
🗞️ Share and discuss the latest industry news, trends, and updates in cybersecurity.
Industry News & Updates
124 members
Signal Watch | French tax authority (DGFiP) breach: ANSSI's post-mortem >> @channel Good luck with ECSM tomorrow, and because it always helps to have a recent story about cyber risk...
What happened: ANSSI (France's national cybersecurity agency) published its incident report on 29 Sept 2026 analysing the breach at the French Tax Authority earlier in the year. Over three months, the attacker collected the logins and passwords of several dozen tax agents, probably stolen by infostealers. ANSSI suspects that was via devices the DGFiP doesn't control, notably agents' personal computers.
Impact: Data from the E-Contact application covering nearly 353,000 individuals and 252,000 businesses, plus land registry data, was taken. Around 14 GB left over three months without the tax office or ANSSI raising the alarm.
Interesting detail: A session stayed open roughly sixteen hours after the password was reset. Also, in 2026, two tax portals with access to sensitive data still relied on just a username and password.
Lessons:
BYOD and personal-device hygiene is your risk to manage, even though it’s outside your perimeter. This is where awareness and education can make the difference.
IT Service desks need to remember to revoke sessions as well as resetting passwords.
Least privilege matters: ordinary agent accounts with no special rights gave access to large volumes of sensitive data.
Thanks for comments Lars S. Sabrina H.. My recommendation is definitely to switch from 'data points' to 'indicators' to 'trends and stories' as you go up the hierarchy. Going into a Boardroom with lots of data is asking for trouble, they'll select an outlier point and quiz you on it until you can't answer, then they'll disregard the whole lot. Choosing 'what matters' is always a challenge - but you know your business and what matters. Is it uptime, safety, product design, price, reputation etc? Find the key aspects and then see how you can relate your metrics to those. I did a speech to the SoSafe Virtual Academy a few weeks ago which touched on this topic, and included some examples. I'll be posting that in the community in the first weeks of October.
Thanks Andrew R. choosing the right KPIs for different levels is an art in itself that depends highly on the art of Stakeholder Management or even the standing that you have in an organisation. As a Cybersecurity Professional you see so clear and you also understand what level the Management may understand. Still the main challenge is to get all parties involved to a common understanding on what really makes sense.
Hey thanks Andrew R. for sharing, this definitely helps. I think I mentioned it in another post, but KPI/RPI implementation is one of my biggest struggles. The hard part is figuring out which metrics actually matter and provide real value to management when making decisions. There are a few good ones on this list that I'll definitely take a closer look at.
Signal Watch | Operational Security Metrics @channel Metrics are one of the most challenging aspects of the security management role and trying to think of what to measure, that truly adds value, can be a real problem. I stumbled across this list today and thought it may help people with that process.
Signal Watch | MSFT Exchange Vulnerability - GERMAN USERS PLEASE READ @channel For those us us still running MSFT Exchange servers (and there's a LOT in Germany!), it's important to note that a recent vulnerability now has exploit code available that will allow attackers to take over the mailboxes of all users, send emails, read emails, & download attachments. 🔑 Germany's Federal Office for Information Security (BSI) warned that around 85% of all on-premise Exchange servers in Germany are still vulnerable to this vulnerability 😬 Please take note of this and chase your IT department to patch these issues ASAP! bleepingcomputer.com/news/security/nearly-22-000-microsoft-exchange-servers-vulnerable-to-hijack-attacks
Signal Watch | US Water Attacks @channel The US Cybersecurity and Infrastructure Security Agency (CISA) said that cyber threat actors are targeting programmable logic controllers (PLCs) and modifying passwords to "to lock out operators." It seems ridiculous, but it's said that these PLCs are just sitting online and vulnerable. edition.cnn.com/2026/…/sweeping-cyberattack-us-water-systems Let's just make sure that we all regularly scan our entire enterprise address space (IT and OT) for any assets sitting outside the control perimeter!
