Connect with us

CyberSecurity

CISO Conversations: Andreas Gaetje – Why Business Sense Beats Bit-Crawling in Security Leadership

Published

on

Andreas Gaetje CISO

Not Your Typical Hacker Story

Andreas Gaetje won’t pretend he spent his teenage years breaking into systems or writing exploits. He didn’t. The CISO at Körber AG came to cybersecurity from economics and business politics — a route that was unusual in the 1990s and still raises eyebrows today.

“I’m not the deepest bit-crawler,” Gaetje admits. “That’s just not who I am.” And yet, he now leads security for a global technology and manufacturing group with roughly 13,000 employees across 100 locations. Körber’s machines are behind much of the world’s pharmaceutical supply chain. “Probably every vaccine you ever received has been through our machines,” he notes.

His story is a useful counterpoint to the idea that you need to be a hardcore technical wizard to become a CISO. What you do need, Gaetje argues, is a deep understanding of business, the ability to learn constantly, and the trust of the people around you.

From Public Service Dreams to a Consulting Detour

Gaetje didn’t set out to work in security. In the mid-1990s, fresh out of university with a focus on economics and business politics, he expected to land a job in public services. But reality intervened. He needed money immediately, not someday.

The internet was just beginning to transform from an academic niche into a business necessity. Email was becoming the default communication tool. Gaetje made a pragmatic pivot: “I said to myself, Okay, let’s maybe do something in the computer business.”

He joined a consulting firm, hoping to blend his interest in business and technology. But by the early 2000s, he realized that to truly focus on business inside IT, he needed depth in a single sector. He chose finance. “The best industry at that point in time, where IT was really crucial, was the finance industry,” he recalls. He joined an insurance company as an auditor.

The Compliance Era That Changed Everything

Back then, cybersecurity wasn’t the existential business threat it is today. “ITsec and audit had a natural affinity,” Gaetje explains. “ITsec was primarily about compliance — it wasn’t yet the business threat it has since become.” His mix of business knowledge, IT understanding, and audit experience put him in the right place at the right time.

When cybersecurity began to explode as a discipline, he was asked to manage the growing information security function. The real turning point came in the 2010s, with attacks like WannaCry and NotPetya. “It was very clear: we weren’t talking about a simple compliance issue anymore. This was a serious business threat,” he says. “Cybersecurity had become a hot topic. It was complex, innovative, and really interesting to work in.”

By 2018, Gaetje was CISO at Körber IT Solutions. A year later, he took the top security role at the parent company, Körber AG.

Career Advice: Don’t Get Stuck in One SECTOR

Gaetje credits much of his growth to a single piece of advice: if you want to truly understand security, don’t stay too long in one company or one industry. Different sectors have different risk profiles. Stay in one place too long, and your thinking can get rigid. Attackers change fast. You need to be able to change how you think.

“It’s what made me move from the insurance industry into manufacturing and machine building,” he says. “I wanted to learn something else, to experience something new, and do something different.”

What Makes a Security Leader?

Gaetje is blunt about his own leadership style. “I’m not a born leader. I would never consider that,” he says. But he has a clear philosophy: a leader provides direction and a vision of what can be achieved and how. In any group, someone emerges as the de facto leader. The challenge is to justify that dominance with reliability and trust.

“It’s something you can learn,” he insists. “It’s not something that comes out of the blue. I learned and enhanced that learning with training courses. But of course, your personality is also important. You need to be reliable — you need to be a person that people trust, otherwise it just doesn’t work.”

Leadership, Gaetje believes, isn’t limited to formal management titles. “You’re a leader, even if it’s a thought leader driving and directing other people in a specific direction.”

Building a Security Team in a Talent Crisis

The cybersecurity skills gap is well documented — estimates in 2025 ranged from 2.8 million to 4.8 million unfilled positions globally. Gaetje has felt that pressure firsthand. “In recruiting your team, you have a wish list, and then you have reality — and unfortunately, they don’t always fit together,” he says.

But one requirement is non-negotiable: “I need people who want to learn.” The cybersecurity landscape shifts so fast that prior experience matters less than curiosity. “It’s incredible how fast things change. So, what I always need are people who are engaged, can think out of the box, and want to go the extra mile to understand what’s going on.”

Training and career development he can provide. But that initial spark of enthusiasm? That’s on the candidate. “So, whether I’m looking for an engineer, an analyst or some junior position, experience is good, but enthusiasm to learn is necessary.”

Would He Hire a Hacker?

“That depends,” Gaetje says. The hacker mentality — built-in curiosity and persistence — is valuable. But there are two types. “White hackers I would employ; blackhats, no.” He isn’t comfortable bringing someone with a history of malicious activity into Körber.

