Events

Heads-up: TROOPERS Roundtable – Supply Chain Security

How to strengthen Supply Chain Security: Practical Exchange and Roadmap

Join an open, practitioner-focused roundtable for direct exchange on supply chain security. This session offers a concise overview of core concepts, e.g. SBOM, CSAF, and VEX and digs into the processes behind them: how to obtain, process and apply information to improve security across the supply chain.

We will examine:

  • How SBOM, CSAF and VEX relate and why version-level detail matters.
  • The practical value of an SBOM and why it’s increasingly required by law and IT procurement.
  • How to create and consume SBOMs?
  • Methods to identify dependencies in the context of vulnerabilities.
  • Approaches to triage: not all vulnerabilities affect every stakeholder equally.
  • Techniques to analyze vulnerabilities and identify affected products and product families.
  • Sources of vulnerability information and how to map data unambiguously to products and specific software versions.
  • Reporting obligations: where and how to disclose vulnerabilities.
  • Tools and automation that help manage information volume and complexity.
  • Technical, organizational and personnel challenges to achieving end-to-end supply chain security.
  • The role of AI in supply chain security.
  • How do we protect ourselves from malicious actors / infected dependencies?
  • The Cyber Resilience Act (CRA): implications for companies, products and consumers, the CRA roadmap, and concrete deadlines and actions.
  • We will show a live demonstration of the whole process, e.g. covering the consumption of SBOMs, vulnerability identification and assessment, creation of VEX documents.

This roundtable is designed for security practitioners, product owners, compliance officers and decision-makers who want actionable guidance and peer discussion. Expect candid conversation, real-world examples and next steps you can take to strengthen resilience across your supply chains.

Roundtable Hosts

We are delighted to welcome the following hosts, who will share their expertise and experiences throughout the roundtable.

Dina Truxius1

Dina is a natural scientist by training with high high affinity for technology and non-standard IT. In 2018, she left academia and movied into public administration, joining the Federal Office for Information Security (BSI). Dina started with medical device cybersecurity, touched aviation security and now works in the field of industrial automation and control systems. Her main responsibilities are project management, vulnerability management, standardization, disclosure processes, and legislation. She is currently seconded to the Federal Ministry for Digitalisation and State Modernisation (BMDS) to help establish and expand the Project Management Competence Center with her expertise. There she encounters a flood of dependencies and dives into the depths and of digital projects aimed at making Germany more digital, sovereign, and resilient.

Florian von Samson2

is engaged with UNIX operating systems since 1989 and with Free / Open Source Software (FOSS) since 1990; initially while achieving his master degree in electrical engineering, later both also in professional contexts. At the end of the 1990ties he also started caring about the societal, judicial and economical aspects of FOSS and conducting discussions to that, e.g. at LinuxTag. In addition to that, in the 2000s he focused on the security of and with FOSS, as well as boot chain security by Secure / Verified Boot and Trusted / Authenticated Boot. After a 5 year long, professional stint back into the depths of electromagnetic emanations, he now contributes to suitable conditions for a thriving FOSS ecosystem, to the technical aspects of digital sovereignty, and to the technical requirements for a well working SBOM ecosystem.

Michael Schuster3

Michael studied electrical engineering in Dresden before spending several years at a systems integrator in the telecommunications sector. He now works for the German Federal Office for Information Security (BSI) in market surveillance. In this role, he is involved in the implementation of the EU Cyber Resilience Act, a regulation aimed at strengthening cybersecurity across the entire lifecycle of Products with Digital Elements. He collaborates with standards bodies and working groups to help translate regulatory obligations into practical, interoperable specifications that make compliance more accessible for all stakeholders.

Stefan Fleckenstein4

After working as a software engineer and architect, cyber security became one of Stefan’s focal points, being the CISO of a software development company and being the founder of their cyber security division, advising customers on all matters relating to security. Since 2026 Stefan is the CISO of Stackable, where Stefan is responsible for leading the company to the ISO 27001 certification and the security of the product, an open source data platform. In addition to his day job, Stefan is the creator and maintainer of SecObserve, an open source vulnerability management system.

Lars Franke5

Lars Francke has been working in the Big Data space for over ten years, as a consultant, and as a committer on projects like Apache HBase and Apache Hive. In that time he’s seen firsthand how open source data stacks get deployed, maintained, and occasionally broken in production across a wide range of organizations. He is Co-Founder and CTO at Stackable, and he wants to talk about what supply chain security actually looks like when you’re operating complex, layered open source infrastructure, and where the real problems tend to hide.


  1. Federal Ministry for Digitalisation and State Modernisation (BMDS)↩︎
  2. Technical Lead for SBOMs and Digital Souverainity at German Federal Office for Information Security (BSI)↩︎
  3. Referat S 15 – Marktaufsicht, German Federal Office for Information Security (BSI)↩︎
  4. Chief Information Security Officer (CISO) at Stackable↩︎
  5. CTO & Co-Founder of Stackable↩︎
Continue reading
Breaking

Vulnerability Disclosure: Stealing Emails via Firefox’s AI Features

Imagine the following: You visit a webpage with a lot of text you don’t want to read and ask your AI assistant for a summary. A few moments later, the AI assistant has extracted one of your emails and sent it to an attacker without you ever knowing.

In October 2025, we found exactly this vulnerability in Firefox’s AI chatbot integration1.

Continue reading “Vulnerability Disclosure: Stealing Emails via Firefox’s AI Features”

Continue reading
Misc

Insights into Entra ID’s (Un)Conditional Access

When looking at security measures in Microsoft Entra ID environments, a common recommendation is to implement Conditional Access policies.

