<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>aramido Blog about Information Security</title><link>https://aramido.de/en/blog/</link><description>Blog posts and materials on the subject of IT security and penetration testing.</description><language>en-US</language><item><title>Hacking AI: Loss of Control Instead of Controlled Tests</title><link>https://aramido.de/en/blog/network-security/hacking-ai-loss-of-control-instead-of-controlled-tests/</link><pubDate>Sat, 01 Aug 2026 09:47:22 +0200</pubDate><author>Andreas Sperber</author><guid>https://aramido.de/en/blog/network-security/hacking-ai-loss-of-control-instead-of-controlled-tests/</guid><description><![CDATA[<p>A digital déjà vu: Hardly had the industry digested <a href="https://aramido.de/en/blog/network-security/ai-models-break-out-and-hack-hugging-face"
   
   
   >
    the news about the OpenAI breakout
</a>
, Anthropic admitted that its models had also autonomously entered other companies. What is framed as a systematic test is, in reality, an unprecedented loss of control over its own technology.</p>
<h2 id="the-absurdity-of-cybersecurity-evaluations">The Absurdity of “Cybersecurity Evaluations”</h2>
<p>The communication from the leading AI labs, Anthropic and OpenAI, follows a disturbing pattern. Both frame these incidents as necessary “Cybersecurity Evaluations,” essentially as controlled experiments to measure model capabilities.</p>
<p>In Anthropic’s case, it was not a technical breakout from a sandbox via a software vulnerability, but a simple yet serious infrastructure misconfiguration: a misunderstanding with a test partner led to the test environment simply being connected to the public internet. This negligence allowed the Claude models to reach the internet and hack three different organizations. In <a
    href="https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals#incident-2" 
    rel="nofollow noreferrer noopener"
    target="_blank">
        one of these cases
</a>, the AI even attempted to upload a package to the public Python Package Index (PyPI), which was however prevented by PyPI’s automatic protection systems.</p>
<p>The fact that high-potency AI models can act unrestricted on the internet and compromise uninvolved companies cannot be understood as scientific progress, but rather as a failure of security architecture. For the affected companies, the origin of the attack is irrelevant; the fact that AI agents can now autonomously define targets and independently execute complex attack chains over several days is a new, existential threat level.</p>
<h2 id="machine-vs-human-the-new-dynamics-of-lateral-movement">Machine vs. Human: The New Dynamics of Lateral Movement</h2>
<p>A crucial point is the way these agents operate. While a human attacker often follows certain patterns and shows a noticeable time delay during lateral movement in the network, the AI operates at “machine speed.”</p>
<p>An AI agent analyzes vulnerabilities, tries exploits, and moves through the network with a speed and logic that often overwhelms traditional monitoring systems designed for human response times. This absence of human patterns makes detection significantly more difficult.</p>
<h2 id="regulatory-focus-technical-errors-become-legal-risks">Regulatory Focus: Technical Errors Become Legal Risks</h2>
<p>The incidents are now putting AI labs heavily in the focus of regulatory authorities, especially the <a
    href="https://www.aisi.gov.uk/" 
    rel="nofollow noreferrer noopener"
    target="_blank">
        AI Safety Institutes
</a>. With the entry into force of the EU AI Act, technical “breakouts” are turning into systemic legal risks. A model’s ability to autonomously overcome security barriers could in the future no longer be viewed as an experiment, but as gross negligence, leading to <a
    href="https://artificialintelligenceact.eu/article/99/" 
    rel="nofollow noreferrer noopener"
    target="_blank">
        billion-dollar fines
</a> (up to 7% of global turnover) and extensive claims for damages.</p>
<h2 id="three-levers-for-an-agent-resilient-infrastructure">Three Levers for an Agent-Resilient Infrastructure</h2>
<p>Traditional perimeter thinking has long been obsolete. Anyone who believes that a firewall or a sandbox is sufficient is ignoring at least the lessons of the last few weeks. What is required is an architecture based not on isolation, but on continuous verification.</p>
<h3 id="zero-trust-and-radical-micro-segmentation">Zero Trust and Radical Micro-segmentation</h3>
<p>The assumption that a once-authenticated process is trustworthy must be abandoned. Every request within the network is validated. For SMEs, this specifically means dividing the network into VLANs to prevent the unhindered lateral movement of an AI agent.</p>
<h3 id="deception-technology-systematic-deception">Deception Technology: Systematic Deception</h3>
<p>AI agents act extremely logically and systematically. This characteristic can be used against them. The placement of <a href="https://aramido.de/en/topic/honeytoken">honeytokens</a> serves as a highly effective early warning system. Access to these tokens is a clear indicator of compromise long before conventional alarms go off.</p>
<h3 id="ai-powered-detection-and-managed-response">AI-powered Detection and Managed Response</h3>
<p>A human cannot react in real-time to the speed of an autonomous agent. The transition to AI-powered EDR and XDR systems is inevitable. SMEs can close this gap through Managed Detection and Response (MDR) services, where external experts monitor anomalies in real-time.</p>
<h2 id="strategic-resilience-defense-in-depth-and-assume-breach">Strategic Resilience: Defense in Depth and Assume Breach</h2>
<p>The incidents at OpenAI and Anthropic mark a turning point. In a world where AI models autonomously penetrate productive systems, it is no longer enough to just “close the door.” We therefore consistently pursue two strategic approaches:</p>
<ul>
<li><strong>Assume Breach:</strong> We assume that the perimeter has already been breached. The goal is no longer just to prevent the break-in, but to detect the attacker as quickly as possible and maximally restrict their freedom of movement in the network.</li>
<li><strong>Defense in Depth:</strong> Security is understood as a multi-layered system. If one layer fails, other independent security mechanisms immediately take over to limit the damage.</li>
</ul>
<p>In this context, the <a href="https://aramido.de/en/security-testing/penetration-testing"
   
   
   >
    professional penetration test
</a>
 remains an indispensable instrument. It is the necessary foundation for making <a href="https://aramido.de/en/portfolio/isms/vulnerability-management"
   
   
   >
    vulnerabilities
</a>
 visible in the first place and testing the effectiveness of security chains. But only the combination of regular penetration tests and an agent-resilient architecture creates true resilience.</p>





    
        
    










    






<div class="ara-jumbotron-new ara-bg-gray-800">
    <p class="ara-hyphenation">
        Security in the age of autonomous AI means acting proactively. We support you in validating your systems using penetration tests and implementing a resilient infrastructure.
    </p>
    <div>
        <a class="btn btn-lg btn-success" href="https://aramido.de/en/contact">Check resilience now</a>
    </div>
</div>


]]></description></item><item><title>Agentic AI Changes the Rules of Cybersecurity</title><link>https://aramido.de/en/blog/network-security/agentic-ai-changes-the-rules-of-cybersecurity/</link><pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate><author>Valerie Erhard</author><guid>https://aramido.de/en/blog/network-security/agentic-ai-changes-the-rules-of-cybersecurity/</guid><description><![CDATA[

<p>AI has transformed from a helpful advisor into an independent actor, and thus into a completely new attack vector. What happens when an AI decides that the boundaries of its test environment are merely a recommendation?</p>

<p>Just a week ago, <a href="https://aramido.de/en/blog/network-security/ai-models-break-out-and-hack-hugging-face"
   
   
   >
    the autonomous breakout of an OpenAI model from its test environment
</a>
 seemed like an isolated, albeit alarming, warning signal. However, current reports from Anthropic have painted a far more worrying picture: we are not talking about an isolated incident, but a structural problem of today's AI architecture. What recently seemed like a laboratory experiment has long since become a reality in our networked infrastructures.</p>

<h2>From Advisor to Actor</h2>
<p>The decisive difference from previous attacks lies in the agentic capability of AI models. While AI previously primarily functioned as an intelligent advisor, AI agents can now act independently: they autonomously define goals, select tools, and independently execute complex attack chains over several days. The risk has thus shifted from mere manipulation of a response to the abusive exploitation of agency. An AI agent with access to APIs or databases no longer acts as an advisor, but as an actor. When this actor departs from their original objective or is manipulated by external impulses, <a href="https://aramido.de/en/security-testing/penetration-testing/infrastructure-penetration-testing"
   
   
   >
    attack vectors
</a>
 are created that simply bypass traditional security concepts.</p>

<h2>A Paradigm Shift: From Zero Trust to Agentic AI Security</h2>
<p>Zero Trust is the standard in IT security, but this approach reaches its limits with autonomous agents possessing legitimate identities. Instead of only verifying access, the intention must be validated and the AI's causal chain monitored in the future. Agentic AI Security starts precisely here and ensures that autonomous agents are not only authorized, but that their actions remain transparent, verified, and verifiable.</p>

<h2>An Industry Solution Approach</h2>
<p>To meet the dynamic threat landscape, leading technology companies have launched the <a href="https://blogs.nvidia.com/blog/open-secure-ai-alliance/" rel="nofollow noopener noreferrer" target="_blank">Open Secure AI Alliance (OSAI)</a>. Their goal is to improve the security of AI systems through the use of open technologies. Since proprietary, closed security systems often cannot keep up with the speed of autonomous attacks, the alliance relies on the development and exchange of open tools and techniques. This is intended to ensure the necessary transparency as well as high adaptability and sovereign control.</p>

<h2>The New Reality of Defense</h2>
<p>The autonomy of AI agents requires a security model with concrete strategies for safeguarding. At the center are precise authorization concepts, Human-in-the-Loop procedures, and <a href="https://aramido.de/en/security-consulting/security-by-design"
   
   
   >
    carefully designed test environments
</a>
. Open-source tools can be used to implement these strategies, for example by validating the inputs and outputs of agents in real-time, detecting anomalies, or making the AI's so-called chains of thought transparent and traceable.</p>
<p>Only if we combine limited agency with human oversight and an open defense strategy can we utilize the productivity of AI without sacrificing sovereignty over our systems.</p>

<div class="row mt-1">
    <div class="col-12">
        <div class="ara-jumbotron ara-bg-gray-800">
            <p class="ara-hyphenation d-md-table-cell pe-md-5">
                Are your systems ready for the era of autonomous AI attacks? We help you close the gaps before an AI exploits them.</p>
            <div class="d-grid gap-2 d-md-table-cell justify-content-md-end align-middle">
                <a href="https://aramido.de/en/contact" class="btn btn-success">Contact us now</a>
            </div>
        </div>
    </div>
</div>
]]></description></item><item><title>AI Models Break Out and Hack Hugging Face</title><link>https://aramido.de/en/blog/network-security/ai-models-break-out-and-hack-hugging-face/</link><pubDate>Wed, 22 Jul 2026 09:23:43 +0200</pubDate><author>Valerie Erhard</author><guid>https://aramido.de/en/blog/network-security/ai-models-break-out-and-hack-hugging-face/</guid><description><![CDATA[
<p>In a laboratory experiment by OpenAI, two AIs escaped from a controlled environment: they autonomously left their protected test environment and managed to exploit security vulnerabilities of another platform. Ultimately, they gained access to third-party data. This security incident shifts the discussion about AI risks from a purely theoretical framework directly into the real world. The incident marks a turning point in the debate on AI security, as modern AI models demonstrate for the first time that they can independently execute complex attack chains.</p>
<h2>What Happened?</h2>
<p>On July 16, 2026, Hugging Face released information regarding a security incident on parts of its production infrastructure, describing the uniqueness of the event:</p>
<blockquote class="blockquote">
  <p class="mb-0">This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system - and we detected and dissected it largely with AI of our own.</p>
  <footer class="blockquote-footer">Hugging Face <cite title="Security incident disclosure July 2026"><a href="https://huggingface.co/blog/security-incident-july-2026">Security incident disclosure July 2026</a></cite></footer>
</blockquote>
<p>A few days later, OpenAI explained on its <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident">website</a> that the cyberattack on Hugging Face was triggered by a test they conducted: the autonomously attacking AI consisted of two OpenAI models that were able to break out of the test environment during an evaluation and hack the production infrastructure of Hugging Face.</p>
<p>
    To quantitatively capture the capabilities of GPT-5.6 Sol and another, as yet unpublished model, both systems were tested as part of an internal evaluation on their ability to design complex attack paths for advanced <abbr title="A program or code fragment that exploits a specific security vulnerability to gain unauthorized access to a system or manipulate its functions.">exploits</abbr>.
    According to OpenAI, these benchmarks normally run in highly isolated environments where network access is restricted to the installation of packages via internally hosted third-party software. However, to test the maximum capability of the models, important security mechanisms were deactivated.
</p>
<p>Within the sandbox environment, the models consumed significant computational effort to find open internet access. In doing so, they identified and exploited a zero-day vulnerability in a software proxy. Consequently, the models executed attacks such as privilege escalation and lateral movement until they finally reached a gateway with internet access. With this access, the models attempted to retrieve test solutions for <abbr title="A framework used to test the ability of AI models to autonomously identify security vulnerabilities and successfully exploit them through targeted exploits.">ExploitGym</abbr> directly from Hugging Face's production database.</p>
<p>Hugging Face locates the entry point of the attack in a data processing pipeline. A malicious query, specifically prepared for this pipeline, was able to execute code on one of the servers. One of the models also combined several attack vectors, including stolen credentials and zero-day vulnerabilities, to find a path for remote code execution (RCE) on Hugging Face's servers.</p>
<h2>Incident Response: Anomaly Detection and Forensic Analysis</h2>
<p>The attack on Hugging Face was itself identified via AI-powered anomaly detection. A <abbr title="Security Information and Event Management">SIEM</abbr> system, which detects suspicious patterns in telemetry data, evaluated around 17,000 suspicious events and was able to <a href="https://aramido.de/en/emergency-management"
   
