[{"data":1,"prerenderedAt":938},["ShallowReactive",2],{"post-en-citrix-netscaler-zero-days-update-allein-reicht-nicht":3,"related-en-citrix-netscaler-zero-days-update-allein-reicht-nicht":306},{"id":4,"title":5,"author":6,"body":7,"category":276,"date":277,"description":278,"draft":279,"extension":280,"faq":281,"image":291,"imageAlt":292,"lang":293,"legacyUrl":294,"meta":295,"navigation":296,"path":297,"readingTime":298,"seo":299,"sitemap":300,"stem":301,"tags":302,"translation":304,"updated":294,"__hash__":305},"insightsEn\u002Fen\u002Finsights\u002Fcitrix-netscaler-zero-days-update-allein-reicht-nicht.md","Citrix NetScaler: two zero-days, and patching alone is not enough","blacklens.io Team",{"type":8,"value":9,"toc":267},"minimark",[10,14,19,48,51,79,82,86,89,120,138,142,145,159,167,171,174,245,254],[11,12,13],"p",{},"For many organisations, Citrix NetScaler Gateway is the door through which staff reach the corporate network from outside. Since at least early September, attackers have been opening that door through previously unknown flaws, without logging in and ending up with root. Citrix released updates on 27 September. They close the flaws, but not a backdoor that is already on the device.",[15,16,18],"h2",{"id":17},"what-is-known-about-the-netscaler-zero-days","What is known about the NetScaler zero-days?",[11,20,21,25,26,29,30,37,38,42,43,47],{},[22,23,24],"code",{},"CVE-2026-88771"," and ",[22,27,28],{},"CVE-2026-88772"," are two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway that let attackers run their own code on the device without authenticating. Citrix published them on 27 September 2026 in ",[31,32,36],"a",{"href":33,"rel":34},"https:\u002F\u002Fsupport.citrix.com\u002Fexternal\u002Farticle\u002FCTX697096\u002Fcitrix-netscaler-adc-and-citrix-netscale.html",[35],"nofollow","security bulletin CTX697096",", together with six further flaws, and rated both ",[31,39,41],{"href":40},"\u002Fen\u002Fwissen\u002Fcvss","CVSS"," 9.5 (v4). Citrix has observed both being exploited on unmitigated deployments. The US agency CISA added them to its ",[31,44,46],{"href":45},"\u002Fen\u002Fwissen\u002Fcisa-kev","KEV catalogue"," the same day, and Germany's BSI and Austria's CERT.at issued warnings.",[11,49,50],{},"The flaws affect customer-managed deployments of these versions; Citrix updates the cloud services it runs itself:",[52,53,54,61,67,73],"ul",{},[55,56,57,58],"li",{},"NetScaler ADC and Gateway 14.1 before ",[22,59,60],{},"14.1-73.37",[55,62,63,64],{},"NetScaler ADC and Gateway 13.1 before ",[22,65,66],{},"13.1-64.23",[55,68,69,70],{},"NetScaler ADC FIPS 14.1 before ",[22,71,72],{},"14.1-73.37 FIPS",[55,74,75,76],{},"NetScaler ADC FIPS and NDcPP 13.1 before ",[22,77,78],{},"13.1-37.279",[11,80,81],{},"The Shadowserver Foundation counts more than 20,000 NetScaler instances reachable from the internet and potentially at risk. How many were compromised is unknown. Citrix has disclosed neither the scope nor the timing of the attacks, and as of 30 September no threat actor had been named.",[15,83,85],{"id":84},"how-the-attacks-on-netscaler-work","How the attacks on NetScaler work",[11,87,88],{},"Both flaws end in command execution on the device before anyone has logged in, by different routes.",[52,90,91,106],{},[55,92,93,99,100,105],{},[94,95,96,98],"strong",{},[22,97,24],{},", commands via the device's own log:"," It affects every deployment in its default configuration. ",[31,101,104],{"href":102,"rel":103},"https:\u002F\u002Fcert.europa.eu\u002Fblog\u002Ftaking-execute-logging-a-bit-too-literally-cve-2026-88771",[35],"CERT-EU's analysis"," describes a script that, after a Packet Engine failure, searches the log files for the name of the crash dump and inserts the match unquoted into a shell command. Attackers write crafted lines into the log without authenticating, and the script executes them.",[55,107,108,113,114,119],{},[94,109,110,112],{},[22,111,28],{},", memory overflow via DTLS:"," It requires DTLS, which is enabled by default on VPN virtual servers and therefore on most gateways. According to ",[31,115,118],{"href":116,"rel":117},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Fdefending-against-active-exploitation-of-citrix-netscaler-adc-and-gateway-appliances",[35],"Mandiant and Google Threat Intelligence",", attackers send fragmented, malformed DTLS packets to UDP port 443. These corrupt the Packet Engine's heap memory and yield root privileges on the underlying FreeBSD system.",[11,121,122,123,126,127,25,130,133,134,137],{},"Mandiant has documented what happens next at government bodies, financial services firms, education institutions and legal and professional services firms in North America and Europe. The attackers modify the web server configuration ",[22,124,125],{},"\u002Fetc\u002Fhttpd.conf"," so that files ending in ",[22,128,129],{},".sig",[22,131,132],{},".deb"," run as PHP. The WHIPSHOT web shell then receives Base64-encoded commands in HTTP headers such as ",[22,135,136],{},"NSC_LDAP",". The Python tool SLAPSHOT serves as a tunnel into the internal network: for reconnaissance, credential theft and moving on to other systems.",[15,139,141],{"id":140},"why-the-update-alone-is-not-enough","Why the update alone is not enough",[11,143,144],{},"The update closes