don’t link your OpenAI account. Server jurisdiction, USA, Apple custom-silicon data centers.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Microsoft Copilot+/Recall.&lt;/strong&gt; Local by default, partial: Recall makes its snapshots locally and never sends them to the cloud, Copilot general runs in Azure. Public attestation, no: local VBS encryption plus TPM, no opposing auditable server. Cloud opt-in, depends on the feature: Recall purely local, Copilot general cloud by design, the user doesn’t always distinguish which triggers what. Third-party LLM integrated, Azure OpenAI GPT-4, commercial integration without separate opt-in. Server jurisdiction, USA plus global Azure regions.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Google Gemini.&lt;/strong&gt; Local by default, no: cloud Google by default, Gemini Nano local exists but remains limited to high-end Pixel devices. Public attestation, no. Cloud opt-in, the opposite: cloud by default, partial opt-out via Activity, and you lose features along the way. Third-party LLM integrated, none, Google’s stack locked down. Server jurisdiction, EEE/Switzerland via Google Ireland for EU accounts, rest of the world via Google LLC (USA).&lt;/p&gt;
&lt;p&gt;A quick read: on this specific dossier, Apple does better. Recall version 2025 is solid locally but remains an attack vector on shared devices (Kevin Beaumont has documented it repeatedly). Gemini keeps a subset of chats for up to three years for human review, even when you turn off activity. Apple is the only one to publish its server code and pay $1 million to have it broken.&lt;/p&gt;
&lt;p&gt;Apple spent $1 million to have its code broken. The others spent $1 million on TV spots. That doesn’t make PCC an E2EE. It makes it the least opaque cloud IA option on the market in 2026.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;macks-verdict&quot;&gt;Mack’s verdict&lt;/h2&gt;
&lt;p&gt;Apple has built the most auditable cloud IA architecture on the mass market. That’s a fact. Trail of Bits, Matthew Green, and Schneier all recognize it, each in their own way, while pointing out what’s wrong.&lt;/p&gt;
&lt;p&gt;What’s wrong is three UX decisions that betray &lt;strong&gt;a marketing intent superior to privacy intent&lt;/strong&gt;: the opt-out by default since 15.3, the complete absence of a visual indicator when a request switches to PCC, and the silent OpenAI account link trap. None of these three points is a bug. &lt;strong&gt;They’re choices.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;What you can reasonably do: turn off the master if you don’t need it, keep the ChatGPT confirmation toggle on if you use it, &lt;strong&gt;never link your OpenAI account&lt;/strong&gt;, check Improve Siri &amp;#x26; Dictation after each major update. That’s five minutes of settings, to be redone two or three times a year.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;em&gt;Also read: &lt;a href=&quot;https://macsouverain.com/en/cloud-ordinateur-quelquun-dautre&quot;&gt;The cloud, it’s someone else’s computer&lt;/a&gt;, &lt;a href=&quot;https://macsouverain.com/en/privacy-macos-les-parametres-a-changer-immediatement&quot;&gt;Privacy macOS: the settings to change immediately&lt;/a&gt;, and &lt;a href=&quot;https://macsouverain.com/en/convergence-libertes-numeriques&quot;&gt;Convergence of digital freedoms&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;sources&quot;&gt;Sources&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Apple, primary sources&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://machinelearning.apple.com/research/introducing-apple-foundation-models&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Apple Machine Learning Research, Introducing Apple’s On-Device and Server Foundation Models&lt;/a&gt;, official publication of the on-device model specifications (June 10, 2024).&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://machinelearning.apple.com/research/apple-foundation-models-tech-report-2025&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Apple Machine Learning Research, Foundation Models Tech Report 2025&lt;/a&gt; and &lt;a href=&quot;https://arxiv.org/abs/2507.13575&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;arXiv 2507.13575&lt;/a&gt;, technical details of the 2-bit QAT, PT-MoE, 15 languages (July 17, 2025).&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://security.apple.com/blog/private-cloud-compute/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Apple Security Research, Private Cloud Compute: A new frontier for AI privacy in the cloud&lt;/a&gt; and &lt;a href=&quot;https://security.apple.com/blog/pcc-security-research/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Security research on PCC&lt;/a&gt;, the complete PCC doc and the bug bounty.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.apple.com/legal/privacy/data/en/chatgpt-extension/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Apple Legal, ChatGPT Extension and Privacy&lt;/a&gt; and &lt;a href=&quot;https://support.apple.com/guide/mac-help/use-chatgpt-with-apple-intelligence-mchlfc5cf131/mac&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Apple Support, Use ChatGPT with Apple Intelligence on Mac&lt;/a&gt;, reference source for IP masking and conditional no-logs.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Independent analyses&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://blog.trailofbits.com/2024/06/14/pcc-bold-step-forward-not-without-flaws/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Trail of Bits, PCC: a bold step forward, not without flaws&lt;/a&gt;, recognized security firm, the most cited technical analysis of PCC’s limits (“data decrypted on Apple’s server”).&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://threadreaderapp.com/thread/1800291897245835616.html&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Matthew Green, Mastodon/X thread on PCC&lt;/a&gt;, cryptographer at Johns Hopkins University, on the absence of a visual indicator when a request switches to PCC.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://doublepulsar.com/microsoft-recall-on-copilot-pc-testing-the-security-and-privacy-implications-ddb296093b6c&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Kevin Beaumont (DoublePulsar), Microsoft Recall privacy implications&lt;/a&gt;, Windows security expert, on the residual risks of Recall version 2025.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.macrumors.com/2025/01/21/macos-sequoia-15-3-apple-intelligence-opt-out/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;MacRumors, macOS 15.3 enables Apple Intelligence automatically&lt;/a&gt;, coverage of the opt-in to opt-out switch (January 21, 2025).&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://ironcorelabs.com/blog/2024/apple-chatgpt-privacy-issues/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;IronCore Labs, Privacy Guide to Apple Intelligence with ChatGPT&lt;/a&gt;, for the OpenAI account link trap.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Comparison with competing IAs&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://support.microsoft.com/en-us/windows/privacy-and-control-over-your-recall-experience-d404f672-7647-41e5-886c-a3c59680af15&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Microsoft Support, Privacy and control over your Recall experience&lt;/a&gt;, Microsoft’s official Recall doc after the April 2025 relaunch.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://support.google.com/gemini/answer/13594961?hl=en&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Google Gemini Apps Privacy Hub&lt;/a&gt;, Google’s doc on retention, activity, and human review.&lt;/li&gt;
&lt;/ul&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>apple-intelligence</category><category>confidentialite</category><category>apple</category><category>ia</category><enclosure url="https://macsouverain.com/content/images/2026/06/feature-38-apple-intelligence-ce-qui-sort-de-ton-mac-1.png" length="0" type="image/png"/></item><item><title>Domestic stalkerware, the jealous partner&apos;s malware</title><link>https://macsouverain.com/en/stalkerware-spyzie-domestique-mai-2026/</link><guid isPermaLink="true">https://macsouverain.com/en/stalkerware-spyzie-domestique-mai-2026/</guid><description>Stalkerware Spyzie, Cocospy, Spyic, over 3 million victims combined. Your iPhone drained via your Apple ID. How to check and take back control.</description><pubDate>Tue, 26 May 2026 17:09:58 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;&lt;strong&gt;Public stalkerware (Spyzie, Cocospy, Spyic, mSpy) has over three million victims just within the Cocospy/Spyic/Spyzie family. Thirty to seventy dollars a month, operated by Chinese operators. On iPhone, your spouse knows your Apple ID and drains iCloud from the web. Less commonly, a hidden MDM profile installed by a close one in just two minutes. On Android, a hidden app. Premium modules: real-time GPS tracking and remote microphone activation. The victim never searches for the term “stalkerware” and doesn’t even know it exists.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What you need to do&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Check Settings, General, VPN and Device Management. Any profile you didn’t set yourself, especially vague ones like “iOS Update”, delete it. Check Screen Time, disable any password you didn’t set.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Change your Apple ID password, enable two-factor authentication, remove unknown devices from your list, and enable Advanced Data Protection to switch your iCloud backups to end-to-end encryption.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Switch to Signal for sensitive messages, Bitwarden or KeePassXC for passwords, never a shared vault.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4.&lt;/strong&gt; If you suspect active installation, act from another device and network. The Coalition Against Stalkerware lists resources by country.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;On May 26th, Joseph Cox of 404 Media interviewed Zack Whittaker, the journalist who’s been leaking pretty much all the major consumer stalkerware cases for the past five years. Verdict? It’s not a niche market, it’s a mass market. Hundreds of thousands of victims on just one network. Targets iPhones and Androids. Installation by your partner, ex, roommate, in two minutes while you’re in the shower.&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id=&quot;the-deal&quot;&gt;The Deal&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Stalkerware&lt;/strong&gt; is spyware sold to Joe and Jane Public. Not Pegasus, not Predator, not the mercenary spyware grade that Citizen Lab tracks from Toronto. The stuff you install on your girlfriend’s phone to read her messages, listen to her calls, track her location, and turn on her mic remotely. Brands like &lt;strong&gt;Spyzie&lt;/strong&gt;, &lt;strong&gt;Cocospy&lt;/strong&gt;, &lt;strong&gt;Spyic&lt;/strong&gt;, &lt;strong&gt;mSpy&lt;/strong&gt;, &lt;strong&gt;TheTruthSpy&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;Whittaker’s been leaking these since 2021. The latest wave, February 2025, exposed &lt;strong&gt;518,000 Spyzie clients&lt;/strong&gt; including at least &lt;strong&gt;4,900 compromised iPhones&lt;/strong&gt;, and &lt;strong&gt;2.65 million email addresses&lt;/strong&gt; on the twin network Cocospy + Spyic. That’s &lt;strong&gt;over three million victims&lt;/strong&gt; just from this one family of operators.&lt;/p&gt;
&lt;p&gt;Monthly subscription? Thirty to seventy dollars for the standard plan, more if you add premium modules like mic and cam access. Companies live in offshore holdings, Cyprus, British Virgin Islands, or straight out of China. &lt;strong&gt;Cocospy, Spyic, and Spyzie are all the same team&lt;/strong&gt;, traced back to one Chinese operator by Whittaker.&lt;/p&gt;
&lt;p&gt;mSpy runs the same business model under a separate brand, legacy Cyprus-Ukraine. When leaks expose them, they shut down and reopen under a new name. Market size? Around &lt;strong&gt;$145 million a year&lt;/strong&gt;, according to Future Market Insights.&lt;/p&gt;
&lt;p&gt;On the &lt;strong&gt;iPhone&lt;/strong&gt; side, the dominant method doesn’t even need physical access. Your partner knows your Apple ID password because you shared it, they’ve seen your iPhone unlock a hundred times, or you’ve used the same one for fifteen years. They log in to iCloud via browser, download your backups, and the stalkerware app does its thing server-side. No app on your phone, nothing to detect locally. Exactly how Whittaker documented Cocospy, Spyic, and Spyzie in 2025.&lt;/p&gt;
&lt;p&gt;Rarer but more comprehensive variant: a configuration profile MDM, the mechanism designed for managing business fleets. The close one installs the stalkerware app via &lt;a href=&quot;https://support.apple.com/apple-configurator&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Apple Configurator&lt;/a&gt; on their Mac, supervising your phone with a Lightning or USB-C cable. The profile’s marked &lt;code&gt;removalDisallowed&lt;/code&gt;, named something innocuous like “iOS Update” or “Battery Optimizer”. A Screen Time password your partner set hides the “Device Management” entry in Settings. You’re clueless. On &lt;strong&gt;Android&lt;/strong&gt;, it’s the app disguised as a system tool, hidden behind a generic name, with accessibility turned on to read everything for you.&lt;/p&gt;
