[{"data":1,"prerenderedAt":735},["ShallowReactive",2],{"post-en-threat-center-neue-cves-automatisch-verifiziert":3,"related-en-threat-center-neue-cves-automatisch-verifiziert":220},{"id":4,"title":5,"author":6,"body":7,"category":188,"date":189,"description":190,"draft":191,"extension":192,"faq":193,"image":203,"imageAlt":204,"lang":205,"legacyUrl":206,"meta":207,"navigation":208,"path":209,"readingTime":180,"seo":210,"sitemap":211,"stem":215,"tags":216,"translation":218,"updated":206,"__hash__":219},"insightsEn\u002Fen\u002Finsights\u002Fthreat-center-neue-cves-automatisch-verifiziert.md","Threat Center: From CVE alarm to confirmed exposure","blacklens.io Team",{"type":8,"value":9,"toc":178},"minimark",[10,14,19,22,25,29,32,35,75,79,82,89,97,101,104,135,141,148,152,155,163],[11,12,13],"p",{},"Critical new vulnerabilities in firewalls, VPN gateways and mail servers now arrive week after week. The question that matters is never whether there is a new CVE. It is whether it affects your organisation. The Threat Center in blacklens.io answers exactly that: automatically, for your systems, with evidence.",[15,16,18],"h2",{"id":17},"what-is-the-threat-center","What is the Threat Center?",[11,20,21],{},"The Threat Center is the blacklens.io early warning system for new vulnerabilities. It continuously matches newly published CVEs against the technologies your organisation runs and shows only the matches that really affect you. It builds on the inventory blacklens.io already creates from external scans, the Sentry agent and your cloud connectors. There is nothing extra to set up.",[11,23,24],{},"Behind it sits a threat feed of more than 140,000 CVEs, over 26,000 of them with a public exploit. From that volume, your team gets the short list of vulnerabilities that apply to your firewall, your Exchange server or your Citrix gateway.",[15,26,28],{"id":27},"why-a-cve-newsletter-is-no-longer-enough","Why a CVE newsletter is no longer enough",[11,30,31],{},"CVE newsletters and CERT warnings matter, but they are written for everyone. Whether the product runs in your environment, in which version and on which system, your team has to work out afterwards. With several critical notices a week, that search costs hours, and those are the hours in which attackers start scanning.",[11,33,34],{},"The Threat Center reverses the order. Instead of a general warning, you get a list of affected systems, each with the signals that matter for prioritisation:",[36,37,38,51,60,66],"ul",{},[39,40,41,50],"li",{},[42,43,44,49],"strong",{},[45,46,48],"a",{"href":47},"\u002Fen\u002Fwissen\u002Fepss","EPSS",":"," how likely is exploitation within the next 30 days?",[39,52,53,59],{},[42,54,55,49],{},[45,56,58],{"href":57},"\u002Fen\u002Fwissen\u002Fcisa-kev","CISA KEV"," is the vulnerability already under active attack, and by when should it be fixed?",[39,61,62,65],{},[42,63,64],{},"Exploit:"," is attack code publicly available?",[39,67,68,74],{},[42,69,70,49],{},[45,71,73],{"href":72},"\u002Fen\u002Fwissen\u002Fcvss","CVSS"," how severe is the vulnerability technically?",[15,76,78],{"id":77},"from-warning-to-certainty","From warning to certainty",[11,80,81],{},"A match in the inventory is a suspicion. So blacklens.io checks it: where a verification template exists for the CVE, a targeted scan against the affected system starts automatically. The result is clear, either confirmed or not confirmed. Your team spends its time on real findings, not guesswork.",[11,83,84],{},[85,86],"img",{"alt":87,"src":88},"Threat detail view in the Threat Center with CVSS 10, EPSS score, CISA KEV due date and a running verification scan","\u002Fimages\u002Finsights\u002Fthreat-center-neue-cves-automatisch-verifiziert-2.webp",[11,90,91,92,96],{},"The detail view shows at a glance how critical a vulnerability is, whether it is already being exploited and which systems are affected. Confirmed matches become regular findings in the same ",[45,93,95],{"href":94},"\u002Fen\u002Fwissen\u002Fvulnerability-management","vulnerability management"," workflow as everything else, with assignment, ticket and retest.",[15,98,100],{"id":99},"fewer-alarms-more-impact","Fewer alarms, more impact",[11,102,103],{},"An early warning system that rings all the time gets ignored. The Threat Center is built to stay quiet:",[36,105,106,112,118,129],{},[39,107,108,111],{},[42,109,110],{},"Threshold per workspace:"," alerts start at a CVSS score of your choice, 7 by default.",[39,113,114,117],{},[42,115,116],{},"Grouped, not one by one:"," new CVEs for the same product produce one alert, not dozens.",[39,119,120,123,124,128],{},[42,121,122],{},"To the