His advice to ambitious team members is simple: “Be curious. Things are really changing. If you think you know everything about anything, you’re wrong. That’s never true. There’s always something new coming for you to learn and experience.”

AI: The Double-Edged Sword That’s Reshaping Security

Gaetje’s biggest concern today isn’t a specific threat — it’s the sheer speed of technological change. “Just think about the many things you’ve learned in the last few weeks, about new developments, new products and new techniques that have been deployed to the public. AI is an example — we learn new things about the potential of generative AI and agentic AI every week. What used to occur over a period of two years or more now happens in a couple of weeks.”

AI presents a unique challenge because it’s used by both attackers and defenders. Attackers are using it to scale and sophisticate their operations. Defenders are fighting back with their own AI, but those defenses can be manipulated. Meanwhile, shadow AI — systems deployed without IT or security knowledge — is proliferating inside organizations.

“The pace of new technology is truly hard to manage,” Gaetje says. “For each new technology you must find time to learn and understand it — but that’s on top of everything else you’re already doing. And it’s not just you — everyone on your team must find time to understand the new technology, and you must personally motivate them to do so when they are already fully occupied.”

Will AI reduce the need for human security staff? Gaetje doesn’t think so. “I think the role of cybersecurity, and even my own role will be much more important in the future than it is today. But it may change.” As AI spreads across the business, security problems will become too widespread for the security team to handle alone. Other departments — product development, software engineering — will need to be brought into the fold.

The Risk of Losing Core Skills

Gaetje worries that AI could erode foundational skills, especially among programmers and SOC analysts. “AI coding assistants require prompt engineers and architects above programmers — and that can be a problem. How do you bring people from this level to the next level if they are not able to program on their own?”

A similar issue looms for security analysts. The standard view is that AI will collapse the SOC tier hierarchy — no more tier 1 analysts doing triage because AI will handle it. But Gaetje asks: “If the security analyst job can be done via an agentic AI tool, then how will analysts learn how to analyze an event? Maybe in the future, if we just rely on AI, we will lose the ability to see the tricky things in the incident.”

Still, he’s not pessimistic. “I’m pretty sure we will find different ways to handle the changes. And honestly, there’s so much out there that I’m not really concerned that we will lose anything.”

The real challenge, he says, is guiding the security team through this transition. “The job of the security team will change dramatically in the future. That’s my strong belief. The CISO challenge is to help team members along this road to a new level, where they are able to think out of the box to see what else they can bring to the job.”

For more insights from security leaders, check out our other CISO Conversations with Aimee Cardwell and Tarah Wheeler.

Continue Reading

CyberSecurity

PostgreSQL Patches 12-Year-Old Logical Decoding Flaw That Allowed Code Execution

Published

on

logical decoding flaw

PostgreSQL Ships Emergency Updates for a Decade-Old Security Hole

The PostgreSQL Global Development Group has pushed out urgent patch releases to close a security vulnerability that lets anyone with the REPLICATION attribute run arbitrary code as the database server’s operating-system user. The bug, tracked as CVE-2026-6471, carries a CVSS score of 7.2 — high severity by any measure.

What makes this one particularly nasty is its age. The flaw has been lurking since logical decoding was first introduced in PostgreSQL 9.4 back in 2014. That’s twelve years of exposure. Twelve years of potential exploitation for anyone who managed to obtain replication privileges.

The fix lands in versions 18.6, 17.11, 16.15, 15.19, and 14.24. If you’re running any earlier release, you’re vulnerable. No ifs, ands, or bugs.

What Exactly Is Logical Decoding, and Why Should You Care?

Logical decoding is a feature that lets you extract changes from a PostgreSQL database in a format that’s independent of the physical storage. It’s what powers streaming replication, change data capture (CDC) pipelines, and many modern data integration tools. In short, it’s the backbone of real-time data movement for countless organizations.

But here’s the catch: the vulnerability allows a user with the REPLICATION attribute — a role typically reserved for backup and replication processes — to escalate privileges and execute code as the OS user running PostgreSQL. That means an attacker who compromises a replication account could potentially take over the entire database server, read sensitive files, or even pivot to other systems on the network.

Who’s at Risk?

Any organization running PostgreSQL with logical decoding enabled and replication roles granted to non-trusted users is in the danger zone. Even if you don’t use logical decoding actively, the vulnerability exists in the code path, and a determined attacker could trigger it.

The PostgreSQL team’s advisory is clear: upgrade immediately. There are no workarounds that fully mitigate the issue, though restricting REPLICATION privileges to only the most trusted accounts can reduce your attack surface.

A Timeline of Neglect: How a 12-Year-Old Bug Survived

It’s almost unbelievable that a flaw this severe could persist for over a decade. Logical decoding was a major feature addition in 9.4, and it’s been a core part of PostgreSQL’s appeal ever since. Yet somewhere in the complex code that handles replication slots and WAL (write-ahead log) processing, a subtle bug slipped through.