the flaws but removes neither a web shell nor stolen credentials. Mandiant states explicitly that patching does not remove an existing compromise. By Mandiant's account, the attacks have been running since at least early September, and security researcher Kevin Beaumont describes attacks unfolding throughout the month. CERT-EU therefore recommends a compromise assessment for every internet-facing appliance running an affected build.",[11,146,147,148,151,152,25,155,158],{},"The August update is a second trap. On 19 August, Citrix fixed ",[22,149,150],{},"CVE-2026-19490",", an authentication bypass (CVSS 9.3), in builds ",[22,153,154],{},"14.1-73.32",[22,156,157],{},"13.1-63.21",". Those builds are below the new minimum versions and remain vulnerable. Patching quickly in August is not enough now.",[11,160,161,162,166],{},"A NetScaler Gateway also accepts VPN logins and queries LDAP or RADIUS servers behind it. Anyone with root on it sees the credentials and sessions passing through. The pattern is familiar from ",[31,163,165],{"href":164},"\u002Fen\u002Finsights\u002Ffortibleed-wenn-zehntausende-firewalls-zur-offenen-tur-werden","FortiBleed",": the compromised perimeter device becomes a collection point for credentials.",[15,168,170],{"id":169},"what-helps-and-why-visibility-is-decisive","What helps – and why visibility is decisive",[11,172,173],{},"Order matters, because the reboot after the update wipes evidence held in memory:",[175,176,177,183,189,214,239],"ol",{},[55,178,179,182],{},[94,180,181],{},"Check the inventory:"," record every NetScaler instance, including test, disaster-recovery and HA partner devices, and compare the build number against the minimum versions above.",[55,184,185,188],{},[94,186,187],{},"Preserve evidence:"," before updating, the Dutch NCSC advises backing up memory and at least one month of log files. For virtual appliances, Mandiant recommends a snapshot that includes memory.",[55,190,191,194,195,198,199,202,203,205,206,209,210,213],{},[94,192,193],{},"Check for compromise:"," unfamiliar ",[22,196,197],{},"AddHandler"," or ",[22,200,201],{},"AliasMatch"," entries in ",[22,204,125],{},", PHP files under ",[22,207,208],{},"\u002Fvar\u002Fnetscaler\u002Fgui\u002F",", a SUID bit on ",[22,211,212],{},"\u002Fbin\u002Fsh",", and log entries reading \"PPE missed too many heartbeats\" alongside Base64 text in the User-Agent. Mandiant provides hunting commands and YARA rules.",[55,215,216,219,220,198,222,224,225,228,229,234,235,238],{},[94,217,218],{},"Update:"," to ",[22,221,60],{},[22,223,66],{},", or the corresponding FIPS and NDcPP builds. For ",[22,226,227],{},"CVE-2026-88778",", ",[31,230,233],{"href":231,"rel":232},"https:\u002F\u002Fwww.cert.at\u002Fde\u002Fwarnungen\u002F2026\u002F9\u002Fkritische-sicherheitslucken-in-citrix-netscaler-adc-und-netscaler-gateway-aktiv-ausgenutzt-updates-verfugbar",[35],"CERT.at"," (in German) also recommends ",[22,236,237],{},"set ns tcpparam -enhancedISNgeneration ENABLED",".",[55,240,241,244],{},[94,242,243],{},"Renew credentials:"," rotate admin passwords, SSH keys, TLS certificates and LDAP, RADIUS and API credentials, and terminate active admin, VPN and ICA sessions.",[11,246,247,248,250,251,253],{},"If you cannot update immediately, disabling DTLS or blocking UDP port 443 upstream reduces the risk from ",[22,249,28],{},". It does nothing against ",[22,252,24],{},": that flaw has no precondition, and Citrix lists no workaround.",[11,255,256,257,261,262,266],{},"In weeks like this, the inventory takes the longest: which NetScaler instances exist and which are reachable from the internet. blacklens.io builds that inventory continuously from the outside through ",[31,258,260],{"href":259},"\u002Fen\u002Fplatform\u002Fattack-surface-management","Attack Surface Management",", including devices nobody internally remembers. The ",[31,263,265],{"href":264},"\u002Fen\u002Fplatform\u002Femerging-threats","Threat Center"," matches new CVEs like these against the detected technologies, flags KEV entries with the date added and due date, and confirms affected systems with a verification scan where a verification template exists. It does not detect a web shell on the device; that check remains work on the appliance itself.",{"title":268,"searchDepth":269,"depth":269,"links":270},"",3,[271,273,274,275],{"id":17,"depth":272,"text":18},2,{"id":84,"depth":272,"text":85},{"id":140,"depth":272,"text":141},{"id":169,"depth":272,"text":170},"threat","2026-09-30","Two zero-days in Citrix NetScaler ADC and Gateway are under active exploitation: which builds are affected and what to do before and after updating.",false,"md",[282,285,288],{"q":283,"a":284},"What are CVE-2026-88771 and CVE-2026-88772?","CVE-2026-88771 and CVE-2026-88772 are two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway, rated CVSS 9.5, that let attackers run code on the device without authenticating. Citrix released updates on 27 September 2026 and confirms active exploitation. CVE-2026-88771 affects every deployment in its default configuration; CVE-2026-88772 affects devices with DTLS enabled, the default on VPN virtual servers. Both are fixed from builds 14.1-73.37 and 13.1-64.23.",{"q":286,"a":287},"Is updating Citrix NetScaler enough after the zero-days?","Updating