right team:"," notification policies route alerts by e-mail, push or through ",[45,125,127],{"href":126},"\u002Fen\u002Fplatform\u002Fintegrations","integrations"," such as Jira, Microsoft Teams and Microsoft Sentinel.",[39,130,131,134],{},[42,132,133],{},"Escalated automatically:"," when exploitation is likely and an exploit is available, urgency rises on its own.",[11,136,137],{},[85,138],{"alt":139,"src":140},"Alert list with grouped threat intel alerts, such as \"35 Emerging CVEs may affect Microsoft Sql Server\"","\u002Fimages\u002Finsights\u002Fthreat-center-neue-cves-automatisch-verifiziert-4.webp",[11,142,143,144,147],{},"The ",[42,145,146],{},"Advisories"," view adds vendor security notices, so broader warnings sit in the same tool.",[15,149,151],{"id":150},"what-this-means-for-your-organisation","What this means for your organisation",[11,153,154],{},"The time between a vulnerability's disclosure and the first attack is the window in which you can act. The Threat Center shortens the path from \"a new CVE is out\" to \"these systems are affected, it is confirmed, and the responsible team has the ticket\".",[11,156,157,158,162],{},"At the same time, it builds a traceable record of which vulnerabilities were detected, checked and handled. That helps in audits and with requirements such as ",[45,159,161],{"href":160},"\u002Fen\u002Fwissen\u002Fnis2","NIS2",", which call for structured vulnerability handling.",[11,164,165,168,169,172,173,177],{},[42,166,167],{},"Get started:"," the Threat Center is active in blacklens.io under ",[42,170,171],{},"Threat Center → Emerging Threats"," as soon as your technology inventory is in place. Read more about the ",[45,174,176],{"href":175},"\u002Fen\u002Fplatform\u002Femerging-threats","early warning system for zero-days and new CVEs"," on the platform page.",{"title":179,"searchDepth":180,"depth":180,"links":181},"",3,[182,184,185,186,187],{"id":17,"depth":183,"text":18},2,{"id":27,"depth":183,"text":28},{"id":77,"depth":183,"text":78},{"id":99,"depth":183,"text":100},{"id":150,"depth":183,"text":151},"release","2026-09-24","The blacklens.io Threat Center is your early warning system for new vulnerabilities: it shows which CVEs affect your systems and confirms it by scan.",false,"md",[194,197,200],{"q":195,"a":196},"What does the blacklens.io Threat Center do?","The Threat Center is the blacklens.io early warning system for new vulnerabilities. It continuously matches newly published CVEs against the technologies your organisation actually runs and shows only the matches that affect you. Where a verification template exists, a targeted scan automatically confirms whether your system is vulnerable. Signals such as EPSS and CISA KEV show what needs fixing first.",{"q":198,"a":199},"How do I know whether a new vulnerability affects my organisation?","Whether a new vulnerability affects your organisation depends on whether the named product runs in an affected version in your environment and whether it can be reached. That requires an up-to-date inventory of your technologies. An early warning system such as the Threat Center matches new CVEs against this inventory automatically and checks the affected systems by scan, instead of your team chasing every warning by hand.",{"q":201,"a":202},"How does the Threat Center prevent alert fatigue?","The Threat Center only raises alerts above a CVSS threshold you set per workspace, 7 by default. blacklens.io groups new CVEs for the same product into a single alert instead of reporting each one. Notification policies route alerts by severity to the right team, by e-mail, push or through integrations such as Jira, Microsoft Teams and Microsoft Sentinel. Every match stays visible in the list.","\u002Fimages\u002Finsights\u002Fthreat-center-neue-cves-automatisch-verifiziert.webp","Emerging Threats list in the blacklens.io Threat Center with new CVEs, state and risk signals per technology","en",null,{},true,"\u002Fen\u002Finsights\u002Fthreat-center-neue-cves-automatisch-verifiziert",{"title":5,"description":190},{"loc":209,"images":212},[213,214],{"loc":88},{"loc":140},"en\u002Finsights\u002Fthreat-center-neue-cves-automatisch-verifiziert",[217],"Release notes","threat-center-neue-cves-automatisch-verifiziert","wEIzwGFMdqPmNnfyQFG5AXJO_wvJ_zy5tF6u2YMMIHE",[221,404,659],{"id":222,"title":223,"author":6,"body":224,"category":379,"date":380,"description":381,"draft":191,"extension":192,"faq":382,"image":392,"imageAlt":393,"lang":205,"legacyUrl":206,"meta":394,"navigation":208,"path":395,"readingTime":396,"seo":397,"sitemap":398,"stem":399,"tags":400,"translation":402,"updated":206,"__hash__":403},"insightsEn\u002Fen\u002Finsights\u002Fnisg-2026-oesterreich-fristen-nachweise.md","NISG 