Security researchers have long noted that PostgreSQL’s security record is generally solid — but this incident is a stark reminder that even the most reputable open-source projects can carry hidden landmines. The fact that it took this long to discover highlights the challenges of auditing complex, long-lived codebases.

What Should PostgreSQL Admins Do Right Now?

Here’s a practical checklist for anyone running PostgreSQL:

  • Identify your current version: SELECT version(); or check with your package manager.
  • If you’re on 14.x, 15.x, 16.x, 17.x, or 18.x, upgrade to the latest patch release listed above.
  • If you’re on an older version (e.g., 13 or below), you need to plan a major upgrade — those branches are no longer supported and won’t receive fixes.
  • Audit all roles that have the REPLICATION attribute. Revoke it from any account that doesn’t absolutely need it.
  • Review your database logs for any suspicious activity related to logical decoding or replication slots.

Don’t Forget About Your Replication Setup

If you’re using streaming replication or a tool like Debezium that relies on logical decoding, pay extra attention. Your replication slots might be active, and the vulnerability could be triggered through them. After upgrading, test your replication thoroughly to ensure nothing breaks.

Also, consider using a connection pooler or proxy to limit direct database access. It’s not a fix for this specific bug, but it’s good defense-in-depth practice.

Broader Implications for Open-Source Security

This incident raises uncomfortable questions about the sustainability of security auditing in open-source projects. PostgreSQL is maintained by a dedicated community, but it’s a massive codebase. Finding a bug that’s been hidden for 12 years requires either luck or a very thorough review.

For organizations that rely on PostgreSQL — and that’s a huge portion of the internet’s data infrastructure — this is a wake-up call. Regular security audits, prompt patching, and a strong understanding of your database’s privilege model are non-negotiable.

If you’re also using tools that interact with PostgreSQL’s logical decoding, like change data capture tools, make sure those are updated as well. And if you’re new to PostgreSQL security, check out our PostgreSQL hardening guide for baseline practices. For broader context, see how database security advisories are handled across major systems.

The bottom line: don’t wait. The exploit is public knowledge now, and attackers will be scanning for vulnerable instances. Patch your systems, tighten your roles, and hope that this 12-year-old skeleton in PostgreSQL’s closet is the last one.

Continue Reading

CyberSecurity

Millions of Phishing Emails Hide ‘Funding’ in Invisible Unicode to Slip Past Filters

Published

on

invisible Unicode phishing

Microsoft Warns of High-Volume Phishing Campaign

Microsoft’s security team has issued an alert about a phishing campaign that’s been blasting out millions of emails. The trick? Invisible Unicode tag characters that split financial lure words like ‘funding’ to dodge email filters.

Instead of hiding instructions from humans while exposing them to AI models, the attackers used these invisible characters to break up keywords. That way, the filters never see the full word — but the recipient’s email client renders it seamlessly.

How the Invisible Unicode Attack Works

Unicode tag characters are normally used for language tagging in plain text. They’re invisible in most rendering engines. Attackers inserted them mid-word, so ‘funding’ becomes ‘f-u-n-d-i-n-g’ with invisible tags between each letter.

Filters that scan for exact strings don’t match. The email lands in the inbox looking perfectly normal. It’s a clever piece of social engineering that targets the gap between what machines parse and what humans read.

The Role of AI in Detection

Microsoft’s research team noted that while AI models can often spot these anomalies, the attackers deliberately avoided that route. They weren’t trying to trick AI — they wanted to slip past traditional signature-based filters that haven’t caught up to Unicode obfuscation.

This marks a shift in tactics. Earlier campaigns used Unicode to hide malicious instructions from human reviewers while keeping them visible to AI. This one flips the script entirely.

Why Financial Lure Words Matter

Words like ‘funding’, ‘transfer’, and ‘invoice’ are common hooks in business email compromise (BEC) scams. By splitting them, attackers ensure their emails don’t trigger the same automated checks that would normally flag them.

  • Filter evasion: Splitting keywords means regex patterns and string matches fail.
  • Human perception: Invisible characters don’t alter how the email looks to a recipient.
  • Scale: Microsoft describes this as high-volume, meaning millions of emails are involved.

The campaign appears to target organizations that handle financial transactions — payroll departments, accounts payable teams, and CFOs.

How to Protect Against Unicode Phishing

Email security teams need to update their detection rules. Look for emails that contain Unicode tag characters (U+E0000 to U+E007F) in suspicious positions, especially inside common financial keywords.

Regular users should be cautious of unexpected emails asking for wire transfers or payment changes, even if they look legitimate. Verify requests through a second channel — a phone call, not a reply email.