Citrix NetScaler to 14.1-73.37 or 13.1-64.23 closes the flaws but does not remove a backdoor that attackers have already installed. According to Mandiant, the attacks had been running since at least early September and left web shells and tunnelling tools behind. Before updating, back up logs and memory and check the device for compromise; afterwards, renew passwords, certificates and service accounts and terminate active sessions. The August update does not protect against these flaws either.",{"q":289,"a":290},"How does blacklens.io help find affected NetScaler systems?","blacklens.io uses Attack Surface Management to continuously identify which of an organisation's systems are reachable from the internet and which technologies run on them, including NetScaler gateways. The Threat Center matches new CVEs against this inventory, flags entries in the CISA KEV catalogue with date added and due date, and confirms affected systems with a verification scan where a verification template exists. A compromise on the device itself, such as a web shell, still has to be investigated on the device.","\u002Fimages\u002Finsights\u002Fcitrix-netscaler-zero-days-update-allein-reicht-nicht.webp","Hooded figure with a hidden face in front of blurred lines of code","en",null,{},true,"\u002Fen\u002Finsights\u002Fcitrix-netscaler-zero-days-update-allein-reicht-nicht",4,{"title":5,"description":278},{"loc":297},"en\u002Finsights\u002Fcitrix-netscaler-zero-days-update-allein-reicht-nicht",[303],"Threat landscape","citrix-netscaler-zero-days-update-allein-reicht-nicht","vuUX3gg10P6lsBk0bqGskTTBtJw5D16CBJVpWmSX9LY",[307,504,686],{"id":308,"title":309,"author":6,"body":310,"category":477,"date":478,"description":479,"draft":279,"extension":280,"faq":480,"image":490,"imageAlt":491,"lang":293,"legacyUrl":294,"meta":492,"navigation":296,"path":493,"readingTime":269,"seo":494,"sitemap":495,"stem":499,"tags":500,"translation":502,"updated":294,"__hash__":503},"insightsEn\u002Fen\u002Finsights\u002Fthreat-center-neue-cves-automatisch-verifiziert.md","Threat Center: From CVE alarm to confirmed exposure",{"type":8,"value":311,"toc":470},[312,315,319,322,325,329,332,335,368,372,375,382,390,394,397,428,434,441,445,448,456],[11,313,314],{},"Critical new vulnerabilities in firewalls, VPN gateways and mail servers now arrive week after week. The question that matters is never whether there is a new CVE. It is whether it affects your organisation. The Threat Center in blacklens.io answers exactly that: automatically, for your systems, with evidence.",[15,316,318],{"id":317},"what-is-the-threat-center","What is the Threat Center?",[11,320,321],{},"The Threat Center is the blacklens.io early warning system for new vulnerabilities. It continuously matches newly published CVEs against the technologies your organisation runs and shows only the matches that really affect you. It builds on the inventory blacklens.io already creates from external scans, the Sentry agent and your cloud connectors. There is nothing extra to set up.",[11,323,324],{},"Behind it sits a threat feed of more than 140,000 CVEs, over 26,000 of them with a public exploit. From that volume, your team gets the short list of vulnerabilities that apply to your firewall, your Exchange server or your Citrix gateway.",[15,326,328],{"id":327},"why-a-cve-newsletter-is-no-longer-enough","Why a CVE newsletter is no longer enough",[11,330,331],{},"CVE newsletters and CERT warnings matter, but they are written for everyone. Whether the product runs in your environment, in which version and on which system, your team has to work out afterwards. With several critical notices a week, that search costs hours, and those are the hours in which attackers start scanning.",[11,333,334],{},"The Threat Center reverses the order. Instead of a general warning, you get a list of affected systems, each with the signals that matter for prioritisation:",[52,336,337,347,355,361],{},[55,338,339,346],{},[94,340,341,345],{},[31,342,344],{"href":343},"\u002Fen\u002Fwissen\u002Fepss","EPSS",":"," how likely is exploitation within the next 30 days?",[55,348,349,354],{},[94,350,351,345],{},[31,352,353],{"href":45},"CISA KEV"," is the vulnerability already under active attack, and by when should it be fixed?",[55,356,357,360],{},[94,358,359],{},"Exploit:"," is attack code publicly available?",[55,362,363,367],{},[94,364,365,345],{},[31,366,41],{"href":40}," how severe is the vulnerability technically?",[15,369,371],{"id":370},"from-warning-to-certainty","From warning to certainty",[11,373,374],{},"A match in the inventory is a suspicion. So blacklens.io checks it: where a verification template exists for the CVE, a targeted scan against the affected system starts automatically. The result is clear, either confirmed or not confirmed. Your team spends its time on real findings, not guesswork.",[11,376,377],{},[378,379],"img",{"alt":380,"src":381},"Threat detail view in the Threat Center with CVSS 10, EPSS score, CISA KEV due date and a running verification scan","\u002Fimages\u002Finsights\u002Fthreat-center-neue-cves-automatisch-verifiziert-2.webp",[11,383,384,385,389],{},"The detail view shows at a glance how critical a vulnerability is, whether it is already being exploited and which systems are affected. Confirmed