2026: Austria's NIS2 deadlines from 1 October",{"type":8,"value":225,"toc":371},[226,229,233,236,239,259,262,266,273,276,280,283,286,290,293,299,305,311,315,348,352,363],[11,227,228],{},"Austria's Network and Information System Security Act 2026 enters into force on 1 October 2026, nine months\nafter its publication. From that day, deadlines run that cannot be extended: three months to register,\ntwelve months to file the self-declaration. Anyone who starts collecting evidence once the authority asks\nwill be describing the state of yesterday.",[15,230,232],{"id":231},"what-the-nisg-2026-requires-from-1-october","What the NISG 2026 requires from 1 October",[11,234,235],{},"The NISG 2026 transposes Directive (EU) 2022\u002F2555 into Austrian law, and it applies from the day it enters\ninto force, not from the day you register. It was published on 23 December 2025 as BGBl. I No. 94\u002F2025,\nafter the Nationalrat passed it on 12 December 2025 with the two-thirds majority its constitutional\nprovisions require. Supervision and enforcement sit with the cyber security authority at the Ministry of\nthe Interior.",[11,237,238],{},"Three deadlines shape the next twelve months:",[36,240,241,247,253],{},[39,242,243,246],{},[42,244,245],{},"Registration:"," within three months of entry into force, so by the end of December 2026.",[39,248,249,252],{},[42,250,251],{},"Self-declaration:"," within twelve months of the registration obligation arising. The structured\ndeclaration covers the network and information systems in use, supply chain security and the results of\nthe risk analysis. What is new is that it is due on a fixed deadline rather than on request.",[39,254,255,258],{},[42,256,257],{},"Incident reporting:"," an early warning without undue delay and within 24 hours at the latest, a full\nnotification within 72 hours, and a final report within one month.",[11,260,261],{},"Penalties follow the directive: up to 10 million euros or 2 per cent of global annual turnover for\nessential entities, up to 7 million euros or 1.4 per cent for important ones. Accountability sits with the\nmanagement body, not with the IT department.",[15,263,265],{"id":264},"who-is-affected-in-austria","Who is affected in Austria",[11,267,268,269,272],{},"You are affected if you operate in one of the directive's 18 sectors and meet the size thresholds: as a\nrule from 50 employees or 10 million euros in turnover, and in some sectors regardless of size. The act\ndistinguishes between essential and important entities, which determines both supervisory intensity and\nthe maximum penalty. The glossary entry on the ",[45,270,271],{"href":160},"NIS2 directive"," sets out the\nclassification in detail.",[11,274,275],{},"Nobody makes that assessment for you. There is no official notice establishing that you are in scope and\nno letter marking the start: the assessment itself is part of the obligation. That is where companies which\ndo not think of themselves as critical tend to fail — suppliers in manufacturing, for instance, or\noperators running data centre services for others.",[15,277,279],{"id":278},"in-germany-the-deadline-has-already-passed","In Germany the deadline has already passed",[11,281,282],{},"Germany went down the same road nine months earlier. The NIS2 implementation act entered into force on\n6 December 2025, the BSI registration portal has been live since 6 January 2026, and the original\nregistration deadline of 6 March 2026 was extended to 31 July 2026. That date has passed; anyone not\nregistered by now risks supervisory measures regardless of whether an incident has ever occurred.",[11,284,285],{},"For companies with sites in both countries this means two registrations, two authorities and two reporting\npaths. The technical evidence underneath can be the same, provided it is built from the start to serve\nboth supervisory logics.",[15,287,289],{"id":288},"where-the-self-declaration-comes-unstuck","Where the self-declaration comes unstuck",[11,291,292],{},"The self-declaration does not ask for intentions, it asks for results. Three of its elements are the\nhardest to produce in practice, because they do not come from a document but from a running process.",[11,294,295,298],{},[42,296,297],{},"The inventory."," Which systems are reachable from the internet, running which services, since when? A\nlist from the last audit describes a state that no longer exists: subdomains get created, test environments\nstay open, cloud resources appear without a ticket.",[11,300,301,304],{},[42,302,303],{},"Vulnerability