&lt;h2 id=&quot;why-this-matters-to-you&quot;&gt;Why This Matters to You&lt;/h2&gt;
&lt;p&gt;Here’s where the usual cybersec press coverage drops off. We hear a lot about the mercenaries, NSO, Intellexa, Paragon, the billion-euro budgets and diplomatic targets. But the statistical danger for you? It’s not some state watching you, it’s your ex stalking you. States have their part too, pushing for mass control legislatively, as I’ve broken down in &lt;a href=&quot;https://macsouverain.com/en/convergence-libertes-numeriques/&quot;&gt;Six Months and Nineteen Global Texts, the Terrible Convergence&lt;/a&gt;. But the sheer frequency of domestic victims trumps all.&lt;/p&gt;
&lt;p&gt;Whittaker’s been saying since 2021 that &lt;strong&gt;domestic stalkerware outdoes all mercenary spyware combined&lt;/strong&gt;. The press ignores it because it’s dirty, intimate, lacks Pegasus’ geopolitical cachet.&lt;/p&gt;
&lt;p&gt;Information asymmetry is total. Buyers find these products in three clicks: fake “Top 10 spy apps” sites owned by sellers, SEO on jealous searches, Reddit with affiliate accounts, TikTok in “POV I hooked my guy” format, Google Ads hijacked on “Find My iPhone” or “family locator”.&lt;/p&gt;
&lt;p&gt;Marketing facade: “parental control for kids” quickly pivots to “monitor your spouse”. Potential victims never search for “stalkerware”. They don’t even know it exists. That’s the definition of a threat you don’t see coming.&lt;/p&gt;
&lt;p&gt;You’re the target. Couple with iPhone and Mac, integrated Apple ecosystem, shared iCloud family, common passwords “because we trust each other”. When trust cracks, siphoning takes a few clicks from a browser, or two minutes MDM installation while you’re out. You’ll only know reading this.&lt;/p&gt;
&lt;h2 id=&quot;what-you-do-now&quot;&gt;What You Do Now&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;1. Check your iPhone, configuration profiles, and Screen Time.&lt;/strong&gt;&lt;br&gt;
Settings, General, VPN &amp;#x26; Device Management. If you see a profile you didn’t install, especially with a vague name like “iOS Update”, “Battery Saver”, “Profile Service”, delete it. Then Settings, Screen Time. If a password’s active and it’s not yours, disable via your Apple ID. That password often hides the VPN &amp;#x26; Device Management entry. If the delete button’s greyed out or the profile returns after “Reset All Settings”, it’s &lt;code&gt;removalDisallowed&lt;/code&gt; with active DEP supervision: need Apple Store server-side break. Apple reference: &lt;a href=&quot;https://support.apple.com/guide/iphone/install-or-remove-configuration-profiles-iph6c493b1fb/ios&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;remove a configuration profile&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2. Take back control of your critical accounts.&lt;/strong&gt;&lt;br&gt;
Change your Apple ID password immediately and enable &lt;a href=&quot;https://support.apple.com/HT204915&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;two-factor authentication&lt;/a&gt; with a number your close circle doesn’t control. Check the list of devices connected to your Apple ID in Settings, top. Any unknown device, delete it. Enable &lt;a href=&quot;https://support.apple.com/HT202303&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Advanced Data Protection&lt;/a&gt; for end-to-end encrypted backups, server-side exfiltration becomes useless.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3. Switch to E2EE tools for sensitive stuff.&lt;/strong&gt;&lt;br&gt;
Critical messages on &lt;a href=&quot;https://signal.org/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Signal&lt;/a&gt;, not iMessage. Passwords in your own manager, &lt;a href=&quot;https://bitwarden.com/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Bitwarden&lt;/a&gt; self-hosted or KeePassXC local file, not a shared Apple Keychain. Local encrypted backups on external drive, not just iCloud.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4. If you suspect active installation, leave the physical perimeter before acting.&lt;/strong&gt;&lt;br&gt;
Stalkerware with mic and GPS rats you out in real-time. Contact specialized help services from an unsurveilled device and network. The &lt;a href=&quot;https://stopstalkerware.org/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Coalition Against Stalkerware&lt;/a&gt; lists resources by country and a response kit for victims.&lt;/p&gt;
&lt;h2 id=&quot;sources&quot;&gt;Sources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.404media.co/millions-of-people-are-installing-malware-on-their-partners-phones-with-zack-whittaker/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Millions of people are installing malware on their partner’s phones, with Zack Whittaker, 404 Media, 26/05/2026&lt;/a&gt; (primary source)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://techcrunch.com/2025/02/27/spyzie-stalkerware-spying-on-thousands-of-android-and-iphone-users/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Spyzie stalkerware spying on thousands of Android and iPhone users, TechCrunch, 27/02/2025&lt;/a&gt; (Whittaker’s investigation, 518k clients + 4,900 iPhones)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://techcrunch.com/2025/02/20/stalkerware-apps-cocospy-spyic-exposing-phone-data-of-millions-of-people/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Cocospy and Spyic exposing phone data of millions of people, TechCrunch, 20/02/2025&lt;/a&gt; (market architecture, 711.icu China link)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://techcrunch.com/2025/05/19/cocospy-stalkerware-apps-go-offline-after-data-breach/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Cocospy stalkerware apps go offline after data breach, TechCrunch, 19/05/2025&lt;/a&gt; (post-leak rebranding pattern)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://techcrunch.com/2020/08/11/stalkerware-apps-google-ads/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Stalkerware apps escape Google’s ad ban, TechCrunch, 11/08/2020&lt;/a&gt; (Google Ads workaround)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://stopstalkerware.org/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Coalition Against Stalkerware, victim resources&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;em&gt;Tech terms? &lt;a href=&quot;https://macsouverain.com/en/glossaire/&quot;&gt;Check the glossary.&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-alerte</category><category>stalkerware</category><category>spyzie</category><category>cocospy</category><category>spyic</category><category>mspy</category><category>privacy</category><category>iphone</category><category>mdm</category><category>surveillance-domestique</category><category>cybersec</category></item><item><title>The U.S. cyber regulator let its AWS keys slip six months ago.</title><link>https://macsouverain.com/en/cisa-nightwing-govcloud-leak-mai-2026/</link><guid isPermaLink="true">https://macsouverain.com/en/cisa-nightwing-govcloud-leak-mai-2026/</guid><description>A US federal cyber agency&apos;s subcontractor left their AWS GovCloud admin keys on a public GitHub repo for six months. Why not delegate your security, huh?</description><pubDate>Tue, 26 May 2026 13:39:33 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;**CISA, the U.S. federal cyber agency, just found out that one of its subcontractors left a public GitHub repository full of AWS GovCloud admin keys, tokens, and cleartext passwords for &lt;strong&gt;six months&lt;/strong&gt;. External detection by GitGuardian, not internal. The keys remained valid for 48 hours after the repo was removed. If the federal cyber regulator can’t even keep its own secrets, how are you supposed to? Let me explain!&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What you need to do&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Inventory what you’re currently entrusting to a third-party cloud, and for each item ask yourself who has the decryption key. At-rest encryption with server-side keys equals zero.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Choose your cloud providers based on one criterion: end-to-end encryption, client-side keys (Proton, Tuta, Mullvad for EU).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; What happens at home stays at home: backups on encrypted APFS external disk, double offsite encrypted copy.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;The Deal&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;On May 22, 2026, Brian Krebs published the investigation. An employee of &lt;a href=&quot;https://www.nightwing.com/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Nightwing&lt;/a&gt;, a historic subcontractor of CISA based in Dulles, Virginia, created a GitHub repository named “Private-CISA” on November 13, 2025. The word “Private” in the name, the &lt;code&gt;public&lt;/code&gt; setting in the parameters. The repo remained online, accessible to anyone, until mid-May 2026. Six months.&lt;/p&gt;
&lt;p&gt;Inside, there’s heavy stuff. &lt;strong&gt;Three sets of admin keys&lt;/strong&gt; for AWS GovCloud accounts, Amazon’s cloud environment dedicated to US federal agencies, certified FedRAMP High for hosting non-classified sensitive data (CUI).&lt;/p&gt;
&lt;p&gt;Access tokens, SSH keys, internal logs, and clear-text passwords following the “platform-year” pattern that a third-year intern wouldn’t dare to try. Plus some internal documents about the agency’s software development processes. Almost nothing, huh!&lt;/p&gt;
&lt;p&gt;And the detection? Neither CISA internal nor Nightwing audit. It’s &lt;a href=&quot;https://blog.gitguardian.com/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Guillaume Valadon&lt;/a&gt;, a researcher at &lt;a href=&quot;https://www.gitguardian.com/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;GitGuardian&lt;/a&gt;, who continuously scans public repos for forgotten secrets, who found the repo. Krebs and the consulting firm Seralys notified CISA, which had the repo taken down. The cherry on top: &lt;strong&gt;the AWS keys remained valid for 48 hours after the repo was removed&lt;/strong&gt; before the agency decided to revoke them.&lt;/p&gt;
&lt;p&gt;CISA’s official statement is one sentence we’ve seen a hundred times: “At this stage, there’s no indication that sensitive data has been compromised.” Nightwing refers to CISA, CISA refers to the investigation. Krebs qualifies the incident as “one of the most scandalous government data breaches in recent history,” and Bruce Schneier repeats the phrase without qualification.&lt;/p&gt;
&lt;h2 id=&quot;why-it-matters-to-you&quot;&gt;Why it matters to you&lt;/h2&gt;
&lt;p&gt;You’re not CISA, you don’t have a Nightwing subcontractor, you don’t use AWS GovCloud. Great. Now, do the cold calculation. &lt;strong&gt;The agency that sets the cybersecurity standards for US administrations&lt;/strong&gt;, that publishes “secure by design” guides and CVE alerts followed by the entire industry, &lt;strong&gt;just left its own cloud admin keys open for six months without noticing&lt;/strong&gt;. Not some dodgy subcontractor or some third-rate SaaS: the cyber regulator itself.&lt;/p&gt;
&lt;p&gt;The argument is structural, not anecdotal. When you entrust your secrets to a third party, no matter how serious they claim to be, you inherit &lt;strong&gt;their entire supply chain&lt;/strong&gt;. CISA entrusts to Nightwing, Nightwing employs someone, that someone pushes to GitHub. The weak link compromises the entire chain in an instant. That’s bad enough on its own, but add the IA threat surge, and you’ve potentially got a backdoor into more confidential systems.&lt;/p&gt;
&lt;p&gt;Let’s get back to you. You have a personal GitHub repo? You’ve ever pasted an API key into a commit for “quick testing” before forgetting to remove it from history? You use a cloud-owned password manager for creds that open your infrastructure? You trust a SaaS editor under foreign jurisdiction to keep your secrets securely encrypted for you? The CISA radar is you in miniature, but with fewer zeros on the consequences.&lt;/p&gt;
&lt;p&gt;The MacSouverain angle doesn’t change by a millimeter from the first article. Keep your secrets &lt;strong&gt;with you&lt;/strong&gt;. On your machine, in your local vault, under your key. You can delegate the formatting, syncing, encrypted backup. You don’t delegate security itself. Because the day your provider screws up, and they will, you want the blast radius to stop at them.&lt;/p&gt;
&lt;h2 id=&quot;what-you-do-now&quot;&gt;What you do now&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;1. Inventory what you’re currently entrusting to a cloud third party.&lt;/strong&gt;&lt;br&gt;