matches become regular findings in the same ",[31,386,388],{"href":387},"\u002Fen\u002Fwissen\u002Fvulnerability-management","vulnerability management"," workflow as everything else, with assignment, ticket and retest.",[15,391,393],{"id":392},"fewer-alarms-more-impact","Fewer alarms, more impact",[11,395,396],{},"An early warning system that rings all the time gets ignored. The Threat Center is built to stay quiet:",[52,398,399,405,411,422],{},[55,400,401,404],{},[94,402,403],{},"Threshold per workspace:"," alerts start at a CVSS score of your choice, 7 by default.",[55,406,407,410],{},[94,408,409],{},"Grouped, not one by one:"," new CVEs for the same product produce one alert, not dozens.",[55,412,413,416,417,421],{},[94,414,415],{},"To the right team:"," notification policies route alerts by e-mail, push or through ",[31,418,420],{"href":419},"\u002Fen\u002Fplatform\u002Fintegrations","integrations"," such as Jira, Microsoft Teams and Microsoft Sentinel.",[55,423,424,427],{},[94,425,426],{},"Escalated automatically:"," when exploitation is likely and an exploit is available, urgency rises on its own.",[11,429,430],{},[378,431],{"alt":432,"src":433},"Alert list with grouped threat intel alerts, such as \"35 Emerging CVEs may affect Microsoft Sql Server\"","\u002Fimages\u002Finsights\u002Fthreat-center-neue-cves-automatisch-verifiziert-4.webp",[11,435,436,437,440],{},"The ",[94,438,439],{},"Advisories"," view adds vendor security notices, so broader warnings sit in the same tool.",[15,442,444],{"id":443},"what-this-means-for-your-organisation","What this means for your organisation",[11,446,447],{},"The time between a vulnerability's disclosure and the first attack is the window in which you can act. The Threat Center shortens the path from \"a new CVE is out\" to \"these systems are affected, it is confirmed, and the responsible team has the ticket\".",[11,449,450,451,455],{},"At the same time, it builds a traceable record of which vulnerabilities were detected, checked and handled. That helps in audits and with requirements such as ",[31,452,454],{"href":453},"\u002Fen\u002Fwissen\u002Fnis2","NIS2",", which call for structured vulnerability handling.",[11,457,458,461,462,465,466,469],{},[94,459,460],{},"Get started:"," the Threat Center is active in blacklens.io under ",[94,463,464],{},"Threat Center → Emerging Threats"," as soon as your technology inventory is in place. Read more about the ",[31,467,468],{"href":264},"early warning system for zero-days and new CVEs"," on the platform page.",{"title":268,"searchDepth":269,"depth":269,"links":471},[472,473,474,475,476],{"id":317,"depth":272,"text":318},{"id":327,"depth":272,"text":328},{"id":370,"depth":272,"text":371},{"id":392,"depth":272,"text":393},{"id":443,"depth":272,"text":444},"release","2026-09-24","The blacklens.io Threat Center is your early warning system for new vulnerabilities: it shows which CVEs affect your systems and confirms it by scan.",[481,484,487],{"q":482,"a":483},"What does the blacklens.io Threat Center do?","The Threat Center is the blacklens.io early warning system for new vulnerabilities. It continuously matches newly published CVEs against the technologies your organisation actually runs and shows only the matches that affect you. Where a verification template exists, a targeted scan automatically confirms whether your system is vulnerable. Signals such as EPSS and CISA KEV show what needs fixing first.",{"q":485,"a":486},"How do I know whether a new vulnerability affects my organisation?","Whether a new vulnerability affects your organisation depends on whether the named product runs in an affected version in your environment and whether it can be reached. That requires an up-to-date inventory of your technologies. An early warning system such as the Threat Center matches new CVEs against this inventory automatically and checks the affected systems by scan, instead of your team chasing every warning by hand.",{"q":488,"a":489},"How does the Threat Center prevent alert fatigue?","The Threat Center only raises alerts above a CVSS threshold you set per workspace, 7 by default. blacklens.io groups new CVEs for the same product into a single alert instead of reporting each one. Notification policies route alerts by severity to the right team, by e-mail, push or through integrations such as Jira, Microsoft Teams and Microsoft Sentinel. Every match stays visible in the list.","\u002Fimages\u002Finsights\u002Fthreat-center-neue-cves-automatisch-verifiziert.webp","Emerging Threats list in the blacklens.io Threat Center with new CVEs, state and risk signals per technology",{},"\u002Fen\u002Finsights\u002Fthreat-center-neue-cves-automatisch-verifiziert",{"title":309,"description":479},{"loc":493,"images":496},[497,498],{"loc":381},{"loc":433},"en\u002Finsights\u002Fthreat-center-neue-cves-automatisch-verifiziert",[501],"Release notes","threat-center-neue-cves-automatisch-verifiziert","wEIzwGFMdqPmNnfyQFG5AXJO_wvJ_zy5tF6u2YMMIHE",{"id":505,"title":506,"author":6,"body":507,"category":661,"date":662,"description":663,"draft":279,"extension":280,"faq":664,"image":674,"imageAlt":675,"lang":293,"legacyUrl":294,"meta":676,"navigation":296,"path":677,"readingTime":678,"seo":679,"sitemap":680,"stem":681,"tags":682,"translation":684,"updated":294,"__hash__":685},"insightsEn\u002Fen\u002Finsights\u002Fnisg-2026-oesterreich-fristen-nachweise.md","NISG 