For more on protecting yourself, check out our guide on recognizing phishing email signs. If you’re dealing with a potential breach, our article on incident response steps for small businesses can help you react quickly.

Technical Mitigations

Administrators can configure their email gateways to either strip or flag Unicode tag characters in incoming messages. Microsoft Defender for Office 365 has also been updated to detect this pattern, but organizations using other filters should test their own systems.

Security researchers recommend adding decoy keywords to honeypots — traps that catch attackers when they use the same obfuscation technique.

The Bottom Line

This campaign is a reminder that email filters are only as good as their understanding of attacker tricks. Invisible Unicode is not new — but using it to split lure words for mass distribution is a fresh twist that many defenses aren’t ready for.

Stay alert. If an email asks for money or sensitive data, scrutinize it — even if it looks perfect. And if you’re in IT, audit your mail flow for Unicode anomalies before the next wave hits.

Continue Reading

CyberSecurity

Microsoft Cloud Patches, 5,000 Hacked Dropbox Accounts, and a $1.1B Security Startup: What You Missed

Published

on

Microsoft cloud patches

The Week’s Under-the-Radar Security Stories

Some stories don’t get the headline treatment they deserve. They still matter, though. This week’s quiet-but-significant batch includes a wave of cloud patches from Microsoft, a credential-stuffing attack on Dropbox, and a cybersecurity startup hitting unicorn status.

Here’s what you need to know.

Microsoft Rolls Out Patches for Cloud Services

Microsoft has been busy behind the scenes. The company pushed out fixes for several of its cloud offerings, addressing vulnerabilities that could have given attackers a foothold in enterprise environments.

The patches cover a range of services, though Microsoft hasn’t disclosed every detail. What’s clear is that IT teams should treat these updates as priority. Cloud misconfigurations and unpatched flaws remain a top attack vector, and this is a reminder that even the biggest providers need constant upkeep.

For admins, the takeaway is straightforward: check your Microsoft cloud security dashboard, review the latest advisories, and apply the updates before they become a problem. Delaying patches in a cloud environment is a gamble, and the house usually wins.

What the Patches Target

Microsoft’s advisory points to vulnerabilities in Azure and related services. Specifics are sparse, but the company’s track record suggests these could range from privilege escalation to information disclosure. If you’re running any Microsoft cloud workload, the official security update guide is your first stop.

5,000 Dropbox Accounts Hacked via Credential Stuffing

Dropbox confirmed that attackers compromised roughly 5,000 user accounts. The method? Credential stuffing — using usernames and passwords stolen from other breaches to break into accounts where people reuse passwords.

This isn’t a breach of Dropbox’s own systems. The company says its infrastructure wasn’t compromised. Instead, the attackers leveraged the all-too-common habit of password reuse. Once they had valid credentials from elsewhere, they simply tried them on Dropbox.

Dropbox has reset passwords for affected users and is rolling out additional protections. But the incident underscores a persistent problem: credential stuffing attacks remain one of the most effective ways for hackers to get in. No fancy exploits needed, just a list of leaked passwords and a bit of patience.

How to Protect Yourself

  • Use a unique password for every account. Yes, every single one.
  • Enable two-factor authentication, especially on cloud storage and email.
  • Check haveibeenpwned.com to see if your credentials have been exposed.
  • If you’re a Dropbox user, change your password now, even if you weren’t affected.

It’s tedious, but it works. The hackers who did this weren’t geniuses — they were just counting on people to make the same mistake twice.

Guardio Hits $1.1 Billion Valuation

In brighter news, Guardio, a browser security startup, has reached a valuation of $1.1 billion. The company, which focuses on protecting consumers from phishing, malware, and malicious extensions, has been growing quietly but steadily.

Guardio’s approach is simple: a lightweight browser extension that blocks threats before they reach the user. It’s a consumer-focused product, but the underlying tech has broader implications. As more people work from home, the browser has become the new perimeter.

The Guardio funding round signals that investors see value in endpoint protection that doesn’t require a degree in cybersecurity to operate. That’s a good sign for the industry, and an even better one for users who just want to browse without getting hacked.

Why These Stories Matter

On the surface, these three items seem disconnected. A cloud patch, a credential stuffing attack, and a funding round — what’s the thread?

It’s this: security is a moving target. Microsoft’s patches show that even the giants are constantly fixing holes. The Dropbox incident shows that human behavior — password reuse, ignored 2FA — often undoes even the best technical defenses. And Guardio’s valuation shows that the market rewards products that make security accessible.

None of these stories will dominate tomorrow’s headlines. But together, they paint a picture of an industry that’s always fighting, always adapting, and always finding new ways to protect users. That’s worth paying attention to, even if it doesn’t make the front page.

Stay patched, stay vigilant, and for heaven’s sake, stop reusing your passwords.

Continue Reading

Trending