Grab a sheet of paper. Passwords, emails, contacts, files, notes, photo backups. For each one, write where it’s stored and who has the decryption key. If the answer to “who has the key” is “the provider, or one of their subcontractors,” you’re in exactly the same position as CISA. You’re trusting a chain you don’t control a link of.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2. Choose your cloud providers based on “end-to-end encrypted, key on client side”.&lt;/strong&gt;&lt;br&gt;
For what you have to put in the cloud (multi-device sync, sharing, backup), only accept providers who can’t read your content, even if they wanted to or were asked to.&lt;/p&gt;
&lt;p&gt;For email and storage: &lt;a href=&quot;https://proton.me/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Proton&lt;/a&gt; or &lt;a href=&quot;https://tuta.com/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Tuta&lt;/a&gt;, European jurisdiction, end-to-end encrypted by default. For VPN: &lt;a href=&quot;https://mullvad.net/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Mullvad&lt;/a&gt; or &lt;a href=&quot;https://protonvpn.com/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Proton VPN&lt;/a&gt;, no logs. The difference from AWS, Google Drive, iCloud non-ADP: you don’t have to take the provider’s word for it, the architecture makes unauthorized access technically impossible.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3. What happens at your place stays at your place.&lt;/strong&gt;&lt;br&gt;
Whatever you can keep local, keep it local. Photos, archives, sensitive documents, backups: an encrypted APFS external drive at home, plus a second encrypted copy you store with a friend or in a safe. If you need to sync files between your own devices without going through a third party, &lt;a href=&quot;https://syncthing.net/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Syncthing&lt;/a&gt; does direct P2P between your devices, period. You don’t go to the cloud by default, you go there deliberately. The CISA rule applies in miniature to everyone: the day your provider screws up, and they will, you want the blast radius to stop at them, not take you down with them.&lt;/p&gt;
&lt;h2 id=&quot;sources&quot;&gt;Sources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;CISA Admin Leaked AWS GovCloud Keys on GitHub, Krebs on Security, May 22, 2026&lt;/a&gt; (primary source)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.schneier.com/blog/archives/2026/05/cisa-security-leak.html&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;CISA Security Leak, Schneier on Security, May 22, 2026&lt;/a&gt; (commented repost)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.gitguardian.com/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;GitGuardian, scanner of secrets in public repos&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;see-also&quot;&gt;See also&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read: &lt;a href=&quot;https://macsouverain.com/en/cloud-ordinateur-quelquun-dautre/&quot;&gt;The cloud, it’s someone else’s computer&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read: &lt;a href=&quot;https://macsouverain.com/en/gestionnaire-mots-de-passe-mac-comparatif/&quot;&gt;Password manager on Mac, comparison&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;em&gt;What are those tech terms? &lt;a href=&quot;https://macsouverain.com/en/glossaire/&quot;&gt;Check the glossary.&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-alerte</category><category>severite-5</category><category>cisa</category><category>nightwing</category><category>aws</category><category>govcloud</category><category>souverainete</category><category>cybersec</category><category>delegation</category><category>cloud</category></item><item><title>Your Mac was patched by XProtect without your knowledge, it&apos;s for your own good</title><link>https://macsouverain.com/en/ton-mac-patche-a-ton-insu-xprotect/</link><guid isPermaLink="true">https://macsouverain.com/en/ton-mac-patche-a-ton-insu-xprotect/</guid><description>On May 11, 2026, 170 npm packages in the TanStack ecosystem were compromised in six minutes. The next day, Apple pushed an XProtect signature onto your Mac without telling you. Here&apos;s how to check.</description><pubDate>Tue, 19 May 2026 07:25:30 GMT</pubDate><content:encoded>&lt;p&gt;&lt;strong&gt;While you were sleeping, on the evening of May 11th, 170 software packages, used by half of the web, became malicious in just six minutes. The next day, Apple pushed an XProtect signature onto your Mac, without telling you.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The two events are likely connected. However, you’ll never know for sure. This incident has a name, &lt;strong&gt;TanStack&lt;/strong&gt;. The mechanism that may have reacted on your Mac is called &lt;strong&gt;XProtect&lt;/strong&gt;. You didn’t see anything, neither did I. Apple makes sure of that.&lt;/p&gt;
&lt;p&gt;Welcome to the silent defense system of your Mac.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;the-tanstack-incident-in-30-seconds&quot;&gt;The TanStack Incident in 30 Seconds&lt;/h2&gt;
&lt;p&gt;On the evening of May 11th, 2026, the &lt;strong&gt;TanStack&lt;/strong&gt; ecosystem, an ultra-popular JavaScript toolkit used by millions of developers (including those from OpenAI, Netflix, Shopify), was compromised. In six minutes, &lt;strong&gt;170 packages&lt;/strong&gt; were released with malicious versions. The most visible one, &lt;code&gt;react-router&lt;/code&gt;, is downloaded &lt;strong&gt;12 million times a week&lt;/strong&gt;. In other words, a significant portion of the web that updates this week is getting infected without knowing it.&lt;/p&gt;
&lt;p&gt;The malware is called &lt;strong&gt;Mini Shai-Hulud&lt;/strong&gt;, a variant of the npm worm that has been around since 2024. Its target is whatever is on the developer’s Mac: passwords, cloud access keys, GitHub tokens, session files. On macOS, it installs itself discreetly and relaunches every time a session is opened. Clean, professional.&lt;/p&gt;
&lt;p&gt;The worrying detail is the vector. The attacker didn’t steal any passwords or exploit any code flaws. They just &lt;strong&gt;submitted a false contribution&lt;/strong&gt; to the open-source TanStack project, exploiting an imprudent automation system configuration.&lt;/p&gt;
&lt;p&gt;Any contribution was executed with the real publication rights. A malicious pull request was enough to retrieve the signature token and publish 170 packages under the legitimate identity of the project. On npm’s side, everything seemed normal, signed, and verified. Stamped by TanStack itself.&lt;/p&gt;
&lt;p&gt;OpenAI was affected by association, via one of its dependencies. Officially, &lt;strong&gt;there’s no proof of any product or user data compromise&lt;/strong&gt;. But they still &lt;strong&gt;rotated all their applicative signature keys&lt;/strong&gt; on macOS, iOS, Windows, and Android, and republished all their apps under new certificates.&lt;/p&gt;
&lt;p&gt;You don’t do that when everything’s fine.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Apple reacted the next day&lt;/strong&gt;. No communiqué, no notification, no tab in Settings. &lt;strong&gt;An XProtect signature was silently pushed&lt;/strong&gt;. Macs picked it up over the hours, one by one, without telling anyone.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;xprotect-apples-silent-antivirus&quot;&gt;XProtect, Apple’s Silent Antivirus&lt;/h2&gt;
&lt;p&gt;XProtect is macOS’s integrated antivirus. It’s been there since Snow Leopard, and most users don’t even know it exists. That’s by design.&lt;/p&gt;
&lt;p&gt;It works in two parts. The first is the &lt;strong&gt;signature engine&lt;/strong&gt;: a file that macOS consults before executing a downloaded app to check if it matches a known malware. The second is &lt;strong&gt;XProtect Remediator, XPR&lt;/strong&gt;, a scanner that runs in the background and inspects your disk for threats that are already installed. When it finds one, it neutralizes it.&lt;/p&gt;
&lt;p&gt;Signatures are pushed by Apple via &lt;strong&gt;CloudKit&lt;/strong&gt;, the same silent pipeline that synchronizes your iCloud photos and keychain. When a significant malware emerges, Apple compiles a signature, signs it, deposits it on CloudKit. Your Mac picks it up during the next check, usually within 24 to 72 hours.&lt;/p&gt;
&lt;p&gt;No notification. No restart. No “your Mac has been updated” message. Apple made an editorial choice not to alarm users. The downside is that you have no way of knowing, at a glance, if you’re properly patched for the recent incident.&lt;/p&gt;
&lt;p&gt;That’s where it gets interesting.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;the-push-5344-may-12th-the-day-after-tanstack&quot;&gt;The Push 5344, May 12th, the day after TanStack&lt;/h2&gt;
&lt;p&gt;The XProtect version published on May 12th, 2026, is called &lt;strong&gt;5344&lt;/strong&gt;. The previous one, 5342, was from May 5th. Perfect temporal match with TanStack, one day later.&lt;/p&gt;
&lt;p&gt;Except Apple never publicly documents the content of an XProtect signature. Howard Oakley, who dissects each release on eclecticlight.co, notes on 5344 “some adjustments on known malware families”. No TanStack or Shai-Hulud signature. Nothing officially saying “this is the response to yesterday’s incident”.&lt;/p&gt;
&lt;p&gt;Coincidence or targeted reaction? Apple isn’t saying. That’s precisely what justifies looking into it.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;check-in-30-seconds-if-your-mac-is-patched&quot;&gt;Check in 30 Seconds if Your Mac is Patched&lt;/h2&gt;
&lt;p&gt;On macOS 15 Sequoia and macOS 26 Tahoe, Apple moved XProtect to a new location and provides a native command. That’s the recommended way. On macOS 14 Sonoma and earlier, the old location is still valid. I’ll give you both.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1. The XProtect signature version&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;On Sequoia and Tahoe:&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; xprotect&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; version&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;You’ll get a number like &lt;code&gt;5344&lt;/code&gt; or &lt;code&gt;5347&lt;/code&gt;. That’s the signature base. The higher the number, the more recent it is.&lt;/p&gt;
&lt;p&gt;On Sonoma and earlier:&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;defaults&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; read&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; /Library/Apple/System/Library/CoreServices/XProtect.bundle/Contents/Info&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; CFBundleShortVersionString&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The old path still exists on Sequoia and Tahoe, but macOS doesn’t consult it first anymore. You can read it and get an outdated version while &lt;code&gt;sudo xprotect version&lt;/code&gt; gives you the real one. That’s exactly the kind of trap that makes you think your Mac is behind when it’s not.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2. The XProtect Remediator version&lt;/strong&gt;&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;defaults&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; read&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; /Library/Apple/System/Library/CoreServices/XProtect.app/Contents/Info&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; CFBundleShortVersionString&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;You’ll get a number like &lt;code&gt;157&lt;/code&gt;. That’s the scanner itself, updated much less often than the signatures.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3. The installation history&lt;/strong&gt;&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;system_profiler&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; SPInstallHistoryDataType&lt;/span&gt;&lt;span style=&quot;color:#D73A49&quot;&gt; |&lt;/span&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt; grep&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; -A&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; 2&lt;/span&gt;&lt;span style=&quot;color:#005CC5&quot;&gt; -i&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; xprotect&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;You’ll see all the XProtect versions installed with their dates. Great for checking if your Mac isn’t stuck on an old base because CloudKit has a problem.&lt;/p&gt;
&lt;p&gt;To compare your version with what Apple publishes in real-time, the public tracker on Howard Oakley’s &lt;a href=&quot;https://eclecticlight.co/category/macos/security/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;eclecticlight.co&lt;/a&gt; keeps the list up-to-date. Oakley is a British engineer who’s been dissecting macOS for fifteen years. He’s the reference on the subject.&lt;/p&gt;
&lt;p&gt;And if your Mac is behind, force the check:&lt;/p&gt;
&lt;pre class=&quot;astro-code github-light&quot; style=&quot;background-color:#fff;color:#24292e; overflow-x: auto;&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span style=&quot;color:#6F42C1&quot;&gt;sudo&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; xprotect&lt;/span&gt;&lt;span style=&quot;color:#032F62&quot;&gt; update&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;On Sonoma and earlier, the old command &lt;code&gt;sudo softwareupdate --background-critical&lt;/code&gt; still works.&lt;/p&gt;
