Latest Cyber Security News

Knowledge, trends and tips for greater IT security and
reliable protection against digital threats.

DemocracyHackerSecurityLearn to hack – but for the right reasons: On the road at the Democracy Days in Wismar and Halle
9. September 2026

Learn to hack – but for the right reasons: On the road at the Democracy Days in Wismar and Halle

What does hacking have to do with democracy? From electronic voting machines to the Bundestag hack and our own security research: why an open society needs hackers.
Hacking Democracy: Featured imageSecurityHacking and Democracy: Why an open society needs hackers
24. August 2026

Hacking and Democracy: Why an open society needs hackers

What does hacking have to do with democracy? From electronic voting machines to the Bundestag hack and our own security research: why an open society needs hackers.
AISecurityThe first autonomous AI attack: OpenAI, Hugging Face and what security experts can learn from it
18. August 2026

The first autonomous AI attack: OpenAI, Hugging Face and what security experts can learn from it

In July 2026, a swarm of autonomous OpenAI agents compromised Hugging Face’s infrastructure. What the first documented autonomous AI attack means for defenders.
Cloud SecurityCybercrimeThe end of SMS and phone-based MFA in Microsoft 365: Why admins need to act now
12. August 2026

The end of SMS and phone-based MFA in Microsoft 365: Why admins need to act now

Microsoft is phasing out SMS and voice-based MFA in Entra ID. From September 2026, Passkeys will be the standard; from February 2027, Microsoft’s own SMS/voice service will be discontinued altogether.…
North Korea IT professionals – Featured imageCybercrimeHackerSecurityWarning from the Federal Foreign Office: North Korean IT specialists as an insider threat
5. August 2026

Warning from the Federal Foreign Office: North Korean IT specialists as an insider threat

North Korean IT specialists: The Foreign Office is warning businesses. Here’s how to spot the scam, protect your systems and ensure you comply with the law when recruiting.
Gittea vulnerability – featured imageComputerHackerSecurityCritical Gitea vulnerability: Unauthenticated file access leading to code execution (CVE-2026-59774 & CVE-2026-60004)
5. August 2026

Critical Gitea vulnerability: Unauthenticated file access leading to code execution (CVE-2026-59774 & CVE-2026-60004)

Two critical Gitea vulnerabilities (CVE-2026-59774, CVSS 9.8) allow unauthenticated file access, potentially leading to code execution. What to do now.
ClickFix featured imageComputerHackerSecurityClickFix – When the instinct to help becomes a loophole
5. August 2026

ClickFix – When the instinct to help becomes a loophole

One click, one keyboard shortcut, one command: ClickFix tricks users into executing malicious code themselves. Here’s how to detect and stop this wave of attacks.
Credential Stuffing Featured ImageCybercrimeSecurityCredential Stuffing
29. July 2026

Credential Stuffing

Billions of stolen credentials are circulating on the Darknet, freely accessible and often available for free. Credential stuffing exploits precisely these datasets: attackers automatically test huge numbers of username-password combinations…
wp2shell featured imageComputerHackerSecuritywp2shell: Critical WordPress vulnerability allows server takeover without logging in
24. July 2026

wp2shell: Critical WordPress vulnerability allows server takeover without logging in

Security researchers at Searchlight Cyber (Assetnote team) have discovered a chain of two vulnerabilities in the WordPress core which, when combined, enable a complete takeover of a website. The entry…
SecuritySOC 1, 2 or 3: Which report is your client actually referring to?
15. July 2026

SOC 1, 2 or 3: Which report is your client actually referring to?

  SOC 1, 2 or 3: Which report is your client actually referring to? Category ISMS & Compliance Topic SOC 1, SOC 2 & SOC 3 Audience Service providers &…
Cloud SecurityWhat is a SOC? And what different types are there?
9. July 2026

What is a SOC? And what different types are there?

Cyberattacks no longer occur only during the day between 9 am and 5 pm. Ransomware groups deliberately target weekends and public holidays, when companies have the fewest staff on duty.
ComputerSecurityQuantum cryptography – The future of secure communication
3. July 2026

Quantum cryptography – The future of secure communication

Category Cryptography Topic Quantum cryptography & QKD Audience Businesses & IT managers Reading time approx. 4 minutes As digitalisation advances, ever-increasing volumes of sensitive data are being transmitted over the…
ComputerResponsible Disclosure: How to report security vulnerabilities responsibly
26. June 2026

Responsible Disclosure: How to report security vulnerabilities responsibly

Finding a security vulnerability is only half the job – what happens afterwards is crucial. This article explains the different disclosure models available, why we favour coordinated disclosure, what the…
ComputerSecurityCVE-2026-8732: WP Maps Pro vulnerability
11. June 2026