handling."," Article 21(2) of the directive explicitly names vulnerability handling and\ndisclosure. You cannot evidence that with scanner output alone; you evidence it with a chain: found on,\nassessed by, decided by, fixed by. An annual penetration test gives you a snapshot, not a chain.",[11,306,307,310],{},[42,308,309],{},"The supply chain."," The directive requires you to account for risks arising from relationships with\nsuppliers and service providers. That includes incidents that happen at a supplier and only reach you\nthrough them — when their data shows up on a leak site, for example.",[15,312,314],{"id":313},"what-you-can-prepare-in-the-coming-weeks","What you can prepare in the coming weeks",[316,317,318,324,330,336,342],"ol",{},[39,319,320,323],{},[42,321,322],{},"Assess and document whether you are in scope."," Sector, size, classification, with a date and a\nrationale. A well-argued \"no\" is evidence too.",[39,325,326,329],{},[42,327,328],{},"Name the accountable people."," The management body is liable and must approve and oversee the measures.",[39,331,332,335],{},[42,333,334],{},"Map the external attack surface."," Not the systems listed in your documentation, but the ones that\nanswer from outside.",[39,337,338,341],{},[42,339,340],{},"Put deadlines on the vulnerability process."," Who prioritises, by which criterion, within what time.\nWithout a deadline it is a list, not a process.",[39,343,344,347],{},[42,345,346],{},"Rehearse the reporting path."," 24 hours is short if the question of who reports what to whom is only\nsettled during the incident.",[15,349,351],{"id":350},"what-blacklensio-contributes","What blacklens.io contributes",[11,353,354,355,357,358,362],{},"blacklens.io provides the technical part of that evidence base: a continuously updated inventory of\nexternally reachable systems with an exposure score, internal scans through the Sentry agent, cloud\nconfiguration and dark web findings in one shared findings workflow, plus a supplier watchlist that polls\nransomware leak sites roughly every 30 minutes. Prioritisation draws on EPSS, the CISA KEV catalogue,\navailable exploits and ",[45,356,73],{"href":72},", so the reasoning behind an order of work is documented rather than\nreconstructed afterwards. Scheduled reports and CSV export hand those records, dated, to your ISMS or GRC\nsystem; which evidence maps to which requirement is set out on the\n",[45,359,361],{"href":360},"\u002Fen\u002Fcompliance\u002Fnis2","NIS2 and vulnerability management"," page.",[11,364,365,366,370],{},"One detail that matters for Austrian entities: scanning runs exclusively from Austria, Germany and\nSwitzerland, and the platform is hosted in ISO 27001 and SOC 2 certified data centres in the DACH region.\nNone of this replaces a management system, and this article is technical orientation, not legal advice —\nwhich obligations apply to you specifically is a question for your legal team, your auditor or the\nauthority. What blacklens.io adds is the part a document cannot provide:\n",[45,367,369],{"href":368},"\u002Fen\u002Fplatform\u002Fvulnerability-management","continuous vulnerability data"," instead of a snapshot.",{"title":179,"searchDepth":180,"depth":180,"links":372},[373,374,375,376,377,378],{"id":231,"depth":183,"text":232},{"id":264,"depth":183,"text":265},{"id":278,"depth":183,"text":279},{"id":288,"depth":183,"text":289},{"id":313,"depth":183,"text":314},{"id":350,"depth":183,"text":351},"guide","2026-09-22","Austria's NISG 2026 enters into force on 1 October. Which deadlines apply for registration and self-declaration, and what evidence you need to produce them.",[383,386,389],{"q":384,"a":385},"When does Austria's NISG 2026 enter into force?","The Network and Information System Security Act 2026 enters into force on 1 October 2026. It was published on 23 December 2025 as BGBl. I No. 94\u002F2025, after the Nationalrat passed it on 12 December 2025 with the required two-thirds majority. The act takes effect nine months after publication, on the first day of the following month, and transposes Directive (EU) 2022\u002F2555 into Austrian law.",{"q":387,"a":388},"By when must affected entities in Austria register?","Affected entities must register with the cyber security authority within three months of the act entering into force, so by the end of December 2026. The self-declaration follows: within twelve months of the registration obligation arising, entities submit a structured declaration covering the network and information systems they use, supply chain security and the results of their risk analysis.",{"q":390,"a":391},"How does the