Tag Archives: Security

Cyber attack on logistics service provider – Production at German Airbus site Nordenham partially affected

[German]Currently (March 8, 2023), production at the Airbus site in Nordenham/Germany seems to be halted (at least in parts). The background to this seems a cyber attack on the logistics service provider (named by my informants as LTS), whose systems … Continue reading

Posted in Security | Tagged | Leave a comment

Veeam fixes critical vulnerability CVE-2023-27532 in Backup & Replication V11a/V12

[German]A small note for users of the backup software from the manufacturer Veeam. As of March 7, 2023, Veeam has fixed a critical vulnerability (CVE-2023-27532) in its Backup & Replication product in versions V11a/V12 via an update. The update via … Continue reading

Posted in Security, Software, Windows | Tagged , , | Leave a comment

Fortinet March 2023 Security Advisory

[German]Administrators of Fortinet's FortiOS and FortiProxy must become active. The manufacturer has published various security advisories for different products as of March 7, 2023. Among other things, a DoS vulnerability CVE-2022-45861 in FortiOS and FortiProxy are addressed. Some of the … Continue reading

Posted in Security, Software | Tagged , | Leave a comment

Google Chrome version 111.0.5563.64/65 and 110.0.5481.192

[German]Google has released updates to Google Chrome Browser 111 in the stable channel for Mac, Linux and Windows as of March 7, 2023. Mac and Linux now reach version 111.0.5563.64, while for Windows, versions 111.0.5563.64/.65 are ready. These are security … Continue reading

Posted in browser, Security, Software, Update | Tagged , , | Leave a comment

Europol took action against DoublePaymer cyber gang

[German]International investigators and law enforcement (FBI, Europool, German LKA, etc.) have succeeded in identifying members of a cybergang that operated under the names "DoppelSpider" and "DoppelPaymer". The cybergang was responsible for ransomware attacks on companies and the University Hospital in … Continue reading

Posted in Security | Tagged | Leave a comment

Why ISL Online: Critical factors when choosing a remote desktop solution

[Sponsored Post]In the rapidly evolving IT world, choosing the right remote desktop software is critical for organizations that value security, ease of use and reliability. One provider of secure remote access that has been on the market since 2001 is ISL Online, which presents some considerations for choosing such software below. More ...


Security: DJI drones and it's AeroScope vulnerabilities

[German]Drones from the Chinese manufacturer DJI have vulnerabilities that allow third parties to read radio traffic and determine the location of the drone pilot. This vulnerability comes from a monitoring feature called AeroScope (DroneID), developed by the manufacturer for "law … Continue reading

Posted in devices, Security | Tagged , | Leave a comment

Critical vulnerability CVE-2023-0656 in SonicWall firewalls

[German]SonicWall has issued a security alert SNWLID-2023-0004 as of March 2, 2023. Several applications are at risk from critical vulnerability CVE-2023-0656. A stack-based buffer overflow vulnerability in SonicOS allows an unauthenticated attacker to remotely cause a denial of service (DoS) … Continue reading

Posted in Security, Software, Update | Tagged , , | Leave a comment

DCOM hardening (CVE-2021-26414) on March 14, 2023 patchday for Windows 10/11 and Server

[German]Just a reminder for administrators of Windows in enterprise environments. There is a vulnerability in Microsoft's Windows DCOM implementation (Windows DCOM Server Security Feature Bypass, CVE-2021-26414) that allowed security features to be bypassed. Microsoft documented this in 2021, and patched … Continue reading

Posted in Security, Update, Windows | Tagged , , | Leave a comment

Busted: Instagram influencer with 40 million followers uses Russian Zeus bot

[English]Security researchers have come across an open Cassandra database instance that probably contained data from the Russian website instarobot.pro. The website is known for offering services for spamming and botting on Instagram under the name Zeus. The records also included … Continue reading

Posted in Security | Tagged | Leave a comment

Reminder: Changes to Certificate-Based Authentication for Domain Controllers in April 2023

[German]It is still a few weeks until the April 2023 patchday. However, I would like to remind administrators who are responsible for updating Windows Domain Controllers about a topic in the Domain Controller area. It is about the fact that … Continue reading

Posted in Security, Update, Windows | Tagged , | Leave a comment