Blackfort Technology

Insights & Articles

Technical analyses, incident reports and practical articles on cybersecurity, DNS security and IT infrastructure — straight from the field.

Threat BriefingJuly 22, 2026·Technical

Open in Orbit: Why Half of the Observed Satellite Downlinks Carry No Encryption

A research team read geostationary satellite traffic with about 800 US dollars of gear — 50% of the observed links ran in the clear. We reproduce the core in the lab, software-defined, showing why this is not a hack, and how the very same reception sees only ciphertext once the payload is encrypted.

Satellite communicationsGEO satelliteEncryptionSATCOMSDRGNU RadioISMSTransport encryption
Read article →
RegulationJuly 22, 2026·Technical

BSI A5: The New Audit Architecture for Trustworthy AI — and Its Bridge to C5

On 6 July 2026 the BSI published the community draft of A5, an audit architecture for AI systems. We explain how A5 is structured, who it addresses, how it connects to the cloud catalogue C5 through ISAE 3000 and which readiness steps make sense now.

BSI A5trustworthy AIC5ISAE 3000EU AI ActOSCALAI governanceCloud Security
Read article →
Incident AnalysisJuly 22, 2026·Technical

CVE-2026-65008: Critical Remote Code Execution in Grav CMS before 2.0.7

A critical flaw (CVSS 9.3) in the PHP CMS Grav allows code execution through a blueprint directive. We show the mechanism, a real lab execution, the detection rule firing in the SIEM and why upgrading to 2.0.7 is the effective fix.

CVE-2026-65008Grav CMSRemote Code ExecutionCWE-94WazuhMITRE ATT&CKPatch ManagementVulnerability Management
Read article →
Threat BriefingJuly 19, 2026·Technical

Kerberoasting: How a Weak Service Account Password Opens Your Active Directory — and the Hardening

A standard domain user account is enough: Kerberoasting extracts service ticket hashes for offline cracking, enabling full privilege escalation. We demonstrate the mechanics in a lab environment and cover the effective countermeasures — from password policies and Managed Service Accounts to SIEM detection rules.

Active DirectoryKerberoastingIAMHardeningMITRE ATT&CKService AccountsPassword PolicyNIS2DORA
Read article →
Threat BriefingJuly 17, 2026·Technical

React2Shell: CVE-2025-55182 — Critical RCE in Next.js Server Components (CVSS 10.0)

A single HTTP POST is all it takes: CVE-2025-55182 enables unauthenticated remote code execution in React 19 and Next.js 15/16 via the RSC Flight protocol. We reproduced the vulnerability in an isolated lab environment and demonstrate how SBOM-based dependency tracking automatically detects the affected packages.

CVE-2025-55182Next.jsReactRCEServer ComponentsSBOMSupply Chain
Read article →
Threat BriefingJuly 16, 2026·Technical

LegacyHive: Windows Zero-Day in the User Profile Service — Detection Without a Patch

An unpatched Windows zero-day in the User Profile Service lets standard users load foreign registry hives. No patch — here is how to detect and contain the attack with Sysmon and Wazuh.

LegacyHiveWindows Zero-DayUser Profile ServiceProfSvcPrivilege EscalationSysmonWazuhDetection Rule
Read article →
RegulationJune 20, 2026·General

Section 393 SGB V: Why Your Cloud Provider’s C5 Attestation Often Isn’t Enough

Since July 1, 2025, Section 393 SGB V requires a current C5 Type 2 attestation of the data-processing entity itself whenever cloud software processes health or social data. A checklist for practices on what the fine print actually needs to say.

Section 393 SGB VC5 AttestationBSI C5Cloud Computing Compliance Criteria CatalogueGDPRHealth DataPsychotherapyPractice Software
Read article →
Incident AnalysisJune 11, 2026·Technical

DENIC Final Report: The Rollover Agent Bug Behind the May 5, 2026 DNS Outage

DENIC has published its final root-cause analysis of the May 5, 2026 DNS outage: a bug in the rollover agent generated a separate key pair per HSM instead of one shared pair. Full technical breakdown and remediation steps.