&lt;p&gt;At the time of publishing, the latest version is &lt;strong&gt;5344, on May 12th, 2026&lt;/strong&gt;. If your Mac shows less, your CloudKit channel is slow.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;the-sovereign-downside&quot;&gt;The Sovereign Downside&lt;/h2&gt;
&lt;p&gt;XProtect is a black box signed by Cupertino. You don’t know which signatures are pushed, what telemetry is sent back, or who decides that a binary is malicious. Apple decides, Apple pushes, your machine executes.&lt;/p&gt;
&lt;p&gt;The mechanism is useful, very useful even. Blocking known malwares before they execute is the base of modern defense, and doing it without bothering you will prevent you from disabling it when you’re fed up with that &lt;strong&gt;rognutudju!!&lt;/strong&gt; pop-up (look it up, if you’re under 50, you won’t get the reference).&lt;/p&gt;
&lt;p&gt;The three commands above give you a minimal right to look into what your OS does without asking. It’s a small step towards sovereignty, not taking control back, just knowing.&lt;/p&gt;
&lt;p&gt;The difference between a passive user and a sovereign user isn’t just in the tools they use. It’s also in the questions they ask. What version do I have? When was it pushed? What’s in it?&lt;/p&gt;
&lt;p&gt;Apple answers the first two with three Terminal lines. On the third, they stay silent. It’s Howard Oakley who dissects the content afterwards and publishes the diffs on &lt;a href=&quot;https://eclecticlight.co/category/macos/security/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;eclecticlight.co&lt;/a&gt;. You’ll never know directly what Apple has stamped as malicious that night.&lt;/p&gt;
&lt;p&gt;Every month, I still check the XProtect versions on my Macs. Nothing heroic, just a habit. The day CloudKit’s channel screws up, I’ll have a reference point.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read also: &lt;a href=&quot;https://macsouverain.com/en/privacy-macos-les-parametres-a-changer-immediatement/&quot;&gt;The macOS settings to change immediately&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;hr&gt;
&lt;h2 id=&quot;in-summary&quot;&gt;In Summary&lt;/h2&gt;
&lt;p&gt;XProtect is useful, silent, and out of your control. The topic is knowing that it exists, knowing the three commands that tell you where you stand, and understanding that in the 2026 JavaScript supply chain, like others, it patches the leaks.&lt;/p&gt;
&lt;p&gt;Run the three commands. Note your numbers. Compare them to &lt;a href=&quot;https://eclecticlight.co/category/macos/security/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;eclecticlight.co&lt;/a&gt; every now and then. It takes thirty seconds, and it lets you know if you’re properly patched and up-to-date.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read also: &lt;a href=&quot;https://macsouverain.com/en/lockdown-mode-face-a-coruna-toolkit-espionnage-gouvernemental/&quot;&gt;Lockdown Mode vs. Coruña, the government spy toolkit&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;em&gt;Technical terms? &lt;a href=&quot;https://macsouverain.com/en/glossaire/&quot;&gt;Check the glossary.&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>securite</category><category>macos</category><category>xprotect</category><category>supply-chain</category><category>informatif</category><enclosure url="https://macsouverain.com/content/images/2026/05/feature-37-xprotect-v3.png" length="0" type="image/png"/></item><item><title>Five years of defending memory M5 down in five days</title><link>https://macsouverain.com/en/apple-m5-mie-bypass-calif-mythos-mai-2026/</link><guid isPermaLink="true">https://macsouverain.com/en/apple-m5-mie-bypass-calif-mythos-mai-2026/</guid><description>Three California researchers bypassed Memory Integrity Enforcement M5 in five days using Mythos. First public kernel exploit on Apple M5 silicon. Patched in macOS Tahoe 26.5.</description><pubDate>Tue, 19 May 2026 07:23:49 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;&lt;strong&gt;Three researchers took full control of a Mac M5 in five days&lt;/strong&gt;, with a helping hand from &lt;strong&gt;Mythos&lt;/strong&gt;, Anthropic’s specialized IA vulnerability AI. In the process, &lt;strong&gt;they took down MIE, Apple’s five-year-old memory protection&lt;/strong&gt;. Apple patched it in macOS Tahoe 26.5 on May 11. First public kernel exploit on M5 silicon, and a real-world show that AI can speed this kind of work by a factor of ten.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What you need to do&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Update macOS Tahoe 26.5 immediately (System Preferences, Software Update).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Enable Lockdown Mode if you’re professionally exposed (journalist, activist, executive).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Avoid all unverified user binaries. Strict Gatekeeper, signatures on Homebrew.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;The Deal&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;On May 14, 2026, Calif.io spilled the beans on how they did it. Three researchers (Bruce Dang, Dion Blazakis, Josh Maine) found two bugs in the macOS kernel on a brand-new Mac M5. They chained them together. Result: a regular user, with no special privileges, &lt;strong&gt;gains full control of the machine (root)&lt;/strong&gt;. Reading all memory, accessing the Keychain, disabling protections. Everything.&lt;/p&gt;
&lt;p&gt;What makes this historical is what came out alongside it. The M5 chip debuts &lt;strong&gt;MIE&lt;/strong&gt; (Memory Integrity Enforcement), a protection hard-coded into the silicon. In other words, Apple tagged every piece of memory used by the kernel, and the hardware refuses tampering. &lt;strong&gt;Five years of work.&lt;/strong&gt; Unveiled last year as the new frontier of Mac security. &lt;strong&gt;Calif bypassed it in five days.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The game-changer: &lt;strong&gt;Mythos&lt;/strong&gt;. It’s Anthropic’s frontier model, restricted access for vulnerability research. The researchers clarify that Mythos didn’t find the exploit alone. Bypassing MIE requires sharp human expertise. But Mythos spotted the bugs fast, where humans alone would’ve taken weeks. &lt;strong&gt;Months of work now takes days.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Calif handed the details to Apple in Cupertino. Apple released the fixes in macOS Tahoe 26.5 on &lt;strong&gt;May 11, 2026&lt;/strong&gt;. The release notes credit “Calif.io in collaboration with Claude and Anthropic Research”. The full technical report (55 pages) is under embargo until the patches roll out everywhere. Apple hasn’t publicly commented on the exploit chain.&lt;/p&gt;
&lt;h2 id=&quot;why-it-matters-to-you&quot;&gt;Why it matters to you&lt;/h2&gt;
&lt;p&gt;If you’ve got a Mac M5, your hardware was sold as the high-water mark of Apple security. Five days after the exploit was released, &lt;strong&gt;the frontier moved&lt;/strong&gt;. Hardware protection alone isn’t enough; a well-equipped human can bring it down in a week.&lt;/p&gt;
&lt;p&gt;Good news: &lt;strong&gt;it’s not a remote attack&lt;/strong&gt;. To exploit the bugs on your Mac, the attacker needs a foothold. A booby-trapped binary you ran yourself (compromised Homebrew, app grabbed outside the App Store, file opened from a sketchy shared drive). From there, though, they’re root and can do whatever they want.&lt;/p&gt;
&lt;p&gt;The bigger picture: Mythos is making waves. On May 11, curl maintainer Daniel Stenberg confirmed a flaw in his code found by Mythos (Stenberg’s still skeptical, but acknowledges the result). Three days later, Calif.io took down MIE. &lt;strong&gt;The window between ‘bug discovered’ and ‘functional exploit’ is closing&lt;/strong&gt;. Apple, Google, and Microsoft have all publicly acknowledged that the latest AI models are changing the threat model. We’re seeing it in practice now.&lt;/p&gt;
&lt;h2 id=&quot;what-you-do-now&quot;&gt;What you do now&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;1. Update macOS Tahoe 26.5 right now&lt;/strong&gt;, on all your Macs (M5, M4, M3, M2, M1, Intel). The update covers bugs beyond just the M5. System Preferences, General, Software Update. If you’re still on macOS Sequoia 15.7.7 or macOS Sonoma 14.8.7, they got the cousin fixes the same day.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2. Turn on Lockdown Mode&lt;/strong&gt; if you’re professionally exposed (journalist, activist, executive, researcher). Lockdown Mode severely cuts the kernel memory attack surface, exactly what Calif exploited. System Preferences, Privacy &amp;#x26; Security, Lockdown Mode. Beware, there’ll be friction.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Read: &lt;a href=&quot;https://macsouverain.com/en/lockdown-mode-face-a-coruna-toolkit-espionnage-gouvernemental/&quot;&gt;Lockdown Mode, why to turn it on&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;3. Avoid binaries from nowhere&lt;/strong&gt;. No out-of-App Store apps without audit, no random executables. Verify signatures (GPG, SHA256) on sensitive tools, Homebrew included. Set Gatekeeper to strict in System Preferences, Privacy &amp;#x26; Security, allow only the App Store.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4. Stay tuned&lt;/strong&gt;: Calif’s 55-page tech report comes out once the patches are widely deployed. When it’s public, expect a wave of copies on GitHub and a full Mac fleet scan by security teams. Until then, just stay updated.&lt;/p&gt;
&lt;h2 id=&quot;sources&quot;&gt;Sources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://blog.calif.io/p/first-public-kernel-memory-corruption&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;First public macOS kernel memory corruption exploit on Apple M5, blog.calif.io&lt;/a&gt; (primary source Calif.io)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://support.apple.com/en-us/127115&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;About the security content of macOS Tahoe 26.5, Apple Security, 11/05/2026&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://9to5mac.com/2026/05/14/calif-team-details-how-anthropic-mythos-helped-build-a-working-macos-exploit-in-five-days/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Calif team details how Anthropic Mythos helped build a working macOS exploit in five days, 9to5Mac, 14/05/2026&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Mythos finds a curl vulnerability, Daniel Stenberg, 11/05/2026&lt;/a&gt; (skeptical counterpoint)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;also-see&quot;&gt;Also see&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://macsouverain.com/en/radar-anthropic-mythos-acces-non-autorise-avril-2026/&quot;&gt;Anthropic Mythos: unauthorized access identified&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-alerte</category><category>apple</category><category>macos</category><category>m5</category><category>kernel</category><category>mythos</category><category>anthropic</category><category>calif-io</category><category>mie</category></item><item><title>Google Ads and real cat Claude share your credentials</title><link>https://macsouverain.com/en/radar-macsync-google-ads-claude-share-mai-2026/</link><guid isPermaLink="true">https://macsouverain.com/en/radar-macsync-google-ads-claude-share-mai-2026/</guid><description>Google sponsored ads redirect to real, shared claude.ai links that are baited. Fake Apple Support makes you paste a base64 into Terminal. MacSync payload empties your Keychain.</description><pubDate>Thu, 14 May 2026 11:58:10 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;&lt;strong&gt;A malicious ad campaign is hijacking Google Ads and Claude.ai’s Share function to promote MacSync, an info-stealing macOS malware that empties your Keychain with a simple terminal command you paste yourself. The pattern combines two trust signals (official claude.ai domain + fake Apple Support) to lure you into running base64 without suspicion.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What you need to do&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Never paste a terminal command dictated by a website, AI chat, or an “official” PDF.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Enable Little Snitch or LuLu and monitor unexpected network traffic.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; If already executed: disconnect from Wi-Fi, change all your browser passwords, and scan with KnockKnock.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;You’re searching “Claude mac download” on Google. The first sponsored result points to claude.ai, so the URL is legitimate. Except it’s a shared Claude chat where a fake “Apple Support” dictates a Terminal command to paste. You paste it, and MacSync steals your Keychain, cookies, and browser credentials.&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id=&quot;the-fact&quot;&gt;The Fact&lt;/h2&gt;