2026: Austria's NIS2 deadlines from 1 October",{"type":8,"value":508,"toc":653},[509,512,516,519,522,542,545,549,556,559,563,566,569,573,576,582,588,594,598,630,634,645],[11,510,511],{},"Austria's Network and Information System Security Act 2026 enters into force on 1 October 2026, nine months\nafter its publication. From that day, deadlines run that cannot be extended: three months to register,\ntwelve months to file the self-declaration. Anyone who starts collecting evidence once the authority asks\nwill be describing the state of yesterday.",[15,513,515],{"id":514},"what-the-nisg-2026-requires-from-1-october","What the NISG 2026 requires from 1 October",[11,517,518],{},"The NISG 2026 transposes Directive (EU) 2022\u002F2555 into Austrian law, and it applies from the day it enters\ninto force, not from the day you register. It was published on 23 December 2025 as BGBl. I No. 94\u002F2025,\nafter the Nationalrat passed it on 12 December 2025 with the two-thirds majority its constitutional\nprovisions require. Supervision and enforcement sit with the cyber security authority at the Ministry of\nthe Interior.",[11,520,521],{},"Three deadlines shape the next twelve months:",[52,523,524,530,536],{},[55,525,526,529],{},[94,527,528],{},"Registration:"," within three months of entry into force, so by the end of December 2026.",[55,531,532,535],{},[94,533,534],{},"Self-declaration:"," within twelve months of the registration obligation arising. The structured\ndeclaration covers the network and information systems in use, supply chain security and the results of\nthe risk analysis. What is new is that it is due on a fixed deadline rather than on request.",[55,537,538,541],{},[94,539,540],{},"Incident reporting:"," an early warning without undue delay and within 24 hours at the latest, a full\nnotification within 72 hours, and a final report within one month.",[11,543,544],{},"Penalties follow the directive: up to 10 million euros or 2 per cent of global annual turnover for\nessential entities, up to 7 million euros or 1.4 per cent for important ones. Accountability sits with the\nmanagement body, not with the IT department.",[15,546,548],{"id":547},"who-is-affected-in-austria","Who is affected in Austria",[11,550,551,552,555],{},"You are affected if you operate in one of the directive's 18 sectors and meet the size thresholds: as a\nrule from 50 employees or 10 million euros in turnover, and in some sectors regardless of size. The act\ndistinguishes between essential and important entities, which determines both supervisory intensity and\nthe maximum penalty. The glossary entry on the ",[31,553,554],{"href":453},"NIS2 directive"," sets out the\nclassification in detail.",[11,557,558],{},"Nobody makes that assessment for you. There is no official notice establishing that you are in scope and\nno letter marking the start: the assessment itself is part of the obligation. That is where companies which\ndo not think of themselves as critical tend to fail — suppliers in manufacturing, for instance, or\noperators running data centre services for others.",[15,560,562],{"id":561},"in-germany-the-deadline-has-already-passed","In Germany the deadline has already passed",[11,564,565],{},"Germany went down the same road nine months earlier. The NIS2 implementation act entered into force on\n6 December 2025, the BSI registration portal has been live since 6 January 2026, and the original\nregistration deadline of 6 March 2026 was extended to 31 July 2026. That date has passed; anyone not\nregistered by now risks supervisory measures regardless of whether an incident has ever occurred.",[11,567,568],{},"For companies with sites in both countries this means two registrations, two authorities and two reporting\npaths. The technical evidence underneath can be the same, provided it is built from the start to serve\nboth supervisory logics.",[15,570,572],{"id":571},"where-the-self-declaration-comes-unstuck","Where the self-declaration comes unstuck",[11,574,575],{},"The self-declaration does not ask for intentions, it asks for results. Three of its elements are the\nhardest to produce in practice, because they do not come from a document but from a running process.",[11,577,578,581],{},[94,579,580],{},"The inventory."," Which systems are reachable from the internet, running which services, since when? A\nlist from the last audit describes a state that no longer exists: subdomains get created, test environments\nstay open, cloud resources appear without a ticket.",[11,583,584,587],{},[94,585,586],{},"Vulnerability handling."," Article 21(2) of the directive explicitly names vulnerability handling and\ndisclosure. You cannot evidence that with scanner output alone; you evidence it with a chain: found on,\nassessed by, decided by, fixed by. An annual penetration test gives you a snapshot, not a chain.",[11,589,590,593],{},[94,591,592],{},"The supply chain."," The directive requires you to account for risks arising from relationships with\nsuppliers and service providers. That includes incidents that happen at a supplier and only reach you\nthrough them — when their data shows up on a leak site, for example.",[15,595,597],{"id":596},"what-you-can-prepare-in-the-coming-weeks","What you can prepare in the coming weeks",[175,599,600,606,612,618,624],{},[55,601,602,605],{},[94,603,604],{},"Assess and document whether you are in scope."," Sector, size, classification, with a date and a\nrationale. A well-argued \"no\" is evidence too.",[55,607,608,611],{},[94,609,610],{},"Name the accountable people."," The management body is liable and must approve and oversee the measures.",[55,613,614,617],{},[94,615,616],{},"Map the external attack surface."," Not the systems listed in your documentation, but the ones that\nanswer from outside.",[55,619,620,623],{},[94,621,622],{},"Put deadlines on the vulnerability process."," Who prioritises, by which criterion, within what time.