Skip to content
View in the app

A better way to browse. Learn more.

hosang I.T.

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

CSOonline

Members
  • Joined

  • Last visited

    Never

Everything posted by CSOonline

  1. abdullah Ghashqeen – Shutterstock Ein turbulentes Jahr 2025 neigt sich dem Ende zu. Es war geprägt von wirtschaftlicher Unsicherheit, geopolitischen Spannungen und dem ungebremsten Siegeszug der Künstlichen Intelligenz. Grund genug für die Redaktion von Computerwoche, CIO und CSO, in der letzten TechTalk-Podcast-Folge des Jahres Bilanz zu ziehen. Im Fokus: Die IT-Tops und -Flops 2025. Kaum ein Thema hat die IT-Welt 2025 so stark dominiert wie KI – mit Licht und Schatten. Einer der größten Flops des Jahres ist dabei der massive Stellenabbau, der vielerorts mit dem Verweis auf KI begründet wird. Laut einer Analyse von Surfshark haben weltweit mindestens 200.000 Menschen infolge des KI-Booms ihren Job verloren – vermutlich sind es sogar deutlich mehr. KI: Große Versprechen, bittere Realität Das Groteske daran, betont Manfred Bremmer, Editorial Manager Computerwoche: „Oft sind solche Entlassungsrunden eine Mogelpackung. Teilweise wurden später wieder Mitarbeitende eingestellt, weil sich eben doch nicht alles automatisieren lässt.“ Auch mit Blick auf die Zukunft sei das Vorgehen alles andere als nachhaltig, so Bremmer, weil vor allem Junior-Jobs wegfallen. Einen weiteren KI-spezifischen Flop bringt sein Kollege Tristan Fincken ins Spiel: Cyberkriminelle nutzen KI zunehmend zur Automatisierung von Angriffen. Während Angreifer dadurch schneller und effizienter werden, kämpfen Unternehmen und Sicherheitsverantwortliche häufig mehr mit regulatorischen Vorgaben als mit technischen Lösungen. CIOs bleiben pragmatisch Ein Lichtblick im KI-Bereich hebt Jens Dose, Editor in Chief bei CIO.de, hervor: Trotz vollmundiger KI-Versprechen in den Marketing-Botschaften der Anbieter würden sich viele IT-Verantwortliche weiterhin auf die Basics konzentrieren, nämlich Datenqualität, Datensichtbarkeit, stabile Prozesse und belastbare Infrastrukturen. Auch innovatives Change-Management im KI-Kontext sticht aus seiner Sicht positiv hervor – etwa beim Schweizer TK-Anbieter Mobilezone, der KI-Agenten nicht wie Software, sondern wie neue Mitarbeiter behandelt. Digitale Souveränität zwischen Anspruch und Wirklichkeit Das Thema digitale Souveränität bleibt 2025 ambivalent. Positiv bewertet Computerwoche-Redakteur Jürgen Hill etwa das Rennen um KI-Gigafactories in Europa. So investiere Schwarz IT elf Milliarden Euro in ein Rechenzentrum, um eine souveräne Alternative zu US-Hyperscalern zu schaffen. Auch die Gründung eines Digitalministeriums soll die Digitalisierungsbemühungen von Bund und Ländern besser koordinieren – wenngleich Hill angesichts des geplanten Etats seine Zweifel an der Effektivität der Behörde hat. Als Vorzeigeprojekt in Sachen Digitale Souveränität gilt Schleswig-Holstein: Das Bundesland setzt in der Landesverwaltung konsequent auf Open Source und verabschiedet sich schrittweise von Microsoft. Ab 2026 sollen so jährlich über 15 Millionen Euro an Lizenzkosten eingespart und gleichzeitig Abhängigkeiten von Tech-Giganten reduziert werden. Demgegenüber steht ein deutlicher Flop im FreistaatBayern. Dieser plant, sich langfristig an Microsoft 365 zu binden. Kostenpunkt: fast eine Milliarde Euro über fünf Jahre. Security: Lichtblicke trotz regulatorischem Chaos Im Bereich IT-Sicherheit fällt die Bilanz gemischt aus, urteilt Julia Mutzbauer, Editorial Manager bei der CSO. So sollte NIS2 eigentlich EU-weit für einheitliche Standards sorgen, sorgt in der Praxis aber für Verunsicherung: Unterschiedliche nationale Umsetzungen, unklare Zuständigkeiten und abgeschwächte Vorgaben – etwa beim Schwachstellenmanagement – stießen auf breite Kritik. Gleichzeitig gebe es aber in 2025 auch Erfolge zu vermelden, betont sie. Internationale Ermittlungen hätten zur Zerschlagung der Ransomware-Gruppe 8Base, zur Abschaltung krimineller Infrastrukturen im Rahmen der Operation Endgame sowie zur Stilllegung gefährlicher Malware geführt. Auch mit der Operation „Olympia“ wurde eine große Geldwäsche-Plattform vom Netz genommen. Angesichts dieser vielfältigen Entwicklungen bleibt mit Spannung zu erwarten, was 2026 in der IT-Welt passieren wird. Wir wünschen frohe Feiertage und halten Sie auch im neuen Jahr auf unseren Kanälen auf dem Laufenden! width="100%" height="152" frameborder="0" allowfullscreen allow="autoplay; clipboard-write; encrypted-media; fullscreen; picture-in-picture" loading="lazy" src="https://open.spotify.com/embed/episode/4gZLpXaoXCrmXQsaNnNNUA?utm_source=oembed"> View the full article
