News
From Unicode to Exploit: The Security Risks of Overlong UTF-8 Encodings
In the dynamic field of cybersecurity, it is often the obscure and long-forgotten vulnerabilities that pose a hidden threat to otherwise hardened...
KRITIS: These Sectors Are Required to Provide Proof of Compliance in 2025
According to Section 8a (1) BSIG, operators of critical infrastructures (KRITIS) in Germany are obliged to take appropriate organizational and...
When Pentest Planning Becomes a Game of Tetris - A Look behind the Scenes of an Extensive Pentest Project with HanseMerkur
In a world where security and efficiency must go hand in hand, our recent project with HanseMerkur Krankenversicherung AG shows how crucial good...
usd AG Re-Accredited Worldwide as an Approved Scanning Vendor (ASV)
On 20.08.2024, we once again received worldwide accreditation as an Approved Scanning Vendor (ASV) for the scanning services of our usd PCI Platform...
New Partner Contribution to Allianz für Cyber-Sicherheit: usd AG Continues Its Commitment to Germany-Wide Initiative
usd AG has been actively involved in the Allianz für Cyber-Sicherheit (ACS) since 2020 and this year again supports the Germany-wide initiative's...
Operating Kubernetes Securely: Attack Targets, Processes and Meaningful Testing
Kubernetes is an open source platform for automating the deployment, scaling and management of containerized applications. This has many advantages....
Top 3 Vulnerabilities in AD Pentests
Today we look at the three most common security-critical vulnerabilities that our analysts have identified in Active Directory Pentests (AD Pentests) in recent years.
Corporate Social Responsibility: usd Awarded EcoVadis Silver Medal Again in 2024
In 2024, usd AG was once again awarded the EcoVadis silver medal.
usd AG Member of PCI SSC GEAR 2024-2026
The PCI Security Standards Council (PCI SSC) has reappointed usd AG to the Global Executive Assessor Roundtable (GEAR).
Information Security in Third-Party Risk Management: How to Monitor Your TPRM Program
Companies often work with a large number of service providers in order to be able to concentrate on their core business or save costs. For this to...
Coffee Break with Pentesters: 5 Questions about Black Hat & DEF CON 2024
“Have you heard? We can present the CSTC at Black Hat again.” - This or something similar is how a chat at the coffee machine between Matthias...
Security Advisories on hugocms and Gitea
The pentest professionals at usd HeroLab examined hugocms and Gitea during their pentests. Thereby, several vulnerabilities were identified. The...











