SEC Consult Unternehmensberatung GmbH

Cyber- und Applikationssicherheit

location

Wien

nicht verfügbar Mitarbeiter

SEC Consult ist ein führender Berater für Cyber- und Applikationssicherheit, der Strategien zur Informationssicherheit, Sicherheitsaudits, Penetrationstests, ISO 27001 Zertifizierungsbegleitung, Cyber Defence und Entwicklung sicherer Software bietet.
oozu logo

Keine Jobs für junge Talente

Dieses Unternehmen bietet aktuell keine Jobs für junge Talente

Social Media

LinkedIn Post

Today’s the day! 🚀 On May 5 & 6, we’re heading to Security Forum Hagenberg with a real‑world physical security demo: a real door, original dormakaba hardware, and a live test setup. In the closing talk 🎤 “Hands‑Free Lockpicking: Opening Doors Like in the Movies”, Clemens Stockenreitner and Werner Schober will show how doors using the exos 9300 access control system could be opened without authentication - and share insights into 20 vulnerabilities uncovered during their research. 🗓️ May, 6 | 17:10 | Closing Talk 📍 Hagenberg Campus Together with Edgar J. & Johannes Greil we’re looking forward to meeting many of you there - and to inspiring talks and discussions! 👋 #SecurityForum #PhysicalSecurity #VulnerabilityResearch #HandsFreeLockpicking #dormakaba #Hagenberg #Lockpicking

LinkedIn Post

🔓 Like in the movies - but very real. On May 6, we’ll be heading to Security Forum Hagenberg, and we’re really looking forward to bringing something special with us: A real door, original dormakaba hardware, and a full test setup that lets us demonstrate physical security research exactly how it happens in the real world. In the closing talk 🎤 “Hands‑Free Lockpicking: Opening Doors Like in The Movies” our colleagues Clemens Stockenreitner and Werner Schober will walk through how doors controlled by the exos 9300 access control system could be opened without authentication – and share insights into 20 vulnerabilities they identified during their research. 🗓️ May 6, 2026 | 17:10 | Closing Talk 📍 University of Applied Sciences Upper Austria - Hagenberg Campus We’re excited to discuss the implications with the community & answer your questions on site. See you in Hagenberg! 👋 #SecurityForum #PhysicalSecurity #VulnerabilityResearch #HandsFreeLockpicking #dormakaba #Hagenberg #Lockpicking

LinkedIn Post

💼 We’re hiring: Senior Security Consultant (DFIR) - and yes, incidents will happen. With you, they’ll just end better. 🚒💻 At SEC Consult Group , we help companies navigate some of the most chaotic moments in their digital lives: cyberattacks. And let’s be honest: when things go sideways, we love stepping in to bring order, clarity, and a solid forensics report. We’re looking for a (Senior) Security Consultant – Digital Forensics & Incident Response (w/m/x) to join our team in Vienna. Someone who enjoys diving deep into logs, securing evidence like a digital detective, and guiding clients through incidents without losing their calm… or their humor. 😉 Would you like to join our team? You can find all the details here: 👉 https://lnkd.in/dfty3-xk We look forward to welcoming you 😎 #joboffer #teamsecconsult #DFIR #cyberjobs

LinkedIn Post

🚨 Critical Vulnerabilities in dormakaba’s Enterprise Grade Physical Access Control System‼️ After a long, exhausting but rewarding coordinated responsible disclosure process, we are excited to finally share all #vulnerabilities we identified in dormakaba’s physical access control system exos 9300, the access managers, responsible for opening electronic locks, as well as PIN pads. Our researchers Clemens Stockenreitner and Werner Schober detailed their discoveries in their blogpost, titled “Hands-Free Lockpicking”. The blogpost and the advisories are available at the following location: 👉 https://lnkd.in/dNwqQc9v What’s the impact❓ By exploiting these vulnerabilities, it is possible to open all doors controlled by the physical access control system without prior authentication, only network access is required. Some systems are even available via the Internet due to end user misconfigurations. But that’s not all. Overall, 20 CVEs have been assigned, most of them rated critical or high. The vendor dormakaba handled the responsible disclosure process exceptionally well. Patches are available and have been already applied for many customers! #ResponsibleDisclosure #PhysicalSecurity #AccessControl #Lockpicking #SecurityResearch #OffensiveSecurity

LinkedIn Post

🕵️♂️ Sind Sie bereit für eine Reise in die dunklen Ecken der IT-Sicherheit? 💀 In unserem kommenden Webinar entführen wir Sie in eine Welt voller erschreckender Schwachstellen und verwaister Software. 🔦 Unsere beiden „Jonathan Frakes“ — Moritz Gruber und Werner Schober — berichten aus ihrer jahrelangen Pentest-Praxis und zeigen, wie kleine Fehler zu großen Sicherheitsrisiken werden können. Erleben Sie: 📖 Echte Fallgeschichten aus dem Alltag von Sicherheitsexperten 💡 Technische Einblicke, die Sie so noch nicht gehört haben 🧰 Praktische Tipps, um Ihre Systeme besser zu schützen 😱 Gänsehaut garantiert. 🧠 Das nehmen Sie mit: Konkrete Beispiele realer Sicherheitslücken Wie Angreifer vorgehen — und wie Sie das verhindern Handlungsempfehlungen für Entwickler & Security-Teams 📅 Wann: 30. Oktober 2025 // 10:00 Uhr 🎟️ Jetzt Platz sichern: 👉 https://lnkd.in/eWwZwNze #CyberSecurity #Webinar #Pentesting #ITSecurity #SECConsult #SecurityAwareness #Infosec #AufDeutsch