&lt;p&gt;Berk Albayrak (Trendyol Group) and BleepingComputer have been documenting since May 10, 2026, an active macOS malvertising campaign that exploits two legitimate mechanisms simultaneously. First, Google Ads: a sponsored ad for “Claude mac download” points to &lt;code&gt;claude.ai&lt;/code&gt;, Anthropic’s official domain. Then, Claude.ai Share: this feature is used to host a fake installation guide signed “Apple Support” that tells the user to paste a base64-encoded command into Terminal.&lt;/p&gt;
&lt;p&gt;The command downloads a polymorphic shell script from the attacker’s infrastructure, checks the keyboard layout (exits immediately if Russian or CIS), then executes the second-stage payload via &lt;code&gt;osascript&lt;/code&gt; (macOS’s native AppleScript engine) for fileless delivery. The malware is called MacSync, an infostealer that collects browser credentials and cookies, exfiltrates the macOS Keychain, and fingerprints the victim (IP, hostname, OS version, keyboard language).&lt;/p&gt;
&lt;p&gt;The indicators of compromise published are payload &lt;code&gt;customroofingcontractors[.]com/curl/&lt;/code&gt; and &lt;code&gt;bernasibutuwqu2[.]com/debug/loader.sh&lt;/code&gt;, exfiltration to &lt;code&gt;briskinternet[.]com&lt;/code&gt;. The two identified Claude.ai Share URLs are &lt;code&gt;claude[.]ai/share/9aac1046-a39e-4618-8265-f54c4be863f7&lt;/code&gt; and &lt;code&gt;claude[.]ai/share/eb2db455-1d47-4baf-8671-0a689e165902&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Don’t worry, the links are disabled here, but Anthropic hadn’t disabled the Share mechanism at the time of BleepingComputer’s publication.&lt;/p&gt;
&lt;h2 id=&quot;why-this-is-a-game-changer&quot;&gt;Why This is a Game-Changer&lt;/h2&gt;
&lt;p&gt;Two things, really. First, &lt;strong&gt;the “shared chat” feature of a public AI platform becomes a malware distribution surface&lt;/strong&gt;. Claude.ai’s shared pages are public, indexable, and notably, &lt;strong&gt;not moderated like typical user content&lt;/strong&gt;. They inherit Anthropic’s visual trust, and at the time of BleepingComputer and GBHackers’ publications, both compromised share URLs were still online.&lt;/p&gt;
&lt;p&gt;Second, &lt;strong&gt;AI brand hijacking&lt;/strong&gt; joins known malvertising schemes (Homebrew, Loom, Notion, AnyDesk), with Claude Code being a recent dev tool, its official installation page isn’t yet a muscle memory reflex, leaving an exploitable window.&lt;/p&gt;
&lt;p&gt;This is also a case study on &lt;strong&gt;Google Ads&lt;/strong&gt;, despite announced controls, ads impersonating brands continue to slip through, exploiting the legitimate display URL while pointing to a compromised page on the editor’s own site.&lt;/p&gt;
&lt;p&gt;Domain validation isn’t enough when the editor hosts user content. Responsibility is shared, &lt;strong&gt;Anthropic&lt;/strong&gt; needs to beef up shared chat moderation (detect chats posing as official support of other brands, banner on chats containing shell commands, visual watermark distinguishing a shared chat from a product page), &lt;strong&gt;Google&lt;/strong&gt; needs to go beyond display domain in Ads validation. But the last line is &lt;strong&gt;you, never paste a Terminal command blindly&lt;/strong&gt;.&lt;/p&gt;
&lt;h2 id=&quot;why-this-matters-to-you&quot;&gt;Why This Matters to You&lt;/h2&gt;
&lt;p&gt;The social engineering pattern here is ruthless because it chains two usually legitimate trust signals. The &lt;code&gt;claude.ai&lt;/code&gt; official domain, native Anthropic Share feature, fake “Apple Support” in a supposedly serious AI environment. You’re not clicking on some obscure download site, you’re clicking on what looks like official documentation brought up by a search engine, exactly the kind of attack that slips under usual vigilance.&lt;/p&gt;
&lt;p&gt;The target is wide. Not just developers (Homebrew, GitHub), but any Mac user curious to try Claude desktop. The malware doesn’t require any system elevation, no 0day, no TCC bypass, the user does all the work themselves by pasting the command. And since &lt;code&gt;osascript&lt;/code&gt; is a native, signed Apple binary, it slips under most commercial EDRs and even XProtect.&lt;/p&gt;
&lt;p&gt;The angle that concerns you directly: it’s the offensive return of the macOS Keychain as a prime target. You’ve learned to protect your Mac’s user password, enable FileVault, use Touch ID. But a Terminal command launched by yourself circumvents all that, because you’re the one opening the door.&lt;/p&gt;
&lt;h2 id=&quot;what-you-do-now&quot;&gt;What You Do Now&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Never paste a Terminal command dictated by a website, AI chat, or “official support” PDF. If you must install a tool like Claude desktop, go directly to &lt;code&gt;claude.ai/download&lt;/code&gt; by typing the URL yourself, never via a sponsored Google result. The universal rule: if someone tells you to paste anything into Terminal, it’s a no.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Enable Little Snitch or LuLu in hardened silent mode. Both log and block unexpected outgoing network connections to the published IOCs (&lt;code&gt;customroofingcontractors[.]com&lt;/code&gt;, &lt;code&gt;bernasibutuwqu2[.]com&lt;/code&gt;, &lt;code&gt;briskinternet[.]com&lt;/code&gt;). If you suspect a hasty command, check outgoing connections in the minutes after.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; If you’ve run a suspicious command recently: disconnect from Wi-Fi immediately, change all your browser passwords (from a clean device), revoke all active cloud session tokens (mail, sync, password manager), scan with KnockKnock or ReiKey from Objective-See, check launch agents in &lt;code&gt;~/Library/LaunchAgents/&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4.&lt;/strong&gt; Monitor your Keychain. &lt;code&gt;security dump-keychain | grep -i password&lt;/code&gt; tells you what’s inside. For the future, migrate sensitive passwords to Apple Passwords or Proton Pass, not the general iCloud Keychain by default.&lt;/p&gt;
&lt;h2 id=&quot;sources&quot;&gt;Sources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.bleepingcomputer.com/news/security/hackers-abuse-google-ads-claudeai-chats-to-push-mac-malware/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://www.bleepingcomputer.com/news/security/hackers-abuse-google-ads-claudeai-chats-to-push-mac-malware/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://objective-see.org/products/knockknock.html&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://objective-see.org/products/knockknock.html&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;see-also&quot;&gt;See Also&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://macsouverain.com/en/radar-clickfix-script-editor-avril-2026/&quot;&gt;The ClickFix script editor (the paste-and-pwn pattern)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://macsouverain.com/en/radar-sparkcat-app-store-avril-2026/&quot;&gt;SparkCat on the App Store (when Apple lets something through)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://macsouverain.com/en/little-snitch-vs-lulu-pare-feu-sortant-mac/&quot;&gt;Little Snitch vs LuLu (outgoing firewall for Mac)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-alerte</category><category>mac-malware</category><category>social-engineering</category><category>claude-ai</category><category>ingenierie-sociale</category></item><item><title>Apple patches iOS and macOS CVE vulnerabilities: fixes, then tweaks Safari profiles</title><link>https://macsouverain.com/en/radar-profils-safari-segmentation-privacy-20260513/</link><guid isPermaLink="true">https://macsouverain.com/en/radar-profils-safari-segmentation-privacy-20260513/</guid><description>iOS 26.5 fixes 98 CVEs, including 21 in WebKit; macOS Tahoe 26.5 fixes 98 CVEs, including 22. Instead of enabling Lockdown Mode everywhere, segment with a dedicated Safari profile.</description><pubDate>Wed, 13 May 2026 14:15:25 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;&lt;strong&gt;iOS 26.5 and macOS Tahoe 26.5, released on May 11, fix 98 CVEs each (including 21 and 22 in WebKit). Global Lockdown Mode is overkill for daily use. Safari profiles, available since iOS 17, segment usage for you.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What you need to watch out for&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Install iOS 26.5 and macOS Tahoe 26.5 today.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Create a “Cautious” Safari profile with only privacy extensions enabled, use it for banking, webmail, suspicious links, and medical research. Keep your default profile untouched for everything else.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;Apple Publishes iOS 26.5 and macOS Tahoe 26.5, Fixing 98 CVEs&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;On May 11, Apple released iOS 26.5 and macOS Tahoe 26.5. These updates address 98 security vulnerabilities on iOS (including 21 on WebKit, Safari’s engine) and 98 on macOS (including 22 WebKit). Several of these vulnerabilities allowed malicious websites to execute code or bypass sandbox protections. As usual with Apple releases, WebKit takes the biggest hit, as it’s the largest attack surface on an iPhone or Mac.&lt;/p&gt;
&lt;p&gt;Patch now. That’s a no-brainer. The real question is, what do you do between patches, when clicking on mail links, conducting sensitive searches, or logging into online banking?&lt;/p&gt;
&lt;h2 id=&quot;why-lockdown-mode-all-the-time-is-too-much&quot;&gt;Why Lockdown Mode All the Time is Too Much&lt;/h2&gt;
&lt;p&gt;Lockdown Mode is robust. MacSouverain praised it in &lt;a href=&quot;https://macsouverain.com/en/lockdown-mode-face-a-coruna-toolkit-espionnage-gouvernemental/&quot;&gt;article 29&lt;/a&gt;. It’s perfect for journalists, dissidents, or lawyers handling sensitive cases.&lt;/p&gt;
&lt;p&gt;But for freelancers or small businesses just checking email, doing online accounting, or watching recipes, it’s overkill. Disabled JIT JavaScript, cut Safari extensions, restricted media formats, filtered Messages attachments. Too much friction, too many websites breaking. The usual result: you enable it for a few days, find it annoying, disable it, and end up with nothing.&lt;/p&gt;
&lt;h2 id=&quot;what-are-safari-profiles&quot;&gt;What are Safari Profiles?&lt;/h2&gt;
&lt;p&gt;Since iOS 17 and macOS Sonoma (September 2023), Safari supports multiple profiles within the same app. It’s been quiet, never highlighted in keynotes. Most people you talk to don’t know it exists.&lt;/p&gt;
&lt;p&gt;Each profile has its own history, cookies, enabled extensions, search engine, favorites, and tab groups. No mixing: Google’s session cookie from your “Personal” profile isn’t seen by your “Sensitive” profile. Privacy extensions active on “Sensitive” don’t slow down “Personal” navigation. Switch in two taps (tap on tabs on iPhone, Safari menu on Mac), syncs with iCloud between Mac and iPhone.&lt;/p&gt;
&lt;p&gt;It’s the usage segmentation we’ve advised for years in security, without installing a second browser.&lt;/p&gt;
&lt;h2 id=&quot;what-to-do-now&quot;&gt;What to Do Now&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Install iOS 26.5 and macOS Tahoe 26.5. Settings, General, Software Update. Twenty minutes, including restart.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Create a “Sensitive” Safari profile. On Mac: Safari, menu, Create Profile. On iPhone: Settings, Apps, Safari, Profiles, New Profile. Name, icon, color.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; Configure the “Sensitive” profile: DuckDuckGo or Qwant search engine (setting per profile), empty favorites, and add two or three privacy extensions active &lt;strong&gt;only&lt;/strong&gt; on this profile: AdGuard for Safari (free on App Store, network and cosmetic filtering), Vinegar if you want a clean YouTube (one-time purchase), StopTheMadness Pro if you already have its license. Your default profile remains untouched, no slowdown when surfing normally.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4.&lt;/strong&gt; What the profile &lt;strong&gt;doesn’t&lt;/strong&gt; isolate: advanced Safari settings (block all cookies, disable JavaScript, tracking block) are &lt;strong&gt;global&lt;/strong&gt;, applying to all profiles. If you want to toughen these toggles, do it globally in Settings, Apps, Safari, knowing it’ll affect your default profile too.&lt;/p&gt;
&lt;h2 id=&quot;when-to-switch-to-the-sensitive-profile&quot;&gt;When to Switch to the “Sensitive” Profile&lt;/h2&gt;
&lt;p&gt;Clicking on a link from an unknown sender. Medical or legal research. Bank or broker login. ProtonMail on the web from a less-used device. Any site you’re unsure about and don’t want to cookie your main profile with. Two taps, switch, do what you need to do, switch back.&lt;/p&gt;
&lt;p&gt;Usage segmentation, not global hardening. Keep your comfort on your default profile, have a “clean navigation” mode on hand.&lt;/p&gt;
&lt;h2 id=&quot;what-it-doesnt-replace&quot;&gt;What It Doesn’t Replace&lt;/h2&gt;
