[{"data":1,"prerenderedAt":869},["ShallowReactive",2],{"post-en-einheitliches-cloud-schwachstellen-scanning-nis2-compliance-und-cloud":3,"related-en-einheitliches-cloud-schwachstellen-scanning-nis2-compliance-und-cloud":447},{"id":4,"title":5,"author":6,"body":7,"category":425,"date":426,"description":427,"draft":428,"extension":429,"faq":430,"image":431,"imageAlt":430,"lang":432,"legacyUrl":433,"meta":434,"navigation":435,"path":436,"readingTime":437,"seo":438,"sitemap":439,"stem":443,"tags":444,"translation":430,"updated":430,"__hash__":446},"insightsDe\u002Fde\u002Finsights\u002Feinheitliches-cloud-schwachstellen-scanning-nis2-compliance-und-cloud.md","Einheitliches Cloud-Schwachstellen-Scanning: NIS2-Compliance und Cloud-Sicherheit mit blacklens.io","blacklens.io Team",{"type":8,"value":9,"toc":413},"minimark",[10,15,41,60,64,78,85,125,136,140,166,180,185,199,214,221,224,228,242,263,279,284,287,291,314,337,357,372,376,391,398],[11,12,14],"h2",{"id":13},"cloud-sicherheit-im-fokus-warum-einheitliches-scanning-jetzt-wichtig-ist","Cloud-Sicherheit im Fokus: Warum einheitliches Scanning jetzt wichtig ist",[16,17,18,19,23,24,28,29,32,33,36,37,40],"p",{},"Cloud-Technologien sind aus modernen Unternehmen nicht mehr wegzudenken – und mit ihrer wachsenden Beliebtheit steigen auch die Risiken von Cyberangriffen auf Cloud-Infrastrukturen. Insbesondere vor dem Hintergrund der ",[20,21,22],"strong",{},"NIS2-Richtlinie"," der EU stehen Unternehmen vor der Herausforderung, ",[25,26,27],"em",{},"alle"," Teile ihrer IT-Landschaft – inklusive Cloud-Umgebungen – kontinuierlich auf Schwachstellen zu prüfen. NIS2 fordert nämlich explizit, dass relevante Organisationen Informationen über ",[20,30,31],{},"technische Schwachstellen"," in ihren Netz- und Informationssystemen einholen, ihre ",[20,34,35],{},"Exponierung"," gegenüber diesen Schwachstellen bewerten und geeignete Maßnahmen zu deren Behebung ergreifen Zudem müssen Unternehmen ",[20,38,39],{},"nachweisen",", dass sie ein solches Schwachstellen-Management betreiben – etwa durch Dokumentation von Scan-Ergebnissen, Protokolle über behobene Sicherheitslücken und den Einsatz von Schwachstellen-Scanning-Tool.",[16,42,43,44,47,48,51,52,55,56,59],{},"In der Praxis bedeutet das: ",[20,45,46],{},"Cloud-Sicherheit und Compliance"," gehen Hand in Hand. Einerseits bieten Cloud-Anbieter viele Sicherheitsfunktionen, andererseits führen Fehlkonfigurationen oder unentdeckte Lücken in der Cloud schnell zu erheblichen Risiken. Traditionelle Insellösungen (separate Tools für jede Cloud oder nur für On-Prem-Systeme) reichen hier nicht aus. Gefragt ist ein ",[25,49,50],{},"ganzheitlicher"," Ansatz – ein ",[25,53,54],{},"einheitliches Cloud-Schwachstellen-Scanning",", das alle Cloud-Ressourcen umfasst und Ergebnisse zentral bündelt. Genau hier setzt ",[20,57,58],{},"blacklens.io"," mit seinen neuesten Features an.",[11,61,63],{"id":62},"nis2-neue-anforderungen-an-schwachstellen-management-und-cloud-transparenz","NIS2: Neue Anforderungen an Schwachstellen-Management und Cloud-Transparenz",[16,65,66,67,69,70,73,74,77],{},"Die im Januar 2023 in Kraft getretene ",[20,68,22],{}," verschärft die Auflagen für die Cybersicherheit in kritischen Sektoren und darüber hinaus. Unternehmen, die unter NIS2 fallen (sog. “essential” und “important” entities), müssen ein deutlich erweitertes Risikomanagement nachweisen – einschließlich eines fortlaufenden Schwachstellen-Managements. Laut ENISA-Umsetzungshilfe zu NIS2 ist klar: ",[20,71,72],{},"Ohne systematisches Vulnerability Management keine NIS2-Compliance",". Das heißt, Organisationen brauchen Prozesse und Tools, um Schwachstellen ",[20,75,76],{},"laufend zu identifizieren, zu priorisieren und zu beheben",".",[16,79,80,81,84],{},"Vor allem ",[20,82,83],{},"Cloud-Umgebungen"," dürfen dabei nicht zum blinden Fleck werden. NIS2 spricht zwar allgemein von Netz- und Informationssystemen, aber in der heutigen Zeit zählen Cloud-Infrastrukturen genauso dazu. Unternehmensdaten, Anwendungen und Identitäten liegen oft in AWS, Azure, GCP & Co. – entsprechend müssen auch diese auf dem Radar der Security-Teams sein. Entscheider wie CISOs und IT-Leiter stehen hier vor mehreren Herausforderungen:",[86,87,88,99,109],"ul",{},[89,90,91,94,95,98],"li",{},[20,92,93],{},"Unvollständige Sicht",": Unterschiedliche Tools für On-Prem und diverse Clouds führen zu Lücken. Es fehlt eine kontinuierliche, einheitliche Kontrolle der gesamten digitalen ",[20,96,97],{},"Angriffsfläche",", inklusive extern erreichbarer Cloud-Services.",[89,100,101,104,105,108],{},[20,102,103],{},"Mangelnde Echtzeit-Informationen",": Ohne zentralisierte Lösung erfährt man von neuen Bedrohungen oder Fehlkonfigurationen in der Cloud oft zu spät Dynamische Cloud-Assets (wie neue VMs, Serverless Functions, geänderte Rechte) müssen in ",[20,106,107],{},"Echtzeit"," überwacht werden.",[89,110,111,114,115,118,119,77],{},[20,112,113],{},"Nachweis und Dokumentation",": NIS2 verlangt auditierbare Berichte. Viele kämpfen jedoch mit der ",[20,116,117],{},"Nachweisbarkeit"," technischer Security-Maßnahmen in der Cloud – etwa, ob kritische Schwachstellen zeitnah gepatcht wurden",[120,121],"a",{"href":122,"rel":123},"https:\u002F\u002Fwww.holmsecurity.com\u002Fblog\u002Fenisa-has-spoken-vulnerability-management-is-critical-for-nis2-compliance#:~:text=Evidence%20of%20implemented%20vulnerability%20management,measures%20include",[124],"nofollow",[16,126,127,128,131,132,135],{},"Ohne die richtige Plattform ist es also schwierig, ",[20,129,130],{},"Compliance"," zu ",[25,133,134],{},"leben",", nicht nur auf dem Papier. Hier hilft eine integrierte Lösung wie blacklens.io, die speziell darauf ausgelegt ist, solche Vorgaben effizient und nachvollziehbar umzusetzen.",[11,137,139],{"id":138},"neu-bei-blacklensio-einheitliches-cloud-scanning-mit-500-checks-cis-konform","Neu bei blacklens.io: Einheitliches Cloud-Scanning mit 500 Checks (CIS-konform)",[16,141,142,143,145,146,149,150,153,154,157,158,161,162,165],{},"Mit dem neuesten Update von ",[25,144,58],{}," (Release vom 28. September) wurde das ",[20,147,148],{},"Cloud-Scanning"," erheblich ausgebaut und vereinheitlicht. Ab sofort ermöglicht die Plattform automatisierte Sicherheitsprüfungen in allen großen Cloud-Umgebungen – ",[20,151,152],{},"AWS, Google Cloud, Microsoft Azure sowie Entra ID (Azure AD)"," – unter einem Dach. Und das in beeindruckender Tiefe: Rund ",[20,155,156],{},"500 Checks"," prüft blacklens.io pro Cloud-Account, um wirklich alle sicherheitsrelevanten Konfigurationen und Ressourcen abzudecken. Diese Checks orientieren sich an den Best Practices der ",[20,159,160],{},"CIS Benchmarks"," (Center for Internet Security) für Cloud-Plattformen. Unternehmen können damit sicherstellen, dass ihre Cloud-Setups vollumfänglich ",[20,163,164],{},"CIS-konform"," sind – ein wichtiger Schritt zu einer robusten Grundsicherheit und für viele Compliance-Anforderungen.",[16,167,168,171,172,175,176,179],{},[20,169,170],{},"Was bedeuten 500 Checks konkret?"," blacklens.io durchleuchtet die Cloud-Umgebung umfassend – von Identitäts- und Zugriffsmanagement über Netzwerk- und Firewall-Einstellungen bis hin zu Storage-Konfigurationen und Logging. Jede einzelne Prüfung basiert auf anerkannten Sicherheitsrichtlinien (z.B. Überprüfung, ob Multi-Faktor-Authentifizierung aktiviert ist, ob Speicher-Buckets öffentlich zugänglich sind, ob bekannte Schwachstellen-Patches fehlen u.v.m.). Dadurch erhält man ein ",[20,173,174],{},"komplettes Sicherheitsprofil"," der Cloud-Infrastruktur. Erkennt das System Abweichungen von den CIS-Leitlinien oder andere Schwachstellen, werden diese als Findings mit Schweregrad eingestuft und mit konkreten ",[20,177,178],{},"Empfehlungen"," zur Behebung versehen. Das erspart Security-Teams mühsame manuelle Audits und stellt sicher, dass kein Aspekt übersehen wird.",[181,182,184],"h3",{"id":183},"einfache-integration-aller-cloud-konten","Einfache Integration aller Cloud-Konten",[16,186,187,190,191,194,195,198],{},[25,188,189],{},"Cloud-Integrationsübersicht in blacklens.io: Neue AWS-, Azure- oder GCP-Accounts lassen sich in wenigen Minuten anbinden. Über die Integrationsseite können alle Cloud-Tenants zentral verknüpft und konfiguriert werden."," Bereits die Anbindung der Cloud-Provider an blacklens.io ist ",[20,192,193],{},"denkbar einfach",". In der Integrationsübersicht wählt man den gewünschten Provider (AWS, Azure oder GCP) aus und folgt einem kurzen Einrichtungsprozess. Innerhalb von Minuten ist die Verbindung hergestellt. Anschließend kann man entscheiden, ob man alle Assets des Providers – z.B. IP-Adressen, VMs, Load Balancer, WebApps – automatisch in blacklens.io importieren möchte und ob auch vorhandene Ressourcen wie IAM-User\u002FRollen oder andere servicespezifische Komponenten auditiert werden sollen. Dank dieser ",[20,196,197],{},"tiefen Integration"," erfasst blacklens.io sofort die gesamte Cloud-Landschaft des Unternehmens.",[16,200,201,202,205,206,209,210,213],{},"Besonders praktisch ist die ",[20,203,204],{},"Asset-Synchronisierung",": Einmal angebunden, erkennt blacklens.io auch ",[20,207,208],{},"neue Ressourcen"," automatisch. Wenn also z.B. in Azure eine neue VM oder in AWS ein neuer S3 Bucket angelegt wird, erscheint dieses Asset kurze Zeit später automatisch im Scan-Prozess. Security-Teams müssen nicht mehr hinter jeder Änderung manuell herlaufen – die Plattform hält Schritt mit der Dynamik der Cloud. So wird eine ",[25,211,212],{},"kontinuierliche Überwachung"," aller Cloud-Ressourcen gewährleistet.",[16,215,216],{},[217,218],"img",{"alt":219,"src":220},"","\u002Fimages\u002Finsights\u002F68b9579c616692e7ea8c1fa7_Screenshot-2025-09-04-at-11.10.24.png",[16,222,223],{},"Verfügbare blacklens.io Integrationen",[181,225,227],{"id":226},"schnelle-ergebnisse-und-vollständige-transparenz","Schnelle Ergebnisse und vollständige Transparenz",[16,229,230,231,234,235,238,239,77],{},"Nach Einbindung eines Cloud-Kontos liefert blacklens.io in kürzester Zeit die ersten aussagekräftigen Resultate. Durch effizientes ",[20,232,233],{},"Parallel-Scanning"," und API-Abfragen erhält man innerhalb weniger Minuten einen Überblick über kritische Konfigurationsfehler oder Risiken. Ein Beispiel aus unserem Team: Nach Aktivierung des Cloud-Scans für einen Microsoft Azure Tenant identifizierte blacklens.io praktisch sofort eine Schwachstelle in einer Conditional-Access-Policy. Diese hätte es einem Angreifer ermöglichen können, die Policy zu umgehen und eine Anmeldung mit nur einem Faktor durchzuführen – ein erhebliches Risiko für die Account-Sicherheit. Dank blacklens.io wurde dieses Problem umgehend sichtbar, konnte sofort behoben werden und tauchte beim nächsten Scan als ",[20,236,237],{},"gelöst"," auf. Solche schnellen Feedback-Zyklen sind enorm wertvoll, um die Cloud ",[20,240,241],{},"proaktiv abzusichern",[16,243,244,247,248,251,252,255,256,259,260,262],{},[25,245,246],{},"Erkannte Schwachstellen in der Cloud (Beispielansicht aus blacklens.io): Für jedes Finding werden Details, Risikobewertung und konkrete