An npm package that stole the private keys
Cybersecurity: A manipulated npm-SDK accessed private wallet keys and spread across 17 packages. Why every build is affected.
Cybersecurity: A manipulated npm-SDK accessed private wallet keys and spread across 17 packages. Why every build is affected.
Cybersecurity: A Microsoft-signed kernel driver disables EDR protection. Why signature trust fails and which detection is now effective.
ISO 27001 explained: what the standard requires, what certification truly means, and how it compares to BSI IT-Grundschutz and NIS2.
Penetration testing explained: what a simulated attack achieves, how it works, and how it differs from vulnerability scans and red teaming.
Phishing explained: how attacks work, from spear-phishing to quishing, and why passkeys offer the best protection.
EDR and XDR explained: how endpoint detection works, when XDR makes the difference, and how both compare to SIEM and NDR.
Security Operations Center explained: what a SOC does, key roles, and why MDR is often a more realistic choice for mid-sized businesses.
Post-quantum cryptography explained: why quantum computers threaten RSA, what NIST standards cover, and how businesses can start now.
CISA has added four actively exploited vulnerabilities to the KEV catalog, including ColdFusion and Langflow. Here’s why this matters for German teams.
SIEM explained: how centralized log correlation works, how it differs from SOC and XDR, and costly mistakes to avoid during implementation.
Passkeys explained: how passwordless FIDO2 logins work, why they block phishing attacks, and how to make the switch seamlessly.
MDR explained: what Managed Detection and Response offers, how it differs from MSSP and in-house SOC, and key selection factors.
Ransomware explained: how attacks unfold, what double extortion means, and five key BSI-recommended protection measures.
Cyber Resilience Act explained: which products it covers, what manufacturers must report by September 2026, and how it differs from NIS2.
Zero Trust explained: the meaning behind 'never trust, always verify,' key components, and why Zero Trust isn't a product.
On 31 August 2025, systems at Jaguar Land Rover began behaving strangely. A few days later, production came to a standstill. For five weeks, …
The AI Act is viewed by many as an ethics and compliance topic, a question of transparency and discrimination. For security teams, it is …
Passkeys replace passwords with a key pair and remove the foundation for phishing. What matters when implementing them in a company.
Key IT security conferences and trade fairs in the DACH region from autumn 2026 to spring 2027: dates, locations, focus, and links at a …
From September 11, 2026, a new obligation applies that many companies still underestimate. Anyone selling connected products in the EU must report actively exploited …
From October 27 to 29, 2026, the Nuremberg Exhibition Center will once again become the most important meeting point for the IT security industry …