&lt;p&gt;Safari profiles aren’t Lockdown Mode. JIT JavaScript remains active on all profiles. If you’re a journalist handling sensitive sources, a lawyer on a sensitive case, a dissident, or if you’ve received an Apple threat notification, use global Lockdown Mode. Safari profiles are a tool for daily use, not state actor protection.&lt;/p&gt;
&lt;p&gt;Basic hygiene doesn’t change: patch (iOS 26.5 now), don’t open unexpected attachments, verify URLs before entering passwords.&lt;/p&gt;
&lt;h2 id=&quot;sources&quot;&gt;Sources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://support.apple.com/en-us/127110&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Apple, About the security content of iOS 26.5 and iPadOS 26.5&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://support.apple.com/en-us/127115&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Apple, About the security content of macOS Tahoe 26.5&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://support.apple.com/guide/safari/use-profiles-ibrw1011/mac&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Apple, Use profiles in Safari (Safari User Guide)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://support.apple.com/en-us/105120&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Apple, About Lockdown Mode&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://macsouverain.com/en/lockdown-mode-face-a-coruna-toolkit-espionnage-gouvernemental/&quot;&gt;Article 29 MacSouverain, Lockdown Mode, why to activate it&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;see-also&quot;&gt;See Also&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://macsouverain.com/en/lockdown-mode-face-a-coruna-toolkit-espionnage-gouvernemental/&quot;&gt;Lockdown Mode, why you should activate it&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://macsouverain.com/en/privacy-macos-les-parametres-a-changer-immediatement/&quot;&gt;Privacy macOS, settings to change&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-alerte</category><category>apple</category><category>safari</category><category>webkit</category><category>privacy</category><category>ios</category><category>macos</category></item><item><title>kSuite vs Google Workspace, the honest comparison</title><link>https://macsouverain.com/en/ksuite-vs-google-workspace-le-comparatif-honnete/</link><guid isPermaLink="true">https://macsouverain.com/en/ksuite-vs-google-workspace-le-comparatif-honnete/</guid><description>kSuite Infomaniak or Google Workspace for your Mac? Pricing, encryption, jurisdiction, native Apple apps. The honest comparison, no marketing fluff.</description><pubDate>Sun, 10 May 2026 14:27:21 GMT</pubDate><content:encoded>&lt;p&gt;&lt;strong&gt;Introduction&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Every month, you fork out cash for Google Workspace. You’re a MacSouverain reader, so privacy’s a big deal for you. Eventually, the cognitive dissonance gets unbearable.&lt;/p&gt;
&lt;p&gt;The question isn’t “Is Workspace bad?” It’s great, it’s the gold standard. The question is: what exactly are you paying for, and what are you trading for it? And is there an alternative that gives you your Mac, your jurisdiction, and your data back, without forcing you to downgrade?&lt;/p&gt;
&lt;p&gt;kSuite, brought to you by Infomaniak from Geneva, makes that very promise. Let’s see if it delivers.&lt;/p&gt;
&lt;h2 id=&quot;the-criteria-that-matter&quot;&gt;The Criteria That Matter&lt;/h2&gt;
&lt;p&gt;Comparing two collaborative suites without a grid is like doing a PR piece. Here are the six criteria I’ve chosen, and what I’ve deliberately left out.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Jurisdiction and Data Sovereignty.&lt;/strong&gt; Where data is stored, under which law, who can access it legally. This criterion trumps everything else for MacSouverain because it’s structural and non-negotiable with features.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Real Encryption.&lt;/strong&gt; Not “encrypted” in general. At-rest, in-transit, and especially end-to-end: who holds the keys. This is the only grid that withstands a warrant.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Price and Transparency.&lt;/strong&gt; How much you pay per user, what you get, what changes when the editor does a “pricing update”.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Native macOS and iOS Integration.&lt;/strong&gt; Apple Mail, Calendar, Contacts, Files. Can you work without installing a single app from the editor on your Mac. This is the “practical sovereignty” marker.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Professional Functional Coverage.&lt;/strong&gt; Pro mail, shared drive, video conferencing, collaborative docs, admin console, SSO, MDM. A suite that forces you to keep another one nearby is a half-suite.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Exit Strategy.&lt;/strong&gt; Export, standard formats, import from the competitor. You’re not married to your cloud provider, unless you choose to be.&lt;/p&gt;
&lt;p&gt;What I DID NOT evaluate: very specific use cases (Workspace for Education, HIPAA compliance in the US, FedRAMP). If you’re an American hospital, this comparison isn’t for you. If you’re a European SME, a freelancer, or a family office, we continue.&lt;/p&gt;
&lt;h2 id=&quot;ksuite-by-infomaniak&quot;&gt;kSuite, by Infomaniak&lt;/h2&gt;
&lt;figure class=&quot;kg-card kg-image-card&quot;&gt;
&lt;img src=&quot;https://macsouverain.com/content/images/2026/05/capture-01-ksuite-admin-ksuite-vs-google-workspace-le-comparatif-honnete-1.png&quot; class=&quot;kg-image&quot; loading=&quot;lazy&quot; alt=&quot;Infomaniak&amp;#x27;s Console Manager, kSuite dashboard view with sidebar and &amp;#x27;My day&amp;#x27; section listing Mail, Calendar, kMeet, kChat, kDrive&quot;&gt;
&lt;/figure&gt;
&lt;p&gt;&lt;strong&gt;The philosophy in two sentences.&lt;/strong&gt; A collaborative suite edited by a Swiss hosting provider of 316 employee-owned people, ISO 27001 and 14001 certified, operating its own datacenters in Geneva and Winterthur. Not a reseller slapping a UI on third-party bricks, a vertically integrated editor.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The strengths.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Swiss, no FADP, outside CLOUD Act.&lt;/strong&gt; Infomaniak is under Swiss jurisdiction, governed by the new Federal Act on Data Protection (FADP, in effect since 01/09/2023). No CLOUD Act applies. Switzerland benefits from an adequacy decision for GDPR transfers. For an EU client or anyone attached to keeping their data from making a legal detour to Washington, that’s argument enough.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Built-in, free, transparent OpenPGP in kMail.&lt;/strong&gt; &lt;a href=&quot;https://finance.yahoo.com/news/infomaniak-democratises-email-encryption-users-072800175.html&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Infomaniak enabled end-to-end encryption via OpenPGP in kMail webmail on June 17, 2025&lt;/a&gt;, for all plans, no add-on required. You enable, you exchange keys with your contact, your emails are encrypted end-to-end. Among major suites, only Proton and kSuite offer free OpenPGP in webmail. Google Workspace, Microsoft 365, and Zoho reserve their native encryption for Enterprise plans.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;OnlyOffice under the hood of Docs, Grids, Points.&lt;/strong&gt; The office suite engine in kSuite is &lt;a href=&quot;https://www.infomaniak.com/en/ksuite/kdrive/onlyoffice&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;OnlyOffice, AGPLv3, open source&lt;/a&gt;. High-fidelity compatibility with.docx,.xlsx,.pptx, better than Google Docs with native Office files. If your accountant sends you a.xlsx with macros and a wonky layout, OnlyOffice renders it correctly.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Open protocols everywhere.&lt;/strong&gt; IMAP, SMTP, CalDAV, CardDAV, WebDAV. You configure Apple Mail, Calendar, Contacts, and Files.app without installing a single Infomaniak executable on your Mac. That’s rare, and it’s the purest integration criterion a cloud suite can tick.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;kMeet with optional, free E2E.&lt;/strong&gt; WebRTC video conferencing with optional end-to-end encryption activable when creating the meeting (shared key), &lt;a href=&quot;https://www.infomaniak.com/en/support/faq/2464/securing-a-kmeet-meeting-password-encryption-key&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;documented by Infomaniak&lt;/a&gt;. Limited to Chromium browsers and desktop app, but it exists. Google Workspace’s equivalent (CSE) requires Enterprise Plus.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Transparent, stable pricing.&lt;/strong&gt; kSuite Pro at 7.90 €/user/month for 3TB storage and full mail pro. No documented price increase since launch in 10/2022. The pricing promise holds.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The weaknesses.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;MDM and Apple Business Manager: the gaping hole.&lt;/strong&gt; No official ABM integration for kSuite. If you deploy a fleet of iPhones and Macs for business with federated authentication via Managed Apple ID, Workspace does it natively. kSuite requires a third-party MDM (Jamf, Mosyle, Kandji) with classic IMAP/CalDAV auth. It works, it’s less integrated.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Limited third-party marketplace.&lt;/strong&gt; Google Workspace Marketplace has over 4,500 connected apps. kSuite has mostly Infomaniak suite and standard integrations. If your workflow relies on fifteen SaaS connected to Google Calendar, plan for a transition.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Mobile apps: solid, not reference.&lt;/strong&gt; Infomaniak Mail and kDrive iOS are clean, but Gmail and Google Drive iOS remain the UX reference. It’s an experience gap, not a blocker.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Real-time co-editing: good, not excellent.&lt;/strong&gt; OnlyOffice handles multi-user co-editing, but Google Docs is the absolute reference for latency and collaborative undo. If you spend all day simultaneously editing the same document with six people, you’ll feel the difference. Otherwise, not so much.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Euria vs Gemini.&lt;/strong&gt; Infomaniak has its sovereign AI (Euria) for kMeet transcription and assistance. It’s decent, it’s not Gemini. If advanced AI-driven office suite is your top criterion, Google Workspace wins this point hands down.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Who it’s for.&lt;/strong&gt; The freelancer, the SME, the family office, the liberal profession that wants a complete pro suite without CLOUD Act and without installing another proprietary app on their Mac. The MacSouverain profile, in short.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Prices (excerpts, real editor page on &lt;a href=&quot;https://www.infomaniak.com/en/ksuite/ksuite-pro/prices&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;infomaniak.com/en/ksuite/ksuite-pro/prices&lt;/a&gt;).&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;my kSuite&lt;/strong&gt; : free, 20GB, 1 @ksuite.infomaniak.com address, kMeet included. No personal domain.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;my kSuite+&lt;/strong&gt; : CHF 5.75/month, 2TB, 1 domain + 5 aliases.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;kSuite Standard&lt;/strong&gt; : 1.90 €/user/month, 15GB per user, pro mail with domain.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;kSuite Pro&lt;/strong&gt; : 7.90 €/user/month, 3TB per user, pro mail + aliases, SSO SAML.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;kSuite Enterprise&lt;/strong&gt; : 14.90 €/user/month, 6TB per user, advanced admin.&lt;/li&gt;
&lt;/ul&gt;
&lt;h1 id=&quot;google-workspace-by-google-llc&quot;&gt;Google Workspace, by Google LLC&lt;/h1&gt;