Handlungsempfehlungen angezeigt."," Die Scan-Ergebnisse präsentiert blacklens.io übersichtlich auf seinem Dashboard. Sicherheitsverantwortliche sehen sofort, ",[20,249,250],{},"welche Schwachstellen"," gefunden wurden, wie kritisch sie sind und wo Handlungsbedarf besteht. Die Plattform liefert kontextreiche Informationen – z.B. welche Asset-Typen betroffen sind, ob öffentlich exponiert oder intern, welcher ",[20,253,254],{},"CVSS-Score"," vorliegt und wie ein Angreifer dies ausnutzen könnte. Dadurch lassen sich die Funde ",[20,257,258],{},"priorisieren",": Kritische Cloud-Lücken (etwa öffentlich zugängliche sensible Dienste ohne Authentifizierung) ganz nach oben, weniger dringliche Punkte nachrangig. Zu jedem Finding gibt es zudem klare ",[20,261,178],{}," (Remediation Steps), oft direkt verlinkt mit Dokumentation des Cloud-Anbieters, um die Behebung zu erleichtern.",[16,264,265,266,269,270,274,275,278],{},"Ein weiterer Vorteil: ",[20,267,268],{},"False Positives"," werden minimiert. Durch Kontext und Korrelation – auch mit der externen Angriffsflächen-Analyse von blacklens.io – konzentriert man sich auf tatsächliche Risiken und nicht bloß auf theoretische Checklisten-Punkte",[120,271],{"href":272,"rel":273},"https:\u002F\u002Fwww.blacklens.io\u002Fuse-case\u002Funified-vulnerability-management#:~:text=In%20modernen%20IT,False%20Positives%20und%20echte%20Sicherheitswirkung",[124],". Dieser ",[20,276,277],{},"ganzheitliche"," Ansatz (Cloud + extern + intern) vermeidet Alarmmüdigkeit und stellt sicher, dass Ressourcen der IT effizient eingesetzt werden.",[16,280,281],{},[217,282],{"alt":219,"src":283},"\u002Fimages\u002Finsights\u002F68b958182ce33fb0f4a1c8c5_Screenshot-2025-09-04-at-11.12.38.png",[16,285,286],{},"Ergebnisse - Cloud Vulnerabilities",[11,288,290],{"id":289},"einheitliche-plattform-für-cisos-und-it-leitungen-mehr-überblick-weniger-lücken","Einheitliche Plattform für CISOs und IT-Leitungen: Mehr Überblick, weniger Lücken",[16,292,293,294,297,298,301,302,305,306,309,310,313],{},"Für ",[20,295,296],{},"CISOs und IT-Verantwortliche"," bietet die Unified-Vulnerability-Management-Plattform von blacklens.io einen strategischen Mehrwert. Anstatt dutzende Einzellösungen zu verwalten, erhält man ",[20,299,300],{},"eine zentrale Sicht"," auf alle Schwachstellen in der Organisation – sei es in der traditionellen Infrastruktur, in Cloud-Services oder sogar in weniger beachteten Bereichen wie IoT-Geräten. Blacklens.io vereint ",[25,303,304],{},"Best-of-Breed","-Scanning für ",[20,307,308],{},"Cloud, On-Prem-Infrastruktur und Web-Anwendungen in einer Oberfläche",". So entsteht ein ",[20,311,312],{},"vollständiges Schwachstellen-Inventory"," ohne blinde Flecken. Insbesondere Cloud-Risiken, die früher leicht übersehen wurden, stehen nun gleichberechtigt neben on-premise Findings im Gesamtbericht.",[16,315,316,317,320,321,324,325,328,329,332,333,336],{},"Diese ",[20,318,319],{},"Vereinheitlichung"," zahlt sich direkt in der Compliance aus: Unternehmen mit verteilten Infrastrukturen (Multi-Cloud, Hybrid-IT, Remote Work) und hohen regulatorischen Anforderungen (z.B. ",[20,322,323],{},"ISO 27001, NIS2, TISAX",") profitieren enorm von der zentralen Steuerung. Blacklens.io wurde genau für solche Szenarien entwickelt. So nutzen etwa Kunden aus dem KRITIS-Umfeld (kritische Infrastruktur) die Plattform, um ihre NIS2-Pflichten im Griff zu haben. Ein Praxisbeispiel: Ein europaweiter Logistik-Dienstleister stand vor der Herausforderung, Schwachstellen aus verschiedenen Netzwerken, Cloud-Accounts und Landesgesellschaften zentral zu konsolidieren. Mit blacklens.io konnte zuerst ein vollständiges ",[20,326,327],{},"Asset-Inventar"," erstellt werden, über das alle Schwachstellen standardisiert erfasst und bewertet wurden Anschließend flossen die Ergebnisse nahtlos in ",[20,330,331],{},"Workflows"," ein – inklusive Zuständigkeiten, Prioritäten und Nachverfolgung der Behebung. Besonders hilfreich war die kontinuierliche Erkennung neu auftauchender Risiken durch das Attack Surface Monitoring, selbst ",[25,334,335],{},"zwischen"," geplanten Scans. Das Resultat: eine deutlich reduzierte Angriffsfläche, klare Verantwortlichkeiten und eine prüffähige Umsetzung der Maßnahmen nach ISO 27001 bzw. NIS2 Auditoren bewerteten die technische Absicherung der externen Systeme in diesem Fall als “vorbildlich und durchgehend dokumentiert”.",[16,338,339,340,343,344,347,348,351,352,356],{},"Auch ",[20,341,342],{},"Reporting und Audits"," werden durch die Plattform massiv erleichtert. Blacklens.io generiert auf Knopfdruck ",[20,345,346],{},"auditfähige Berichte",", die sich an gängige Standards anlehnen – ideal für NIS2-Nachweise, ISO-27001-Audits oder Management-Reports Sämtliche Aktionen sind lückenlos dokumentiert: Von der Erkennung einer Schwachstelle über die Zuweisung an einen Bearbeiter bis zum Retest nach der Behebung. Diese Transparenz macht es einfach, den geforderten ",[20,349,350],{},"Nachweis"," gegenüber Prüfern zu führen, dass man Schwachstellen systematisch im Griff hat. Darüber hinaus integriert sich blacklens.io bei Bedarf in vorhandene Governance-, Risk- und Compliance-(GRC)-Tools oder Ticketing-Systeme",[120,353],{"href":354,"rel":355},"https:\u002F\u002Fwww.blacklens.io\u002Fuse-case\u002Fcompliance-audit-readiness#:~:text=Bedrohungen%20mit%20Bezug%20zum%20Unternehmen,und%20Ma%C3%9Fnahmenverwaltung",[124],", damit Sicherheitsprozesse nahtlos in den Betriebsablauf eingebettet sind.",[16,358,359,360,363,364,367,368,371],{},"Nicht zuletzt unterstützt