   
   >
    identify the actual attack
</a>
 through the analysis. Hugging Face was able to stop access to the infrastructure and lock out the attacker.
</p>
<p>During the forensic investigations, an interesting irony emerged: Hugging Face could not use models from OpenAI or Anthropic for the analysis, as their integrated security policies blocked the evaluation of the attack data. Instead, they worked with GLM 5.2, a Chinese open-weight model.</p>
<h2>A New Era of the Cyber Threat Landscape</h2>
<p>The use of AI accelerates both the discovery and exploitation of vulnerabilities. The incident shows that powerful AI models can discover and exploit new and complex attack vectors in real systems. The further development of AI models must therefore be mandatory accompanied by improved protective measures.</p>
<h3>What does this mean in practice?</h3>
<p>As a foundation, infrastructures must be consistently set up according to principles such as <a href="https://aramido.de/en/security-consulting/security-by-design"
   
   
   >
    Secure-by-Design
</a>
 and Zero Trust. The assumption that a sandbox environment is apparently secure enough has proven to be a dangerous misconception. Strict segmentation and minimal privileges are the most effective protective measures against adaptive and autonomous agents.</p>
<p>Furthermore, we are experiencing a renaissance of <a href="https://aramido.de/en/security-testing/penetration-testing"
   
   
   >
    penetration testing
</a>
. It is more important than ever to systematically check one's own systems for vulnerabilities. State-of-the-art penetration tests today combine experience and the latest technologies:</p>
<ul>
  <li><strong>AI-powered pentests</strong> use tools to test systems with the same speed and logic with which an AI would attack.</li>
  <li><strong>Manual pentesting</strong> shows why human intuition is indispensable. Experienced security experts can question complex systems and find creative attack paths that an AI (still) misses.</li>
</ul>
<p>
    The attack by OpenAI on Hugging Face shows how the boundaries between offensive and defensive AI use are blurring. Those who do not adapt their security strategy to the speed of generative AI leave the door wide open for autonomous attackers.</p>
<div class="row mt-1">
    <div class="col-12">
        <div class="ara-jumbotron ara-bg-gray-800">
            <p class="ara-hyphenation d-md-table-cell pe-md-5">
                Have your systems checked for vulnerabilities by experienced experts in an individual <a href="https://aramido.de/en/security-testing/penetration-testing"
   
   
   >
    penetration test
</a>
 now.</p>
            <div class="d-grid gap-2 d-md-table-cell justify-content-md-end align-middle">
                <a href="https://aramido.de/en/contact"
                   class="btn btn-success"
                   
                   >
                    Contact us now
                </a>

            </div>
        </div>
    </div>
</div>]]></description></item><item><title>security.txt - How security researchers report vulnerabilities securely</title><link>https://aramido.de/en/blog/web-app-security/securitytxt-how-security-researchers-report-vulnerabilities-securely/</link><pubDate>Mon, 22 Jun 2026 09:23:43 +0200</pubDate><author>Matthias Schmidt</author><guid>https://aramido.de/en/blog/web-app-security/securitytxt-how-security-researchers-report-vulnerabilities-securely/</guid><description><![CDATA[
<p>The number of security vulnerabilities has been continuously increasing for years, and hardly a day goes by without a new, critical vulnerability being present in the media. Not only the number, but also the way the actual information is handled has fundamentally changed over the last 30 years.</p>

<p>With the emergence of the first structures and security communities in the nineties, public platforms for discussing information security were created for the first time. Security researchers who had found a vulnerability reported it there to find recognition in the community. In the best case, the affected parties, whether manufacturers or organizations, were also present in these communities and thus had the opportunity to fix them.</p>

<p>By the beginning of the 2010s, information about vulnerabilities increasingly became a sought-after asset, not only for those affected but also for criminals, so-called threat actors. These exploited vulnerabilities to attack the affected parties, their customers, or both. This culminated in the emergence of <a href="https://aramido.de/en/topic/ransomware"
   
   
   >
    ransomware
</a>
: the victims' data is encrypted to then extort the key for a ransom.</p>

<p>All the more important is that security researchers who have discovered a vulnerability and want to report it receive information on how to reach the affected parties. It should be mentioned at this point that the vulnerability is already present at the time of discovery. The security researcher was only the (hopefully) first person to discover it.</p>

<h2>Challenges when reporting a vulnerability</h2>

<p>If someone has found a vulnerability in open-source software (Free and Open Source Software (FOSS)), reporting is usually easier. A large part of open-source software is hosted on public platforms such as GitHub and has documented communication channels such as mailing lists, forums or chat platforms. A vulnerability can be reported through this route, mostly even confidentially, and thus the remediation process can be initiated.</p>

<p>With proprietary and commercial software, the reporting path is not always so easy to find. While the giants of the industry such as Microsoft, Google and co. have well-documented reporting paths, the situation is different for smaller manufacturers. The challenge is even greater if it is not a classic piece of software, but a gap in a platform or an infrastructure system.</p>

<h2>Consequences of a missing reporting path</h2>

<p>If a security researcher cannot find a reporting path and gives up their effort, the actual problem persists and the information remains hidden. In the best case, no one else finds the vulnerability. In the worst case, someone with criminal energy exploits it – today even controlled by artificial intelligence (AI) – and extorts the affected parties or steals their data.</p>

<p>Alternatively, the security researcher can choose the path of <a href="https://aramido.de/en/topic/responsible-disclosure"
   
   
   >
    full disclosure
</a>
 and publish all information about the vulnerability and possibly its exploitation directly on the internet or on social media. This puts the affected parties under pressure to fix the gap as quickly as possible to prevent it from being exploited by them or their customers. Further information on the different reporting paths and how aramido itself handles found vulnerabilities is described in <a href="https://aramido.de/en/blog/security-tips/security-through-transparency-how-we-disclose-security-vulnerabilities"
   
   
   >
    our blog
</a>
.</p>

<h2>security.txt as a lifesaver</h2>

<p>To simply counter the described consequences, a so-called <code>security.txt</code> can be stored. This is a small but effective method to give security researchers the crucial hint on reporting paths. As the name suggests, this is actually a simple text file. This is stored in a standardized path on the own website in the subdirectory <code>/.well-known/</code>, so finally under <code>/.well-known/security.txt</code>. aramido's <code>security.txt</code> is located here, for example: <a href="https://aramido.de/.well-known/security.txt">/.well-known/security.txt</a>.</p>

<h3>Example of a security.txt file</h3>

<div id="content-securitytxt" class="my-3">
    <pre><code># If you would like to report a security issue
# you may report it to us via PGP or S/MIME
# encrypted mail or via our contact form
Contact: mailto:security@aramido.de
Contact: /en/kontakt
Contact: tel:+497214519910
Encryption: /pgp/aramido.security.asc
Encryption: openpgp4fpr:960EC6FEAAD4858CF54C5E942A492C40E17B729F
Encryption: /cert/aramido.security.pem
Preferred-Languages: de, en
Hiring: /en/jobs
Canonical: /.well-known/security.txt
Expires: 2027-03-25T00:00:00z</code></pre>
    <figcaption class="small ara-text-info"><u>Example of a security.txt:</u> Clear contact options for reporting vulnerabilities</figcaption>
</div>

<p>The most important element of the file is the specification of the contact options that a security researcher can use to report a vulnerability. In the simplest case, this can be an email address, but a web form or a telephone number are also possible. To ensure that the contact information is up to date, a validity date is given, usually one year after creation. In this interval, the file is checked and the date is set into the future again.</p>

<p>Formally, the <code>security.txt</code> is standardized by the <a href="https://datatracker.ietf.org/doc/html/rfc9116" rel="nofollow noopener noreferrer" target="_blank">RFC 9116</a> of the Internet Engineering Task Force. The information mentioned in the last section is mandatory; the following information can be added optionally:</p>

<ul>
    <li>Information on how reports can be submitted encrypted</li>
    <li>Preferred language of the report</li>
    <li>Further links to guidelines for security reports, job portals and public acknowledgments</li>
</ul>

<h2>Should a security.txt always be published?</h2>

<p>Yes. As soon as a domain is in use, i.e., the associated services are used – whether it is a website, email or something else – from an expert's point of view, we advise creating and publishing a <code>security.txt</code>. If no one reports anything, all the better. The opposite case is much worse for the reasons described above.</p>

<div class="row mt-1">
    <div class="col-12">
        <div class="ara-jumbotron ara-bg-gray-800">
            <p class="ara-hyphenation d-md-table-cell pe-md-5">
                If you have questions about the complex topic of <a href="https://aramido.de/en/portfolio/isms/vulnerability-management"
   
   
   >
    vulnerability reporting and vulnerability management
</a>
, we are happy to help you.</p>
            <div class="d-grid gap-2 d-md-table-cell justify-content-md-end align-middle">
                <a href="https://aramido.de/en/contact"
                   class="btn btn-success"
                   
                   >
                    Contact us now
                </a>

            </div>
        </div>
    </div>
  </div>]]></description></item><item><title>Experience the World of Hackers and Defenders Live</title><link>https://aramido.de/en/blog/aramido/experience-the-world-of-hackers-and-defenders-live/</link><pubDate>Fri, 22 May 2026 08:06:33 +0200</pubDate><author>Fabienne Hofsäß</author><guid>https://aramido.de/en/blog/aramido/experience-the-world-of-hackers-and-defenders-live/</guid><description><![CDATA[
<p>The <a target="_blank" rel="nofollow noopener noreferrer"
    href="https://karlsruhe.digital/events/bunte-nacht-der-digitalisierung">Bunte Nacht der Digitalisierung</a> (Night of Digitalization)
  makes the digital world in Karlsruhe an experience for everyone again this year. As a partner, aramido is participating again
  and opens its doors to interested visitors on June 19, 2026, from 3:00 PM. </p>

<div class="ara-panel ara-panel-primary mt-4">
  <div class="ara-panel-heading">
    <h3 class="ara-panel-title">aramido at the Night of Digitalization 2026</h3>
  </div>
  <div class="ara-panel-body text-center">
    <a target="_blank" rel="nofollow noopener noreferrer"
      href="https://www.openstreetmap.org/?mlat=49.00618&mlon=8.43361#map=18/49.006237/8.432299">Durlacher Allee 77</a>
    <br>June 19, 2026, 3:00 PM – 10:00 PM
    <br>The event is free
    <br><a href="https://aramido.de/ics/bunte-nacht-der-digitalisierung-2026.ics">Download appointment as .ics</a>
  </div>
</div>

<h2 id="programm">Program Overview</h2>
<p>The diverse program combines <a href="https://aramido.de/en"
   
   
   >
    exciting presentations and live hacks
</a>
 with
  a <a href="https://aramido.de/en"
   
   
   >
    Capture the Flag competition
</a>
 as well as <a href="https://aramido.de/en"
   