  2. A warning for WhatsApp users: cybercriminals have discovered an alarmingly simple way to access a user’s conversations in real time by manipulating the app’s device pairing or linking routine. Termed ‘GhostPairing’ by researchers at security company Gen Digital (owner of Norton, Avast, Avira, and AVG), no passwords or account details are needed to execute the attack, which was recently detected in Czechia. All the attacker has to do is persuade a user to click on a malicious link sent to them as a WhatsApp message purporting to reveal a Facebook photo. In the most common variant of the attack, this throws up a fake page which asks the user to verify themselves by entering their mobile number. This number is then forwarded by the attackers to WhatsApp to initiate the ‘link device via phone number’ feature which adds new devices to an account. WhatsApp generates an 8-digit pairing code, which is intercepted and forwarded to the user. The user, who sees a new pairing prompt in WhatsApp, enters this code to confirm the pairing. Unfortunately, this adds the attacker’s browser session as a ‘trusted device.’ Unless the user becomes suspicious, it’s game over: the attacker now has full access to their account, messages, and message history, as well as the ability to view messages as they are sent and received. “After their device is linked, the attacker does not need to exploit anything else. They have the same capabilities that any user has when connecting WhatsApp Web on their own computer,” said Gen Digital’s researchers. “Everything happens inside the boundaries of the feature set that WhatsApp intended.” Worse, the attackers can also send messages that impersonate the user to spread the campaign to the victim’s contacts and WhatsApp groups. E2EE bypass GhostPairing is an example of an attack that exploits one of WhatsApp’s biggest draws: signing up, connecting to other users, and adding up to four additional devices to an account is incredibly convenient. It’s one reason why WhatsApp has become so popular. All users need to join is a phone number, with no username or password to remember. Another draw is that the app is built on end-to-end encryption (E2EE) privacy in which the private keys used to secure messages are stored on the device itself. This should make it impossible to eavesdrop on private messages without either having physical access to the device or remotely infecting it with malware. GhostPairing demonstrates that a social engineering attack can bypass this. Interestingly, although still possible, the attack is less practical when asking users to pair via QR codes. That offers some reassurance for users of messaging apps such as Signal, which only allows pairing requests via QR Codes. Defending WhatsApp Users can check which devices are paired via WhatsApp via Settings > Linked Devices. A rogue device link will appear here. Despite having access to a user’s WhatsApp account, the attacker can’t revoke their device access, which must be initiated by the primary device. Another tip is to enable two-step PIN verification. This won’t stop the attacker accessing messages but will mean they can’t change the primary email address. The threat to enterprises is that large numbers of employees use WhatsApp as well as communicating in larger employee discussion groups. The risk is that many of these won’t be documented and will therefore be overlooked by security teams. The recommendation is to assume that multiple groups do exist and educate users to report suspicious phishing or spam from unknown numbers. The message should be clear: WhatsApp messaging might look private, but the app itself has gaps that attackers can exploit. GhostPairing comes only weeks after university researchers uncovered a major WhatsApp flaw that allowed them to discover the mobile numbers of the app’s 3.5 billion global user base. Earlier this year, Meta discovered a weakness in the WhatsApp Desktop app that could be used to target Windows users. And it’s not only WhatsApp; researchers recently uncovered a hack affecting the company that created a modified version of Signal for use by senior US politicians. View the full article

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.