blacklens.io auch Bereiche wie ",[20,361,362],{},"Darknet-Monitoring und Threat Intelligence",", um frühzeitig vor externen Gefahren zu warnen – aber das sprengt den Rahmen dieses Artikels. Wichtig ist: Als ",[25,365,366],{},"CISO"," behält man mit einer ganzheitlichen Plattform ",[20,369,370],{},"den Überblick",", kann Risiken priorisiert adressieren und erfüllt gleichzeitig Vorgaben wie NIS2 effizienter.",[11,373,375],{"id":374},"fazit-cloud-sicherheit-vereinheitlichen-für-mehr-sicherheit-und-compliance","Fazit: Cloud-Sicherheit vereinheitlichen – für mehr Sicherheit und Compliance",[16,377,378,379,382,383,386,387,390],{},"Die Einführung des einheitlichen Cloud-Schwachstellen-Scannings in blacklens.io markiert einen wichtigen Schritt für Unternehmen, die ihre ",[20,380,381],{},"Cloud-Sicherheit auf das nächste Level"," heben wollen. Durch die ",[20,384,385],{},"Kombination"," aus breiter Abdeckung (AWS, Azure, GCP, Entra ID) und tiefer Prüfung (500 CIS-konforme Checks) schließt blacklens.io die Lücke zwischen verschiedenen Umgebungen. ",[20,388,389],{},"NIS2-Compliance"," wird dadurch erheblich vereinfacht, denn alle erforderlichen Maßnahmen – von kontinuierlicher Überwachung bis hin zu audit-sicheren Reports – lassen sich über eine Plattform steuern.",[16,392,393,394,397],{},"Blacklens.io verwandelt damit herkömmliches Schwachstellen-Scanning in ein strategisches Vulnerability Management mit nachhaltiger Wirkung Anstatt nur Listen von Schwachstellen zu “produzieren”, sorgt die Plattform für ",[20,395,396],{},"konkrete Sicherheitsverbesserungen",": Risiken werden kontextbewusst bewertet, Verantwortlichkeiten zugewiesen und Fortschritte überwacht. Die Cloud wird nicht mehr isoliert betrachtet, sondern als integraler Bestandteil der Gesamt-Angriffsfläche – transparent, kontrolliert und abgesichert.",[16,399,400,401,404,405,408,409,412],{},"Unternehmen, die frühzeitig auf ein solches ",[20,402,403],{},"unified"," Vorgehen setzen, sind besser gewappnet gegen Cyber-Bedrohungen und erfüllen regulatorische Auflagen ohne Aktionismus. Wenn Sie also Ihre Cloud-Infrastruktur ",[20,406,407],{},"sicher und NIS2-ready"," machen möchten, ist jetzt der richtige Zeitpunkt, einen Blick durch die „Angreifer-Brille“ zu wagen. Blacklens.io bietet Ihnen diese Sicht – ",[20,410,411],{},"proaktiv, automatisiert und umfassend",". Überzeugen Sie sich selbst von den neuesten Features: Starten Sie eine kostenlose Testphase und erleben Sie, wie einheitliches Cloud-Scanning Ihre Sicherheitsstrategie transformieren kann! 🚀",{"title":219,"searchDepth":414,"depth":414,"links":415},3,[416,418,419,423,424],{"id":13,"depth":417,"text":14},2,{"id":62,"depth":417,"text":63},{"id":138,"depth":417,"text":139,"children":420},[421,422],{"id":183,"depth":414,"text":184},{"id":226,"depth":414,"text":227},{"id":289,"depth":417,"text":290},{"id":374,"depth":417,"text":375},"guide","2025-09-08","Einheitliches Cloud-Scanning mit blacklens.io: Über 500 CIS-konforme Checks für mehr Sicherheit, Transparenz und NIS2-Compliance.",false,"md",null,"\u002Fimages\u002Finsights\u002F68b957328538d29553d58d1b_shutterstock_2615797201.jpeg","de","\u002Finsights\u002Feinheitliches-cloud-schwachstellen-scanning-nis2-compliance-und-cloud-sicherheit-mit-blacklens-io",{},true,"\u002Fde\u002Finsights\u002Feinheitliches-cloud-schwachstellen-scanning-nis2-compliance-und-cloud",9,{"title":5,"description":427},{"loc":436,"images":440},[441,442],{"loc":220},{"loc":283},"de\u002Finsights\u002Feinheitliches-cloud-schwachstellen-scanning-nis2-compliance-und-cloud",[445],"Leitfaden","sjFDzASWzPj4ZAF6mvBvXziBd80jzOdfKS_KybiGoKE",[448,706,782],{"id":449,"title":450,"author":6,"body":451,"category":679,"date":680,"description":681,"draft":428,"extension":429,"faq":682,"image":692,"imageAlt":430,"lang":693,"legacyUrl":430,"meta":694,"navigation":435,"path":695,"readingTime":696,"seo":697,"sitemap":698,"stem":701,"tags":702,"translation":704,"updated":430,"__hash__":705},"insightsEn\u002Fen\u002Finsights\u002Fwas-zuerst-intelligente-schwachstellen-priorisierung-mit-blacklens.md","What First? Intelligent Vulnerability Prioritisation with blacklens",{"type":8,"value":452,"toc":671},[453,458,465,471,475,482,511,514,518,521,566,569,574,578,585,604,608,614,638,642,653,657,660],[454,455,457],"h1",{"id":456},"what-first-intelligent-vulnerability-prioritisation-with-blacklens","What first? Intelligent vulnerability prioritisation with blacklens",[16,459,460,461,464],{},"The uncomfortable truth in vulnerability management: the problem is rarely ",[25,462,463],{},"finding"," vulnerabilities. The problem is spotting, among a thousand findings, the ten that really matter today. Anyone who works through the list by raw CVSS score burns time on findings that will never be exploited – while the one genuinely reachable, genuinely exploitable flaw waits in row 847 of the spreadsheet.",[16,466,467,468],{},"With its latest release, blacklens answers the three questions on which prioritisation really hinges: ",[20,469,470],{},"What first? Why that one? And how do we fix it?",[11,472,474],{"id":473},"a-plan-instead-of-a-spreadsheet-the-remediation-plan","A plan instead of a spreadsheet: the Remediation Plan",[16,476,477,478,481],{},"Under ",[20,479,480],{},"Vulnerabilities → Remediation",", blacklens generates a prioritised action plan from all open findings at the push of a button – external, internal and cloud considered together:",[86,483,484,490,496,502],{},[89,485,486,489],{},[20,487,488],{},"Grouped by the fix, not by the