Whether Conditional Access is implemented can be quickly checked, and you can put a check mark next to it in your best-practice compliance form. However, simply implementing conditional access will not provide much security. A phishing attack that we recently analyzed highlights this very well.

Continue reading “Insights into Entra ID’s (Un)Conditional Access”

Continue reading
Breaking, Misc

CVE-2026-47237 – Overly Permissive Istio Permissions Allow Kubeflow Authorization Token Stealing

Kubeflow is vulnerable to the theft of authorization tokens by any user of the Kubeflow UI or APIs, such as the Dashboard, Pipelines API, or Notebooks. With this token, the attacker can take over the user’s account and the data that is processed by that user. The attacker needs a valid user with the kubeflow-edit or Contributor role in a random Kubeflow namespace to perform this attack. This is given if Automatic Profile Creation is enabled. A setup based on the official manifests prior to version 1.10, and on most other packaged Kubeflow distributions, is vulnerable.

The Istio edit permissions were removed by Kubeflow in a timely manner. Affected users should update to the latest version to mitigate this issue.

Continue reading “CVE-2026-47237 – Overly Permissive Istio Permissions Allow Kubeflow Authorization Token Stealing”

Continue reading
Misc

ERNW White Paper 77: Unified Security Hardening with Cross-Platform Native Binaries

When configuring a new device, achieving an acceptable Lynis hardening score is a challenge most practitioners are familiar with.

Navigating its recommendations often requires significant background knowledge, leaving administrators without clear guidance on which settings are vulnerable and how to remediate them effectively.
We believe that security hardening should be insightful and accessible, a philosophy that drove this research and the development of our tool, Hardener, built around three identified deficits in established frameworks:

Continue reading “ERNW White Paper 77: Unified Security Hardening with Cross-Platform Native Binaries”

Continue reading
Misc

ERNW White Paper 76: Linux Client Hardening Guide

Hardening a Linux client system to an acceptable degree is a time-consuming process, one that demands familiarity with a broad set of configuration parameters, framework recommendations, and the reasoning behind each control.

This post introduces our new Linux client hardening guide (MD, PDF), a comprehensive, publicly available hardening reference for Linux systems.

Continue reading “ERNW White Paper 76: Linux Client Hardening Guide”

Continue reading
Misc

When paradigms are shifting: InfoSec in the age of AI

Over the last few weeks, I have had a very productive exchange with Christoph Klaassen on the impact of AI on security governance and compliance. In this post, we summarize our thoughts.

When the Perimeter Dissolves: InfoSec in the Age of Agentic AI

There’s an old saying among hackers coined by Dr. Eugene Spafford: “The only truly secure system is powered off, cast in a block of concrete and sealed in a lead-lined room with armed guards – and even then I have my doubts.”1

It was a joke, a wry nod to the impossibility of perfect security. But here’s the thing: the joke doesn’t land anymore. Because in the world we’re building right now, the systems don’t stay powered off. They reason. They plan. They act. And they do it faster than any human security team can keep up.

Welcome to the age of agentic AI. If you work in Information Security Management and/or Governance, Risk & Compliance, this is the inflection point you may have been sensing in your gut for months.

Continue reading “When paradigms are shifting: InfoSec in the age of AI”

Continue reading
Breaking

Disclosure: Command Injection in Geutebrück Cameras

During a penetration test for a customer, we identified a command injection vulnerability in Geutebrück security cameras that allows authenticated attackers to execute arbitrary commands as root through the web interface. The root cause is unsanitized user input being passed into a sed script (and at least 12 other CGI endpoints). In addition to the injection, we identified an XSS vulnerability, an exposed system menu leaking configuration and log data, and an insecure GET-parameter-to-environment-variable mapping that enables abuse of variables like LD_PRELOAD and LD_DEBUG. We reported the findings to Geutebrück and a patched firmware was provided. This post walks through how we got from a  sed error message to a root shell.

Geutebrück cameras are used as security cameras for enterprises, industry, and critical infrastructure, and support video streaming and configuration via a web interface. If the web interface is compromised, attackers can manipulate the video stream, potentially having a high impact on physical security, as they could use it to display fake images and videos to hide the camera’s real feed.

Continue reading “Disclosure: Command Injection in Geutebrück Cameras”

Continue reading
Misc

Windows Early Boot Configuration: The CmControlVector and PspSystemMitigationOptions

While investigating how process mitigation settings are initialized, I encountered the global variable PspSystemMitigationOptions. Tracing how this value is populated led me to the CmControlVector. In this blog post, we take a look at the Windows kernel land configuration manager, especially its global CmControlVector variable. Quick note: the kernel’s configuration manager is not related to Microsoft Intune’s Configuration Manager. In short, the configuration manager is responsible for managing and implementing the registry. However, it is also responsible for setting up parts of the system during early boot.

Continue reading “Windows Early Boot Configuration: The CmControlVector and PspSystemMitigationOptions”

Continue reading
Misc

KubeCon + CloudNativeCon Europe 2026

Exactly one week ago, Sven and I had the incredible opportunity to give our very first talk at KubeCon + CloudNativeCon 2026: How To Break Multi-Tenancy Again and Again …and What We Can Learn From It. We discussed the challenges of namespace-based multi-tenancy and presented real-world exploits in Kubeflow, Istio, and Traefik that bypass threat boundaries between namespaces and workloads. Based on these problems, we developed a methodology to assess and address them. You can find the methodology discussed in the talk in detail in another blog post or on GitHub. You can also find the slides here.

Continue reading “KubeCon + CloudNativeCon Europe 2026”

Continue reading