CVE-2026-8732: WP Maps Pro vulnerability

WordPress plugins are handy; they expand a website’s functionality with just a few clicks, which is precisely why they are a popular point of entry. CVE-2026-8732 is a critical vulnerability…
CybercrimeHackerSecurity25 years of the ILOVEYOU virus
30. April 2026

25 years of the ILOVEYOU virus

Zero Trust is a security concept based on the assumption that no user, device or network is inherently trustworthy. Instead, every access attempt is continuously verified and authenticated, regardless of…
Cloud SecurityCybercrimeSecurityStored XSS in SPY 24 PLUS (Linergy) webapplication
30. October 2025

Stored XSS in SPY 24 PLUS (Linergy) webapplication

Details about a stored XSS vulnerability in the product / webapplication "SPY 24 PLUS" from Linergy.
Cloud SecurityComputerHackerSecurityBloodHound 8 – Visualising hybrid attack paths
27. August 2025

BloodHound 8 – Visualising hybrid attack paths

BloodHound has been the go-to tool for identifying attack vectors in Active Directory for years. With version 8, SpecterOps is broadening its scope: in addition to traditional AD, it now…
Cloud SecuritySecurityA Brief Guide to Email Security: Looking Ahead to the Year 2025
22. August 2025

A Brief Guide to Email Security: Looking Ahead to the Year 2025

To mark the Year of Email Security 2025, Mint Secure has published a brief guide to email security terminology. Mint Secure has been inducted into the ‘Hall of Fame’ for…
Cloud SecurityComputerSecurityQuantum-secure cryptography & the Quantum Year 2025
11. August 2025

Quantum-secure cryptography & the Quantum Year 2025

2025 is the ‘quantum year’ – not only because 1925 saw the emergence of the groundbreaking work of Werner Heisenberg, Erwin Schrödinger and other pioneers, which continues to shape our…
CybercrimeHackerSecurityThe Art of Deception – Social Engineering and the Psychology Behind Cyberattacks
6. August 2025

The Art of Deception – Social Engineering and the Psychology Behind Cyberattacks

Social Engineering is not a new phenomenon. Yet it has never been more relevant or dangerous. For whilst firewalls, antivirus programmes and password managers are getting better and better, people…
Cloud SecurityComputerSecurityPayment card for refugees
5. August 2025

Payment card for refugees

Payment cards for refugees have been a hotly debated topic for years. The aim is to ensure that refugees do not receive cash directly from local authorities, but that all…
Cloud SecurityComputerSecurity2025: Short report IETF 123 in Madrid
28. July 2025

2025: Short report IETF 123 in Madrid

The Internet Engineering Task Force (IETF) is an international organization responsible for the technical development of the Internet. The 123rd IETF meeting took place in Madrid in July 2025.
Cloud SecurityComputerSecuritySmart Cities: Digitalisation with a focus on security
16. July 2025

Smart Cities: Digitalisation with a focus on security

The city of the future is connected, automated and data-driven. From intelligent traffic management and smart street lighting to digital public services – smart cities are no longer a vision,…
AllgemeinData protection and IT security issues with age verification app Yoti
5. June 2025

Data protection and IT security issues with age verification app Yoti

Informationen über Datenschutzrisiken und IT-Sicherheitsrisiken beim Einsatz der Altersverifikationsapp Yoti, welche unter anderem Tracking ohne Einwilligung von Benutzenden vornimmt.
ComputerCybercrimeHackerSecurityCybercrime on the Dark Web: A look behind the scenes
28. May 2025

Cybercrime on the Dark Web: A look behind the scenes

The Dark Web – often shrouded in mystery and misunderstood – is a part of the internet that is not indexed by conventional search engines. It is a place where…
SecurityVulnerability Scanning and Management
21. May 2025

Vulnerability Scanning and Management

Vulnerability scanning is the process of systematically examining an IT system for potential vulnerabilities.
ComputerCybercrimeHackerSecurityUSB & Port Security: An invisible threat at an open port
13. May 2025

USB & Port Security: An invisible threat at an open port

USB ports are convenient interfaces – but they are also extremely dangerous entry points for targeted attacks. Whilst IT security often ...
Cloud SecurityComputerSecuritye-passport photos: a reality check
6. May 2025

e-passport photos: a reality check

The article analyses data protection risks associated with the digital transmission of passport photographs in Germany, criticises providers’ use of the cloud, and recommends having photographs taken by the authorities…
Cloud SecurityComputerSecurityLDAP Signing and Channel Binding – Microsoft’s next mandatory AD hardening measure
28. April 2025

LDAP Signing and Channel Binding – Microsoft’s next mandatory AD hardening measure