finding."," An outdated TLS setup on twelve hosts is not a dozen tasks but one. The plan bundles findings by the measure that fixes them together.",[89,491,492,495],{},[20,493,494],{},"Sorted by risk reduction."," At the top sits the cluster with the greatest leverage – by severity and breadth. Not the loudest one, the most effective one.",[89,497,498,501],{},[20,499,500],{},"With rationale and instructions."," Each cluster explains why it sits where it does, estimates the effort (low \u002F medium \u002F high) and provides numbered steps, including copy-ready code where appropriate.",[89,503,504,507,508,77],{},[20,505,506],{},"Progress you can see."," While your team works, the plan stays stable – only the counters move: completed steps, resolved instances, coverage of open findings. Right up to ",[25,509,510],{},"\"Plan complete — nice work\"",[16,512,513],{},"Generation takes around 30–60 seconds, and you can keep working in the meantime. The result changes your team's unit of work: no longer \"finding by finding\" but \"step by step\" – with visible movement instead of an endless backlog.",[11,515,517],{"id":516},"prioritising-means-understanding-context-on-every-finding","Prioritising means understanding: context on every finding",[16,519,520],{},"A good order needs good reasons. That is why every finding – external, internal and cloud – gets an explanation layer that makes prioritisation decisions robust:",[86,522,523,544,550,560],{},[89,524,525,528,529,532,533,532,536,539,540,543],{},[20,526,527],{},"Urgency with evidence:"," A suggested rating along with an exploit status chip – ",[25,530,531],{},"Exploit available",", ",[25,534,535],{},"PoC public",[25,537,538],{},"No known exploit"," or ",[25,541,542],{},"Exploitability unknown",". The platform severity remains authoritative; the assessment supplements it, it does not override it.",[89,545,546,549],{},[20,547,548],{},"Threat intelligence per CVE:"," CVSS, EPSS (probability of exploitation in the wild within 30 days), exploit\u002FPoC availability, attack vector and advisory link – from the blacklens threat feed. Exactly the data you need to tell \"high\" from \"urgent\".",[89,551,552,555,556,559],{},[20,553,554],{},"Root cause, impact and remediation:"," Why the finding exists, what it exposes and how it is closed – in 1–6 concrete steps. Plus ",[20,557,558],{},"compensating controls"," for the realistic case that the actual fix has to wait.",[89,561,562,565],{},[20,563,564],{},"Follow-up questions right on the finding:"," A chat beneath the analysis answers follow-up questions in the real context of your workspace – the actual service fingerprint, the affected hosts, the same finding on other systems.",[16,567,568],{},"The analyses are generated on request, cached transparently with a timestamp and visibly carry a note to review generated content before taking critical steps. The decision stays with your team – it just gets considerably faster.",[16,570,571],{},[217,572],{"alt":219,"src":573},"\u002Fimages\u002Finsights\u002F6a8eab8037efc3396911b5c6_Screenshot-2026-08-26-at-10.59.14.png",[11,575,577],{"id":576},"prioritisation-beyond-the-cve-which-lookalike-domain-is-dangerous","Prioritisation beyond the CVE: which lookalike domain is dangerous?",[16,579,580,581,584],{},"With typosquatting, too, the question is never \"are there lookalikes?\" but \"which of them is a problem?\". The new detail view provides the basis for that decision: a character diff against your domain, registration and DNS data, a reputation score – and risk badges such as ",[25,582,583],{},"Mail capable"," that show at a glance whether a domain has everything credential phishing needs.",[16,586,587,588,591,592,595,596,599,600,603],{},"On demand, blacklens goes one step further: it captures what the domain actually serves, including a screenshot, and assesses whether it imitates your brand. ",[20,589,590],{},"Evidence and assessment stay cleanly separated",": ",[25,593,594],{},"Observed on the page"," lists objective signals extracted by blacklens itself – a password field, the brand name, a form posting to a foreign domain – while the ",[25,597,598],{},"Assessment"," is the interpretation. Only once the evidence is complete (the checklist shows 5\u002F5) is the ",[20,601,602],{},"Draft abuse report"," unlocked: a pre-filled, factual email to the registrar's abuse contact. Sending it is up to you.",[11,605,607],{"id":606},"getting-to-the-right-view-faster-ask-instead-of-building-filters","Getting to the right view faster: ask instead of building filters",[16,609,610,611,77],{},"Prioritisation often starts with a simple question: \"Show me critical findings on prod hosts.\" That is exactly how you can ask it now – on 17 dashboard lists, blacklens translates the description into a ready-made, editable filter query with a preview. The language model never sees your data at any point, only field names, types and permitted values – and nothing runs until you click ",[25,612,613],{},"Apply filters",[16,615,616,617,532,620,532,623,626,627,630,631,539,634,637],{},"Complementing this is the new status strip above every attack surface list: five metrics per page – such as ",[25,618,619],{},"Exposing",[25,621,622],{},"Vulnerable",[25,624,625],{},"High risk"," – many of them clickable as filters. And a principle we like to quote: ",[20,628,629],{},"Unknown never counts as safe."," Tiles such as ",[25,632,633],{},"Public",[25,635,636],{},"No MFA"," only count what a provider has explicitly