\nWithout a deadline it is a list, not a process.",[55,625,626,629],{},[94,627,628],{},"Rehearse the reporting path."," 24 hours is short if the question of who reports what to whom is only\nsettled during the incident.",[15,631,633],{"id":632},"what-blacklensio-contributes","What blacklens.io contributes",[11,635,636,637,639,640,644],{},"blacklens.io provides the technical part of that evidence base: a continuously updated inventory of\nexternally reachable systems with an exposure score, internal scans through the Sentry agent, cloud\nconfiguration and dark web findings in one shared findings workflow, plus a supplier watchlist that polls\nransomware leak sites roughly every 30 minutes. Prioritisation draws on EPSS, the CISA KEV catalogue,\navailable exploits and ",[31,638,41],{"href":40},", so the reasoning behind an order of work is documented rather than\nreconstructed afterwards. Scheduled reports and CSV export hand those records, dated, to your ISMS or GRC\nsystem; which evidence maps to which requirement is set out on the\n",[31,641,643],{"href":642},"\u002Fen\u002Fcompliance\u002Fnis2","NIS2 and vulnerability management"," page.",[11,646,647,648,652],{},"One detail that matters for Austrian entities: scanning runs exclusively from Austria, Germany and\nSwitzerland, and the platform is hosted in ISO 27001 and SOC 2 certified data centres in the DACH region.\nNone of this replaces a management system, and this article is technical orientation, not legal advice —\nwhich obligations apply to you specifically is a question for your legal team, your auditor or the\nauthority. What blacklens.io adds is the part a document cannot provide:\n",[31,649,651],{"href":650},"\u002Fen\u002Fplatform\u002Fvulnerability-management","continuous vulnerability data"," instead of a snapshot.",{"title":268,"searchDepth":269,"depth":269,"links":654},[655,656,657,658,659,660],{"id":514,"depth":272,"text":515},{"id":547,"depth":272,"text":548},{"id":561,"depth":272,"text":562},{"id":571,"depth":272,"text":572},{"id":596,"depth":272,"text":597},{"id":632,"depth":272,"text":633},"guide","2026-09-22","Austria's NISG 2026 enters into force on 1 October. Which deadlines apply for registration and self-declaration, and what evidence you need to produce them.",[665,668,671],{"q":666,"a":667},"When does Austria's NISG 2026 enter into force?","The Network and Information System Security Act 2026 enters into force on 1 October 2026. It was published on 23 December 2025 as BGBl. I No. 94\u002F2025, after the Nationalrat passed it on 12 December 2025 with the required two-thirds majority. The act takes effect nine months after publication, on the first day of the following month, and transposes Directive (EU) 2022\u002F2555 into Austrian law.",{"q":669,"a":670},"By when must affected entities in Austria register?","Affected entities must register with the cyber security authority within three months of the act entering into force, so by the end of December 2026. The self-declaration follows: within twelve months of the registration obligation arising, entities submit a structured declaration covering the network and information systems they use, supply chain security and the results of their risk analysis.",{"q":672,"a":673},"How does the Austrian implementation differ from the German one?","Germany's NIS2 implementation act entered into force on 6 December 2025, the BSI registration portal has been live since 6 January 2026, and the extended registration deadline expired on 31 July 2026. In Austria this cycle only starts on 1 October 2026. Companies with sites in both countries face two separate registration duties, but can base both on the same body of technical evidence.","\u002Fimages\u002Finsights\u002Fnisg-2026-oesterreich-fristen-nachweise.webp","Person holding a tablet with a green NIS2 shield above it, ringed by the twelve EU stars",{},"\u002Fen\u002Finsights\u002Fnisg-2026-oesterreich-fristen-nachweise",5,{"title":506,"description":663},{"loc":677},"en\u002Finsights\u002Fnisg-2026-oesterreich-fristen-nachweise",[683],"Guide","nisg-2026-oesterreich-fristen-nachweise","GMFZ-LCt2nm3MQRr3hCh3KW1U5AXP_EMnxsOsbImL90",{"id":687,"title":688,"author":6,"body":689,"category":477,"date":915,"description":916,"draft":279,"extension":280,"faq":917,"image":927,"imageAlt":294,"lang":293,"legacyUrl":294,"meta":928,"navigation":296,"path":929,"readingTime":678,"seo":930,"sitemap":931,"stem":934,"tags":935,"translation":936,"updated":294,"__hash__":937},"insightsEn\u002Fen\u002Finsights\u002Fwas-zuerst-intelligente-schwachstellen-priorisierung-mit-blacklens.md","What