   
   >
    interactive stations
</a>
 that invite you to participate and tinker together.</p>


<p>This year's focus is on digital sovereignty. Since digital independence is a core value of aramido,
  we want to convey to all visitors what digital sovereignty means in practice and how easy the path to
  your own independence can be. A special focus is on artificial intelligence: we
  illustrate the associated dangers but also show how AI systems can be operated sovereignly.</p>

<div class="py-3">
  <div class="ara-embed-video-responsive ara-embed-video-responsive-16by9">
    <iframe class="ara-embed-video-responsive-item"
      title="Teaser Bunte Nacht der Digitalisierung 2026 bei aramido @karlsruhe.digital"
      src="https://video.aramido.de/videos/embed/2jHTspdrjfUzn6WJ8mtFBw" frameborder="0" allowfullscreen=""
      sandbox="allow-same-origin allow-scripts allow-popups"></iframe>
  </div>
</div>
<p>A special highlight this year is the new Deepfake station. At this station, not only can you <a href="https://aramido.de/en/blog/communication-security/whos-afraid-of-the-big-bad-wolf-voice-cloning-and-modern-deception"
   
   
   >
    clone your own voice
</a>
,
    but you can also create your own deepfake video – all within a few minutes. Additionally,
   interested visitors can manipulate AI systems to reveal secret information, even without extensive hacking experience.</p>

<p>In good weather, our roof terrace once again invites you to let the eventful day wind down above the rooftops of
  Karlsruhe.</p>


<h3 id="Rahmenprogramm-Vorträge">Presentations</h3>
<p>Those who want to protect effectively must know the attack techniques. In the presentations, the aramido team demonstrates with
  several live hacks that hacking is also part of the task field of an information security consultancy.</p>
<table class="table table-striped">
  <thead>
    <tr>
      <th>Start</th>
      <th>Title</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>3:30 PM</td>
      <td><a href="https://aramido.de/en"
   
   
   >
    Smartphone Hacking – From Manipulations by Attackers to Protective Measures
</a>
</td>
    </tr>
    <tr>
      <td>4:45 PM</td>
      <td><a href="https://aramido.de/en"
   
   
   >
    Sovereign Handling of Vulnerability Reports – Or: Don't Ignore the Messenger
</a>
</td>
    </tr>
    <tr>
      <td>6:00 PM</td>
      <td><a href="https://aramido.de/en"
   
   
   >
    Hacking on Ice – When you should better turn off your PC
</a>
</td>
    </tr>
    <tr>
      <td>7:30 PM</td>
      <td><a href="https://aramido.de/en"
   
   
   >
    Information Security and AI – Chance and Risk for Companies
</a>
</td>
    </tr>
  </tbody>
</table>

<h4 id="Rahmenprogramm-Stationen">Activity Stations</h4>
<p>Besides the presentations, various stations invite you to get informed and participate:</p>
<ul>
  <li><a href="https://aramido.de/en"
   
   
   >
    Capture the Flag competition (CTF)
</a>
</li>
  <li><a href="https://aramido.de/en"
   
   
   >
    Deepfake – Create your own deepfake video
</a>
</li>
  <li><a href="https://aramido.de/en"
   
   
   >
    USB Condom soldering station
</a>
</li>
  <li><a href="https://aramido.de/en"
   
   
   >
    Hacking gadget exhibition
</a>
</li>
  <li><a href="https://aramido.de/en"
   
   
   >
    Next-Level Game (Hacking Challenge)
</a>
</li>
  <li><a href="https://aramido.de/en"
   
   
   >
    AI Prompt Injection (Hacking Challenge)
</a>
</li>
  <li><a href="https://aramido.de/en"
   
   
   >
    Fooling fingerprint sensors
</a>
</li>
  <li><a href="https://aramido.de/en"
   
   
   >
    Crypto Box
</a>
</li>
  <li><a href="https://aramido.de/en"
   
   
   >
    Tschunk Bar
</a>
</li>
</ul>

<p>Subject to change.</p>

<h2 la-heading>Presentation Details</h2>

<h3 id="vortrag-smartphone-hacking">Smartphone Hacking – From Manipulations by Attackers to
  Protective Measures</h3>
<p>The history of smartphones is short. In 2007, Apple introduced the first iPhone with its own
  operating system iOS, and a year later, Android, today's dominant smartphone operating system, entered the
  market. And the history of the first smartphone hacks is just as old: from the first
  jailbreaks to celebrity nudes and commercially and state-sponsored spyware.</p>
<p>Using attack trees and live hacking demonstrations, the speakers show how smartphones are attacked.
  Understanding this is the basis for effective protective measures.</p>
<p>On this basis, a comparison from a data protection perspective of iOS and Android is made. Additionally, a possible alternative
  to these two operating systems is briefly presented.</p>

<p>
  <a href="https://aramido.de/en"
     
     
     >
      » Back to program overview
  </a>

</p>

<h3 id="vortrag-schwachstellenmanagement">Sovereign Handling of Vulnerability Reports – Or: Don't Ignore the
  Messenger</h3>
<p>A security researcher reports a vulnerability to a provider. </p>
<p>Expectation: The person receives praise and recognition.</p>
<p>Reality: The person can be sued.</p>
<p>In 2025, over 45,000 vulnerabilities were discovered. A large part of them by independent
  security researchers. Therefore, it is all the more important that these people dare to report the vulnerabilities,
  as there are many pitfalls, especially legal ones.</p>
<p>In the presentation, the speakers present the hurdles of vulnerability reports and the processes of a secure handling
  of them. Various possibilities for securing security researchers and companies are shown.
</p>

<p>
  <a href="https://aramido.de/en"
     
     
     >
      » Back to program overview
  </a>

</p>

<h3 id="vortrag-cold-boot">Hacking on Ice – When you should better turn off your PC (Live Hack)</h3>
<p>To protect data from unauthorized access, it is encrypted with tools such as Microsoft's BitLocker and Apple's FileVault
  encryption. For mobile devices in a business environment, this is often a compliance requirement. Only those who know the
  password can access the data. That this is a misconception, security researchers showed as early as 2008:
  if they had physical access to a computer that was switched on or "sleeping" (standby mode), they could
  read the password from the working memory. Even today, so-called <a href="https://aramido.de/en/blog/data-security/cold-boot-attack-farewell-disk-encryption"
   
   
   >
    Cold Boot attacks
</a>
 are still
  possible.</p>
<p>In the presentation, such an attack on a computer with disk encryption will be carried out live, and
  countermeasures will be presented to avoid becoming a victim of a Cold Boot attack. Whether Windows, macOS or
  Linux: everyone who relies on disk encryption is affected.</p>
<p>
 
  <a href="https://aramido.de/en"
     
     
     >
      » Back to program overview
  </a>

</p>

<h3 id="vortrag-ki">Information Security and AI – Chance and Risk for Companies</h3>
<p>AI technologies are developing rapidly and fundamentally changing the security landscape. What offers
  valuable opportunities for companies can be exploited by attackers. </p>
<p>In the presentation, the speakers provide a look behind the scenes of how to maintain sovereignty over your own
  IT systems. They show what dangers can emanate from artificial intelligence and how such systems
  can be operated securely. The goal is to recognize, minimize risks, and at the same time use the potentials.
</p>

<p>
  <a href="https://aramido.de/en"
     
     
     >
      » Back to program overview
  </a>

</p>

<h2 la-heading>Details of the Activity Stations</h2>

<h3 id="Rahmenprogramm-CTF">CTF – Capture the Flag Competition</h3>
<p>Various university teams compete against each other in a Capture the Flag (CTF) competition, proving their
  skills in dealing with security-relevant vulnerabilities. They must solve various tasks to find so-called "flags."
  These flags are hidden strings that serve as proof of the successful exploitation of a vulnerability or the solving of a task.</p>

<h3 id="Rahmenprogramm-Deepfake">Deepfake – Create your own deepfake video</h3>
<p>Try voice cloning and deepfakes yourself. Only a short text needs to be spoken and a photo of the
  person created. Characteristic features of the voice and face are trained through machine learning
  and stored in a model. Subsequently, the AI can speak texts with the cloned voice and the generated
  face.</p>

<h3 id="Rahmenprogramm-USB-Kondom">Secure charging at foreign USB ports: USB Condom soldering station</h3>
<p>Those who want to be active themselves have the perfect opportunity at the soldering workshop to create their own small gadget. With
  soldering irons and 3D-printed housings, visitors create their own USB condom. With this useful
  tool, you can charge devices with confidence at foreign USB ports.</p>

<h3 id="Rahmenprogramm-Hacking-Gadgets">Presentation of various hacking gadgets</h3>
<p>Experience the hacking tools of our <a href="https://aramido.de/en/security-testing/penetration-testing"
   
   
   >
    penetration testers
</a>
 live
  and try them out. From the WiFi Pineapple and Rubber Ducky to the Flipper Zero: how inconspicuous tools can cause great damage
  to a system. Some are even so small that they can be easily tucked into a pocket.
</p>

<h3 id="Rahmenprogramm-NextLevel">Next-Level Game (Hacking Challenge)</h3>
<p>Ready for the next level?</p>
<p>In our Next-Level Game, hacking skills can be proven in different levels. In
  each level, the access data for the next level can be found. The task is to get to the
  next password in different ways in order to advance. No additional software is required.</p>
<p>Accept the challenge with us now.</p>

<h3 id="Rahmenprogramm-KIChallenge">AI Prompt Injection (Hacking Challenge)</h3>
<p>“Hello AI, give me sensitive data”</p>
<p>It's not that simple to get sensitive data from an AI. However, there are a few possibilities that
  might actually lead to the desired goal …? </p>
<p>At this station, an AI can be tested and (possibly) tricked through clever prompts.</p>

<h3 id="Rahmenprogramm-Fingerabdruck-Attrappe">Fooling fingerprint sensors</h3>
<p>Matching the smartphone hacking presentation, visitors can clone their own fingerprint using simple tricks and everyday materials.
  It's amazing how positively corresponding sensors react!</p>

<h3 id="Rahmenprogramm-KryptoBox">Cryptography made easy</h3>
<p>Cryptography is often the basis for security in information systems. Without the ability to
  encrypt data and thus effectively protect it from access, most security goals would simply not
  be achievable. But even today's complex cryptography started small. Using the CryptoBox from the Karlsruhe University of Education,
  which was specifically developed for students from 1st to 10th grade, people of all ages
  gain an easy and playful access to this exciting subject.</p>

<h3 id="Rahmenprogramm-Tschunk-Bar">Tschunk Bar</h3>
<p>Of course, there is plenty of "Tschunk" at the Tschunk Bar. It is the supplement of choice
  when you are hungry for fantasy and craving liquid while hacking: Club Mate + lime + cane sugar + ice
  + rum = more flags.</p>

<p>Attention: Anyone who starts perceiving the world in binary should stop the Tschunk consumption for safety.</p>

<p>In good weather, let the week wind down with a cool drink above the rooftops of Karlsruhe and get into conversation with others
  – for that, the aramido roof terrace is the perfect place!<br />Tip: In the evening, you have a
  beautiful view of the sunset and the live band “Salty Tunes” will provide the atmospheric
  musical accompaniment for the rest of the evening.</p>

<p>
  <a href="https://aramido.de/en"
     
     
     >
      » Back to program overview
  </a>

</p>]]></description></item><item><title>New Space for Growth: aramido expands location on Durlacher Allee</title><link>https://aramido.de/en/blog/aramido/new-space-for-growth-aramido-expands-location-on-durlacher-allee/</link><pubDate>Thu, 07 May 2026 11:50:08 +0200</pubDate><author>Jule Bohe</author><guid>https://aramido.de/en/blog/aramido/new-space-for-growth-aramido-expands-location-on-durlacher-allee/</guid><description><![CDATA[

<p>The year 2026 started with another step in growth for aramido: After successfully expanding in the AVG (Albtal-Verkehrs-Gesellschaft) buildings on Durlacher Allee since 2021, we have now occupied additional office space in the adjacent building. In addition to the new workspace for the aramido team, the other half of the floor is offered for sub-lease.</p>