reported.",[11,639,641],{"id":640},"on-your-terms","On your terms",[16,643,644,645,648,649,652],{},"The intelligent features of this release – Remediation Plan, finding explanations, domain verdicts, natural-language search – are ",[20,646,647],{},"opt-in per workspace"," and switched off initially after the update. Workspace admins decide under ",[20,650,651],{},"Settings → General → AI Features",", and \"off\" means off: the server rejects such requests for deactivated workspaces. The analyses run on our self-hosted LLM and are GDPR-compliant – your data never leaves our infrastructure.",[11,654,656],{"id":655},"conclusion","Conclusion",[16,658,659],{},"Less time sorting, more time fixing: this release turns the flood of findings into a reasoned order – a plan with the greatest risk leverage at the top, context and threat intelligence on every finding, evidence instead of gut feeling for lookalike domains. The intelligence lies in the prioritisation. Control stays with you.",[16,661,662,665,666,668,669,77],{},[20,663,664],{},"Get started:"," Workspace admins enable the features under ",[25,667,651],{},". After that, your first Remediation Plan is waiting under ",[25,670,480],{},{"title":219,"searchDepth":414,"depth":414,"links":672},[673,674,675,676,677,678],{"id":473,"depth":417,"text":474},{"id":516,"depth":417,"text":517},{"id":576,"depth":417,"text":577},{"id":606,"depth":417,"text":607},{"id":640,"depth":417,"text":641},{"id":655,"depth":417,"text":656},"release","2026-09-02","What first, why, and how? blacklens turns open findings into a prioritised remediation plan – sorted by risk reduction, with context on every finding.",[683,686,689],{"q":684,"a":685},"What is the blacklens Remediation Plan?","The Remediation Plan, found under Vulnerabilities → Remediation, turns all open external, internal and cloud findings into a prioritised action plan at the push of a button. Findings are grouped by the fix that resolves them, sorted by risk reduction and delivered with a rationale, an effort estimate and numbered steps, while progress counters update as your team works through the plan.",{"q":687,"a":688},"How does blacklens help prioritise vulnerabilities beyond the CVSS score?","Every finding receives an explanation layer with a suggested urgency, an exploit status chip and threat intelligence per CVE, including CVSS, EPSS, exploit or PoC availability, attack vector and advisory link. Root cause, impact, remediation steps and compensating controls are provided, and a chat on the finding answers follow-up questions in the context of your workspace.",{"q":690,"a":691},"Are the AI features in blacklens enabled by default, and where does the data go?","No. Remediation Plan, finding explanations, domain verdicts and natural-language search are opt-in per workspace and switched off after the update; workspace admins enable them under Settings → General → AI Features. The analyses run on blacklens' self-hosted LLM and are GDPR-compliant, so your data does not leave the blacklens infrastructure.","\u002Fimages\u002Finsights\u002F6a8eab1862da2619b8478b7d_Screenshot-2026-08-26-at-10.59.51.png","en",{},"\u002Fen\u002Finsights\u002Fwas-zuerst-intelligente-schwachstellen-priorisierung-mit-blacklens",5,{"title":450,"description":681},{"loc":695,"images":699},[700],{"loc":573},"en\u002Finsights\u002Fwas-zuerst-intelligente-schwachstellen-priorisierung-mit-blacklens",[703],"Release notes","was-zuerst-intelligente-schwachstellen-priorisierung-mit-blacklens","e1t1-bD9PIM1yFeHDE2AjNbJbYmYRx1HL1rehDCrysg",{"id":707,"title":708,"author":6,"body":709,"category":760,"date":761,"description":762,"draft":428,"extension":429,"faq":763,"image":772,"imageAlt":430,"lang":693,"legacyUrl":430,"meta":773,"navigation":435,"path":774,"readingTime":414,"seo":775,"sitemap":776,"stem":777,"tags":778,"translation":780,"updated":430,"__hash__":781},"insightsEn\u002Fen\u002Finsights\u002Ffortibleed-wenn-zehntausende-firewalls-zur-offenen-tur-werden.md","FortiBleed: When Tens of Thousands of Firewalls Become an Open Door",{"type":8,"value":710,"toc":754},[711,714,718,721,724,728,731,734,737,741,744,747,751],[16,712,713],{},"FortiGate firewalls protect corporate networks. That is their sole purpose. What FortiBleed shows: when the firewall itself becomes the attack surface, it no longer protects – it opens up.",[11,715,717],{"id":716},"what-is-fortibleed","What is FortiBleed?",[16,719,720],{},"FortiBleed is not a single breach. It is an industrialised harvesting operation against internet-exposed Fortinet firewalls and SSL VPN gateways. The dataset was discovered in mid-June 2026 by security researcher Volodymyr \"Bob\" Diachenko.",[16,722,723],{},"The scale is extraordinary – even though the exact figures vary by source and are still changing, as the campaign was still active at the time of publication. Security researchers who analysed the leaked dataset estimate the number of affected FortiGate devices at somewhere between 30,000 and 75,000. The entries it contains can be attributed to around 21,600 domains in 194 countries – a cross-section of global corporations, public authorities and critical infrastructure operators across almost every industry.",[11,725,727],{"id":726},"how-the-attack-worked","How the attack worked",[16,729,730],{},"The attack follows an automated, self-reinforcing chain. First, the internet is scanned for reachable FortiGate devices – above all SSL VPN endpoints and management interfaces. Against each device found, the attackers then test a curated list of