Dutch Government Signs ESET Deal, OpenAI Escape Incident, & CRA Rules

ESET GETS A CENTRAL POSITION UN THE NETHERLANDS

The Dutch central government has signed a framework agreement with ESET, valid across the entire administration.This agreement allows public bodies to access ESET’s cybersecurity solutions under pre-negotiated terms. It is part of the Netherlands’ strategy to strengthen its digital resilience while reducing its dependence on non-European technologies. Effective immediately, the framework agreement is now available to all government bodies. They can benefit from the established terms without having to conduct separate contractual negotiations, while retaining complete freedom of choice. The agreement imposes no purchase obligation or minimum spending requirement: each organization remains free to decide if, when, and to what extent it wishes to use it. Provisions have been defined in advance on key topics such as confidentiality, data processing, data location, and oversight mechanisms. On this basis, ESET confirms its role as one of the key European vendors. 

OPEN AI MODEL DELIBERATELY DISRUPTS HUGGING FACE SYSTEM

Open AI sought to assess the hacking capabilities of the models by assigning them tasks in a strictly controlled digital testing environment, where internet access was limited for security reasons. However, “While operating in our test environment, our models devoted a significant amount of computing power to finding a way to gain unrestricted internet access in order to solve the evaluation problem,” OpenAI said. Once connected to the internet, they targeted the Hugging Face platform a vast repository of AI models, datasets, and other information to aid them in their search. In its search for “secret information” that could help it cheat during the evaluation, OpenAI’s system “chained several attack vectors, including using stolen credentials“, added the company. This incident emphasizes what cybersecurity issues are at stake with Agentic AI: once active, agents tend to behave regardless of classical rules! On the other hand, it seems incredible that the OpenAI model could ignore the limits that a “strictly controlled testing environment” should have: either OpenAI is not telling the complete truth, or its security rules are dummies… 

CYBER RESILIENCE ACT: THE RULES FOR AUDIT BOARDS NOW SET

On 21 July, ANSSI released its notification process for notified bodies performing the EU-type examination (Module B) under the Cyber Resilience Act, More details in this post by our member RED ALERT LABS

Share:

More Posts