Austrian implementation differ from the German one?","Germany's NIS2 implementation act entered into force on 6 December 2025, the BSI registration portal has been live since 6 January 2026, and the extended registration deadline expired on 31 July 2026. In Austria this cycle only starts on 1 October 2026. Companies with sites in both countries face two separate registration duties, but can base both on the same body of technical evidence.","\u002Fimages\u002Finsights\u002Fnisg-2026-oesterreich-fristen-nachweise.webp","Person holding a tablet with a green NIS2 shield above it, ringed by the twelve EU stars",{},"\u002Fen\u002Finsights\u002Fnisg-2026-oesterreich-fristen-nachweise",5,{"title":223,"description":381},{"loc":395},"en\u002Finsights\u002Fnisg-2026-oesterreich-fristen-nachweise",[401],"Guide","nisg-2026-oesterreich-fristen-nachweise","GMFZ-LCt2nm3MQRr3hCh3KW1U5AXP_EMnxsOsbImL90",{"id":405,"title":406,"author":6,"body":407,"category":188,"date":636,"description":637,"draft":191,"extension":192,"faq":638,"image":648,"imageAlt":206,"lang":205,"legacyUrl":206,"meta":649,"navigation":208,"path":650,"readingTime":396,"seo":651,"sitemap":652,"stem":655,"tags":656,"translation":657,"updated":206,"__hash__":658},"insightsEn\u002Fen\u002Finsights\u002Fwas-zuerst-intelligente-schwachstellen-priorisierung-mit-blacklens.md","What First? Intelligent Vulnerability Prioritisation with blacklens",{"type":8,"value":408,"toc":628},[409,414,422,428,432,439,469,472,476,479,524,527,532,536,543,562,566,572,596,600,611,615,618],[410,411,413],"h1",{"id":412},"what-first-intelligent-vulnerability-prioritisation-with-blacklens","What first? Intelligent vulnerability prioritisation with blacklens",[11,415,416,417,421],{},"The uncomfortable truth in vulnerability management: the problem is rarely ",[418,419,420],"em",{},"finding"," vulnerabilities. The problem is spotting, among a thousand findings, the ten that really matter today. Anyone who works through the list by raw CVSS score burns time on findings that will never be exploited – while the one genuinely reachable, genuinely exploitable flaw waits in row 847 of the spreadsheet.",[11,423,424,425],{},"With its latest release, blacklens answers the three questions on which prioritisation really hinges: ",[42,426,427],{},"What first? Why that one? And how do we fix it?",[15,429,431],{"id":430},"a-plan-instead-of-a-spreadsheet-the-remediation-plan","A plan instead of a spreadsheet: the Remediation Plan",[11,433,434,435,438],{},"Under ",[42,436,437],{},"Vulnerabilities → Remediation",", blacklens generates a prioritised action plan from all open findings at the push of a button – external, internal and cloud considered together:",[36,440,441,447,453,459],{},[39,442,443,446],{},[42,444,445],{},"Grouped by the fix, not by the finding."," An outdated TLS setup on twelve hosts is not a dozen tasks but one. The plan bundles findings by the measure that fixes them together.",[39,448,449,452],{},[42,450,451],{},"Sorted by risk reduction."," At the top sits the cluster with the greatest leverage – by severity and breadth. Not the loudest one, the most effective one.",[39,454,455,458],{},[42,456,457],{},"With rationale and instructions."," Each cluster explains why it sits where it does, estimates the effort (low \u002F medium \u002F high) and provides numbered steps, including copy-ready code where appropriate.",[39,460,461,464,465,468],{},[42,462,463],{},"Progress you can see."," While your team works, the plan stays stable – only the counters move: completed steps, resolved instances, coverage of open findings. Right up to ",[418,466,467],{},"\"Plan complete — nice work\"",".",[11,470,471],{},"Generation takes around 30–60 seconds, and you can keep working in the meantime. The result changes your team's unit of work: no longer \"finding by finding\" but \"step by step\" – with visible movement instead of an endless backlog.",[15,473,475],{"id":474},"prioritising-means-understanding-context-on-every-finding","Prioritising means understanding: context on every finding",[11,477,478],{},"A good order needs good reasons. That is why every finding – external, internal and cloud – gets an explanation layer that makes prioritisation decisions robust:",[36,480,481,502,508,518],{},[39,482,483,486,487,490,491,490,494,497,498,501],{},[42,484,485],{},"Urgency with evidence:"," A suggested rating along with an exploit status chip – ",[418,488,489],{},"Exploit available",", ",[418,492,493],{},"PoC public",[418,495,496],{},"No known exploit"," or ",[418,499,500],{},"Exploitability unknown",". The platform severity remains authoritative; the assessment supplements