Category Archives: Security

New BITSLOTH backdoor discovered; abuses the Windows BITS service

[German]Another nice story that I came across last week. What I had suspected for some time has been confirmed. The Background Intelligent Transfer Service (BITS) can be abused. A newly discovered Windows backdoor BITSLOTH uses BITS to communicate with command … Continue reading

Posted in Security, Windows | Tagged , | Leave a comment

Identities Inventory: How to certify access rights

[German]What do you think about the certification of access rights for users? Access certification describes the independent review of access rights by an auditor. The auditor examines whether the rights granted to users are really necessary. A thorough user access … Continue reading

Posted in Security | Tagged | Leave a comment

Microsoft discovers VMware ESXi Auth Bypass vulnerability CVE-2024-37085

[German]Microsoft security experts have discovered a ransomware campaign targeting VMware ESXi instances. Via an Auth Bypass vulnerability (CVE-2024-37085) it is possible to gain full administrative privileges on domain-joined ESXi hypervisors. The vulnerability is being exploited by several ransomware operators to … Continue reading

Posted in Security, Virtualization | Tagged , | Leave a comment

Question: Where does Bitlocker store the recovery key in Windows?

[German]Bitlocker, the "unknown entity" I would like to paraphrase the blog post. It's about the question of where the Windows Bitlocker function actually stores the recovery key, which is needed from time to time. Before someone comes around with "in … Continue reading

Posted in Security, Windows | Tagged , | Leave a comment

Possible Pinterest Dat leak with 6 Million affected user (July 2024)

[German]The Pinterest service has (probably) suffered a major data leak affecting its registered users. While it's not confirmed, security researchers from Surfshark have looked at the details and found that the USA and France are the most affected countries among … Continue reading

Posted in Security | Tagged | Leave a comment

Why ISL Online: Critical factors when choosing a remote desktop solution

[Sponsored Post]In the rapidly evolving IT world, choosing the right remote desktop software is critical for organizations that value security, ease of use and reliability. One provider of secure remote access that has been on the market since 2001 is ISL Online, which presents some considerations for choosing such software below. More ...


CrowdStrike incident: sensor failure as a previously unknown side effect?

[German]A faulty update to the CrowdStrike Falcon software brought around 8.5 million Windows computers to a standstill on July 19, 2024. The incident is already considered to be the world's largest computer failure to date and is likely to have … Continue reading

Posted in Security, Windows | Tagged , , , | Leave a comment

FrostyGoop malware infects industrial control systems (OT)

[German]The Dragos OT Cyber Threat Intelligence team encountered FrostyGoop ICS malware targeting ICS/OT systems in April 2024. This malware can interact directly with Industrial Control Systems (ICS) in Operational Technology (OT) environments via the Modbus protocol, a standard ICS protocol … Continue reading

Posted in Security | Tagged | Leave a comment

Review of the CrowdStrike incident, the biggest computer glitch of all time

[German]It is considered to be the world's biggest computer glitch to date, paralyzing 8.5 million Windows systems and causing billions in damage. In the meantime, the clean-up work, the finger-pointing and the "washing of hands in innocence" have begun. I … Continue reading

Posted in Security, Windows | Tagged , , | 1 Comment

Windows Patchday news: MSHTML 0-day vulnerability CVE-2024-38112 exploited by malware

[German]A small addendum to the July 2024 patchday at Microsoft. With the security updates, Microsoft has also closed an MSHTML spoofing vulnerability. There was information that this vulnerability (CVE-2024-38112) was and is being exploited by malware. The vulnerability is in … Continue reading

Posted in Security, Update, Windows | Tagged , , , | Leave a comment

US data brokers offer 3.6 billion location data of German cell phone users

[German]Research by several German media outlets reveals that US data brokers are offering the locations of cell phone users in Germany. Some of the data can even be accessed free of charge, as research by netzpolitik.org and BR shows. A … Continue reading

Posted in Security | Tagged , , | Leave a comment