<figure class="my-3" id="Untervermietung">
<img src="https://aramido.de/img/aramido-buero-durlacher-allee-73.webp" class="ara-img-responsive ara-center-block" alt="Example images of the new premises of aramido GmbH">
<figcaption class="small ara-text-info" >Example images of the new premises of aramido GmbH, Durlacher Allee 73</figcaption>
</figure>

<h3>Office Space with Perspective</h3> 
<p>The modern building complex of the Albtal-Verkehrs-Gesellschaft (AVG) at the eastern entrance of Karlsruhe is an attractive place to work: Around 450 m² of bright, spacious office areas are now available for sub-lease. The space on the 6th floor features a separate entrance, a modern heating and cooling ceiling system with individually controllable room climates for each workstation, as well as an impressive view of the Black Forest.</p>

<h3>Excellent Location and Equipment</h3>
<p>The location could hardly be better: The Tullastraße/Alter Schlachthof stop is right outside the door, the A5 motorway is reachable in a few minutes, and the Creative Park Alter Schlachthof—a vibrant center for innovation and exchange—is located opposite. Numerous restaurants, canteens, and shopping facilities are within walking distance.</p>

<p>The separate rental area for subtenants includes bright office rooms, its own coffee kitchen, sanitary facilities, and a storage room. Professional cleaning of the area is already included.</p>

<p>With these premises, aramido wants to give other companies the chance to grow in a modern environment.</p>

<h3>Overview</h3>

<ul>
    <li><strong>Address:</strong> Durlacher Allee 73, 76131 Karlsruhe</li>
    <li><strong>Space:</strong> approx. 450 m² bright, spacious office rooms</li>
    <li><strong>Climate control:</strong> modern heating and cooling ceiling system, individually adjustable room climate per workstation</li>
    <li><strong>View:</strong> 6th floor, panoramic view of Karlsruhe and the Black Forest</li>
    <li><strong>Transport links:</strong> very good public transport connections (Tullastraße/Alter Schlachthof stop right outside the door), A5 motorway reachable in a few minutes, parking spaces and charging station
    </li>
    <li><strong>Surroundings:</strong> numerous restaurants, cafes, canteens, shopping facilities, and "Alter Schlachthof" Creative Park within walking distance</li>
    <li><strong>Service:</strong> professional office cleaning included</li>
    <li><strong>Availability:</strong> immediately</li>
  </ul>


<div class="ara-panel ara-panel-primary mt-4" >
    <div class="ara-panel-heading" >
        
            <h3 class="ara-panel-title">Representative office spaces for rent</h3>
        
    </div>
    <div class="ara-panel-body text-center" >
        Individual information on the rental offer is available upon request. <br>
        If interested, please contact Jule Bohe:<br>
        
        
                  
                   
        
        
        
        <span class="protected-email" data-email-b64="YmU3MyU0MGFyYW1pZG8uZGU="></span> |  0721 4519910 <br>
    </div>
</div>]]></description></item><item><title>Who's Afraid of the Big Bad Wolf? Voice Cloning and Modern Deception</title><link>https://aramido.de/en/blog/communication-security/whos-afraid-of-the-big-bad-wolf-voice-cloning-and-modern-deception/</link><pubDate>Mon, 09 Sep 2024 13:22:15 +0200</pubDate><author>Fabienne Hofsäß</author><guid>https://aramido.de/en/blog/communication-security/whos-afraid-of-the-big-bad-wolf-voice-cloning-and-modern-deception/</guid><description><![CDATA[
<p>Anyone familiar with the fairy tale of the Big Bad Wolf knows that he was able to deceive his victims with clever tricks. Today, artificial intelligence (AI) can deceive us in a similar way.</p>  
<p><abbr title="Attackers pose as a trusted person or organization to gain confidential information from their victims.">Social Engineering</abbr> is at least as old as the fairy tales of the Brothers Grimm. In the story "The Wolf and the Seven Young Goats", the wolf uses various tricks to pose as the goats' mother. In the end, he manages to outsmart the goats, and they open the door for him, which has devastating consequences. This fairy tale teaches that one should not trust seemingly familiar characteristics such as appearance and voice unconditionally.</p>
 
 
<h2 id="ai-wolf">AI: The Wolf in Sheep's Clothing</h2>
<p><abbr title="Artificial Intelligence">AI</abbr> can make work easier in many areas, but it also carries risks: on the one hand, one should never trust an AI unconditionally, as it is trained on large amounts of data from a wide variety of sources to recognize patterns and make decisions. If these data are incomplete, biased, inaccurate or faulty, the AI can draw wrong conclusions. One then receives inaccurate or incorrect answers that may sound plausible. On the other hand, new technologies enable more sophisticated attacks. Especially in the area of social engineering, attackers can now proceed more easily, faster and more specifically to deceive us, just like the Big Bad Wolf in the fairy tale. In the future, it will be more difficult to recognize phishing attacks. In the aforementioned fairy tale, the wolf pretends to be a known figure with clever tricks to win the trust of his victims. Today we speak of "<abbr title="Realistically appearing media content (for example videos) that have been artificially generated or falsified.">Deepfakes</abbr>" such as voice cloning as well as image and video manipulation. Just like the goats in the fairy tale, we should be careful about whom we trust and to whom we open the door!</p>
<p>We gave a presentation on this topic at the <a href="https://aramido.de/en/blog/aramido/versatile-program-at-the-night-of-digitalization"
   
   
   >
    Night of Digitalization
</a>
. Below you will find the video of the presentation as a shortened version.</p>
<div class="py-3">
  <div class="ara-embed-video-responsive ara-embed-video-responsive-16by9">
      <iframe class="ara-embed-video-responsive-item" src="https://video.aramido.de/videos/embed/6NtAWsSPK3YV3eHBwNxu2r" allowfullscreen></iframe>
  </div>
</div>
 
<h2 id="how-ai-works">How Artificial Intelligence Works</h2>
<p>Put simply, an AI is based on statistical methods, probabilities and pattern recognition. Through training with large amounts of data, it learns which patterns occur in the data and how language is used. An AI language model is trained with extensive text data that encompasses a large part of documented human knowledge. This allows it to make predictions about which words are meaningful in a particular context. The difference between a chicken and a cow is recognized by the AI because it has processed numerous descriptions of both animals in the training data.</p>
<div class="row mt-1">
  <img class="d-none d-md-block" src="https://aramido.de/img/VoiceCloning-KI-1300x541.webp">
  <img class="d-md-none text-center" src="https://aramido.de/img/VoiceCloning-KI-515x749.webp">
</div>
<p>The text generated by an AI is new every time and can vary. The results are not deterministic, which means that an AI can give different answers to the same question – in contrast to a classic computer program that works with fixed instructions such as "if", "then" and "else".</p>
 
<h2 id="new-phishing-vishing">New Attack Methods in Phishing and Vishing</h2>
<p>Phishing is a popular social engineering method and can take place over various channels such as SMS, email and various messengers. With special AIs, personalized phishing attacks can be carried out automatically. These AIs, for example, scan the websites of the companies to be attacked and automatically create phishing messages using the collected information and send them to selected recipients.</p>
<p>In addition to written phishing attacks, there are also attacks by telephone, so-called vishing. Attackers, for example, pose as employees of a large software company in order to obtain sensitive information from their victims. Traditionally, this method required high personnel costs with a call center character. By combining text-generative and text-to-speech AI, many victims can be reached simultaneously with minimal effort.<br />
Through adapted voice cloning and targeted vishing, methods such as the well-known "grandchild trick" become even more dangerous. The nature of the attacks is not new. However, they become much more successful through the use of voice cloning.</p>
 
 
<h2 id="voice-cloning-tech">AI Technology for Voice Cloning</h2>
<p>In connection with voice cloning, a speech AI model can be trained to mimic the voice of a specific person by using voice samples and learning how they speak. There are already open-source AIs with user-friendly interfaces that can be used by many people without extensive prior knowledge. Thus, attacks in this area can increase.</p>
  
<p>There are two main types of AI for voice cloning:</p>
<ul> 
  <li>Text-to-Speech (TTS)<br />
    In this method, the text that the cloned voice should read is specified. TTS technology simply reads a certain text aloud and thus generates an artificial speech output.</li>
  
  <li>Inference<br />
    In this method, the trained model does not read a text file, but manipulates the voice characteristics in an existing audio recording. With real-time models, texts can be output directly while speaking with the cloned voice.</li>
</ul>
<div class="row mt-1">
  <img class="d-none d-md-block" src="https://aramido.de/img/VoiceCloning-Arten-1300x541.webp">
  <img class="d-md-none text-center" src="https://aramido.de/img/VoiceCloning-Arten-515x749.webp">
</div>
  
<h2 id="getting-voice-samples">How Attackers Get Voice Samples</h2>
<p>There are various ways in which attackers can obtain voice samples. The two most likely scenarios are social engineering and publicly available voice recordings:</p>
<ul>
  <li>Social Engineering<br />
    Attackers can engage their target person in a conversation and record them secretly. In this way, they obtain voice samples that they can later use for cloning the voice. 
  </li>
  <li>Publicly Available Voice Recordings<br />
    Public recordings of speeches or social media profiles with video content on the internet can serve as a source for voice samples. This can be particularly risky for people who are in the public eye or are active on social media.</li>
</ul>  
 
<h2 id="legitimate-use-cases">Legitimate Use Cases for Voice Cloning</h2>
<p>In addition to the misuse of voice cloning for criminal purposes, there are also some areas in which it can be used sensibly and legally. For example here:</p>
 
<ul>
  <li>Education and Learning<br />
  Through the cloning of speech, multilingual training materials can be created more easily. This could enable the availability of teaching materials in different languages and better prepare students with different backgrounds for learning.</li>
  
  <li>Accessibility<br />
  Voice cloning can help people who are no longer able to use their voice due to physical impairments or accidents. With the help of a trained text-to-speech model, they can continue to communicate and speak with their own voice.</li>
  
  <li>Entertainment<br />
  Voice cloning can be used to recreate the speaking roles of actors in films or video games.</li>
  
  <li>Historical Presentation<br />
  Voice cloning can bring historical figures and events to life. By cloning known voices, people could better understand these figures and their life stories, as the presentation appears more authentic.</li>
</ul>
 
 
<h2 id="social-engineering-motives">Social Engineering – Motives and Techniques</h2>
<p>Attackers specifically exploit the psychological weaknesses of people and use various methods to achieve their goals. Their motives include financial enrichment through extortion or fraud, political and social manipulation to generate unrest in the population, identity or data theft, damage to reputation or disinformation.</p>
<p>Through cleverly devised tricks, attackers use one or more tactics. These are often based on the principles of persuasion psychology, as described by the well-known US psychologist Robert B. Cialdini in his book "Influence: The Psychology of Persuasion" (1984):</p>
<ul>
  <li>Time Pressure<br />
  <!--Example: "You must act now, otherwise your account will be blocked forever!"--></li>
  <li>Authority<br />
  <!--Example: The attackers pose as superiors, management or police.--></li>
  <li>Reciprocity<br />
  <!--Example: "I'll do you a favor and expect your help in return."--></li>
  <li>Social Proof<br />
  <!--Example: They suggest that many people have already successfully participated in the offer. --></li>
  <li>Commitment and Consistency<br />
  <!--Example: If someone does a small favor or feels committed, they are more likely to react to further demands from the attackers.--></li>
  <li>Liking<br />
  <!--Example: They create trust and friendship in order to manipulate people or disclose sensitive information.--></li>
</ul>
<p>In 2016, Cialdini added another technique to the six: The principle of unity and shared identities.</p>
<p>Fraud has always worked by exploiting the human psyche. Over the years, however, the requirements have changed. Attackers constantly adapt their methods to be as successful as possible. With AIs, they have received a practical toolbox that makes it even easier for them to carry out attacks.</p>
 