Signal Watch | Rogue AI Attacks @channel OpenAI has confirmed that its AI software escaped a sandboxed security evaluation, reached the open internet, stole credentials and breached the servers of a firm called “Hugging Face”, with no human direction or intervention. Hugging Face was selected because the AI thought they’d have the answers it was looking for! 🤖 bbc.co.uk/news/articles/c3ek3gvdnj3o Safety filters had been switched off for the test, because OpenAI assumed that the sandbox would be effective.. 😬 For CISOs, the Hollywood risk of a ‘rogue AI’ just became real. But note the human root cause: engineers trusted a sandbox and removed guardrails. Machines executed the attack, but people enabled it. What to do next: · Review every AI agent — yours and your vendors' — for risk as a potential insider threat, with least-privilege credentials, strict egress controls and a kill switch; · Demand containment-test evidence from AI suppliers before deployment; · Consider incident response against an adversary operating at machine speed, and confirm your defensive tooling will actually engage; · Finally, brief your board this week — they're reading the same headlines, and they'll want your plan, not your surprised face.😮
Signal Watch | More vishing risks @channel Following on from my recent post on vishing (), I wanted to highlight this one which is specifically targeting food and beverage, technology, healthcare, automotive, construction, and aviation industries. This one is leveraging recent MSFT communications about the need for 'passkey registration'. The attack aims to talk your staff through a (fake) passkey registration which allows the attacker access to your enterprise. thehackernews.com/2026/07/hackers-use-fake-microsoft-entra.html Assess this threat, and consider reaching out to your staff to let them know that, yet again, they are being targeted. Try and get those clear authentication processes in place to help them spot a good IT request from a bad one!
Signal Watch | Nextcloud misconfiguration leaves data unprotected @channel The German modular workspace platform, Nextcloud, left a database unprotected containing 367,000 records, spilling invoices, contracts, scripts for managing infrastructure, and numerous other files. The company says no customer servers were exposed in the incident. They claim it was an error by their hosting infrastructure provider. The exposed files include sensitive data, such as Nextcloud employee data, client company data, numerous contracts, and scripts developed for the company’s clients to integrate the service on their systems, potentially opening up their systems to threat actor activity. If you are a user of Nextcloud, reach out to your engineers and procurement teams - make sure they verify any communications from Nextcloud for the coming months, just in case that information allows for credible, personalised phishing attacks. cybernews.com/security/nextcloud-cloud-provider-data-leak
Thanks for sharing. DPOs surely want to read the letter to the EU Commission: linkedin.com/posts/max-schrems_letter-to-the-eu-commission-on-eu-us-data-activity…?…
Signal Watch | Transatlantic Data Privacy Framework @channel OK, let me start this by saying that I'm no data privacy expert, however this seems important and it comes from a voice I trust. A recent Supreme Court ruling (Trump vs Slaughter) seems to undermine the very basis for the TADPF and could cause significant issues for the transatlantic application of GDPR. Those of you who are better educated in the details of GDPR will probably appreciate the issues better than I do, but it's worth getting your Data Privacy folk to be aware of this ruling. linkedin.com/posts/michael-colao-70a64b_today-the-us-supreme-court-ruled-in-trump-share…?rcm=…&…
Signal Watch | Fortibleed @channel Just last week, CISA issued an urgent alert about FortiBleed — it's a reused name for a new campaign that's compromised working admin credentials for more than 86,000 Fortinet firewalls across 194 countries. Here's what makes this one different: no zero-day; no sophisticated exploit; Just 1.16 billion brute force password attempts against devices that were "patched" but still had weak password hashes sitting in config files. So what was the vulnerability? When organisations upgraded FortiOS firmware, the new password security only activated if an admin logged in afterward. Thousands never did. Those old SHA-256 hashes stayed intact for years — until someone built a 45-GPU cracking cluster and broke them at industrial scale. The compromised credentials are now packaged with company revenue data and sector classifications. That's the format ransomware affiliates use to pick targets. If you have a Fortinet device, it's probably best to assume you're in the dataset and consider following CISA's advice:
Terminate all active SSL VPN and administrator sessions.
Reset all Fortinet administrative and VPN passwords.
Review logs for:
unusual VPN logins,
administrator logins,
configuration changes,
lateral movement.
Enable phishing-resistant MFA wherever possible.
Ensure management interfaces are not exposed directly to the Internet.
Keep FortiOS fully patched, even though this campaign isn't centred on a new software vulnerability.
cisa.gov/news-events/…/cisa-urges-hardening-fortinet-devices-after-reports-credential-exposure
Some may say that it's difficult to differentiate between a scam and the official FIFA ticketing system, but I couldn't possibly comment..🤭 Seriously, criminals always jump on major events, so we should too. Use the world cup as an opportunity to talk to your staff about the dangers of illegal streaming sites, 'too good to be true' offers, and fake websites! It's a topic they'll be interested in, so lets take advantage. ⚽❤️
⚽ Signal Watch | FIFA World Cup 2026 @channel The World Cup kicks off tomorrow and cybercriminals are already in play. Researchers are warning of a wave of FIFA-themed fraud: thousands of fake domains, banking malware hidden in pirate streaming apps and cloned FIFA login pages designed to hijack real accounts. One tell-tale sign? Any seller asking for crypto payments, FIFA's official ticketing never asks for it. A good reminder that major events are prime time for scams and phishing & a good moment to remind your workforce to stay vigilant, on and off the clock. 👉 FIFA World Cup 2026 Scams Are Already Live