&lt;p&gt;&lt;strong&gt;Philosophy in two sentences.&lt;/strong&gt; The collaborative suite that redefined the standard since 2006. Market reference for Gmail, Docs, Sheets, and Meet, integrated with almost every SaaS worldwide, under US jurisdiction and CLOUD Act.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Strengths.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Reference anti-spam email.&lt;/strong&gt; Gmail filters better than anyone else, period. Fifteen years of machine learning feedback on billions of messages, that’s hard to beat. If you switch email providers, your spam folder will miss you for two months.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Co-editing Docs, Sheets, Slides.&lt;/strong&gt; The inventor of the genre is also the master of it. Latency, suggestions, mentions, granular history: Google Workspace’s online office suite remains the reference, and all other suites measure up to it.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Giant third-party ecosystem.&lt;/strong&gt; &lt;a href=&quot;https://workspace.google.com/marketplace&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Google Workspace Marketplace&lt;/a&gt;, 4,500+ apps. Your CRM, your billing, your HR tool, your ATS: they all have a native Google connector. For kSuite, expect manual CalDAV/IMAP integrations when the third-party app allows it, or nothing when it doesn’t.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Official Apple Business Manager.&lt;/strong&gt; Federated authentication with Managed Apple ID, DEP token, MDM deployment Workspace Endpoint Management covering macOS, iOS, ChromeOS, Android, Windows. For an SME managing a heterogeneous fleet, this is a real operational argument.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Gemini AI integrated into all plans.&lt;/strong&gt; Since March 17, 2025, Google has bundled Gemini into the core tariff of Workspace. NotebookLM, Gemini in Docs, Gemini in Sheets, Meet transcription: it’s powerful, and it’s available without additional add-ons.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Vault, eDiscovery, DLP, BigQuery audit.&lt;/strong&gt; If your profession has legal retention, legal hold, or serious data loss prevention obligations, Workspace Plus and Enterprise are mature on these topics for ten years. kSuite has audit logs, not the full regulatory stack.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Weaknesses.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;CLOUD Act, the structural argument.&lt;/strong&gt; Google LLC is a US company, subject to the &lt;a href=&quot;https://wire.com/en/blog/cloud-act-eu-data-sovereignty&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;2018 CLOUD Act&lt;/a&gt;, which allows US authorities to demand data stored anywhere in the world from a provider under US jurisdiction. “European datacenter” doesn’t change anything: Microsoft France confirmed this under oath to the Senate. Workspace is not qualified SecNumCloud by ANSSI. The partnership with Thales S3NS to carry a qualification is underway, Workspace itself does not carry it.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Price increase in 03/2025, Gemini bundle imposed.&lt;/strong&gt; Google increased the core tariff of all Workspace plans by integrating Gemini into the package: +16.7% on Business Starter and Standard (annual), +22.2% on Business Plus. You don’t have generative AI in your workflow? You’re still paying. This is the second global increase after 2023, Workspace pricing is continuously increasing.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;End-to-end encryption reserved for Enterprise Plus.&lt;/strong&gt; S/MIME hosted and CSE (Client-Side Encryption) are only available in &lt;a href=&quot;https://workspace.google.com/learn-more/security/security-whitepaper/page-5/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Enterprise Plus and Education Plus&lt;/a&gt;, with an external KMS to configure (Thales, Fortanix, Stormshield, Flowcrypt). On Business Starter, Standard, and Plus, you have TLS in-transit and AES-256 at-rest with Google keys. That’s not E2E.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Native Apple apps: it works, but not great.&lt;/strong&gt; Apple Mail with Google Account works, but Gmail labels become IMAP folders, the experience is degraded. CardDAV is officially deprecated by Google in favor of People API (still functional via native Google Account iOS, but long-term signal). In practice, the Workspace user ends up opening Gmail web and Drive iOS app: the “100% native Apple apps” argument falls apart.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Gmail lock-in.&lt;/strong&gt; Gmail’s labels, filters, categorization are specific. Google Takeout exports everything (.mbox, EML), but reformatting on the new provider’s side isn’t trivial. You can leave, but it won’t be comfortable.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Customer data vs AI training.&lt;/strong&gt; Google contractually commits not to use Workspace B2B data to train Gemini. That’s a contractual commitment, evolvable, separate from the commercial Gmail consumer engagement (which does share signals). Keep an eye on this over time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Who it’s for.&lt;/strong&gt; The company whose critical workflows depend on the Marketplace, the large group with serious eDiscovery needs, the US client where local compliance requires Google certifications, the team already set up with no operational argument to move.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Prices HT (annual, editor page &lt;a href=&quot;https://workspace.google.com/pricing&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;workspace.google.com/pricing&lt;/a&gt;).&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Business Starter&lt;/strong&gt;: €6.80/user/month (annual), 30GB per user, Meet 100 participants, max 300 users.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Business Standard&lt;/strong&gt;: €13.60/user/month, 2TB pooled, Meet 150 + recording.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Business Plus&lt;/strong&gt;: €21.10/user/month, 5TB pooled, Vault eDiscovery, Meet 500.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Enterprise&lt;/strong&gt;: quote-based, 5TB+, Meet 1,000, CSE, advanced DLP.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Launch promotion: 50% off for the first 3 months for the first 20 users, then standard pricing applies.&lt;/p&gt;
&lt;h2 id=&quot;face-to-face-on-the-criteria-that-matter&quot;&gt;Face-to-face on the criteria that matter&lt;/h2&gt;
&lt;p&gt;Instead of a flat table that levels everything, let’s look at the six criteria one by one.&lt;/p&gt;
&lt;h3 id=&quot;jurisdiction-and-sovereignty&quot;&gt;Jurisdiction and sovereignty&lt;/h3&gt;
&lt;p&gt;kSuite is Swiss, under the Swiss Federal Act on the Surveillance of Post and Telecommunications (FADP), hosted in Switzerland (datacenters in Geneva and Zurich region), outside the CLOUD Act, outside the GDPR (but with a valid EU adequacy decision). Workspace is US, under the CLOUD Act, global datacenters with the “data regions” Europe option in Enterprise plans. On this criterion, it’s not a comparison, it’s a difference in nature. If jurisdiction is decisive for you, the subject is already settled.&lt;/p&gt;
&lt;h3 id=&quot;real-encryption&quot;&gt;Real encryption&lt;/h3&gt;
&lt;p&gt;kSuite: Native and free OpenPGP E2E in kMail, optional in kMeet, AES-256 at-rest on kDrive with Infomaniak keys. No native E2EE drive. Workspace: TLS and AES-256 at-rest everywhere, hosted S/MIME and Customer-Supplied Encryption in Enterprise Plus only, BYOK with external KMS in Enterprise Plus. For email, kSuite wins hands down and for free. For the drive, both ask for a compromise: Infomaniak keeps the keys, or you pay for Workspace Enterprise Plus to have CSE.&lt;/p&gt;
&lt;h3 id=&quot;price-and-transparency&quot;&gt;Price and transparency&lt;/h3&gt;
&lt;p&gt;At equivalent tiers, kSuite is cheaper everywhere. Solo 2 To: my kSuite+ at 5.75 € against Business Starter at 6.80 € for 30 Go (a factor of 70 in storage). SME standard: kSuite Pro at 7.90 € against Business Standard at 13.60 € (kSuite 42% cheaper, 50% more storage). SME premium: kSuite Enterprise at 14.90 € against Business Plus at 21.10 € (kSuite 29% cheaper). And Workspace pricing goes up, kSuite’s hasn’t changed since 10/2022.&lt;/p&gt;
&lt;h3 id=&quot;native-macos-and-ios-integration&quot;&gt;Native macOS and iOS integration&lt;/h3&gt;
&lt;p&gt;kSuite exposes IMAP, SMTP, CalDAV, CardDAV, WebDAV. Apple Mail, Calendar, Contacts, Files.app work natively without a single proprietary app installed. It’s the “100% Apple” scenario pure and simple. Workspace also works natively, but the real experience pushes the user towards Gmail web and Drive iOS. On the criterion of “installing nothing from the vendor”, kSuite wins without moving; on the criterion of “polished experience”, Workspace keeps the lead with its own apps.&lt;/p&gt;
&lt;h3 id=&quot;professional-functional-coverage&quot;&gt;Professional functional coverage&lt;/h3&gt;
&lt;p&gt;Both suites cover email, drive, calendar, contacts, video conferencing, collaborative docs, admin console, SSO. Workspace adds native MDM, official ABM, Marketplace with 4500 apps, advanced DLP, Vault eDiscovery. kSuite adds high-fidelity OnlyOffice, free OpenPGP, E2E kMeet. On pure coverage, Workspace has more depth; on functional sovereignty, kSuite has an edge.&lt;/p&gt;
&lt;h3 id=&quot;exit-possibility&quot;&gt;Exit possibility&lt;/h3&gt;
&lt;p&gt;kSuite exports EML, MBOX, vCard, iCal, native OnlyOffice files. Workspace exports via Takeout (mbox, vCard, ics,.docx via conversion). Both let you leave. kSuite makes arrival easier: it has a documented Workspace import in the Manager console. The reverse (leaving Workspace for something else) works technically but isn’t guided.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;macks-recommendation&quot;&gt;Mack’s Recommendation&lt;/h2&gt;
&lt;p&gt;I’ll say it straight up because that’s my job: if you have a choice, &lt;strong&gt;kSuite is better than Workspace for your Privacy.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Not because Workspace is bad. Workspace is an excellent collaborative suite. But the MacSouverain user isn’t the average Workspace user. The reader of this site is a freelancer, a European SME, a family office, an independent who pays for a service and wants to know who can read their files, who can force them to be communicated, and what happens when an audit arrives. On these three questions, Workspace answers “Google, the CLOUD Act, we’ll handle it”, and &lt;strong&gt;kSuite answers “you, nobody, and an export EML file”, total Privacy.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;If you’re a freelancer or solo and budget matters.&lt;/strong&gt; my kSuite+ at CHF 5.75/month for 2TB is an obvious choice over Business Starter and its 30GB.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;If you’re a 5-50 person SME in Europe.&lt;/strong&gt; kSuite Pro at €7.90/user. You save 42% compared to Business Standard, keep your pro mail with domain, can configure Apple Mail and Calendar on the whole fleet without installing an app, and you’re out of the CLOUD Act. The only question to ask: does your fleet need federated MDM via ABM? If yes, seriously evaluate the cost of a Mosyle or Jamf as a complement.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;If you’re already on Workspace with your whole workflow tied to it.&lt;/strong&gt; A migration costs. You don’t have to do it this quarter. But there are two moments when reconsidering it makes sense: every time Workspace raises its prices (the next one is coming), and when a critical workflow breaks due to a Google change. Both moments will happen, statistically.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;If you’re a family office in Switzerland, Germany, or elsewhere in the EU and US jurisdiction bothers you.&lt;/strong&gt; You don’t pay an American cloud to store your pro correspondence and financial documents, it’s as simple as that. kSuite is the shortest answer.&lt;/p&gt;
&lt;p&gt;For my personal use, I made a different choice, &lt;a href=&quot;https://macsouverain.com/en/ma-stack/&quot;&gt;Proton Workspace&lt;/a&gt;, which makes the same sovereignty promise from a different angle (E2E everywhere by default, complete Proton ecosystem). If you’re hesitating between the two sovereign worlds, remember this grid: &lt;strong&gt;kSuite has the edge on pure native Apple integration&lt;/strong&gt; (standard CalDAV, CardDAV, IMAP) and &lt;strong&gt;high-fidelity OnlyOffice&lt;/strong&gt;; Proton has the edge on systematic E2E and the cohesive app suite. Neither brings you back to the CLOUD Act, that’s the essential part.&lt;/p&gt;
&lt;h2 id=&quot;in-summary&quot;&gt;In summary&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;kSuite is cheaper&lt;/strong&gt; than its equivalent, more sovereign by design (Switzerland, nFADP, employee-owned, ISO 27001), &lt;strong&gt;exposes open protocols&lt;/strong&gt; that make native Apple apps fully usable, and &lt;strong&gt;includes free OpenPGP encryption&lt;/strong&gt; in mail. Workspace is more polished on Gmail, Docs, and third-party ecosystems, more integrated with Apple Business Manager, and much more mature on Vault and DLP topics, at the cost of a US jurisdiction and continuous price increases.&lt;/p&gt;
&lt;p&gt;In practice:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Freelance or solo, budget-conscious&lt;/strong&gt; → &lt;a href=&quot;https://www.infomaniak.com/fr/ksuite/myksuite&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;my kSuite+ at CHF 5.75/month&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;European SME 5-50 people&lt;/strong&gt; → &lt;a href=&quot;https://www.infomaniak.com/fr/ksuite&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;kSuite Pro at €7.90/user/month&lt;/a&gt;, with a third-party MDM if needed.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Critical Workspace workflow already in place&lt;/strong&gt; → stay, prepare migration for the next pricing update.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Heavy US regulatory compliance&lt;/strong&gt; → stay on Workspace.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;EU family office, non-negotiable jurisdiction&lt;/strong&gt; → &lt;a href=&quot;https://www.infomaniak.com/fr/ksuite&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;kSuite, no hesitation&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;p&gt;&lt;em&gt;Transparency: MacSouverain is affiliated with Infomaniak. Subscribing to kSuite via the links in this article supports the site, without changing the price you pay. If you want to help, &lt;a href=&quot;https://www.infomaniak.com/fr/ksuite&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;it’s this way&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;
