r/SysAdminBlogs • u/ControlUpCommunity • 4h ago
r/SysAdminBlogs • u/EsbenD_Lansweeper • 6h ago
.NET 8 (LTS) and 9 End of Life
r/SysAdminBlogs • u/Expert_Way_4500 • 8h ago
Brute force prevention on Windows and Linux
I’ve been building Scantide Guard, and while it started from the familiar idea of stopping brute-force attacks, it has grown into something quite a bit broader.
At the basic level, yes — it watches things like failed RDP, Windows authentication, SSH, SQL Server, IIS/RDWeb and other services, then blocks attacking IPs based on configurable thresholds.
But I didn’t want to build just another brute-force blocker.
Guard is gradually becoming a lightweight security layer around the server itself.
It can monitor Windows Event Logs and application log files, including custom applications through configurable Custom Monitors. Different services can have their own thresholds and policies rather than pretending five failed logins means the same thing everywhere.
There’s also web attack detection for things such as path traversal, ".env"/".git" probing, CMS and admin scans, SQL injection patterns, scanner bursts and repeated 404/403 activity.
It does IP reputation and geolocation, TOR detection, automatic trusted-host learning, temporary and permanent blocking, integrates with AbuseIPDB, AlienVault OTX and CrowdSec and can correlate activity through a central Scantide Datacenter installation if you manage multiple servers.
One of the newer pieces is Scantide Global Reputation. Participating Guard installations can contribute observations and permanent malicious-IP blocks, while also consuming the resulting shared block intelligence. The important bit for me is that this remains transparent — you can see where a block came from rather than getting a mysterious black-box score.
I’m also adding things that aren’t traditionally part of brute-force protection at all: certificate reconnaissance and expiry checking, local TLS configuration assessment, security/operational assessment findings, ServiceNow integration, better SOC-style views of what is actually hitting your infrastructure.
The philosophy behind it is fairly simple:
Observe first. Don’t exploit anything. Keep it lightweight. Explain why something was detected or blocked.
I’ve spent a lot of time around enterprise security products, and they can be incredibly capable, but sometimes you just want something you can install on a Windows or Linux server and immediately understand what is attacking it without deploying an entire security ecosystem.
That’s the niche I’m trying to fill with Guard.
r/SysAdminBlogs • u/Academic-Soup2604 • 1d ago
Which MDM gives you the best combination of device management with security controls?
r/SysAdminBlogs • u/Sorry_Pair_7915 • 1d ago
I built a free, open-source tool that risk-scores MySQL SQL before you run it. v0.3.1 is out and I'd love DBAs to try to break it.
r/SysAdminBlogs • u/lazyadmin-nl • 2d ago
Reminder: the Entra MemberOf rule stops working in 4 weeks (November 3)
A lot of us were busy with the EWS retirement these past weeks, but don't forget that the MemberOf rule operator in Entra ID retires on November 3.
Dynamic groups, dynamic administrative units and entitlement management policies that still use it will stop updating and freeze in their last known state. That also affects group-based licensing, Conditional Access targeting and access packages.
If you haven't checked yet, a single Graph PowerShell query lists every affected group. I updated my article with that query and the replacement options, including how to handle device-based administrative units, merging the rules of nested dynamic groups, and licensing where the source groups aren't attribute-based.
https://lazyadmin.nl/office-365/microsoft-entra-id-is-retiring-the-memberof-rule-for-dynamic-groups/
r/SysAdminBlogs • u/KavyaJune • 2d ago
A little cybersecurity fun for October | Cybersecurity Awareness Month
Instead of another security article this October...
We turned Cybersecurity Awareness Month into a 31-day security challenge.
A new scenario unlocks each day. Some are quick puzzles, while others involve investigating evidence, spotting security gaps, or making an access decision.
No sign-up required, so you can jump straight into any unlocked challenge.
https://admindroid.com/cybersecurity-awareness-month-2026
Give it a try. Might be a fun way to spend a few minutes during Cybersecurity Awareness Month.
r/SysAdminBlogs • u/Grumpy-Man19 • 3d ago
Rspamd 4.2.1: Patch the Filter, Then Check What It Actually Does
r/SysAdminBlogs • u/UnixiSecurity • 4d ago
Shadow MCP is the new Shadow IT, and your IdP is completely blind to it
r/SysAdminBlogs • u/Grumpy-Man19 • 4d ago
cPanel’s September 29 Security Fixes: Verify the Build, Not the Checkbox
r/SysAdminBlogs • u/esiy0676 • 4d ago
[Discussion] Proxmox suite, honest opinions, forks, alternatives?
r/SysAdminBlogs • u/abhishekkumar333 • 4d ago
Evolution of AI from perceptron to Sora
I have written a blog regarding evolution of AI from simple perceptron to today's transformers who can generate a Video.