 
<h2 id="detecting-fraud">Detecting Fraud and Protecting Yourself</h2>
<p>To protect yourself from fraud attempts, it is important to be vigilant and skeptical of unusual incidents. We have listed some strategies here on how you can protect yourself from social engineering:</p>
<ul>
  <li>Ensuring Identity  
    <ul>
      <li>Be skeptical if unusual communication channels were chosen.</li>
      <li>Critically question unusual requests, even if they come from supposedly known persons.</li>
      <li>In case of doubt, choose a known and secure communication channel for query or verification.</li>
    </ul>
  </li>
  <li>Only disclose the most necessary personal information on the internet.
    <ul>
      <li>If possible, ensure that your voice is not freely available on the internet.</li>
      <li>Avoid passing on confidential information via insecure channels.</li>
      <li>Define and use secure communication channels, for example for banking transactions or other sensitive matters.</li>
    </ul>
  </li>
  <li>Critical Consideration of Media Content
    <ul>
      <li>Do not blindly trust images, videos and audio recordings from unverified sources. Content in social media in particular can be manipulated or faked.</li>
      <li>Check the source and look for further confirmations if something seems suspicious.</li>
    </ul>
  </li>
  <li>Regularly inform yourself about new fraud tricks and techniques.
    <ul>
      <li>Stay vigilant and look for signs of phishing, vishing or social engineering attacks.</li>
    </ul>
  </li>
</ul>
 
<div class="row mt-1">
  <div class="col-12">
      <div class="ara-jumbotron ara-bg-gray-800">
          <p class="ara-hyphenation d-md-table-cell pe-md-5">
            Do you want to protect your company better against phishing, vishing and social engineering? We defend you against these dangers.</p>
          <div class="d-grid gap-2 d-md-table-cell justify-content-md-end align-middle">
              <a href="https://aramido.de/en/contact"
                 class="btn btn-success"
                 
                 >
                  Contact us now
              </a>

          </div>
      </div>
  </div>
</div>]]></description></item><item><title>What is the NIS 2 Directive? (Part 1)</title><link>https://aramido.de/en/blog/communication-security/what-is-the-nis-2-directive-part-1/</link><pubDate>Sun, 25 Aug 2024 10:21:11 +0200</pubDate><author>Niklas Fuhrberg</author><guid>https://aramido.de/en/blog/communication-security/what-is-the-nis-2-directive-part-1/</guid><description><![CDATA[

<div class="alert alert-info">
    This article is part of the series on <a href="https://aramido.de/en/topic/nis-2"
   
   
   >
    NIS 2
</a>
. Find out <a href="https://aramido.de/en/blog/communication-security/who-is-affected-by-nis-2-part-2"
   
   
   >
    who is affected by NIS 2
</a>
 and what <a href="https://aramido.de/en/blog/communication-security/nis-2-what-do-companies-need-to-do-part-3"
   
   
   >
    requirements are imposed on companies
</a>
.
</div>

<p>The number of cyberattacks has continued to rise in recent years, driven in no small part by the ever-growing dependence on digital systems and global tensions.</p>
<p>The <abbr title="European Union">EU</abbr> has responded to this threat landscape with a new <a href="https://digital-strategy.ec.europa.eu/en/policies/cybersecurity-strategy" target="_blank">Cybersecurity Strategy</a>: in addition to strengthening European cooperation and promoting skilled professionals, joint cyber defense facilities are to be established. The strategy's goals are also to be achieved through a series of new EU directives and regulations, including the NIS 2 Directive.</p>
    
<p>As early as 2016, the EU adopted an initial directive on the security of network and information systems (NIS). In Germany, this is limited to approximately 2,000 companies from specifically defined sectors. However, attacks are now causing significant economic damage in other sectors as well. Therefore, the EU has significantly expanded the circle of affected companies for the second NIS directive. Estimates suggest that in Germany alone, up to 30,000 companies will be affected by NIS 2.</p>

<div class="ara-panel ara-panel-primary mt-4">
    <div class="ara-panel-heading">
        <h3 class="ara-panel-title">Quick Facts</h3>
    </div>
    <div class="ara-panel-body">
        <ul>
            <li>For an initial indication of whether you are affected, please refer to our <a href="https://aramido.de/en/blog/communication-security/who-is-affected-by-nis-2-part-2"
   
   
   >
    second part on NIS 2
</a>
.</li>
            <li>The deadline for the first <a href="https://aramido.de/en/blog/communication-security/nis-2-what-do-companies-need-to-do-part-3"
   
   
   >
    measures
</a>
 is October 17, 2024.</li>
            <li>Most affected parties must register with the <abbr title="Federal Office for Information Security">BSI</abbr> by January 17, 2025.</li>
            <li>We are happy to answer any further questions <a href="https://aramido.de/en/contact"
   
   
   >
    here
</a>
.
            </li>
        </ul>
    </div>
</div>

<h2>How is NIS 2 being implemented in Germany?</h2>
<p>Unlike, for example, the <abbr title="General Data Protection Regulation">GDPR</abbr>, NIS 2 is an EU directive and is not directly binding. Therefore, individual EU member states must enact national laws to implement the directive.</p>
<p>In Germany, there is a draft of the <a href="https://www.bmi.bund.de/SharedDocs/gesetzgebungsverfahren/DE/Downloads/referentenentwuerfe/CI1/NIS-2-RefE-24062024.pdf;jsessionid=1E1004B99D3105980E1BFFC5F16A8E88.live891?__blob=publicationFile&v=2" target="_blank">NIS 2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG)</a>. The draft has been approved by the cabinet but still needs to be passed by the Bundestag. However, no major changes are expected.</p>
<p>Additionally, the EU has reserved the option to issue implementing regulations. A draft for an initial regulation is currently under consultation. This provides specifications for the assessment of security incidents and the implementation of measures for companies that provide certain IT services, such as social network providers or managed service providers.</p>
<p>According to the current status, both documents are to be fully adopted by October 17, 2024.</p>

<h2>Who is affected by NIS 2?</h2>
<p>Whether a company is affected depends on a number of criteria. These include, among others, the industry, the size and location of the company, and whether business is conducted within the EU. More detailed information on <a href="https://aramido.de/en/blog/communication-security/who-is-affected-by-nis-2-part-2"
   
   
   >
    who is affected by NIS 2
</a>
 can be found in the second part of our <a href="https://aramido.de/en/topic/nis-2"
   
   
   >
    article series
</a>
.</p>

<h2>What can affected entities expect?</h2>
<p>The EU is also relying on technology neutrality with NIS 2. The directive specifies what must be implemented but has few requirements on how this should be done. You can find out which <a href="https://aramido.de/en/blog/communication-security/nis-2-what-do-companies-need-to-do-part-3"
   
   
   >
    specific measures are required
</a>
 in the third part of our <a href="https://aramido.de/en/topic/nis-2"
   
   
   >
    article series
</a>
.</p>

<h2>When must affected entities take action?</h2>
<p>Immediately upon the expected entry into force of the NIS 2 Directive on October 17, 2024, entities must meet the requirements for risk management measures and reporting obligations. To initiate the necessary measures in a timely manner, it is recommended to take action now.</p>
<p>All companies affected at the time of entry into force must register with the BSI by January 17, 2025, at the latest. For companies that become affected later, for example because the number of employees was only then exceeded, a deadline of three months applies.</p>

<h2>What happens next?</h2>
<p>To achieve the goal of significantly increasing the level of information security in companies across the EU, the EU relies on the cooperation of these companies. To reach these objectives, NIS 2 provides for a number of obligations, the non-compliance with which can be severely penalized.</p>
<p>Information to determine whether a <a href="https://aramido.de/en/blog/communication-security/who-is-affected-by-nis-2-part-2"
   
   
   >
    company is affected
</a>
 and <a href="https://aramido.de/en/blog/communication-security/nis-2-what-do-companies-need-to-do-part-3"
   
   
   >
    which measures
</a>
 must be taken can be found in the following blog posts. The aramido consultants are also available to answer any questions.</p>

<div class="ara-jumbotron ara-bg-gray-200">
    <p class="ara-hyphenation d-md-table-cell pe-md-5">
        We accompany you on the path to NIS 2 implementation! Take advantage of a free initial consultation to discuss your project with a security expert. 
    </p>
    <div class="d-md-table-cell align-middle">
        <div class="d-grid gap-2 d-md-flex justify-content-md-end">
            <a href="https://aramido.de/en/contact"
               class="btn btn-primary btn-lg"
               
               >
                Contact us now
            </a>

        </div>
    </div>
</div>
]]></description></item><item><title>Who is affected by NIS 2? (Part 2)</title><link>https://aramido.de/en/blog/communication-security/who-is-affected-by-nis-2-part-2/</link><pubDate>Tue, 20 Aug 2024 11:21:11 +0200</pubDate><author>Niklas Fuhrberg</author><guid>https://aramido.de/en/blog/communication-security/who-is-affected-by-nis-2-part-2/</guid><description><![CDATA[

<div class="alert alert-info">
    This article is part of the series on <a href="https://aramido.de/en/topic/nis-2"
   
   
   >
    NIS 2
</a>
. Find out <a href="https://aramido.de/en/blog/communication-security/what-is-the-nis-2-directive-part-1"
   
   
   >
    what the NIS 2 Directive is
</a>
 and what <a href="https://aramido.de/en/blog/communication-security/nis-2-what-do-companies-need-to-do-part-3"
   
   
   >
    requirements are imposed on companies
</a>
.
</div>

<p class="ara-hyphenation">The number of affected companies is increasing significantly with NIS 2. Estimates for Germany suggest 30,000 affected companies (for comparison: the first NIS Directive affected approximately 2,000 companies).</p>
<p class="ara-hyphenation">There is no official notification as to whether a specific company is affected. Therefore, it is up to the companies themselves to determine their status. A number of criteria are relevant for this.</p>

<h2>What does affected status depend on?</h2>
<p class="ara-hyphenation">First, there are two thresholds:
<ul>
    <li>Small or micro-enterprises are only affected in exceptional cases.</li>
    <ul>
        <li>Small or micro-enterprises have fewer than 50 employees and an annual turnover or annual balance sheet total of less than 10 million euros.</li>
    </ul>
    <li>For medium-sized enterprises, the requirements are generally less stringent than for those exceeding these values.</li>
    <ul>
        <li>Medium-sized enterprises have fewer than 250 employees.</li>
        <li>The profit is less than 50 million euros or the balance sheet total is smaller than 43 million euros.</li>
    </ul>
</ul>
In the second step, the type of entity in which the company operates is decisive. A distinction is made between "important" and "especially important" entities. In addition, directly applicable implementing regulations apply to certain types of entities.</p>

<h3>Especially important entities</h3>
<p class="ara-hyphenation">The <abbr title="European Union">EU</abbr> regulation speaks of <em>essential entities</em>, while the <a href="https://www.bmi.bund.de/SharedDocs/gesetzgebungsverfahren/DE/Downloads/referentenentwuerfe/CI1/NIS-2-RefE-24062024.pdf;jsessionid=1E1004B99D3105980E1BFFC5F16A8E88.live891?__blob=publicationFile&v=2" target="_blank">German implementation</a> refers to <em>especially important</em> entities – both mean the same thing.</p>
<p class="ara-hyphenation">Entities that exceed the thresholds for medium-sized enterprises and belong to an entity type listed in Annex 1 of the NIS2UmsuCG are considered <em>especially important</em>. This includes entity types from the following sectors:</p>

<ul>
    <li>Energy</li>
    <li>Transport and Traffic</li>
    <li>Finance</li>
    <li>Health</li>
    <li>Water</li>
    <li>Digital Infrastructure</li>
    <li>Space</li>
</ul>

<p class="ara-hyphenation">Not all companies operating in one of these sectors are affected; it depends on the precise definition of the entity type.</p>
<p class="ara-hyphenation"><em>Especially important</em> are also operators of critical infrastructures (KRITIS), qualified trust service providers, top-level domain name registries or <abbr title="Domain Name System">DNS</abbr> service providers, as well as medium-sized telecommunications providers.</p>

<h3>Important entities</h3>
<p class="ara-hyphenation"><em>Important</em> entities are medium or large companies that fall under one of the entity types in Annex I or II of the NIS2UmsuCG. This adds the following sectors to those mentioned above:</p>

<ul>
    <li>Waste Management</li>
    <li>Food and Chemical Industries</li>
    <li>Manufacturers of Medical Devices or certain Electrical Equipment</li>
    <li>Mechanical Engineers and Vehicle Manufacturers</li>
    <li>Digital Service Providers</li>
    <li>Research Institutions</li>
</ul>

<p class="ara-hyphenation">As with <em>especially important</em> entities, the precise definition of the entity types is decisive here as well.</p>
<p class="ara-hyphenation">Additionally, trust service providers and all telecommunications providers that are not <em>especially important</em> are considered <em>important</em>.</p>