it, it does not override it.",[39,503,504,507],{},[42,505,506],{},"Threat intelligence per CVE:"," CVSS, EPSS (probability of exploitation in the wild within 30 days), exploit\u002FPoC availability, attack vector and advisory link – from the blacklens threat feed. Exactly the data you need to tell \"high\" from \"urgent\".",[39,509,510,513,514,517],{},[42,511,512],{},"Root cause, impact and remediation:"," Why the finding exists, what it exposes and how it is closed – in 1–6 concrete steps. Plus ",[42,515,516],{},"compensating controls"," for the realistic case that the actual fix has to wait.",[39,519,520,523],{},[42,521,522],{},"Follow-up questions right on the finding:"," A chat beneath the analysis answers follow-up questions in the real context of your workspace – the actual service fingerprint, the affected hosts, the same finding on other systems.",[11,525,526],{},"The analyses are generated on request, cached transparently with a timestamp and visibly carry a note to review generated content before taking critical steps. The decision stays with your team – it just gets considerably faster.",[11,528,529],{},[85,530],{"alt":179,"src":531},"\u002Fimages\u002Finsights\u002F6a8eab8037efc3396911b5c6_Screenshot-2026-08-26-at-10.59.14.png",[15,533,535],{"id":534},"prioritisation-beyond-the-cve-which-lookalike-domain-is-dangerous","Prioritisation beyond the CVE: which lookalike domain is dangerous?",[11,537,538,539,542],{},"With typosquatting, too, the question is never \"are there lookalikes?\" but \"which of them is a problem?\". The new detail view provides the basis for that decision: a character diff against your domain, registration and DNS data, a reputation score – and risk badges such as ",[418,540,541],{},"Mail capable"," that show at a glance whether a domain has everything credential phishing needs.",[11,544,545,546,549,550,553,554,557,558,561],{},"On demand, blacklens goes one step further: it captures what the domain actually serves, including a screenshot, and assesses whether it imitates your brand. ",[42,547,548],{},"Evidence and assessment stay cleanly separated",": ",[418,551,552],{},"Observed on the page"," lists objective signals extracted by blacklens itself – a password field, the brand name, a form posting to a foreign domain – while the ",[418,555,556],{},"Assessment"," is the interpretation. Only once the evidence is complete (the checklist shows 5\u002F5) is the ",[42,559,560],{},"Draft abuse report"," unlocked: a pre-filled, factual email to the registrar's abuse contact. Sending it is up to you.",[15,563,565],{"id":564},"getting-to-the-right-view-faster-ask-instead-of-building-filters","Getting to the right view faster: ask instead of building filters",[11,567,568,569,468],{},"Prioritisation often starts with a simple question: \"Show me critical findings on prod hosts.\" That is exactly how you can ask it now – on 17 dashboard lists, blacklens translates the description into a ready-made, editable filter query with a preview. The language model never sees your data at any point, only field names, types and permitted values – and nothing runs until you click ",[418,570,571],{},"Apply filters",[11,573,574,575,490,578,490,581,584,585,588,589,497,592,595],{},"Complementing this is the new status strip above every attack surface list: five metrics per page – such as ",[418,576,577],{},"Exposing",[418,579,580],{},"Vulnerable",[418,582,583],{},"High risk"," – many of them clickable as filters. And a principle we like to quote: ",[42,586,587],{},"Unknown never counts as safe."," Tiles such as ",[418,590,591],{},"Public",[418,593,594],{},"No MFA"," only count what a provider has explicitly reported.",[15,597,599],{"id":598},"on-your-terms","On your terms",[11,601,602,603,606,607,610],{},"The intelligent features of this release – Remediation Plan, finding explanations, domain verdicts, natural-language search – are ",[42,604,605],{},"opt-in per workspace"," and switched off initially after the update. Workspace admins decide under ",[42,608,609],{},"Settings → General → AI Features",", and \"off\" means off: the server rejects such requests for deactivated workspaces. The analyses run on our self-hosted LLM and are GDPR-compliant – your data never leaves our infrastructure.",[15,612,614],{"id":613},"conclusion","Conclusion",[11,616,617],{},"Less time sorting, more time fixing: this release turns the flood of findings into a reasoned order – a plan with the greatest risk leverage at the top, context and threat intelligence on every finding, evidence instead of gut feeling for lookalike domains. The intelligence lies in the prioritisation. Control