Cybersecurity Expertise
In-depth analyses of network security, behavioral analysis and the evolving Swiss cybersecurity landscape.
Detected but Not Blocked: What a Web Shell Attack Reveals About the Gap Between EDR and NDR
A real-world incident: the endpoint protection alerted correctly, then the attacker silenced the agent with a kernel module. Two further attack waves remained invisible at the endpoint. IRONATE NDR kept recording and blocked automatically.

GigaWiper: Anatomy of a Destructive Backdoor That Unites Three Malware Families
In July 2026, Microsoft exposed GigaWiper: a Golang backdoor that bundles disk wiper, Crucio code and FlockWiper into destruction on demand. Analysis, IOCs and defense measures for Swiss organizations.

Ransomware in Europe 2026: What the New Numbers Mean for Switzerland
2,066 incidents, +55.1% in spring 2026, concentration in five countries. An assessment of the European ransomware landscape and what it means for Swiss companies.

When the Supplier Becomes the Entry Point: Supply Chain Ransomware Under NIS2 and DORA
64 European organizations were hit through their suppliers. What NIS2, DORA, CER and the revised Swiss Data Protection Act (revDSG) mean for supply chain liability, and how continuous visibility helps.

YellowKey, GreenPlasma & Teams: The Chaotic Eclipse Campaign and the BitLocker Bypass in Detail
Three vulnerabilities published on May 13, 2026, one complete attack chain: YellowKey bypasses BitLocker, GreenPlasma escalates to SYSTEM, a Teams flaw delivers initial access. Analysis and immediate measures.

Ransomware on the Network: How NDR Stops Lateral Movement Before the Damage Is Done
A technical analysis of modern ransomware tactics and how Network Detection & Response forms the decisive line of defense.

DNS as the First Line of Defense: Why Zero Trust Remains Incomplete Without DNS Security
Over 90% of all malware uses DNS for C2 communication. A technical deep dive into DNS-based threats and how to defend against them.

EDR Killers Explained: How Attackers Deliberately Disable Endpoint Protection
Analysis of over 90 EDR killers shows: ransomware groups rely on the systematic deactivation of endpoint protection. Why NDR is the decisive complement.

FortiGate Under Fire: How Attackers Compromise Firewalls and Take Over Entire Networks
Analysis of the 2024-2026 FortiGate attack wave: five CVEs, stolen credentials, NTDS.dit exfiltration. Why patching alone is not enough and which immediate measures are needed now.
