Many companies invest in security awareness training—yet participation often falls short of expectations. Why is that? And what actually works in practice? This article shows how organizations can specifically foster motivation, which measures have proven effective, and how security awareness…
Category: Security Blog G Data Software AG
Browser Spy-Ons: Threat Actor’s Extension Hijack Your AI Conversations
User beware: Not every browser extension is useful, and some of them might disclose the chats you have with AI systems. This article has been indexed from Security Blog G Data Software AG Read the original article: Browser Spy-Ons: Threat…
G DATA Managed SOC in use by the town of Sundern: “We haven’t had any serious incidents so far”
Cybercrime happens around the clock – including at night, on public holidays and at weekends. Local authority IT teams struggle to ensure IT systems are monitored, particularly during off-peak hours. As a result, in the worst-case scenario, attacks remain undetected…
Deceptively Sweet: DonutLoader Reloaded in a modern Remcos RAT Infection
This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Security Blog G Data Software AG Read the original article: Deceptively Sweet: DonutLoader Reloaded in a modern…
An AI-generated phishing attack on myself: How Cybercriminals Use ChatGPT and Similar Tools
A phishing attack that is frighteningly well tailored to me. The tone is right, the context fits, and details from my professional environment are correctly referenced. For a brief moment, everything appears credible. But I ask myself: Where does this…
“G DATA’s Security Awareness trainings have significantly increased security awareness at HBC-radiomatic”
As a globally leading manufacturer of industrial radio control systems, HBC-radiomatic has firmly embedded security awareness into its corporate culture. In this interview, Soenke Knipp, Head of IT at HBC-radiomatic, explains why the long-established company from Crailsheim in Baden-Württemberg chose…
NIS-2 in Practice: How a Managed SOC Supports Compliance with Regulatory Requirements
Implementing the requirements of the NIS 2 Directive involves more than just introducing new tools: it requires effective processes, continuous monitoring of IT systems, and specialized IT security expertise. This is precisely where the challenge lies for many companies. A…
Fake Document, Real Access: Foxit Impersonation Enables Stealth VNC Control
Attackers who impersonate trusted vendors do not only damage the reputation of the original vendor, but also cause heaps of trouble down the line. This article has been indexed from Security Blog G Data Software AG Read the original article:…
Claude Mythos: Dangers and rewards, right next to each other
A lot has already been written about Anthropic’s “Mythos.” While some welcome it and embrace the new possibilities, others are heralding the end of cybersecurity. The truth lies somewhere in between. This article has been indexed from Security Blog G…
“Implementing NIS-2 is an organizational stress test”
Many companies still do not fully have NIS-2 on their radar. Yet it is no longer just about a registration requirement. In this interview, Dr. Matthias Zuchowski, regulatory expert at G DATA CyberDefense, explains what companies need to do now,…
“Pics or it didnt happen” – What BlueHammer tells us about Vulnerability Disclosure
Last week, reports circulated about an unpatched security vulnerability in Microsoft Windows. The “BlueHammer” 0-day vulnerability allows a normal user to gain system-level privileges. Microsoft allegedly refused to accept a report about the vulnerability—because video proof was missing. This article…
Security Awareness: Why employees are essential for IT security
Technical protection measures are only half the battle. In this interview, Frank Queißer from Cyber Samurai explains why security awareness is a crucial component of modern IT security, how companies can identify knowledge gaps among employees, and why realistic training…
Phishing SMS: How to Recognize Fraudulent Messages and Protect Yourself Effectively
A short message pops up: a supposed SMS from a delivery service announces a package, a warning from your bank urges you to immediately confirm your account details, or a supposed friend reaches out from a new number. These text…
When Malware Talks Back: Real-Time Interaction with a Threat Actor During the Analysis of Kiss Loader
Talking to a malware author is a rare occurrence, something most analysts hear about but rarely experience themselves. Identifying the individual behind a malware campaign is often one of the most difficult aspects of threat research. In this case, what…
When Malware Talks Back: Real-Time Interaction with a Threat Actor During the Analysis of Kiss Loader
Talking to a malware author is a rare occurrence, something most analysts hear about but rarely experience themselves. Identifying the individual behind a malware campaign is often one of the most difficult aspects of threat research. In this case, what…
Sweet Minecraft Mods – The Dark Tale of SugarSMP Scam, Malware & Extortion
This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Security Blog G Data Software AG Read the original article: Sweet Minecraft Mods – The Dark Tale…
Sweet Minecraft Mods – The Dark Tale of SugarSMP Scam, Malware & Extortion
This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Security Blog G Data Software AG Read the original article: Sweet Minecraft Mods – The Dark Tale…
Endgame Harvesting: Inside ACRStealer’s Modern Infrastructure
The vector is deceptive. The Loader is sophisticated and at this point, it’s already game over. This article has been indexed from Security Blog G Data Software AG Read the original article: Endgame Harvesting: Inside ACRStealer’s Modern Infrastructure
NIS-2: What the end of the registration period means for management teams
March 6, 2026, marks the end of the registration period for companies that fall under the NIS-2-Directive. Registration with the “Bundesamt für Sicherheit in der Informationstechnik” (BSI) will transform the regulatory transition period into a binding supervisory situation. This will…
Use of LLMs for Malware Analysis: Doing it the right way
This post doesn’t have text content, please click on the link below to view the original article. This article has been indexed from Security Blog G Data Software AG Read the original article: Use of LLMs for Malware Analysis: Doing…