known passwords. A successful login is not followed by a noisy attack – instead, the compromised device is used as a silent \"listening post\": it sits at the network perimeter and reads the traffic passing through in order to harvest further credentials. These flow back into the scanner and compromise the next device. The system feeds itself.",[16,732,733],{},"The password list being tested is not random. It consists of credentials that had already leaked in earlier Fortinet incidents and via infostealer logs – many organisations never changed their passwords after a previous incident. In addition, according to Diachenko's reconstruction, the attackers intercepted SSL VPN authentication hashes and cracked them offline with a GPU cluster (a Hashtopolis-managed setup of around 45 GPUs has been reported).",[16,735,736],{},"As things stand, this is not a confirmed zero-day. How the configuration data originally left the devices remains open: candidates include known but unpatched vulnerabilities (in particular CVE-2026-24858, a FortiCloud SSO SAML bypass with a CVSS score of up to 9.8), a still-unknown flaw, infostealer credentials, or a combination of these. A further contributing factor is that on many devices admin passwords are still stored in the older SHA-256 format – namely wherever admins never logged in again after a firmware update. In any case, the core of the problem remains the same: exposed management interfaces and reused or crackable credentials.",[11,738,740],{"id":739},"the-role-of-infostealers","The role of infostealers",[16,742,743],{},"A significant share of the credentials does not come from classic brute force but from infostealer campaigns. Infostealer malware on employee devices steals saved VPN credentials and passwords from browsers and password managers before they end up in dark web forums and dumps. In many cases these credentials enabled a valid login without any brute force at all.",[16,745,746],{},"That also makes FortiBleed a dark web monitoring topic: the infostealer activity that led to these credentials was visible in the relevant forums and dumps – to anyone actively looking there.",[11,748,750],{"id":749},"what-helps-and-why-visibility-is-decisive","What helps – and why visibility is decisive",[16,752,753],{},"This is exactly where blacklens.io comes in. Dark Web Monitoring detects when credentials or infostealer activity affect your own company – the Emerging Threat Notification System informs you proactively, before someone else reacts. Continuous attack surface analysis shows which systems are really reachable from the outside – including the ones nobody internally remembers any more.",{"title":219,"searchDepth":414,"depth":414,"links":755},[756,757,758,759],{"id":716,"depth":417,"text":717},{"id":726,"depth":417,"text":727},{"id":739,"depth":417,"text":740},{"id":749,"depth":417,"text":750},"threat","2026-08-06","FortiGate firewalls exist to protect corporate networks. FortiBleed shows what happens when the firewall itself becomes the attack surface – and opens the door.",[764,766,769],{"q":717,"a":765},"FortiBleed is an industrialised credential-harvesting operation against internet-exposed Fortinet FortiGate firewalls and SSL VPN gateways, discovered in mid-June 2026 by security researcher Volodymyr Diachenko. Estimates put the number of affected devices between 30,000 and 75,000, spread across roughly 21,600 domains in 194 countries.",{"q":767,"a":768},"How did the FortiBleed attackers gain access to FortiGate devices?","The attackers scanned the internet for exposed SSL VPN endpoints and management interfaces and tested curated lists of previously leaked passwords and infostealer credentials against them. Compromised devices were then used as silent listening posts to harvest further credentials, and intercepted VPN authentication hashes were cracked offline on a GPU cluster.",{"q":770,"a":771},"How can companies protect themselves against attacks like FortiBleed?","Keep management interfaces off the public internet, rotate every credential that may have leaked in earlier incidents and enforce MFA on VPN access. Dark web monitoring detects leaked credentials and infostealer activity affecting your company early, and continuous attack surface analysis shows which systems are actually reachable from outside.","\u002Fimages\u002Finsights\u002F6a33e0062536b90c9b6edd6f_FortiBleed.png",{},"\u002Fen\u002Finsights\u002Ffortibleed-wenn-zehntausende-firewalls-zur-offenen-tur-werden",{"title":708,"description":762},{"loc":774},"en\u002Finsights\u002Ffortibleed-wenn-zehntausende-firewalls-zur-offenen-tur-werden",[779],"Threat landscape","fortibleed-wenn-zehntausende-firewalls-zur-offenen-tur-werden","PneGkfhcZR06I9jQQwlU1RBHTQ-Dg_89axBdXXbdu8k",{"id":783,"title":784,"author":6,"body":785,"category":846,"date":847,"description":848,"draft":428,"extension":429,"faq":849,"image":859,"imageAlt":430,"lang":693,"legacyUrl":430,"meta":860,"navigation":435,"path":861,"readingTime":417,"seo":862,"sitemap":863,"stem":864,"tags":865,"translation":867,"updated":430,"__hash__":868},"insightsEn\u002Fen\u002Finsights\u002Faccess-broker-economy-wenn-der-zugang-zu-eurem-netzwerk-im-darknet-zum-verkauf.md","Access Broker Economy: When Network Access Is Sold on the Dark Web",{"type":8,"value":786,"toc":840},[787,791,798,801,804,808,811,814,817,821,824,827,831,834,837],[11,788,790],{"id":789},"initial-access-brokers-an-industry-of-their-own","Initial Access Brokers – an industry of their own",[16,792,793,794,797],{},"The