{"id":8800,"date":"2021-02-11T16:13:00","date_gmt":"2021-02-11T15:13:00","guid":{"rendered":"https:\/\/usd.formwandler.rocks\/news-usd-herolab-jahresbericht-2020\/"},"modified":"2021-10-15T14:07:20","modified_gmt":"2021-10-15T12:07:20","slug":"news-usd-herolab-annual-report-2020","status":"publish","type":"post","link":"https:\/\/www.usd.de\/en\/news-usd-herolab-annual-report-2020\/","title":{"rendered":"usd HeroLab Annual Report 2020: Risks. Consequences. More Security"},"content":{"rendered":"\n<p>2020 was a year of special threats \u2013 even in the world of IT security. The HeroLab Annual Report reviews the year from the perspective of our security analysts.&nbsp;<strong>Matthias G\u00f6hring, Co-Head of usd HeroLab<\/strong>, and&nbsp;<strong>Tobias Neitzel, usd Managing Consultant IT Security<\/strong>, talk about the backgrounds.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What contents can we expect in the annual report?<\/h3>\n\n\n\n<p><strong>TN<\/strong>: In our pentests, we increasingly identify the same vulnerabilities in different IT systems. In the annual report, we have prepared the most notable vulnerabilities to show how hackers proceed and how companies can better protect themselves. It is alarming to us that we keep finding vulnerabilities that have been known for years, such as cross-site scripting, in many systems and applications.<\/p>\n\n\n\n<p><strong>MG<\/strong>: Not only do we find these vulnerabilities in software our clients have developed in-house, we often find them in purchased software products as well. Vulnerabilities that are not publicly known by the time we discover them, are called&nbsp;<a href=\"https:\/\/www.usd.de\/en\/news-what-is-responsible-disclosure\/\">zero-day vulnerabilities<\/a>. We take a very responsible approach in such cases, in accordance with our&nbsp;<a href=\"https:\/\/herolab.usd.de\/en\/responsible-disclosure\/\" target=\"_blank\" rel=\"noopener\">Responsible Disclosure Policy,<\/a>&nbsp;and work with the software vendors who close this vulnerability with the help of updates. We then publish the details in the form of \u201cSecurity Advisories\u201d on our website \u2013 43 in the past year alone. This high number shows how important it is to work with vendors to find solutions to better protect businesses and users. The top 3 are listed in our annual report.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What prompted you to publish your first annual report now?<\/h3>\n\n\n\n<p><strong>MG:<\/strong>&nbsp;2020 was a special year for our clients and for us, in which we mastered many challenges. More than ever, we were there for our clients and also contributed to continuous development in different areas: we made great progress in the further development of our tool landscape, the usd HeroLab Toolchain, which helps us to support our clients with even more transparency, efficiency and highest quality. We invested more in the optimization of our internal training program, which new team members graduate from as \u201cusd HeroLab Certified Professional\u201d, UCP for short. At the same time, we intensified our university cooperation with the TU Darmstadt with the digital Hacker Contest and held the online event \u201cusd Hacking Night\u201d with over 100 participants.<\/p>\n\n\n\n<p><strong>TN:<\/strong>&nbsp;Our mission drives us forward \u2013 the toolchain helps us assess the individual threat situation of our clients and create a meaningful overview of all identified vulnerabilities. We are really very proud of what we have already achieved with our toolchain. It is important to us that with the help of the usd HeroLab annual report we provide insights into the general threat situation and show what consequences we draw from it.<\/p>\n\n\n\n<hr class=\"wp-block-separator\" \/>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:33.33%\">\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.usd.de\/wp-content\/uploads\/icon-symbol-orange-007-1.png\" alt=\"\" class=\"wp-image-4460\" width=\"143\" height=\"155\" \/><figcaption> <\/figcaption><\/figure>\n\n\n\n<p><\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66.66%\">\n<p>You can download the usd HeroLab Annual Report 2020&nbsp;<a href=\"https:\/\/www.usd.de\/wp-content\/uploads\/usd-HeroLab-Annual-Report-2020.pdf\">here<\/a>.<\/p>\n\n\n\n<p>Learn more about our toolchain <a href=\"https:\/\/herolab.usd.de\/en\/our-platforms-and-tools\/\" data-type=\"URL\" data-id=\"https:\/\/herolab.usd.de\/en\/our-platforms-and-tools\/\" target=\"_blank\" rel=\"noopener\">here<\/a>.<\/p>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>2020 was a year of special threats \u2013 even in the world of IT security. The HeroLab Annual Report reviews the year from the perspective of our security analysts.&nbsp;Matthias G\u00f6hring, Co-Head of usd HeroLab, and&nbsp;Tobias Neitzel, usd Managing Consultant IT Security, talk about the backgrounds. What contents can we expect in the annual report? TN: [&hellip;]<\/p>\n","protected":false},"author":96,"featured_media":8801,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"off","_et_pb_old_content":"","_et_gb_content_width":"","inline_featured_image":false,"footnotes":""},"categories":[373,7,374],"tags":[],"class_list":["post-8800","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-en","category-lifeatusd","category-pentests-security-analyses-en"],"_links":{"self":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/posts\/8800","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/users\/96"}],"replies":[{"embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/comments?post=8800"}],"version-history":[{"count":0,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/posts\/8800\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/media\/8801"}],"wp:attachment":[{"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/media?parent=8800"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/categories?post=8800"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.usd.de\/en\/wp-json\/wp\/v2\/tags?post=8800"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}