DNSSECDENICDNSRollover AgentHSMFinal Report
Read article →
RegulationJune 16, 2026·Technical

BSI TR-03184 in Practice: Securing Space Systems with ISO 27001 and IT-Grundschutz Experience

BSI TR-03184 governs information security for space systems — space and ground segment. How the requirements translate into practice with years of ISO 27001 and BSI IT-Grundschutz experience.

BSI TR-03184Space SystemsISO 27001BSI IT-GrundschutzISMSSatellite SecurityAerospaceNIS2KRITIS
Read article →
RegulationJune 16, 2026·Technical

NIS2 for the Space Sector: What the GOVSATCOM Hub Cologne Means for Ground Station Operators

NIS2 classifies the space sector as highly critical. With GOVSATCOM Hub and SpaceHub Cologne, new infrastructure is emerging in Cologne — what this means for cybersecurity under BSI TR-03184.

NIS2Space SectorBSI TR-03184GOVSATCOMKRITISGround StationsSatellite CommunicationCologne
Read article →
Security AdvisoryJune 10, 2026·Technical

Check Point VPN CVE-2026-50751: Active Exploitation Detected

Critical authentication bypass CVE-2026-50751 in Check Point VPN is being actively exploited. CVSS 9.3, CISA KEV, IKEv1 certificate validation bypass — Qilin ransomware affiliate activity observed.

CVE-2026-50751Check PointVPNAuthentication BypassIKEv1CISA KEVQilin RansomwareZero-Day
Read article →
RegulationJune 9, 2026·Technical

DORA, GDPR & AI Act: Bitkom Guide for Insurers 2026

Bitkom publishes a guide on integrated compliance with DORA, GDPR and the EU AI Act for the insurance sector. Practical implementation for 2026.

DORAGDPRAI ActInsuranceComplianceBitkomEU RegulationInsurTechGovernanceRisk Management
Read article →
Security AdvisoryMay 27, 2026·Technical

7-Zip CVE-2026-48095: Critical RCE Vulnerability Patched

7-Zip 26.00 contains critical vulnerability CVE-2026-48095 with CVSS 8.8. A heap overflow in the NTFS handler enables remote code execution. Update to 26.01 available.

CVE-2026-480957-ZipRemote Code ExecutionHeap OverflowNTFSVulnerability ManagementPatch Management
Read article →
RegulationMay 20, 2026·Technical

TKG Amendment Act 2026: New Network Expansion Rules

The 2026 TKG Amendment Act introduces new rules for fibre and mobile network expansion in Germany. Key changes for telecommunications operators at a glance.

TKGTelecommunicationsNetwork ExpansionFibreMobileRegulationBMDSLegislation
Read article →
Security AdvisoryMay 18, 2026·Technical

CVE-2026-31718: Linux Kernel ksmbd Use-After-Free Vulnerability

CVE-2026-31718 affects Linux ksmbd with a use-after-free in __ksmbd_close_fd(), enabling kernel memory corruption via SMB connections.

CVE-2026-31718Linux KernelksmbdUse-After-FreeSMBMemory CorruptionVulnerability
Read article →
Security ResearchMay 15, 2026·Technical

BSI C3A: New Criteria for Sovereign Cloud Services

Germany’s BSI publishes the C3A criteria catalog for cloud autonomy. Six sovereignty objectives extend the C5 standard and make digital self-determination measurable.

BSICloud SovereigntyC3AC5ANSSIComplianceIT-GrundschutzDigital Self-Determination
Read article →
Security ResearchMay 14, 2026·Technical

GreenPlasma: Arbitrary Section Creation on Windows – Analysis and Detection

Technical analysis of the GreenPlasma PoC (Nightmare-Eclipse): Object Manager symlinks and registry link abuse as a privilege escalation chain on Windows 11 – with Sysmon and Wazuh detection rules.