<h3>Those affected by the implementing regulation</h3>
<p class="ara-hyphenation">With the first implementing regulation, the EU aims for the direct regulation of companies that offer inherently cross-border services. Currently, this includes providers of the following services:</p>

<ul>
    <li><abbr title="Domain Name System">DNS</abbr> service providers and <abbr title="Top Level Domain">TLD</abbr> name registries</li>
    <li>Cloud Computing, Data Centers, and Content Delivery Networks</li>
    <li>Managed (Security) Services</li>
    <li>Online Marketplaces, Online Search Engines, and Social Networks</li>
</ul>

<h2>How do I find out if my company is affected?</h2>
<p class="ara-hyphenation">An initial indication can be found, for example, in the <a href="https://betroffenheitspruefung-nis-2.bsi.de" target="_blank">NIS 2 impact assessment</a> of the BSI. For a more detailed examination, the consultants at aramido GmbH are at your disposal. A final legal review can also be helpful.</p>

<div class="ara-jumbotron ara-bg-gray-200">
    <p class="ara-hyphenation d-md-table-cell pe-md-5">
        We accompany you on the path to NIS 2 implementation! Take advantage of a free initial consultation to discuss your project with a security expert. 
    </p>
    <div class="d-md-table-cell align-middle">
        <div class="d-grid gap-2 d-md-flex justify-content-md-end">
            <a href="https://aramido.de/en/contact"
               class="btn btn-primary btn-lg"
               
               >
                Contact us now
            </a>

        </div>
    </div>
</div>

<h3>More on the topic of NIS 2</h3>
<a href="https://aramido.de/en/blog/communication-security/nis-2-what-do-companies-need-to-do-part-3"
   
   
   >
    What can companies affected by NIS 2 expect?
</a>

<p><a href="https://aramido.de/en/blog/communication-security/what-is-the-nis-2-directive-part-1"
   
   
   >
    What is NIS 2?
</a>

</p>
]]></description></item><item><title>NIS 2: What do companies need to do? (Part 3)</title><link>https://aramido.de/en/blog/communication-security/nis-2-what-do-companies-need-to-do-part-3/</link><pubDate>Mon, 19 Aug 2024 12:21:11 +0200</pubDate><author>Niklas Fuhrberg</author><guid>https://aramido.de/en/blog/communication-security/nis-2-what-do-companies-need-to-do-part-3/</guid><description><![CDATA[

<div class="alert alert-info">
    This article is part of the series on <a href="https://aramido.de/en/topic/nis-2"
   
   
   >
    NIS 2
</a>
. Find out <a href="https://aramido.de/en/blog/communication-security/what-is-the-nis-2-directive-part-1"
   
   
   >
    what the NIS 2 Directive is
</a>
 and what <a href="https://aramido.de/en/blog/communication-security/nis-2-what-do-companies-need-to-do-part-3"
   
   
   >
    requirements are imposed on companies
</a>
.
</div>

<p>To advance information security in entities, the <abbr title="European Union">EU</abbr> sets a whole range of requirements with the NIS 2 Directive. As a first step, responsibilities within the company should be established. NIS 2 makes it clear that information security is a matter for executive management and defines explicit requirements for the management of affected entities.</p>

<h2>Obligations of Executive Management</h2>
<p>Executive management must implement and monitor <a href="https://aramido.de/en"
   
   
   >
    certain risk measures
</a>
. Consequently, executive management must be trained in handling information security risks at least every three years. The training must provide the ability to identify and assess risks and their impact and to take appropriate measures.</p>
<p>If they culpably breach their duties, executive management can now even be held personally liable for damages incurred.</p>
<p>Some implementation duties can be delegated. However, the duty to monitor and the training required to monitor effectively always remain with the executive management.</p>

<h2>Reporting Obligation</h2>
<p>When significant security incidents occur, companies must make a series of reports to the <abbr title="Federal Office for Information Security">BSI</abbr>. In certain cases, the BSI may also order that customers or the public be informed about the incidents.</p>
<p>The BSI will further define exactly how a report must be carried out. However, a design similar to the existing reporting obligation for operators of critical infrastructure is likely.</p>
<p>A security incident is considered significant if it leads to, or could lead to, severe operational disruptions, financial losses, or significant damage to third parties. Most entities must define for themselves how this assessment is carried out in detail.</p>
<p>For all entities falling under the first <a href="https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/14241-Cybersicherheitsrisikomanagement-und-Berichtspflichten-fur-digitale-Infrastrukturen-Anbieter-und-IKT-Servicemanager_de" target="_blank">implementing regulation</a>, there are concrete specifications on how significant security incidents must be assessed.</p>

<h2>Registration with the BSI</h2>
<p>Affected entities are obliged to register with the BSI. In addition to general company and contact data, information on the industry and the EU countries in which the company operates must be submitted. Changes to this information must be reported to the BSI within two weeks.</p>

<h2 id="nis-2-implement-risk-measures">Implementing Risk Management Measures</h2>
<p>A central part of the <a href="https://www.bmi.bund.de/SharedDocs/gesetzgebungsverfahren/DE/Downloads/referentenentwuerfe/CI1/NIS-2-RefE-24062024.pdf;jsessionid=1E1004B99D3105980E1BFFC5F16A8E88.live891?__blob=publicationFile&v=2" target="_blank">NIS 2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG)</a> is the obligation to implement risk management measures:</p>
<p>"[...] Entities are obliged to take appropriate, proportionate, and effective technical and organizational measures to avoid disruptions in availability, integrity, authenticity, and confidentiality [...] and to keep the impact of security incidents as low as possible."</p>
<p>NIS 2 then describes a series of concrete measures:</p>
<ul>
    <li>Fundamental risk and information security concepts</li>
    <li>Handling of security incidents</li>
    <li>Business Continuity Management (BCM)</li>
    <li>Supply chain security and system development</li>
    <li>Security awareness training</li>
    <li>Cryptography concepts</li>
    <li>Personnel security and physical security</li>
    <li>Assessment of the effectiveness of risk management</li>
</ul>

<p>However, these are merely minimum requirements – depending on the company's risk situation, further measures may be necessary to fulfill the requirement.</p>

<h2>When must affected entities take action?</h2>
<p>Immediately upon the expected entry into force of the NIS 2 Directive on October 17, 2024, entities must meet the requirements for risk management measures and reporting obligations. To initiate necessary measures in a timely manner, it is therefore essential to take action now.</p>
<p>For all those affected at the time of entry into force, the registration of the organization with the BSI must have been completed by January 17, 2025, at the latest. For entities that become affected later, for example because the number of employees was only then exceeded, a deadline of three months applies.</p>

<h2>What should affected entities do now?</h2>
<p>Given the little time remaining before measures must be implemented, affected parties should act swiftly.</p>

<dl>
    <dt>1. Determine affected status</dt>
    <dd>Read about how affected status can be determined in the <a href="https://aramido.de/en/blog/communication-security/who-is-affected-by-nis-2-part-2"
   
   
   >
    second part
</a>
 of the <a href="https://aramido.de/en/topic/nis-2"
   
   
   >
    NIS 2 article series
</a>
.</dd>
  
    <dt>2. Gap Analysis</dt>
    <dd>It must be determined in which areas gaps exist in fulfilling the NIS 2 requirements.</dd>
  
    <dt>3. Define Measures</dt>
    <dd>Appropriate measures must be defined for all gaps.</dd>
  
    <dt>4. Implement Measures</dt>
    <dd>Registration must be prepared, a reporting process set up, and risk management established.</dd>
</dl>

<p>The aramido consultants can support you in all these steps.</p>
<p>To protect the company sustainably in the face of a constantly changing threat landscape, information security must be understood as a process. New risks must be identified and addressed repeatedly – not only to fulfill legal requirements, but above all, to protect the company from significant damage.</p>

<div class="ara-jumbotron ara-bg-gray-200">
    <p class="ara-hyphenation d-md-table-cell pe-md-5">
        We are happy to accompany you on the path to NIS 2 implementation. Take advantage of a free initial consultation to discuss your project with a security expert. 
    </p>
    <div class="d-md-table-cell align-middle">
        <div class="d-grid gap-2 d-md-flex justify-content-md-end">
            <a href="https://aramido.de/en/contact"
               class="btn btn-primary btn-lg"
               
               >
                Contact us now
            </a>

        </div>
    </div>
</div>

<h3>More on the topic of NIS 2</h3>
<p><a href="https://aramido.de/en/blog/communication-security/what-is-the-nis-2-directive-part-1"
   
   
   >
    What is NIS 2?
</a>

</p>
<a href="https://aramido.de/en/blog/communication-security/who-is-affected-by-nis-2-part-2"
   
   
   >
    Who is affected by NIS 2?
</a>

]]></description></item><item><title>Steganography: The Art of Hidden Communication</title><link>https://aramido.de/en/blog/communication-security/steganography-the-art-of-hidden-communication/</link><pubDate>Wed, 05 Jun 2024 11:05:43 +0100</pubDate><author>Fabienne Hofsäß</author><guid>https://aramido.de/en/blog/communication-security/steganography-the-art-of-hidden-communication/</guid><description><![CDATA[

<p>
    Steganography is one of the oldest methods for hiding information from third parties. It was used as early as antiquity, primarily in the military and political spheres.
</p>

<div class="ara-panel ara-panel-primary mt-4">
    <div class="ara-panel-heading">
        <h3 class="ara-panel-title">Steganography</h3>
    </div>
    <div class="ara-panel-body text-center">
        The term steganography is derived from the Greek words "steganos" (secret or hidden) and "graphein" (writing).<br>
    </div>
</div>

<p>
    There are many different types of steganography:
</p>
<ul>
    <li>Double bottoms in packages or envelopes were used as secret hiding places.</li>
    <li>Messages were written with lemon juice as secret ink.</li>
    <li>Information was transformed into ciphertext through ciphers.</li>
    <li>Hidden messages in texts and images were sent as semagrams.</li>
</ul>

<p>
    The only limit to steganography is creativity in transmitting information as securely as possible. Depending on the purpose, effort, and security level, different methods can be used and even combined.
</p>


<h2 id="semagram-coding">Semagram and Coding</h2>

<p>
    A well-known example of a semagram is the <a target="_blank" href="http://docplayer.org/docs-images/66/54535799/images/4-1.jpg" rel="nofollow noopener noreferrer">image of the San Antonio River</a> from the book <a target="_blank" href="https://en.wikipedia.org/wiki/The_Codebreakers" rel="nofollow noopener noreferrer">The Codebreakers – The Story of Secret Writing</a> by David Kahn. 
    In this case, secret messages were hidden in the image. The inconspicuous blades of grass on the bank are Morse code. A short and a long blade of grass in a tuft represent an "A" in this case.
  