LinkedIn Post

🚨 New SEC Consult Advisory: CleverControl Employee Monitoring Software Vulnerability (CVE-2025-10548) The SEC Consult Vulnerability Lab has identified a high-impact security issue in the CleverControl Software employee monitoring software. A missing TLS server certificate validation during installation enables attackers in a man-in-the-middle position to execute arbitrary code with SYSTEM privileges. 📌 Key Details CVE: CVE-2025-10548 Product: CleverControl employee monitoring software Vulnerable Version: 11.5.1041.6 Fixed Version: Not available Impact: Remote Code Execution (RCE) with elevated privileges Advisory: https://lnkd.in/d95huCu2 ⚠️ Vendor Response: Despite multiple attempts to contact CleverControl, the vendor remained unresponsive. No patch is available. 🔒 Business Recommendation We strongly advise all end users to contact the vendor directly and demand a patch. Until then, consider alternatives and ensure thorough network security monitoring. This vulnerability was discovered by Daniel 🦌 Hirschberger ⛰️ , Thorger Jansen , Tobias Niemann and Marius Renner (Office Bochum). #CyberSecurity #InfoSec #RCE

LinkedIn Post

🌩️ Cloud misconfigurations remain one of the top entry points for attackers. From overly permissive IAM roles to exposed storage buckets — cloud-native environments require cloud-native security testing. 🔍 SEC Consult’s Cloud Pentesting service is designed to: 📍Detect misconfigurations across AWS, Azure & GCP 📍Simulate real-world attack paths 📍Deliver actionable remediation guidance Explore how we help organizations stay ahead of evolving threats: 👉 https://lnkd.in/dj6G8UeS #CloudSecurity #Misconfiguration #Pentesting #IAMSecurity #SECConsult

LinkedIn Post

🔐 Live-Hacking & Red Teaming auf der it-sa 2025 – mit SEC Consult! Besuchen Sie uns auf Europas führender IT-Security-Messe und erleben Sie zwei exklusive Live-Events: 🎬 "Wir hacken wie Hollywood (es niemals tun würde)" 📅 Dienstag, 07.10.2025 | 🕔 17:00 – 17:30 Uhr 📍 Halle 9, Forum F ➡️ Live-Hacking mit Aha-Momenten – unterhaltsam, technisch fundiert und garantiert realitätsnah! 🧠 Workshop: "Warum Red Teaming ohne Penetrationstest ins Leere läuft" 📅 Mittwoch, 08.10.2025 | 🕝 14:30 – 17:30 Uhr 📍 NCC Ost, Raum Oslo ➡️ Tiefgehende Einblicke in moderne Angriffssimulationen und wie Unternehmen sich wirklich schützen können. 📌 Mehr Informationen zu den Sessions und unserem Messeauftritt finden Sie hier: 🔗 https://lnkd.in/dYRCFRjM 👉 Jetzt vormerken und vorbeikommen – wir freuen uns auf den Austausch! #AufDeutschDE #itsa2025 #SECConsult #LiveHacking #RedTeaming #CyberSecurity #ITSecurity

LinkedIn Post

🎟️ New Blogpost: Forensics gone wrong? Unpredicted behaviour of writeblockers SEC Consult tested hardware writeblockers in preparation for incident response case work (Wiebetech USB 3.1, Wiebetech Forensic Ultradock, Logicube Portable, Tableau TK8u/T8u USB 3.0 Forensic Bridge). We noticed that two of our writeblockers are behaving differently than expected, namely Wiebetech USB 3.1 and Wiebetech Forensic Ultradock (SATA). 🛡️ Recommendation: Digital forensic investigators should take special care as these writeblockers work differently than familiar writeblockers of other brands. 🔍 Read the full article for technical details: 👉 https://lnkd.in/d_3EE3VW #CyberSecurity #DFIR #digitalforensics #writeblockers #SECConsult

LinkedIn Post

🚀 Nominated for the Pwnie Awards 2025 – the “Oscars of IT Security”! We’re proud to announce that our research at the SEC Consult Group Vulnerability Lab has once again made waves internationally: ⚡ Critical vulnerabilities in EV charging infrastructure (Hardy Barth CPH2 & CPP2) identified. A huge thank you to our expert Stefan Viehböck for his outstanding work – and to our entire team for continuously driving innovation, disruption, and accountability in the field of cybersecurity. 👏 👏 🔍 Read more about the findings: https://lnkd.in/eiBCDwhn #CyberSecurity #PwnieAwards #EVCharging #SECConsult #VulnerabilityResearch #Innovation #ITSecurity

LinkedIn Post

🍂 Oktober ist it-sa-Zeit – und natürlich ist SEC Consult auch dieses Jahr wieder mit dabei! 🍂 Die it-sa – Home of IT Security ist ein Pflichttermin für alle, die sich mit aktuellen Bedrohungen und innovativen Lösungen im Cybersecurity-Bereich auseinandersetzen. Gemeinsam mit unseren Kolleg:innen von Atos Cybersecurity und Eviden freuen wir uns auf den persönlichen Austausch, spannende Gespräche und praxisnahe Einblicke. Wann? 07.–09. Oktober 2025 Wo? Nürnberg, Messezentrum 🧭 Sie finden uns in Halle 9 I Stand 534 🧭 Kommen Sie vorbei und erleben Sie Cybersecurity live! Infos zu Tickets und Agenda 👉 https://lnkd.in/dmbAfVug #AufDeutschDE #itsa2025 #Cybersecurity #SECConsult #ITSecurity #Awareness #Events