CVE-2025-12686: Critical vulnerability in Synology BeeStation (CVSS 9.8)
Analysis of the critical vulnerability CVE-2025-12686 (CVSS 9.8) in Synology BeeStation, which allows unauthenticated remote code execution. Details and measures.
Artikel lesenAktuelle Sicherheitswarnungen, regulatorische Einordnungen und Praxiswissen für fundierte Cyberrisiko-Entscheidungen.
Analysis of the critical vulnerability CVE-2025-12686 (CVSS 9.8) in Synology BeeStation, which allows unauthenticated remote code execution. Details and measures.
Artikel lesen
The identification of unknown infrastructure is a core task in External Attack Surface Management (EASM). LocateRisk provides a specialized interface based on the Model Context Protocol (MCP) for this purpose. LocateRisk is currently the only provider to enable direct machine-to-machine communication, which makes complex detection paths of IT systems immediately analyzable for artificial intelligence.
Artikel lesen
What happened? Facts and allegations According to reports, there were IT disruptions from May 1, 2026, primarily affecting the plant in Mount Pleasant, Wisconsin - an important center for the production of AI servers. On May 11, Foxconn appeared on the Nitrogen Group's leak site. The attackers threatened to release over 11 million [...]
Artikel lesen
The BSI has presented a list of criteria that defines when a cloud service is considered sovereign. The focus is on data control options, transparency of the service provider and the ability to comply with regulatory requirements.
Artikel lesen
Making the invisible visible - that's what drives us at LocateRisk GmbH. Lukas Baumann in the CIO Views Magazine Portrait.
Artikel lesen
LocateRisk provides an interface based on the Model Context Protocol (MCP). LocateRisk is currently the only provider in the field of External Attack Surface Management (EASM) and Cyber Vendor Risk Management (C-VRM) to enable direct machine-to-machine communication. The technology combines security analyses directly with artificial intelligence, making complex data available for automated decisions without any loss of time.
Artikel lesen
Wie Sie mit Preemptive Intelligence kritische Software sofort nach Bekanntmachung absichern und die "Time-to-Action" verkürzen
Artikel lesen
The vulnerable npm ecosystem npm is the heart of the JavaScript world. This is where developers exchange packages and build efficient applications. But it is precisely this openness that criminals are exploiting. Over 40 packages have been compromised. The attackers' goal: stealing data and manipulating build processes. The reach is particularly fatal. A single malicious package upload can affect widely dispersed projects and reduce software quality [...]
Artikel lesen
The new Microsoft specifications offer the opportunity to comprehensively improve your cyber security.
Artikel lesen
LocateRisk wins ATHENE Startup Award UP24@it-sa as Best Cybersecurity Startup 2024 DACH.
Artikel lesen
LocateRisk awarded second place in WirtschaftsWoche's "Best of Technology Award 2024".
Artikel lesen
Increase the efficiency of your supplier evaluations with automated workflows and processes.
Artikel lesen
This article provides you with an overview of the current status regarding GDPR, NIS2, DORA and CRA.
Artikel lesen