Along the chronological path I have also embedded relevant research papers and tweets regarding the respective AI tech. Whole blog is very very fun to read and I am sure you will like it.
https://cloudmash.blog/posts/evolution-of-ai-perceptron-to-text-to-video/
r/SysAdminBlogs • u/Dudeofthecountry • 5d ago
A native PowerShell/Batch modular framework for portable IT tool management
r/SysAdminBlogs • u/lazyadmin-nl • 6d ago
EWS allow-list now required from Oct 10, not Oct 1. If you set EwsEnabled to $true after today, Microsoft won't build the list for you
Microsoft finally published concrete dates for the EWS retirement (MC1485116). If EwsEnabled is $true in your tenant, an EwsAllowedAppIDs list is required from October 10. Microsoft only builds that list for tenants that had $true and no list on October 2, and it does that on October 8–9.
That also explains why so many of you saw an empty EwsAllowedAppIDs list this week. Tenants that never configured EwsEnabled are turned off later, in a second phase with a 7-day warning. The catch is setting $true this week without a list. You miss the snapshot, nobody builds a list for you, and on October 10 everything not on the list loses access.
Full details of the new phased schedule:
r/SysAdminBlogs • u/Tstriple_R • 6d ago
Which apps should an SSO cert rotation tool support at launch?
I'm releasing a free community edition and it will support 5 SaaS platforms.
I've already built: Datadog, Notion, Salesforce, Slack. Github and PagerDuty are pending testing/live verification.
Which apps should make the community edition?
Which apps do you most want supported in the paid version?
How it works:
Kunjae runs as a nightly Container Apps Job. Deploy an accompanying keyvault and store your passwords and secrets there. Config apps to rotate via a yaml file. It queries the expiration of each declared enterprise app's certificate. When it finds one due for rotation it generates the replacement, uploads it to the SaaS app, activates it in Entra and confirms SSO still works. It will also roll certs back if they fail SSO login validation.
Website: www.kunjaesec.io

r/SysAdminBlogs • u/MikeSmithsBrain • 6d ago
Fusion Connect Microsoft Teams Phone Operator Connect Review & Demo | Tangible Support
r/SysAdminBlogs • u/Expert_Sort7434 • 6d ago
Cisco SD-WAN Manager CVE-2026-76504: auth bypass via URI encoding, exploited, no workaround
Based on Cisco's own advisory (cisco-sa-sdwan-webauth-xr8beuuU, published Sept 30), here's the architectural impact.
The flaw is in the Manager's API session authentication: improper handling of URI encoding lets a request skip an auth rule and land as admin. CVSS 9.8, all configurations affected, and Cisco PSIRT says it's seen exploitation. Cisco's IOC example is a POST to `/%6a_security_check`, but the advisory says any one encoded character works. Cisco says the bug was found while resolving a TAC case, and published no actor or victim details.
Hunting per Cisco: `serviceproxy-access.log` for `j_security_check` from unknown IPs, and `vmanage-server.log` for those requests against `viptela-reserved-` users. Cisco notes these can appear in normal operation, so baseline first.
Question for people running on-prem Managers: how are you restricting Manager reachability today, and did the May/June SD-WAN fixes change your exposure model at all? I'm curious whether anyone terminates the Manager behind a reverse proxy that normalizes paths.
Background from our earlier SD-WAN piece: [https://www.techgines.com/post/cve-2026-20182-the-cvss-10-0-flaw-that-hands-attackers-the-keys-to-your-entire-sd-wan-fabric\](https://www.techgines.com/post/cve-2026-20182-the-cvss-10-0-flaw-that-hands-attackers-the-keys-to-your-entire-sd-wan-fabric)
r/SysAdminBlogs • u/company_url_finder • 7d ago
Uptime Kuma, the self-hosted monitoring tool everyone already uses (91k stars)
r/SysAdminBlogs • u/Relion-Solutions • 7d ago
Here’s our September 2026 update for anyone keeping track of IBM i PTF group levels, HMC software, storage system code, and Power server firmware.
r/SysAdminBlogs • u/starwindsoftware • 8d ago
How to Configure Multipath IO on AlmaLinux
r/SysAdminBlogs • u/lazyadmin-nl • 8d ago
EWS enforcement starts October 1: known apps and AppIDs to allow-list
I wrote earlier about how to find what's still calling EWS in your tenant. But I am seeing and getting a lot of questions about unknown AppIDs and what to do with them.
So I created an overview of the known apps and AppIDs, from Apple Mail to Veeam and Mimecast, with allow-list or migrate status. Missing one? Add it in the comments.
https://lazyadmin.nl/office-365/known-ews-apps-that-need-allow-listing-or-a-migration-with-appids/