First? Intelligent Vulnerability Prioritisation with blacklens",{"type":8,"value":690,"toc":907},[691,696,704,710,714,721,750,753,757,760,803,806,811,815,822,841,845,851,875,879,890,894,897],[692,693,695],"h1",{"id":694},"what-first-intelligent-vulnerability-prioritisation-with-blacklens","What first? Intelligent vulnerability prioritisation with blacklens",[11,697,698,699,703],{},"The uncomfortable truth in vulnerability management: the problem is rarely ",[700,701,702],"em",{},"finding"," vulnerabilities. The problem is spotting, among a thousand findings, the ten that really matter today. Anyone who works through the list by raw CVSS score burns time on findings that will never be exploited – while the one genuinely reachable, genuinely exploitable flaw waits in row 847 of the spreadsheet.",[11,705,706,707],{},"With its latest release, blacklens answers the three questions on which prioritisation really hinges: ",[94,708,709],{},"What first? Why that one? And how do we fix it?",[15,711,713],{"id":712},"a-plan-instead-of-a-spreadsheet-the-remediation-plan","A plan instead of a spreadsheet: the Remediation Plan",[11,715,716,717,720],{},"Under ",[94,718,719],{},"Vulnerabilities → Remediation",", blacklens generates a prioritised action plan from all open findings at the push of a button – external, internal and cloud considered together:",[52,722,723,729,735,741],{},[55,724,725,728],{},[94,726,727],{},"Grouped by the fix, not by the finding."," An outdated TLS setup on twelve hosts is not a dozen tasks but one. The plan bundles findings by the measure that fixes them together.",[55,730,731,734],{},[94,732,733],{},"Sorted by risk reduction."," At the top sits the cluster with the greatest leverage – by severity and breadth. Not the loudest one, the most effective one.",[55,736,737,740],{},[94,738,739],{},"With rationale and instructions."," Each cluster explains why it sits where it does, estimates the effort (low \u002F medium \u002F high) and provides numbered steps, including copy-ready code where appropriate.",[55,742,743,746,747,238],{},[94,744,745],{},"Progress you can see."," While your team works, the plan stays stable – only the counters move: completed steps, resolved instances, coverage of open findings. Right up to ",[700,748,749],{},"\"Plan complete — nice work\"",[11,751,752],{},"Generation takes around 30–60 seconds, and you can keep working in the meantime. The result changes your team's unit of work: no longer \"finding by finding\" but \"step by step\" – with visible movement instead of an endless backlog.",[15,754,756],{"id":755},"prioritising-means-understanding-context-on-every-finding","Prioritising means understanding: context on every finding",[11,758,759],{},"A good order needs good reasons. That is why every finding – external, internal and cloud – gets an explanation layer that makes prioritisation decisions robust:",[52,761,762,781,787,797],{},[55,763,764,767,768,228,771,228,774,198,777,780],{},[94,765,766],{},"Urgency with evidence:"," A suggested rating along with an exploit status chip – ",[700,769,770],{},"Exploit available",[700,772,773],{},"PoC public",[700,775,776],{},"No known exploit",[700,778,779],{},"Exploitability unknown",". The platform severity remains authoritative; the assessment supplements it, it does not override it.",[55,782,783,786],{},[94,784,785],{},"Threat intelligence per CVE:"," CVSS, EPSS (probability of exploitation in the wild within 30 days), exploit\u002FPoC availability, attack vector and advisory link – from the blacklens threat feed. Exactly the data you need to tell \"high\" from \"urgent\".",[55,788,789,792,793,796],{},[94,790,791],{},"Root cause, impact and remediation:"," Why the finding exists, what it exposes and how it is closed – in 1–6 concrete steps. Plus ",[94,794,795],{},"compensating controls"," for the realistic case that the actual fix has to wait.",[55,798,799,802],{},[94,800,801],{},"Follow-up questions right on the finding:"," A chat beneath the analysis answers follow-up questions in the real context of your workspace – the actual service fingerprint, the affected hosts, the same finding on other systems.",[11,804,805],{},"The analyses are generated on request, cached transparently with a timestamp and visibly carry a note to review generated content before taking critical steps. The decision stays with your team – it just gets considerably faster.",[11,807,808],{},[378,809],{"alt":268,"src":810},"\u002Fimages\u002Finsights\u002F6a8eab8037efc3396911b5c6_Screenshot-2026-08-26-at-10.59.14.png",[15,812,814],{"id":813},"prioritisation-beyond-the-cve-which-lookalike-domain-is-dangerous","Prioritisation beyond the CVE: which lookalike domain is dangerous?",[11,816,817,818,821],{},"With typosquatting, too, the question is never \"are there lookalikes?\" but \"which of them is a problem?