dark web has developed a functioning division of labour. ",[20,795,796],{},"Initial Access Brokers (IABs)"," are specialised actors who concentrate on a single task: obtaining access to corporate networks and reselling that access.",[16,799,800],{},"Their offering is precisely catalogued and includes VPN credentials with details of company name, industry and annual revenue, RDP access to specific servers, compromised admin accounts with known privilege levels, and active sessions to Citrix or VMware environments. Buyers – including ransomware groups, espionage actors and extortionists – know exactly what they are getting before they even complete the purchase.",[16,802,803],{},"Prices depend on the value of the target. Access to a mid-sized European industrial company with high revenue fetches considerably more than access to a small service provider. The market runs on supply and demand.",[11,805,807],{"id":806},"why-this-division-of-labour-is-dangerous","Why this division of labour is dangerous",[16,809,810],{},"For affected companies this model means a structural shift: the actual breach – the moment someone gains unauthorised access – is not the same as the moment the damage becomes visible.",[16,812,813],{},"By the time ransomware is deployed, the initial access may be weeks old. During that time the original attacker has explored the network, documented credentials, prepared the listing and found the buyer. The ransomware actor walks into an environment that has already been opened up.",[16,815,816],{},"Classic reaction patterns come too late here: anyone who only reacts once files are being encrypted has already missed the decisive window.",[11,818,820],{"id":819},"what-the-dark-web-says-about-your-company","What the dark web says about your company",[16,822,823],{},"IAB listings are often surprisingly extensive. Alongside the access route and company name, they frequently include the number of reachable systems, the privilege level of compromised accounts, the security software in use and sometimes even hints about which EDR solutions are already present and would need to be bypassed in a follow-up attack.",[16,825,826],{},"This information does not come from database leaks. It was actively extracted from the network before the listing was created. An IAB entry means: someone was already inside.",[11,828,830],{"id":829},"how-blacklensio-detects-iab-activity","How blacklens.io detects IAB activity",[16,832,833],{},"blacklens.io's Dark Web Monitoring does not only track classic credential dumps – leaked email\u002Fpassword combinations from known breaches. It also captures active IAB listings on the relevant dark web forums and marketplaces.",[16,835,836],{},"If a listing is discovered that is linked to a company's public domain, an alert is issued immediately with all available context on the entry in question, such as the time of publication or the affected access point, for example a Citrix or VPN login page.",[16,838,839],{},"This is exactly where the difference to classic, reactive incident response lies: an IAB finding does not necessarily mean the actual attack has already taken place. Rather, it shows that a compromise has already occurred and that a follow-on attack could be imminent – which often leaves a limited window for targeted countermeasures.",{"title":219,"searchDepth":414,"depth":414,"links":841},[842,843,844,845],{"id":789,"depth":417,"text":790},{"id":806,"depth":417,"text":807},{"id":819,"depth":417,"text":820},{"id":829,"depth":417,"text":830},"analysis","2026-06-18","Ransomware attacks rarely start with the ransomware. They start with a compromised account or stolen credentials – sold on by Initial Access Brokers.",[850,853,856],{"q":851,"a":852},"What is an Initial Access Broker (IAB)?","An Initial Access Broker is a specialised cybercriminal who obtains access to corporate networks – via VPN credentials, RDP access, compromised admin accounts or active Citrix and VMware sessions – and resells it on dark web forums and marketplaces. Buyers include ransomware groups, espionage actors and extortionists, and prices depend on the value of the target.",{"q":854,"a":855},"Why are IAB listings so dangerous for companies?","An IAB listing means someone has already been inside the network: the details it contains, such as reachable systems, privilege levels and the security software in use, were actively extracted before the sale. By the time ransomware is deployed, the initial access may be weeks old, so reacting only once files are encrypted is far too late.",{"q":857,"a":858},"How does blacklens.io detect Initial Access Broker activity?","blacklens.io's dark web monitoring tracks not only classic credential dumps but also active IAB listings on the relevant forums and marketplaces. If a listing linked to a company's public domain is found, an immediate alert with all available context is issued, which usually leaves a limited window for targeted countermeasures before a follow-on attack.","\u002Fimages\u002Finsights\u002F6a02cb6bd260765318d73c18_7e604755-67bf-4cf9-891c-b14db6012c06.png",{},"\u002Fen\u002Finsights\u002Faccess-broker-economy-wenn-der-zugang-zu-eurem-netzwerk-im-darknet-zum-verkauf",{"title":784,"description":848},{"loc":861},"en\u002Finsights\u002Faccess-broker-economy-wenn-der-zugang-zu-eurem-netzwerk-im-darknet-zum-verkauf",[866],"Analysis","access-broker-economy-wenn-der-zugang-zu-eurem-netzwerk-im-darknet-zum-verkauf","iVgFI5xW1mfYm3QbYA3RaQ9hwi04Yi-mGyaWZrF2Xw0",1789638256110]