GreenPlasmaWindows 11Privilege EscalationCTFSysmonWazuhDetection Engineering
Read article →
Security AdvisoryMay 13, 2026·Technical

Microsoft Patch Tuesday May 2026: 120 Vulnerabilities Fixed

Microsoft fixes 120 security vulnerabilities in the May 2026 Patch Tuesday, including 17 critical flaws in Windows, Office and SharePoint.

MicrosoftPatch TuesdayVulnerabilitiesWindowsPatch Management
Read article →
Security AdvisoryMay 13, 2026·Technical

YellowKey: BitLocker Bypass Discovered in Windows 11

Researchers disclose the YellowKey vulnerability, which bypasses BitLocker protection in Windows 11 and Server 2022/2025. A USB stick is enough for full access.

BitLockerWindows 11YellowKeyVulnerabilityEndpoint Security
Read article →
Security AdvisoryMay 13, 2026·Technical

Ollama CVE-2026-7482: Critical Vulnerability Fixed

Ollama fixes CVE-2026-7482 in v0.17.1, a critical out-of-bounds read vulnerability that could expose API keys and chat data.

OllamaCVE-2026-7482AI SecurityLLM
Read article →
Supply Chain SecurityMay 13, 2026·Technical

RubyGems Halts Registrations After 500+ Malware Packages

More than 500 malicious packages forced RubyGems to suspend new account registrations. The attack targeted the platform itself, not its users.

RubyGemsSupply ChainMalwareRubyPackage Security
Read article →
AI SecurityMay 13, 2026·Technical

Indirect Prompt Injection: A New Threat to Enterprise AI

Indirect prompt injection attacks on enterprise AI agents are up 32%. Attackers hide commands in emails and documents. Protective measures are essential.

AI SecurityPrompt InjectionEnterprise AILLMGenAI
Read article →
AI SecurityMay 13, 2026·Technical

G7 Publish SBOM Minimum Standards for AI Systems

For the first time, the G7 define minimum elements for a Software Bill of Materials (SBOM) for AI systems. More transparency for secure AI supply chains.

SBOMG7AI SecuritySupply ChainCompliance
Read article →
IT SecurityMay 12, 2026·Technical

DORA Resilience: IAM Architecture as a Critical Success Factor

Access security and IAM architecture determine DORA compliance. Formal touch-ups are not enough — genuine resilience requires substantive measures.

DORAIAMComplianceFinancial SectorIdentity Management
Read article →
OT SecurityMay 12, 2026·Technical

Siemens S7 PLC XSS Vulnerabilities: Security Update Required

Critical XSS vulnerabilities discovered in Siemens SIMATIC S7 PLCs Web Server. Authenticated attackers can carry out Cross-Site Scripting attacks.

SiemensS7 PLCXSSOT SecurityICS
Read article →
Security AdvisoryMay 12, 2026·Technical

Apple Patches 170+ Vulnerabilities in May 2026 Updates

Apple fixes more than 170 security flaws in macOS, iOS, iPadOS, watchOS, tvOS and visionOS. Critical components such as the kernel and WebKit are affected.

AppleSecurity UpdateVulnerabilitiesiOSmacOSPatch ManagementMobile SecurityVulnerability Management
Read article →
Incident AnalysisMay 5, 2026·Technical

DNSSEC Failure in the .de Zone: Why bahn.de, spiegel.de and blackfort-tec.de Returned SERVFAIL

Technical deep-dive into a DNSSEC incident at DENIC: malformed RRSIG for NSEC3 records, impact on validating resolvers, and lessons learned for security monitoring.

DNSSECDENICDNSSERVFAILNSEC3
Read article →
Plain EnglishMay 5, 2026·General

bahn.de and spiegel.de Unavailable: What Went Wrong with DNS Today

On May 5, 2026, many users could not reach bahn.de, spiegel.de and other .de websites – even though the internet was working fine. What happened? Explained without jargon.

DNSOutagebahn.despiegel.deDENIC
Read article →