    In this way, entire maps and other tactical information could be transmitted in the past.
</p>

<h3 id="morse-alphabet">The Morse Alphabet</h3>

<div class="row">
    <div class="col-lg-4">
        <table class="table table-sm">
        <tr>
            <td>A</td>
            <td>• —</td>
          </tr>
          <tr>
            <td>B</td>
            <td>— • • •</td>
          </tr>
          <tr>
            <td>C</td>
            <td>— • — •</td>
          </tr>
          <tr>
            <td>D</td>
            <td>— • •</td>
          </tr>
          <tr>
            <td>E</td>
            <td>•</td>
          </tr>
          <tr>
            <td>F</td>
            <td>• • — •</td>
          </tr>
          <tr>
            <td>G</td>
            <td>— — •</td>
          </tr>
          <tr>
            <td>H</td>
            <td>• • • •</td>
          </tr>
          <tr>
            <td>I</td>
            <td>• •</td>
          </tr>
        </table>
    </div>
    <div class="col-lg-4">
        <table class="table table-sm">
            <tr>
                <td>J</td>
                <td>• — — —</td>
              </tr>
              <tr>
                <td>K</td>
                <td>— • —</td>
              </tr>
              <tr>
                <td>L</td>
                <td>• — • •</td>
              </tr>
              <tr>
                <td>M</td>
                <td>— —</td>
              </tr>
              <tr>
                <td>N</td>
                <td>— •</td>
              </tr>
              <tr>
                <td>O</td>
                <td>— — —</td>
              </tr>
              <tr>
                <td>P</td>
                <td>• — — •</td>
              </tr>
              <tr>
                <td>Q</td>
                <td>— — • —</td>
              </tr>
              <tr>
                <td>R</td>
                <td>• — •</td>
              </tr>
        </table>
    </div>
    <div class="col-lg-4">
        <table class="table table-sm">
            <tr>
                <td>S</td>
                <td>• • •</td>
            </tr>
            <tr>
                <td>T</td>
                <td>—</td>
            </tr>
            <tr>
                <td>U</td>
                <td>• • —</td>
            </tr>
            <tr>
                <td>V</td>
                <td>• • • —</td>
            </tr>
            <tr>
                <td>W</td>
                <td>• — —</td>
            </tr>
            <tr>
                <td>X</td>
                <td>— • • —</td>
            </tr>
            <tr>
                <td>Y</td>
                <td>— • — —</td>
            </tr>
            <tr>
                <td>Z</td>
                <td>— — • •</td>
            </tr>
        </table>
    </div>
</div>

<h2 id="camouflage-encryption">Camouflage and Encryption Today</h2>

<p>
    The need for secure data transmission has always existed – whether to communicate tactical decisions or agree on secret meeting points. Steganography is still used today, for example by criminals who hide malware in images.
</p>

<p>
  However, those who wish to transmit confidential information <a href="https://aramido.de/en/security-consulting"
   
   
   >
    are better off relying on recognized, secure methods today
</a>
. Depending on the use case, symmetric or asymmetric encryption methods are used, for example <abbr title="Advanced Encryption Standard">AES</abbr>, <abbr title="Rivest-Shamir-Adleman">RSA</abbr> or <abbr title="Elliptic Curve Cryptography">ECC</abbr>. These methods secure internet communication, encrypted email traffic and also SIP telephone connections.
</p>

<div class="ara-jumbotron">
    <div class="ara-meta-info">
        Only transmit confidential information securely within your company! Talk to us.
    </div>
    <div class="ara-meta-info">
        <a href="https://aramido.de/en/contact"
           class="btn btn-primary btn-lg"
           
           >
            Schedule a consultation
        </a>

    </div>
</div>]]></description></item><item><title>Versatile Program at the Night of Digitalization</title><link>https://aramido.de/en/blog/aramido/versatile-program-at-the-night-of-digitalization/</link><pubDate>Tue, 21 May 2024 08:06:33 +0200</pubDate><author>Fabienne Hofsäß</author><guid>https://aramido.de/en/blog/aramido/versatile-program-at-the-night-of-digitalization/</guid><description><![CDATA[
<p>The <a target="_blank" rel="nofollow noopener noreferrer" href="https://karlsruhe.digital/en/bunte-nacht-der-digitalisierung">Bunte Nacht der Digitalisierung</a> (Night of Digitalization) makes the digital world in Karlsruhe an experience for everyone. aramido is once again taking part and opens its doors to visitors on June 7, 2024, from 3:00 PM. </p>

<div class="ara-panel ara-panel-primary mt-4" >
  <div class="ara-panel-heading" >
        <h3 class="ara-panel-title" >aramido at the Night of Digitalization</h3>
  </div>
  <div class="ara-panel-body text-center" >
<a target="_blank" href= "/pdf/Anfahrt-aramido.pdf">Durlacher Allee 77</a>
<br>June 7, 2024, 3:00 PM – 10:00 PM 
 <br>The event is free
 <br><a href="https://aramido.de/ics/bunte-nacht-der-digitalisierung-2024.ics">Download appointment as .ics</a>
  </div>
</div>

<h2 id="programm">Program Overview</h2>
<p>A colorful program is offered: from exciting <a href="https://aramido.de/en/security-consulting/security-by-design/live-hacking"
   
   
   >
    live hacking presentations
</a>
 and a <a href="https://aramido.de/en"
   
   
   >
    Capture the Flag competition
</a>
 to an exhibition of hacking tools, the aramido team showcases a wide range of valuable content.</p>

<p>Various interactive stations invite you to participate and tinker together. For the first time, it will be possible to <a href="https://aramido.de/en/blog/aramido/meet-aramido-at-the-information-market-the-new-suction-principle"
   
   
   >
    clone your own voice
</a>
 at the Voice Cloning station.</p>

<p>In good weather, our roof terrace once again offers the opportunity to let the eventful day wind down – with a cool drink in hand and a view of the sunset over the rooftops of Karlsruhe.</p>

<h3 la-heading>Presentations</h3>
<p>Those who want to protect effectively must know how attacks are carried out. In the presentations, the aramido team uses several live hacks to show that hacking is also part of the duties of an information security consultant.</p>
<table class="table table-striped" >
<thead>
<tr>
<th>Start</th>
<th>Title</th>
</tr>
</thead>
<tbody>
<tr>
<td>3:30 PM</td>
<td><a href="https://aramido.de/en"
   
   
   >
    Smartphone Hacking – A brief history of vulnerable cyborgs
</a>
</td>
</tr>
<tr>
<td>5:15 PM</td>
<td><a href="https://aramido.de/en"
   
   
   >
    Capture the Flag (CTF) – What the CTF competition is all about
</a>
</td>
</tr>
<tr>
<td>6:30 PM</td>
<td><a href="https://aramido.de/en"
   
   
   >
    Voice Cloning – The art of digital voice replication
</a>
</td>
</tr>
<tr>
<td>8:00 PM</td>
<td><a href="https://aramido.de/en"
   
   
   >
    Hacking on Ice – When you should better turn off your PC
</a>
</td>
</tr>
</tbody>
</table>

<h4 la-heading>Activity Stations</h4>
<p>Besides the presentations, various stations invite you to get informed and participate:</p>
<ul>
<li><a href="https://aramido.de/en"
   
   
   >
    Capture the Flag competition (CTF)
</a>
</li>
<li><a href="https://aramido.de/en"
   
   
   >
    Voice Cloning – Clone your own voice
</a>
</li>
<li><a href="https://aramido.de/en"
   
   
   >
    USB Condom soldering station
</a>
</li>
<li><a href="https://aramido.de/en"
   
   
   >
    Hacking gadget exhibition
</a>
</li>
<li><a href="https://aramido.de/en"
   
   
   >
    Fingerprint dummy
</a>
</li>
<li><a href="https://aramido.de/en"
   
   
   >
    Crypto Box
</a>
</li>
<li><a href="https://aramido.de/en"
   
   
   >
    Tschunk Bar
</a>
</li>
</ul>

<p>Subject to change.</p>

<h2 la-heading>Presentation Details</h2>

<h3 id="vortrag-smartphone-hacking">Smartphone Hacking – A brief history of vulnerable cyborgs</h3>
<p>The history of smartphones is short. In 2007, Apple introduced the first iPhone with its own iOS operating system, and a year later, Android, today's dominant smartphone operating system, entered the market. And the history of the first smartphone hacks is just as old: from the first jailbreaks to celebrity nudes and commercially and state-sponsored spyware.</p>
<p>Using attack trees and live hacking demonstrations, the speakers show how smartphones are attacked. Understanding this is the basis for effective protective measures.</p>

<p>
  <a href="https://aramido.de/en"
     
     
     >
      » Back to program overview
  </a>

</p>


<h3 id="vortrag-capture-the-flag">Capture the Flag (CTF) – What the CTF competition is all about</h3>
<p>Capture the Flag (CTF) is a popular competition in the field of IT security, where participants prove their skills in dealing with vulnerabilities and other puzzles. These competitions are a kind of game in which teams or individuals must solve various security tasks to find so-called <em>flags</em>.</p>
<p>In the presentation, the speakers explain what a CTF is, what types of tasks exist, how to start with CTF games, and what skills and knowledge are required.</p>

<p>
  <a href="https://aramido.de/en"
     
     
     >
      » Back to program overview
  </a>

</p>

<h3 id="vortrag-voice-cloning">Voice Cloning – The art of digital voice replication</h3>
<p>Voice Cloning is a fascinating technology that makes it possible to clone human voices using artificial intelligence (AI). Characteristic features of a voice, such as tone, pauses, and accents, are trained through machine learning and stored in a model. Subsequently, the AI can read texts or change spoken recordings with the cloned voice.</p>
<p>In the presentation, the speakers show live how easily and quickly a voice can be cloned, where the current limits are, and how to best protect yourself from the dangers of "deep fakes."</p>

<p>
  <a href="https://aramido.de/en"
     
     
     >
      » Back to program overview
  </a>

</p>

<h3 id="vortrag-cold-boot">Hacking on Ice – When you should better turn off your PC (Live Hack)</h3>
<p>To protect data from unauthorized access, it is encrypted with tools such as Microsoft's BitLocker and Apple's FileVault. For mobile devices in a business environment, this is often a compliance requirement. Only those who know the password can access the data. That this is a misconception, security researchers showed as early as 2008: if they had physical access to a computer that was switched on or "sleeping" (standby mode), they could read the password from the working memory. Even today, so-called <a href="https://aramido.de/en/blog/data-security/cold-boot-attack-farewell-disk-encryption"
   
   
   >
    Cold Boot attacks
</a>
 are still possible.</p>
<p>In the presentation, such an attack on a computer with disk encryption will be carried out live, and countermeasures will be presented to avoid becoming a victim of a Cold Boot attack. Whether Windows, macOS, or Linux: everyone who relies on disk encryption is affected.</p>

<p>
  <a href="https://aramido.de/en"
     
     
     >
      » Back to program overview
  </a>

</p>

<h2 la-heading>Details of the Activity Stations</h2>

<h3 id="Rahmenprogramm-CTF">CTF – Capture the Flag Competition</h3>
<p>Various university teams compete against each other in a Capture the Flag (CTF) competition, proving their skills in dealing with security-relevant vulnerabilities. They must solve various tasks to find so-called "flags." These flags are hidden strings that serve as proof of the successful exploitation of a vulnerability or the solving of a task.<br>
The award ceremony takes place during the <a href="https://aramido.de/en"
   
   
   >
    CTF presentation
</a>
 (5:15 PM – 5:45 PM).</p>

<h3 id="Rahmenprogramm-VoiceCloning">Voice Cloning – Clone your own voice</h3>
<p>Try voice cloning yourself! Only a short text needs to be spoken. Characteristic features of the voice are trained through machine learning and stored in a model. Subsequently, the AI can read texts with the cloned voice.</p>

<h3 id="Rahmenprogramm-USB-Kondom">USB Condom soldering station</h3>
<p>Those who want to be active themselves have the perfect opportunity at the soldering workshop to create their own small gadget. Using soldering irons and 3D-printed housings, visitors create their own USB condom. With this useful tool, you can charge devices with confidence at foreign USB ports.</p>

<h3 id="Rahmenprogramm-Hacking-Gadgets">Presentation of Hacking Gadgets</h3>
<p>Get an overview of the tools used by <a href="https://aramido.de/en/security-testing/penetration-testing"
   
   
   >
    penetration testers
</a>
 at aramido's hacking tool exhibition. From the WiFi Pineapple and Rubber Ducky to the Flipper Zero, you can learn how seemingly inconspicuous tools can cause significant damage.</p>

<h3 id="Rahmenprogramm-Fingerabdruck-Attrappe">Fingerprint Dummy</h3>
<p>Matching the smartphone hacking presentation, visitors can clone their own fingerprint using simple tricks and everyday materials. It's amazing how positively corresponding sensors react!</p>

<h3 id="Rahmenprogramm-KryptoBox">Cryptography made easy</h3>
<p>Cryptography is often the basis for security in information systems. Without the ability to encrypt data and thus effectively protect it from access, most security goals would simply be unattainable. But even today's complex cryptography started small. Using the CryptoBox from the Karlsruhe University of Education, specifically developed for students from 1st to 10th grade, people of all ages can gain easy and playful access to this fascinating subject.</p>

<h3 id="Rahmenprogramm-Tschunk-Bar">Tschunk Bar</h3>
<p>Of course, there is plenty of "Tschunk" at the Tschunk Bar. It is the supplement of choice when you are hungry for fantasy and craving liquid while hacking: Club Mate + lime + cane sugar + ice + rum = more flags.</p>

<p>Attention: Anyone who starts perceiving the world in binary should stop the Tschunk consumption for safety.</p>
   