stays with you.",[11,619,620,622,623,625,626,468],{},[42,621,167],{}," Workspace admins enable the features under ",[418,624,609],{},". After that, your first Remediation Plan is waiting under ",[418,627,437],{},{"title":179,"searchDepth":180,"depth":180,"links":629},[630,631,632,633,634,635],{"id":430,"depth":183,"text":431},{"id":474,"depth":183,"text":475},{"id":534,"depth":183,"text":535},{"id":564,"depth":183,"text":565},{"id":598,"depth":183,"text":599},{"id":613,"depth":183,"text":614},"2026-09-02","What first, why, and how? blacklens turns open findings into a prioritised remediation plan – sorted by risk reduction, with context on every finding.",[639,642,645],{"q":640,"a":641},"What is the blacklens Remediation Plan?","The Remediation Plan, found under Vulnerabilities → Remediation, turns all open external, internal and cloud findings into a prioritised action plan at the push of a button. Findings are grouped by the fix that resolves them, sorted by risk reduction and delivered with a rationale, an effort estimate and numbered steps, while progress counters update as your team works through the plan.",{"q":643,"a":644},"How does blacklens help prioritise vulnerabilities beyond the CVSS score?","Every finding receives an explanation layer with a suggested urgency, an exploit status chip and threat intelligence per CVE, including CVSS, EPSS, exploit or PoC availability, attack vector and advisory link. Root cause, impact, remediation steps and compensating controls are provided, and a chat on the finding answers follow-up questions in the context of your workspace.",{"q":646,"a":647},"Are the AI features in blacklens enabled by default, and where does the data go?","No. Remediation Plan, finding explanations, domain verdicts and natural-language search are opt-in per workspace and switched off after the update; workspace admins enable them under Settings → General → AI Features. The analyses run on blacklens' self-hosted LLM and are GDPR-compliant, so your data does not leave the blacklens infrastructure.","\u002Fimages\u002Finsights\u002F6a8eab1862da2619b8478b7d_Screenshot-2026-08-26-at-10.59.51.png",{},"\u002Fen\u002Finsights\u002Fwas-zuerst-intelligente-schwachstellen-priorisierung-mit-blacklens",{"title":406,"description":637},{"loc":650,"images":653},[654],{"loc":531},"en\u002Finsights\u002Fwas-zuerst-intelligente-schwachstellen-priorisierung-mit-blacklens",[217],"was-zuerst-intelligente-schwachstellen-priorisierung-mit-blacklens","e1t1-bD9PIM1yFeHDE2AjNbJbYmYRx1HL1rehDCrysg",{"id":660,"title":661,"author":6,"body":662,"category":713,"date":714,"description":715,"draft":191,"extension":192,"faq":716,"image":725,"imageAlt":206,"lang":205,"legacyUrl":206,"meta":726,"navigation":208,"path":727,"readingTime":180,"seo":728,"sitemap":729,"stem":730,"tags":731,"translation":733,"updated":206,"__hash__":734},"insightsEn\u002Fen\u002Finsights\u002Ffortibleed-wenn-zehntausende-firewalls-zur-offenen-tur-werden.md","FortiBleed: When Tens of Thousands of Firewalls Become an Open Door",{"type":8,"value":663,"toc":707},[664,667,671,674,677,681,684,687,690,694,697,700,704],[11,665,666],{},"FortiGate firewalls protect corporate networks. That is their sole purpose. What FortiBleed shows: when the firewall itself becomes the attack surface, it no longer protects – it opens up.",[15,668,670],{"id":669},"what-is-fortibleed","What is FortiBleed?",[11,672,673],{},"FortiBleed is not a single breach. It is an industrialised harvesting operation against internet-exposed Fortinet firewalls and SSL VPN gateways. The dataset was discovered in mid-June 2026 by security researcher Volodymyr \"Bob\" Diachenko.",[11,675,676],{},"The scale is extraordinary – even though the exact figures vary by source and are still changing, as the campaign was still active at the time of publication. Security researchers who analysed the leaked dataset estimate the number of affected FortiGate devices at somewhere between 30,000 and 75,000. The entries it contains can be attributed to around 21,600 domains in 194 countries – a cross-section of global corporations, public authorities and critical infrastructure operators across almost every industry.",[15,678,680],{"id":679},"how-the-attack-worked","How the attack worked",[11,682,683],{},"The attack follows an automated, self-reinforcing chain. First, the internet is scanned for reachable FortiGate devices – above all SSL VPN endpoints and management interfaces. Against each device found, the attackers then test a curated list of known passwords. A successful login is not followed by a noisy attack – instead, the compromised device is used as a silent \"listening post\": it sits at the network perimeter and reads the traffic passing through in order to harvest further credentials. These flow back into the scanner and compromise the next device. The system feeds itself.",[11,685,686],{},"The password list being tested is not random. It consists of credentials that had already leaked in earlier Fortinet incidents and via infostealer logs – many organisations never changed their passwords after a previous incident. In addition, according to Diachenko's reconstruction, the attackers intercepted SSL VPN authentication hashes and cracked them offline with a GPU cluster (a Hashtopolis-managed setup of around 45 GPUs has been reported).",[11,688,689],{},"As things stand, this is not a confirmed zero-day. How the configuration data originally left the devices remains open: candidates include known but unpatched vulnerabilities (in particular CVE-2026-24858, a FortiCloud SSO SAML bypass with a CVSS score of up to 9.8), a still-unknown flaw, infostealer credentials, or a combination of these. A further contributing factor is that on many devices admin passwords are still stored in the older SHA-256 format – namely wherever admins never logged in again after a firmware update. In any case, the core of the problem remains the same: exposed management interfaces and reused or crackable credentials.",[15,691,693],{"id":692},"the-role-of-infostealers","The role of infostealers",[11,695,696],{},"A significant share of the credentials does not come from classic brute force but from infostealer campaigns. Infostealer malware on employee devices steals saved VPN credentials and passwords from browsers and password managers before they end up in dark web forums and dumps. In many cases these credentials enabled a valid login without any brute force at all.",[11,698,699],{},"That also makes FortiBleed a dark web monitoring topic: the infostealer activity that led to these credentials was visible in the relevant forums and dumps – to anyone actively looking there.",[15,701,703],{"id":702},"what-helps-and-why-visibility-is-decisive","What helps – and why visibility is decisive",[11,705,706],{},"This is exactly where blacklens.io comes in. Dark Web Monitoring detects when credentials or infostealer activity affect your own company – the Emerging Threat Notification System informs you proactively, before someone else reacts. Continuous attack surface analysis shows which systems are really reachable from the outside – including the ones nobody internally remembers any more.",{"title":179,"searchDepth":180,"depth":180,"links":708},[709,710,711,712],{"id":669,"depth":183,"text":670},{"id":679,"depth":183,"text":680},{"id":692,"depth":183,"text":693},{"id":702,"depth":183,"text":703},"threat","2026-08-06","FortiGate firewalls exist to protect corporate networks. FortiBleed shows what happens when the firewall itself becomes the attack surface – and opens the door.",[717,719,722],{"q":670,"a":718},"FortiBleed is an industrialised credential-harvesting operation against internet-exposed Fortinet FortiGate firewalls and SSL VPN gateways, discovered in mid-June 2026 by security researcher Volodymyr Diachenko. Estimates put the number of affected devices between 30,000 and 75,000, spread across roughly 21,600 domains in 194 countries.",{"q":720,"a":721},"How did the FortiBleed attackers gain access to FortiGate devices?","The attackers scanned the internet for exposed SSL VPN endpoints and management interfaces and tested curated lists of previously leaked passwords and infostealer credentials against them. Compromised devices were then used as silent listening posts to harvest further credentials, and intercepted VPN authentication hashes were cracked offline on a GPU cluster.",{"q":723,"a":724},"How can companies protect themselves against attacks like FortiBleed?","Keep management interfaces off the public internet, rotate every credential that may have leaked in earlier incidents and enforce MFA on VPN access. Dark web monitoring detects leaked credentials and infostealer activity affecting your company early, and continuous attack surface analysis shows which systems are actually reachable from outside.","\u002Fimages\u002Finsights\u002F6a33e0062536b90c9b6edd6f_FortiBleed.png",{},"\u002Fen\u002Finsights\u002Ffortibleed-wenn-zehntausende-firewalls-zur-offenen-tur-werden",{"title":661,"description":715},{"loc":727},"en\u002Finsights\u002Ffortibleed-wenn-zehntausende-firewalls-zur-offenen-tur-werden",[732],"Threat landscape","fortibleed-wenn-zehntausende-firewalls-zur-offenen-tur-werden","PneGkfhcZR06I9jQQwlU1RBHTQ-Dg_89axBdXXbdu8k",1790259984055]