Home NDR Monitoring DNS Shield UEBA Analytics RECON Scanner Blog Company Deutsch (DE) Contact
Knowledge Base

Cybersecurity Expertise

In-depth analyses of network security, behavioral analysis and the evolving Swiss cybersecurity landscape.

lan
Incident Analysis / EDR & NDR18 min read

Detected but Not Blocked: What a Web Shell Attack Reveals About the Gap Between EDR and NDR

A real-world incident: the endpoint protection alerted correctly, then the attacker silenced the agent with a kernel module. Two further attack waves remained invisible at the endpoint. IRONATE NDR kept recording and blocked automatically.

Stefan Röthlisberger
Stefan RöthlisbergerRead more →
skull
Threat Analysis / Wiper Malware12 min read

GigaWiper: Anatomy of a Destructive Backdoor That Unites Three Malware Families

In July 2026, Microsoft exposed GigaWiper: a Golang backdoor that bundles disk wiper, Crucio code and FlockWiper into destruction on demand. Analysis, IOCs and defense measures for Swiss organizations.

Stefan Röthlisberger
Stefan RöthlisbergerRead more →
trending_up
Threat Report / Ransomware15 min read

Ransomware in Europe 2026: What the New Numbers Mean for Switzerland

2,066 incidents, +55.1% in spring 2026, concentration in five countries. An assessment of the European ransomware landscape and what it means for Swiss companies.

Stefan Röthlisberger
Stefan RöthlisbergerRead more →
hub
Third-Party Risk / Compliance13 min read

When the Supplier Becomes the Entry Point: Supply Chain Ransomware Under NIS2 and DORA

64 European organizations were hit through their suppliers. What NIS2, DORA, CER and the revised Swiss Data Protection Act (revDSG) mean for supply chain liability, and how continuous visibility helps.

Stefan Röthlisberger
Stefan RöthlisbergerRead more →
lock_open
0-Day / Threat Analysis13 min read

YellowKey, GreenPlasma & Teams: The Chaotic Eclipse Campaign and the BitLocker Bypass in Detail

Three vulnerabilities published on May 13, 2026, one complete attack chain: YellowKey bypasses BitLocker, GreenPlasma escalates to SYSTEM, a Teams flaw delivers initial access. Analysis and immediate measures.

Stefan Röthlisberger
Stefan RöthlisbergerRead more →
radar
NDR / Ransomware12 min read

Ransomware on the Network: How NDR Stops Lateral Movement Before the Damage Is Done

A technical analysis of modern ransomware tactics and how Network Detection & Response forms the decisive line of defense.

Stefan Röthlisberger
Stefan RöthlisbergerRead more →
shield
DNS / Zero Trust10 min read

DNS as the First Line of Defense: Why Zero Trust Remains Incomplete Without DNS Security

Over 90% of all malware uses DNS for C2 communication. A technical deep dive into DNS-based threats and how to defend against them.

Stefan Röthlisberger
Stefan RöthlisbergerRead more →
security
EDR / Ransomware14 min read

EDR Killers Explained: How Attackers Deliberately Disable Endpoint Protection

Analysis of over 90 EDR killers shows: ransomware groups rely on the systematic deactivation of endpoint protection. Why NDR is the decisive complement.

Stefan Röthlisberger
Stefan RöthlisbergerRead more →
breaking_news
Threat Analysis15 min read

FortiGate Under Fire: How Attackers Compromise Firewalls and Take Over Entire Networks

Analysis of the 2024-2026 FortiGate attack wave: five CVEs, stolen credentials, NTDS.dit exfiltration. Why patching alone is not enough and which immediate measures are needed now.

Stefan Röthlisberger
Stefan RöthlisbergerRead more →