<p>In good weather, let the week wind down with a cool drink above the rooftops of Karlsruhe and get into conversation with others – the aramido roof terrace is the perfect place for that!<br />Tip: In the evening, you have a beautiful view of the sunset.</p>

<p>
  <a href="https://aramido.de/en"
     
     
     >
      » Back to program overview
  </a>

</p>]]></description></item><item><title>Artificial Intelligence and Social Engineering: The Ingredients for a Hackathon</title><link>https://aramido.de/en/blog/aramido/artificial-intelligence-and-social-engineering-the-ingredients-for-a-hackathon/</link><pubDate>Tue, 14 May 2024 14:04:15 +0200</pubDate><author>Patrick Stracke</author><guid>https://aramido.de/en/blog/aramido/artificial-intelligence-and-social-engineering-the-ingredients-for-a-hackathon/</guid><description><![CDATA[<p>In today’s world, Artificial Intelligence (AI) and Social Engineering are two powerful forces that affect us humans in different ways. While AI revolutionizes our technology and opens up new possibilities, social engineering exploits human weaknesses to achieve its goals. But what happens when these two worlds collide?</p>
<h3 id="hackathon-at-aramido-studenthack2024">Hackathon at aramido: StudentHACK2024</h3>
<p>aramido has been dealing with such questions about AI for some time. That is why this topic is also the reason for StudentHACK 2024 with studentec e.V., a university group of the Karlsruhe Institute of Technology (KIT). Together, a two-day interdisciplinary hackathon was organized, bringing students together to develop innovative solutions for complex problems.</p>
<h3 id="the-impact-of-ai-on-social-engineering">The Impact of AI on Social Engineering</h3>
<p>The success of social engineering ultimately depends on the ability to convince people. Many tactics help increase the chances of tricking people, such as creating urgency or exploiting cognitive biases. One of the most effective methods of persuasion, for example, is to adopt the tone and conversation style that the recipient is accustomed to from the sender.</p>
<p>Thanks to impressive progress in natural language processing, AI systems can now analyze very large amounts of data to understand personal preferences, behavioral patterns, tone, colloquialisms, and demographic data. With the help of AI, attackers can draft personalized and extremely convincing messages, which can increase the success rates of social engineering attacks. The further development of AI technologies means that they are also becoming better at creating content that can bypass defense measures such as spam filters. The most striking improvement in AI recently has been generative algorithms. These algorithms are capable of producing human-like texts that are often barely distinguishable from real human texts. By imitating human writing patterns, AI can create messages that are more likely to reach the intended recipient and be classified as non-suspicious.</p>
<h3 id="the-challenge-for-defense">The Challenge for Defense</h3>
<p>Fortunately, there is also a flip side: the same developments in AI can also improve the ability to detect social engineering. Machine learning algorithms can extract features typical of a social engineering attack by analyzing large amounts of text. Companies and organizations are therefore investing in AI-powered solutions that can both detect attacks and take preventive measures.</p>
<p>In the future, aramido will continue to deal with this dangerous alliance of AI and social engineering and incorporate the innovative ideas and results of the hackathon. Raising awareness of the risks and investing in advanced technologies are crucial for ensuring digital security.</p>
<div class="ara-panel ara-panel-primary mt-4">
    <div class="ara-panel-heading">
        
        
            <h3 class="ara-panel-title"><h4>StudentHACK2024 Karlsruhe</h4></h3>
        
    </div>
    <div class="ara-panel-body text-center">
        
    Wednesday and Thursday, May 15 and 16, 2024<br>
    aramido GmbH<br>
    Durlacher Allee 77, 76131 Karlsruhe<br>

    </div>
</div>
<p>All students can expect intense collaboration in teams to develop groundbreaking solutions, and the opportunity for networking with talented students and industry experts. Excellent catering with Mate, snacks, and full meals, in true aramido style, will be provided.</p>
]]></description></item><item><title>Active Directory Hacked – How Does It Work?</title><link>https://aramido.de/en/blog/penetration-testing/active-directory-hacked-how-does-it-work/</link><pubDate>Mon, 04 Mar 2024 10:57:02 +0200</pubDate><author>Fabienne Hofsäß</author><guid>https://aramido.de/en/blog/penetration-testing/active-directory-hacked-how-does-it-work/</guid><description><![CDATA[
<p>
    An Active Directory (AD) is one of the most important systems in a network. The directory system is used to centrally manage user accounts, computers, groups, and policies: whoever controls it possesses extensive control over the IT landscape.
</p>
<h3>Looking Over the Shoulders of Hackers</h3>
<p>
    Hackers often target the Microsoft <abbr title="Active Directory">AD</abbr>. To attack an Active Directory, several weaknesses in the IT infrastructure are exploited. aramido shows what such an attack looks like in a <a href="https://aramido.de/en/security-testing/penetration-testing"
   
   
   >
    special broadcast on hacker attacks
</a>
. Watch hackers over their shoulders as they take full control of a Windows domain.
</p>

<div class="py-3">
    <div class="ara-embed-video-responsive ara-embed-video-responsive-16by9">
        <iframe class="ara-embed-video-responsive-item" src="https://video.aramido.de/videos/embed/5a5730a8-3dd9-4c50-bc4d-91b71647c468" allowfullscreen></iframe>
    </div>
</div>

<p>
    In the special broadcast on hacker attacks, it is shown how an employee of a company is phished. 
    Hackers succeed in gaining access to the corporate network, where they can take over a server through a dictionary attack.
    They listen in on the network and can take over the account of a local administrator through <abbr title="Link-Local Multicast Name Resolution">LLMNR</abbr> poisoning.
    Through the incorrect use of a domain administrator user, their password can be intercepted.
    Insufficient network segmentation can no longer prevent the complete takeover of the Active Directory.
    It turns out that the special broadcast on hacker attacks is a demonstration of a <a href="https://aramido.de/en/security-testing/red-teaming"
   
   
   >
    Red Teaming Assessment
</a>
 that was carried out by aramido as a security audit on behalf of a company.
</p>

<h3>10-Point Plan for Securing Windows Domains</h3>

<p class="ara-hyphenation">
    To keep important systems of an IT infrastructure safe from hackers, a <a href="https://aramido.de/en/security-consulting"
   
   
   >
    good security concept
</a>
, <a href="https://aramido.de/en/security-testing"
   
   
   >
    capable security experts
</a>
 and <a href="https://aramido.de/en/security-testing"
   
   
   >
    regular security audits
</a>
 are needed. In addition to individual measures that meet the requirements of a company, we recommend the following 10-point plan for securing an Active Directory (AD):
</p>

<ol class="ara-hyphenation">
    <li>
        Implement strong authentication
        <ul>
            <li>Use multi-factor authentication (MFA) at least for all domain users and administrators.</li>
            <li>Use smartcards, <a href="https://aramido.de/en/blog/communication-security/fido2-and-webauthn-login-without-a-password"
   
   
   >
    hardware tokens
</a>
 or biometric authentication methods.</li>
        </ul>
    </li>
    <li>
        Harden security settings
        <ul>
            <li>Configure Group Policy Objects (GPOs) to enforce security policies.</li>
            <li>Enable selective authentication for specific users and groups.</li>
            <li>Implement Network Access Control (NAC) solutions to control device access.</li>
        </ul>
    </li>
    <li>
        Protect passwords
        <ul>
            <li>Use a password manager to create and store complex passwords.</li>
            <li>Implement password policies that prescribe a minimum length, uniqueness, and high complexity.</li>
        </ul>
    </li>
    <li>
        Control user access
        <ul>
            <li>Implement role-based access control (RBAC) to restrict user permissions based on their roles.</li>
            <li>Use group policies to control user permissions and access rights.</li>
        </ul>
    </li>
    <li>
        Monitor network traffic
        <ul>
            <li>Use Network Security Monitoring (NSM) tools to detect suspicious activities.</li>
            <li>Monitor for unauthorized access, data breaches, and malicious software.</li>
        </ul>
    </li>
    <li>
        Audit events
        <ul>
            <li>Enable monitoring of important events such as login attempts, changes to user accounts, and security policy violations.</li>
            <li>Regularly review audit logs to identify suspicious activities.</li>
        </ul>
    </li>
    <li>
        Apply updates
        <ul>
            <li>Keep operating systems, applications, and drivers up to date with security patches.</li>
            <li>Implement a patch management process to ensure timely installation.</li>
        </ul>
    </li>
    <li>
        Deploy anti-malware programs
        <ul>
            <li>Install and maintain antivirus and anti-malware software on all devices connected to the domain.</li>
            <li>Regularly scan for malware and viruses.</li>
        </ul>
    </li>
    <li>
        Train users
        <ul>
            <li>Inform users about security risks and best practices, such as the use of secure passwords and the <a href="https://aramido.de/en/blog/communication-security/phishing-smishing-vishing-tishing"
   
   
   >
    avoidance of phishing scams
</a>
.</li>
            <li>Conduct regular security awareness training.</li>
        </ul>
    </li>
    <li>
        Perform security audits
        <ul>
            <li>Conduct regular security audits, for example through <a href="https://aramido.de/en/security-testing/red-teaming"
   
   
   >
    Red Teaming Assessments
</a>
 or <a href="https://aramido.de/en/security-testing/penetration-testing"
   
   
   >
    penetration tests
</a>
, to identify vulnerabilities and weak points.</li>
            <li>Implement plans for remediating security issues so that they are eliminated as quickly as possible.</li>
        </ul>
    </li>
</ol>

<div class="ara-jumbotron ara-bg-gray-800">
    <p class="ara-hyphenation d-md-table-cell pe-md-5">
        Do you need help securing your Windows domain or do you want to test your organization through a <a href="https://aramido.de/en/security-testing/red-teaming"
   
   
   >
    Red Teaming Assessment
</a>
?
    </p>
    <div class="d-grid gap-2 d-md-table-cell justify-content-md-end align-middle">
        <a href="https://aramido.de/en/contact"
           class="btn btn-success"
           
           >
            Contact us now
        </a>

    </div>
</div>]]></description></item><item><title>Become a Domain Admin in 30 Minutes</title><link>https://aramido.de/en/blog/aramido/become-a-domain-admin-in-30-minutes/</link><pubDate>Thu, 27 Apr 2023 13:22:15 +0200</pubDate><author>Leonard Otto</author><guid>https://aramido.de/en/blog/aramido/become-a-domain-admin-in-30-minutes/</guid><description><![CDATA[<p>At the KA-IT-Si event <a href="https://www.ka-it-si.de/events/aktuelle.html">AD = Anno Domini?</a> on May 4, 2023, we will show in real-time how creative hackers take over a company’s infrastructure.
As part of the live hack, we will demonstrate the exploitation of various security vulnerabilities and human errors, which we also observe in reality during our work as pentesters and in IT forensics.</p>
<p>What information can an attacker collect about your company through Open Source Intelligence (OSINT) and use for an attack?
Are your employees sufficiently trained to recognize a well-crafted phishing email as malicious?
How can a dictionary be used for a hacker attack?
During the presentation, we won’t shy away from using “Bloodhounds” and “poisoning network traffic.”</p>
<p>Experience firsthand how important, for example, the correct configuration of servers, the use of secure passwords, or the principle of least privilege is.
In some cases, even multi-factor authentication cannot protect against a hostile takeover!</p>
<p>The demonstration ends with the success of the hackers, who are able to take over the infrastructure completely.
While real attackers would proceed, for example, by encrypting systems to then demand a ransom, the presenting hackers will be available for questions and discussion after their work is done.</p>
<p>The evening will conclude with snacks and drinks.</p>
<!-- raw HTML omitted -->
<!-- raw HTML omitted -->
<div class="ara-panel ara-panel-primary mt-4">
    <div class="ara-panel-heading">
        
        
            <h3 class="ara-panel-title">KA-IT-Si Event <br><b>AD = Anno Domini?</b></h3>
        
    </div>
    <div class="ara-panel-body text-center">
        
    Thursday, May 4, 2023, 6:00 PM<br>
    CyberForum<br>
    Haid-und-Neu-Straße 18, 76131 Karlsruhe<br>
    <a rel="nofollow" href="https://www.ka-it-si.de/events/aktuelle.html">to registration</a>

    </div>
</div>
]]></description></item></channel></rss>