The deactivation of NTLM and RC4 was just the beginning. With LDAP Signing and Channel Binding, Microsoft is enforcing the next round of Active Directory hardening. This time, it affects…
SecurityCyber Resilience Act: Greater security for digital products in the EU
23. April 2025

Cyber Resilience Act: Greater security for digital products in the EU

The Cyber Resilience Act is an EU regulation designed to ensure that all digital products containing ‘electronic components’ meet a minimum standard of ...
AllgemeinPath Traversal Vulnerability in Surveillance Software
19. April 2025

Path Traversal Vulnerability in Surveillance Software

The article describes in more detail a critical security vulnerability (path traversal) in the software of the manufacturer Infodraw.
CybercrimeHackerSecurityFacial recognition software: weaknesses, risks and challenges
18. April 2025

Facial recognition software: weaknesses, risks and challenges

Facial capture and facial recognition systems are increasingly in use, but they can be specifically targeted and manipulated. This blog post takes a closer look at attack techniques and key…
Cloud SecurityComputerCybercrimeSecurityThe Zero Trust approach
8. April 2025

The Zero Trust approach

Zero Trust is a security concept based on the assumption that no user, device or network is inherently trustworthy. Instead, every access attempt is continuously verified and authenticated, regardless of…
ComputerHackerSecurityHacking Gadgets – More than just Hollywood?
3. April 2025

Hacking Gadgets – More than just Hollywood?

Devices such as the Flipper Zero or the WiFi Pineapple offer a wide range of attack vectors and are used not only for legitimate security testing but also for targeted…
Cloud SecurityCybercrimeSecurityModern authentication
27. March 2025

Modern authentication

Passkeys are a new method of authentication based on cryptographic keys. Instead of having to remember a password and also a code ...
Cloud SecurityComputerSecurityCVE-2025-29927: Critical security vulnerability in Next.js
23. March 2025

CVE-2025-29927: Critical security vulnerability in Next.js

On 22 March 2025, Next.js announced a security vulnerability in the middleware layer that allowed authentication to be bypassed.
Cloud SecurityComputerSecurityPyramid of needs for incident response
13. March 2025

Pyramid of needs for incident response

With a few adjustments, Maslow’s hierarchy of needs can also be applied to the field of cyber security.
Cloud SecurityComputerSecurityData Protection in the Cloud: Challenges and Best Practices
10. March 2025

Data Protection in the Cloud: Challenges and Best Practices

Cloud computing has revolutionised the way businesses store and manage data. However, as the use of cloud services increases, so too does the risk of personal data breaches. Businesses must…
CybercrimeHackerSecurityRansomware 2025: The Most Dangerous Groups and Their Tactics
5. March 2025

Ransomware 2025: The Most Dangerous Groups and Their Tactics

In the ever-evolving world of cybercrime, Ransomware remains one of the greatest threats to businesses and individuals. By 2025, attack methods will have evolved further...
HackerSecurityAI-Powered Penetration Testing
13. February 2025

AI-Powered Penetration Testing

By incorporating AI into the penetration testing process, many of these tasks can be automated and carried out more efficiently. Here are some of the key benefits of using AI…
HackerSecuritySocial Engineering
3. February 2025

Social Engineering

In a digitally connected world, companies are increasingly relying on modern security measures such as firewalls, antivirus software and encryption. However, despite these technical safeguards, people often remain the weakest…
SecurityPhishing Simulation – Modern-Day Attacks
20. January 2025

Phishing Simulation – Modern-Day Attacks

These days, there are hardly any communication channels where scamming or Phishing doesn’t take place...
rsync featured imageSecurity6 security vulnerabilities, some of which are critical, in rsync Server
14. January 2025

6 security vulnerabilities, some of which are critical, in rsync Server

Six vulnerabilities in rsync servers, some of which are critical, could lead to data leaks, Path Traversal and, in the worst case, the execution of arbitrary code. Organisations should immediately…
CybercrimeHackerSecurityWP3[.]XYZ Malware has affected more than 5,000 WordPress sites
14. January 2025

WP3[.]XYZ Malware has affected more than 5,000 WordPress sites

The WP3XYZ Malware campaign has compromised over 5,000 WordPress websites and, amongst other things, creates a hidden administrator account called “wpx_admin” to grant attackers permanent access. Website operators should check…
SecurityNIS2 compliance
7. January 2025

NIS2 compliance

In order to meet the legal requirements in the field of IT security, compliance with ... is required
SecurityPhysical Penetration Test
6. January 2025

Physical Penetration Test

In the world of cybersecurity, the protection of digital assets is a ...
SecurityActive Directory Security
5. January 2025

Active Directory Security

What is Active Directory, and why is it so important to secure it? In the ...