This is an German blog post as it is a recap from a German conference.
Sven und ich hatten zwei unglaublich spannende und lehrreiche Tage bei der heise devSec in Marburg.
Besonders hängen geblieben ist bei uns die Keynote von Volodymyr Styran zum Thema “Predictability Is Vulnerability: What Four Years of Cyber War Teach About Software Security”. Eine Erkenntnis daraus deckt sich stark mit unseren Erfahrungen aus zahlreichen Pentests: Angriffe müssen nicht immer aus einer hochkomplexen Exploit Chain bestehen. Oft sind es nicht die Zero-Day Exploit, die zur kritischen Kompromittierung der Umgebung führen würden, sondern banale Konfigurationsprobleme, wie schwache oder geleakte Credentials. Seine Erkenntnis ist, dass durch vorhersehbare Umgebungen, stabile Konfigurationen und kompromittierte Credentials die Angreifer lange unentdeckt und persistent bleiben und sich bewegen können.
Exactly one week ago, Sven and I had the incredible opportunity to give our very
first talk at KubeCon + CloudNativeCon
2026: How To Break Multi-Tenancy Again and Again …and What We Can Learn From It.
We discussed the challenges of namespace-based multi-tenancy and presented
real-world exploits in
Kubeflow, Istio,
and Traefik that bypass threat boundaries between namespaces and workloads.
Based on these problems, we developed a methodology to assess and address them.
You can find the methodology discussed in the talk in
detail in another blog post or
on GitHub. You can also find the
slides here.
Three weeks ago, I attended MCTTP 2025 in Munich,
organized by Vogel IT and curated by the fine folks Florian Hansemann, Dr. Marc
Maisch, and Florian Oelmaier. Awesome event with some very cool talks, and great
conversations over dinner and most notably at the Oktoberfest on Saturday
(thanks again for that special trip, Flo!). I had the pleasure and honor to give
the keynote on the 2nd day. The goal was to make it a bit entertaining and
enlightening for the international audience, so I covered some German
literature, too ;-). The slides can be found
here, and the transcript
here. Looking forward
to meeting some folks again next year, maybe even at
TROOPERS26 😉
The IMF Conference is the International Conference on IT Security Incident
Management & IT Forensics. This year it took place from May 23 to 24 in Munich.
The schedule lists
a lot of interesting talks.
One of the talks was my presentation on a paper about Ceph forensics, based on
my Master Thesis:
The concept of Software Defined Storage (SDS) has become very popular over the
last few years. It is used in public, private, and hybrid clouds to store
enterprise, private, and other kinds of data. Ceph is an
open-source software that implements an SDS stack.
In Mai 2018, Tobias and me were in Cologne at the Building IoT conference. The
topics of the talks covered a broad spectrum of the Internet of Things field.
There were three tracks covering different topics ranging from the jungle of IoT
protocols, secure Linux hypervisors specially developed for IoT modules to
machine learning and blockchain.
In “How to secure over the air updates” the speaker showed how to securely
deploy updates over the standard communication channel to the target device.
Many consumer IoT devices have a short support for updates if they get any
updates at all. This leads and in the future will lead to bad news like botnets,
bricked devices and exploited IP cameras streaming publicly. Therefore, a patch
and vulnerability management is required – especially in industrial Internet of
Things devices. Some updates have to be performed over the air due to the
physical inaccessibility of some IoT devices in production environments. There
are two possibilities to update such systems: First, a rescue OS (Operating
System) boots and overwrites the existing production OS. The second option is a
redundant OS, which copies the updates to the inactive OS and reboots to that.
From May 8th to 12th I was able to attend the 74th RIPE meeting in Budapest,
Hungary. Being rather new to the networking community, I enjoyed learning a lot
of different things, not only from the various interesting talks but also from
inspiring conversations with a variety of people from all areas during the
beautiful social events.
As it was the first RIPE meeting for me, I was very thankful for the “Newcomer’s
Introduction” on Monday morning, containing a RIPE and RIPE NCC 101. It was
quite helpful to get into the mindset and understand the structure of the
meeting, like the division into different working groups based on the
participants’ interests. After familiarizing myself with the concept, I chose to
attend several sessions on Address Policy, IPv6, Routing, Open Source, and DNS
working groups besides the general plenary sessions. I’ll be reviewing those
sessions here.