News

Latest news on the subject of B2B cyber security >>> PR agencies: Add us to your mailing list - see contact! >>> Book an exclusive PartnerChannel for your news!

Cloud security according to BSI criteria: C5 attestation for Trend Micro 
Trend Micro News

Trend Micro, one of the world's leading providers of cyber security solutions, received the attestation according to the criteria of the C2023:5 standard (Cloud Computing Compliance Criteria Catalogue) in January 2020. These are based on the catalog of requirements of the Federal Office for Information Security (BSI) and have become the recognized security standard for cloud computing in Germany. The Japanese company thus offers its customers cloud security based on Software as a Service (SaaS) solutions for a modern and up-to-date level of security that meets the strict and demanding criteria of the BSI. C5: Cloud security according to BSI criteria The C5 catalog has been around since 2016. It…

Read more

BSI: Critical vulnerability in Control Web Panel
B2B Cyber ​​Security ShortNews

The well-known and widely used Web Hosting Control Web Panel (CWP) has a critical security vulnerability from 9.8 to CVSSv3.1. Attackers can install shells on the server or collect and extract information. On January 3, 2023, IT security researcher Numan Türle from Gais Cyber ​​Security published a proof of concept for a vulnerability in the server management software Control Web Panel (CWP) - formerly CentOS Web Panel. The vulnerability allows a remote, unauthenticated attacker to execute code on the affected system based on a lack of input neutralization. The information was released...

Read more

BSI warns: Multiple vulnerabilities in Microsoft Edge
B2B Cyber ​​Security ShortNews

The BSI has issued a warning about vulnerabilities in the new Chromium-based web browser Edge. Users should update the browser on MacOS X or Windows, since attackers could execute arbitrary program code and escalate their privileges. The Federal Office for Information Security warns of two vulnerabilities in the new Chrome-based browser Edge. The vulnerabilities CVE-2023-21775 and CVE-2023-21796 are classified as “High” dangerous with a CVSS Base Score of 8.3. In this way, attackers could exploit the vulnerabilities to execute arbitrary program code and thus increase their privileges on the system. Open Edge...

Read more

BSI magazine on ransomware
B2B Cyber ​​Security ShortNews

As usual, the BSI publishes the second edition for 2022 of the BSI magazine "Mit Sicherheit". In this BSI magazine, the Federal Office for Information Security (BSI) focuses on one of the currently greatest threats to IT security in a special section: ransomware. What happens when a ransomware incident is reported? How do we know what countermeasures are necessary in the event of a ransomware attack? And what do cybercrime and the economy have in common? These and other questions are answered in the current issue of the BSI magazine "Mit Sicherheit". Magazine on the topic of ransomware Other topics include automotive security, the…

Read more

Safety check for artificial intelligence in automobiles
B2B Cyber ​​Security ShortNews

Over the past twelve months, the Federal Office for Information Security (BSI) and the technology company ZF have been developing concepts and methods for testing the IT security of AI systems in motor vehicles in the joint AIMobilityAuditPrep project. Based on scientific findings and existing standards, 50 technically relevant requirements for AI systems were compiled, an expandable test environment for AI systems was developed and the basic feasibility and practical feasibility of the tests were demonstrated using selected use cases in a simulation. Safety checks for AI in the car With the follow-up project AIMobilityAudit, the practical implementation of safety checks for AI in automated…

Read more

BSI: IT Security in Germany 2022 - Management Report
B2B Cyber ​​Security ShortNews

With its report on the situation of IT security in Germany, the Federal Office for Information Security (BSI) presents its comprehensive overview of the threats in cyberspace. This year's report is also in the context of the Russian war of aggression in Ukraine. Overall, the already tense situation worsened in the reporting period. The threat in cyberspace is higher than ever. As in the previous year, a high threat of cybercrime was observed in the reporting period. Added to this were various threats related to the Russian war of aggression on…

Read more

Kaspersky is asking BSI to withdraw the warning 
Kaspersky is asking BSI to withdraw the warning

In a recent report, Kaspersky is asking the BSI to adapt the warning from March 15, 2022 or to withdraw it altogether. At that time, the BSI warned against the use of Kaspersky solutions. Since then, Kaspersky has made extensive information available to the BSI, which has not yet been taken into account. On March 15, 2022, the BSI published a warning about Kaspersky antivirus software. This warning is legally and technically controversial. To date, the BSI has not been able to identify any security gaps in the AV software in the warning or in the wake of it. There were also…

Read more

BSI: Cyber ​​security advice for SMEs 
B2B Cyber ​​Security ShortNews

The Federal Office for Information Security (BSI) has published a publication on cyber security advice for small and medium-sized enterprises (SMEs). The brochure offers SMEs an easy-to-understand introduction to improving their cyber security level, because information security is a prerequisite for secure digitization. The brochure starts with the most important basics of IT security - in a nutshell with 14 questions. Among other things, it provides information on who is responsible for information security in the company, why patches and updates should be installed regularly, why an anti-virus program is necessary and why data backup is so important...

Read more

BSI ranks Sophos as a Qualified APT Response Provider
SophosNews

After an intensive examination, the Federal Office for Information Security (BSI) included Sophos in its list of qualified service providers in the APT area. The official list of the BSI makes it easier for operators of critical infrastructures to select suitable companies in the field of IT forensic services. After an extensive review process, Sophos is now on the list of qualified APT (Advanced Persistent Threat, or APT) response service providers for KRITIS companies. This overview supports operators of critical infrastructures in identifying suitable service companies that are able to uncover camouflaged cyber attacks that attack a network or system over a longer period of time without much research effort...

Read more

BSI tool for telemetry monitoring of Windows 10
B2B Cyber ​​Security ShortNews

Telemetry in Windows 10 has access to extensive system and usage data of the operating system. The Federal Office for Information Security (BSI) has developed a technical solution for monitoring the telemetry component as part of the "Study on system structure, logging, hardening and security functions in Windows 10" (SiSyPHuS Win10). The developed "System Activity Monitor" (SAM) enables detailed recordings of the system and application behavior of the Windows telemetry for research purposes. The publication is part of an extensive security analysis in which the BSI examines security-critical functions of the operating system. The aim is to improve the security and residual risks for using Windows 10...

Read more