\". The new detail view provides the basis for that decision: a character diff against your domain, registration and DNS data, a reputation score – and risk badges such as ",[700,819,820],{},"Mail capable"," that show at a glance whether a domain has everything credential phishing needs.",[11,823,824,825,828,829,832,833,836,837,840],{},"On demand, blacklens goes one step further: it captures what the domain actually serves, including a screenshot, and assesses whether it imitates your brand. ",[94,826,827],{},"Evidence and assessment stay cleanly separated",": ",[700,830,831],{},"Observed on the page"," lists objective signals extracted by blacklens itself – a password field, the brand name, a form posting to a foreign domain – while the ",[700,834,835],{},"Assessment"," is the interpretation. Only once the evidence is complete (the checklist shows 5\u002F5) is the ",[94,838,839],{},"Draft abuse report"," unlocked: a pre-filled, factual email to the registrar's abuse contact. Sending it is up to you.",[15,842,844],{"id":843},"getting-to-the-right-view-faster-ask-instead-of-building-filters","Getting to the right view faster: ask instead of building filters",[11,846,847,848,238],{},"Prioritisation often starts with a simple question: \"Show me critical findings on prod hosts.\" That is exactly how you can ask it now – on 17 dashboard lists, blacklens translates the description into a ready-made, editable filter query with a preview. The language model never sees your data at any point, only field names, types and permitted values – and nothing runs until you click ",[700,849,850],{},"Apply filters",[11,852,853,854,228,857,228,860,863,864,867,868,198,871,874],{},"Complementing this is the new status strip above every attack surface list: five metrics per page – such as ",[700,855,856],{},"Exposing",[700,858,859],{},"Vulnerable",[700,861,862],{},"High risk"," – many of them clickable as filters. And a principle we like to quote: ",[94,865,866],{},"Unknown never counts as safe."," Tiles such as ",[700,869,870],{},"Public",[700,872,873],{},"No MFA"," only count what a provider has explicitly reported.",[15,876,878],{"id":877},"on-your-terms","On your terms",[11,880,881,882,885,886,889],{},"The intelligent features of this release – Remediation Plan, finding explanations, domain verdicts, natural-language search – are ",[94,883,884],{},"opt-in per workspace"," and switched off initially after the update. Workspace admins decide under ",[94,887,888],{},"Settings → General → AI Features",", and \"off\" means off: the server rejects such requests for deactivated workspaces. The analyses run on our self-hosted LLM and are GDPR-compliant – your data never leaves our infrastructure.",[15,891,893],{"id":892},"conclusion","Conclusion",[11,895,896],{},"Less time sorting, more time fixing: this release turns the flood of findings into a reasoned order – a plan with the greatest risk leverage at the top, context and threat intelligence on every finding, evidence instead of gut feeling for lookalike domains. The intelligence lies in the prioritisation. Control stays with you.",[11,898,899,901,902,904,905,238],{},[94,900,460],{}," Workspace admins enable the features under ",[700,903,888],{},". After that, your first Remediation Plan is waiting under ",[700,906,719],{},{"title":268,"searchDepth":269,"depth":269,"links":908},[909,910,911,912,913,914],{"id":712,"depth":272,"text":713},{"id":755,"depth":272,"text":756},{"id":813,"depth":272,"text":814},{"id":843,"depth":272,"text":844},{"id":877,"depth":272,"text":878},{"id":892,"depth":272,"text":893},"2026-09-02","What first, why, and how? blacklens turns open findings into a prioritised remediation plan – sorted by risk reduction, with context on every finding.",[918,921,924],{"q":919,"a":920},"What is the blacklens Remediation Plan?","The Remediation Plan, found under Vulnerabilities → Remediation, turns all open external, internal and cloud findings into a prioritised action plan at the push of a button. Findings are grouped by the fix that resolves them, sorted by risk reduction and delivered with a rationale, an effort estimate and numbered steps, while progress counters update as your team works through the plan.",{"q":922,"a":923},"How does blacklens help prioritise vulnerabilities beyond the CVSS score?","Every finding receives an explanation layer with a suggested urgency, an exploit status chip and threat intelligence per CVE, including CVSS, EPSS, exploit or PoC availability, attack vector and advisory link. Root cause, impact, remediation steps and compensating controls are provided, and a chat on the finding answers follow-up questions in the context of your workspace.",{"q":925,"a":926},"Are the AI features in blacklens enabled by default, and where does the data go?","No. Remediation Plan, finding explanations, domain verdicts and natural-language search are opt-in per workspace and switched off after the update; workspace admins enable them under Settings → General → AI Features. The analyses run on blacklens' self-hosted LLM and are GDPR-compliant, so your data does not leave the blacklens infrastructure.","\u002Fimages\u002Finsights\u002F6a8eab1862da2619b8478b7d_Screenshot-2026-08-26-at-10.59.51.png",{},"\u002Fen\u002Finsights\u002Fwas-zuerst-intelligente-schwachstellen-priorisierung-mit-blacklens",{"title":688,"description":916},{"loc":929,"images":932},[933],{"loc":810},"en\u002Finsights\u002Fwas-zuerst-intelligente-schwachstellen-priorisierung-mit-blacklens",[501],"was-zuerst-intelligente-schwachstellen-priorisierung-mit-blacklens","e1t1-bD9PIM1yFeHDE2AjNbJbYmYRx1HL1rehDCrysg",1790835183103]