&lt;h1 id=&quot;the-editors-themselves&quot;&gt;&lt;strong&gt;The Editors Themselves&lt;/strong&gt;&lt;/h1&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Infomaniak&lt;/strong&gt;, the employee-owned Swiss hoster from Geneva, has been editing &lt;strong&gt;kSuite&lt;/strong&gt; since 10/2022. Product page, prices, and public ISO 27001 / 14001 / 5001 certifications.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Google Workspace&lt;/strong&gt;, Mountain View, under US jurisdiction and CLOUD Act. Pricing page, security whitepaper, public ISO 27001.&lt;/li&gt;
&lt;/ul&gt;
&lt;h1 id=&quot;technical-documentation&quot;&gt;&lt;strong&gt;Technical Documentation&lt;/strong&gt;&lt;/h1&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;kMail&lt;/strong&gt;’s free OpenPGP announcement, &lt;a href=&quot;https://finance.yahoo.com/news/infomaniak-democratises-email-encryption-users-072800175.html&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;picked up by Yahoo Finance&lt;/a&gt; on June 17, 2025.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://support.apple.com/guide/apple-business-manager/intro-to-google-workspace-axmaef1a0154/web&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Apple Business Manager × Workspace&lt;/a&gt;&lt;/strong&gt;, Apple’s official guide. Native Managed Apple ID federation on Google’s side, not kSuite’s.&lt;/li&gt;
&lt;/ul&gt;
&lt;h1 id=&quot;independent-analyses&quot;&gt;&lt;strong&gt;Independent Analyses&lt;/strong&gt;&lt;/h1&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://wire.com/en/blog/cloud-act-eu-data-sovereignty&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;Wire, CLOUD Act vs EU sovereignty&lt;/a&gt;&lt;/strong&gt;, Swiss messaging app &lt;strong&gt;Wire&lt;/strong&gt; explains why a European datacenter isn’t enough if the company is US-based.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://9to5google.com/2025/01/15/google-workspace-price-increase-2025/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;9to5Google, Workspace price hike 03/2025&lt;/a&gt;&lt;/strong&gt;, tech press documenting the forced Gemini bundle and updated pricing grid.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;also-see&quot;&gt;Also see&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://macsouverain.com/en/quest-ce-que-la-souverainete-digitale-en-pratique/&quot;&gt;Digital sovereignty, in practice&lt;/a&gt;: the general grid of which kSuite is a case study.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://macsouverain.com/en/cloud-ordinateur-quelquun-dautre/&quot;&gt;The cloud, it’s someone else’s computer&lt;/a&gt;: the mental framework behind this comparison.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://macsouverain.com/en/dns-talon-achille-privacy/&quot;&gt;DNS, the Achilles heel of your privacy&lt;/a&gt;: same logic of jurisdiction on another layer.&lt;/li&gt;
&lt;/ul&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>privacy</category><category>mac</category><category>comparatif</category><category>souverainete</category><category>suite-collaborative</category><category>infomaniak</category><category>google-workspace</category><category>comparatifs</category><enclosure url="https://macsouverain.com/content/images/2026/05/feature-ksuite-vs-google-workspace-le-comparatif-honnete-3.png" length="0" type="image/png"/></item><item><title>Proton Mail switches to post-quantum encryption (and it&apos;s free)</title><link>https://macsouverain.com/en/radar-proton-mail-post-quantum-mai-2026/</link><guid isPermaLink="true">https://macsouverain.com/en/radar-proton-mail-post-quantum-mai-2026/</guid><description>Proton Mail offers a quantum-resistant encryption option, available on all plans including the free one. Must be enabled manually, but don&apos;t get your hopes up.</description><pubDate>Wed, 06 May 2026 06:39:41 GMT</pubDate><content:encoded>&lt;div class=&quot;radar-summary&quot;&gt;
&lt;p&gt;&lt;strong&gt;Proton Mail now offers an encryption option that’s quantum-resistant. Available on all plans, even the free one. You’ll need to turn it on yourself, and it only works for new emails.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What you need to watch out for&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Enable the option in Settings, Encryption and keys, but don’t think it’ll protect your old emails, it only works for new ones.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; The benefit is maxed out when the person you’re sending to is also on Proton. If they’re on Gmail or elsewhere, it’s back to classic encryption for that send.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; End-to-end encrypted forwarding is temporarily incompatible. If you’re using it, pick one or the other until it’s fixed.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;Proton Mail has just activated an option that protects your new emails against decryption by a future quantum computer. It’s available on all plans, including the free one, and you can enable it yourself. And it’s not just marketing.&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id=&quot;the-fact&quot;&gt;The Fact&lt;/h2&gt;
&lt;p&gt;On May 5, 2026, Proton pushed a &lt;strong&gt;new option&lt;/strong&gt; into Proton Mail’s settings: « &lt;strong&gt;Enable post-quantum protection&lt;/strong&gt; ». Once enabled, new emails you send are encrypted with a combination of classical plus &lt;strong&gt;post-quantum algorithm&lt;/strong&gt;, a type of cryptography &lt;strong&gt;designed to resist even a quantum computer of tomorrow&lt;/strong&gt;. Available on all plans, including free, which is rare enough in the industry to warrant mention.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The option is not enabled by default&lt;/strong&gt;. You go to Settings, Encryption and keys, and check it yourself. Proton justifies this caution due to the still-experimental status in the external ecosystem.&lt;/p&gt;
&lt;p&gt;The idea behind it is to counter what’s called « harvest now, decrypt later ». In plain terms: an attacker could intercept and store your encrypted emails today, unable to read them, hoping to decrypt them in ten or twenty years when a powerful enough quantum computer exists. Today’s classical encryption (RSA, elliptic curves) would crumble like a house of cards. Post-quantum is the insurance that even this scenario yields nothing to the attacker.&lt;/p&gt;
&lt;h2 id=&quot;why-it-matters-to-you&quot;&gt;Why It Matters to You&lt;/h2&gt;
&lt;p&gt;Several things to know before you rush to enable it.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The protection applies only to new emails&lt;/strong&gt;. Anything already in your mailbox, sent or received before enabling, remains encrypted as before. Proton says so: &lt;em&gt;« Post-quantum protection applies to new encrypted emails going forward. It does not retroactively re-encrypt emails that are already in your mailbox, for now. »&lt;/em&gt; If your old emails have already been intercepted by someone, this option doesn’t change anything for them. The « for now » suggests a retroactive re-encryption is on the roadmap, but it’s not delivered yet.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The recipient matters&lt;/strong&gt;. The best scenario is Proton to Proton, where both sides have post-quantum keys. If your correspondent is elsewhere (Gmail, a classic OpenPGP client, etc.), Proton falls back on the usual encryption for that send, which is the only reasonable thing to do while waiting for others to adopt the same standard.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Some friction&lt;/strong&gt;. If you’re using Proton’s end-to-end encrypted forwarding, it’s temporarily incompatible with the new option. You choose one or the other for now. There’s also a slight performance impact on sending, barely noticeable on recent hardware according to Proton.&lt;/p&gt;
&lt;h2 id=&quot;the-game-changer-angle-open-standard-vs-silos&quot;&gt;The Game-Changer Angle: Open Standard vs Silos&lt;/h2&gt;
&lt;p&gt;Proton isn’t the first email service to offer post-quantum. Tuta (ex-Tutanota) did so since 2024, with its own proprietary scheme. Apple deployed PQ3 on iMessage in February 2024. Signal did the same with PQXDH in September 2023.&lt;/p&gt;
&lt;p&gt;Proton’s difference is that it does so on &lt;strong&gt;OpenPGP&lt;/strong&gt;, the open standard others can adopt. Apple PQ3 remains locked in the Apple ecosystem, Signal PQXDH doesn’t leave Signal, and Tuta’s scheme is proprietary to Tuta. Proton, meanwhile, bets on standardization, announced collaboration with the Thunderbird project, so tomorrow your sovereign email client (Thunderbird, GnuPG, or another) can read and write post-quantum emails compatible with Proton without going through the Proton app itself.&lt;/p&gt;
&lt;p&gt;That’s the sovereignty angle. &lt;strong&gt;An open standard is what prevents your communication security from depending on the whim of a single provider&lt;/strong&gt;. Today in practice, interop is still largely Proton-to-Proton, the external ecosystem isn’t there yet. But the direction is set, and that’s what distinguishes this announcement from mere marketing.&lt;/p&gt;
&lt;h2 id=&quot;what-you-do-now&quot;&gt;What You Do Now&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Go to Proton Mail, Settings, Encryption and keys, and enable « &lt;strong&gt;Enable post-quantum protection&lt;/strong&gt; ». Read the warning banner (forwarding, etc.) before validating.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; Keep in mind that &lt;strong&gt;it only protects your new sends&lt;/strong&gt;. If you have sensitive conversations archived, consider sorting them out. Retroactive re-encryption is coming later, but for now, it’s pure conditional.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; If your correspondent is also on Proton, encourage them to enable it on their end. Until both ends are equipped, the benefit remains partial.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4.&lt;/strong&gt; If you’re using Proton Bridge with Apple Mail (see the &lt;a href=&quot;https://macsouverain.com/en/proton-bridge-apple-mail-mac/&quot;&gt;dedicated article&lt;/a&gt;), ensure your Bridge is up-to-date, or new post-quantum emails might not be readable on the local client side.&lt;/p&gt;
&lt;h2 id=&quot;also-see&quot;&gt;Also See&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://macsouverain.com/en/apple-mail-vs-gmail-vs-proton-mail/&quot;&gt;Apple Mail vs Gmail vs Proton Mail: Which Client for Which Use&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://macsouverain.com/en/migrer-gmail-proton-mail-mac/&quot;&gt;Migrating from Gmail to Proton Mail Without Losing Your Emails&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://macsouverain.com/en/securite-email-client-mail/&quot;&gt;Securing Your Email Client: What You Can Set Before Switching Providers&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://macsouverain.com/en/proton-bridge-apple-mail-mac/&quot;&gt;Proton Bridge Plus Apple Mail on Mac: The Combination That Works&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://macsouverain.com/en/proton-meet-visio-chiffree/&quot;&gt;Proton Meet, the Encrypted Video Call Zoom Can’t Offer&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;sources&quot;&gt;Sources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://proton.me/blog/introducing-post-quantum-encryption&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://proton.me/blog/introducing-post-quantum-encryption&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://proton.me/support/mail-post-quantum-protection&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://proton.me/support/mail-post-quantum-protection&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://proton.me/blog/post-quantum-encryption&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://proton.me/blog/post-quantum-encryption&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://datatracker.ietf.org/doc/draft-ietf-openpgp-pqc/&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://datatracker.ietf.org/doc/draft-ietf-openpgp-pqc/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://csrc.nist.gov/pubs/fips/203/final&quot; rel=&quot;noopener noreferrer&quot; target=&quot;_blank&quot;&gt;https://csrc.nist.gov/pubs/fips/203/final&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</content:encoded><dc:creator>Mac Souverain</dc:creator><category>radar</category><category>radar-signal</category><category>privacy</category><category>mail</category><category>proton</category><category>chiffrement</category><category>quantique</category><category>souverainete</category></item></channel></rss>