HACK BACK …
We reproduce an interesting post by Gérôme Billois, Head of cybersecurity practice at WAVESTONE:
A Mandiant researcher created an undercover persona and gained the trust of a member of #TeamPCP. This very active group is behind the #ShaiHulud supply chain campaign that compromised over 1,000 organizations via malicious npm and PyPI packages (nearly 500,000 credentials stolen). From the start, he was observing everything from the inside through a Telegram channel called “Canister Worm,” where the 12 most active members of the group gathered.
The interesting part is that Google didn’t just watch: the targets were warned in real time, exploitations were blocked, and OPSEC mistakes were reported to the FBI.
This is a major shift in stance. Right after the Munich conference, which put the #HackBack topic back on the table, Google launched its Cyber Disruption Unit in March with an explicit mandate: no longer just publish reports. Larsen summed it up: “Writing reports can only be so useful.” Between infiltrating TeamPCP and dismantling the IPIDEA proxy network, we’re clearly talking about actions that used to be the domain of state forces.
A whole plan, which fits into the Trump administration’s strategy for a proactive cyber stance in the private sector and was formalized in August.
ECA COMMENT: the key question is not the necessity of hack back, but that of entrusting private entities to operate it. Today, it might seem under control . Tomorrow ? What would mean “rule of law” ? And, by the way, what does the EU think of this ?
STORMSHIELD GETS AN EU KEY HABILITATION
The security solutions provider has officially been approved by the General Secretariat of the Council of the European Union for its Stormshield Network Security (SNS) UTM/NG-Firewall software suite, starting from version 4.3.12.
Granted earlier this August, this approval recognizes the solution as a cornerstone of European digital sovereignty, qualifying Stormshield firewalls and VPN solutions as trusted cryptographic products designed to ensure the security and confidentiality of sensitive data exchanges at the ‘EU RESTRICTED’ level. This approval comes after an independent cross-evaluation.
AIRBUS WILL IMPROVE CYBERSECURITY OF THE FRENCH DEFENSE
Airbus Defence and Space will be responsible for studying, producing, and keeping new cybersecurity gateways operational (MCO) for the Ministry of Armed Forces and Veterans.
The goal is to filter and secure data exchanges between networks with sensitivity levels ranging from “unclassified” to “secret.”
Airbus communication gateways won’t be limited to just datacenters or ground command posts. They’re designed to be deployed in highly constrained operational environments, from surface ships and submarines to aircraft, helicopters, and combat drones.
It should be remembered that AIRBUS has recently taken over the UK ULTRA CYBER and the French QUARKSLAB, both experts in mission critical security.
NETHERLANDS: TOGETHER TO CURE VULNERABILITIES BEFORE HACKERS EXPLOIT THEM
Last week, twelve Dutch public and private organizations launched Prometheus, a public-private effort under the flag of Digital Holland. It is building a collective, market-neutral capability that gets vulnerabilities in widely used software and digital supply chains resolved faster than attackers can exploit them. The twelve organizations have signed the manifesto “Samen sneller dan de dreiging” (Faster together than the threat), which was handed to Willemijn Aerdts, State Secretary for Digital Economy and Sovereignty.
The first step for the twelve organizations is to identify, validate, and resolve vulnerabilities in software and digital supply chains more quickly. The process begins by assessing what is actually needed, what is already available on the market, and where there are demonstrable gaps. Only in areas where a collective approach truly adds value will the initiators jointly develop and test new defensive measures.
The first joint pilot focuses on AI-driven software security, tested in practice with users, cybersecurity companies, technology partners, and research institutions. What demonstrably works gets adopted and scaled.
THE CYBERATTACK AGAINST THE FRENCH TAX PAYMENT SYSTEM CONTINUES TO DISTURB OTHER SERVICES
Repercussions of the massive cyberattack that leaked data of nearly 700,000 individuals and professionals, made public in mid-August, is far from done making headlines, are still being felt. One major issue has so far flown under the radar: the potential blockage of payments of property transfer taxes (DMTO), which are mainly paid to local authorities when a property is sold. In concrete terms, this represents hundreds of millions of euros in monthly revenue for departments, the main beneficiaries of this tax. Why ? For a notary to file their deeds, which are subject to transfer taxes, they have to present a cadastral extract. This is generated by a software tool: the professional cadastral data server. However, the DGFiP system has been suspended since mid-August for security reasons following the cyberattack. And, if deeds aren’t registered, that also means the transfer taxes aren’t paid.
SHINYHUNTERS CLAIM THEY HAVE HACKED THE FBI
The cyber extortion group ShinyHunters claims to have breached FBI systems and stolen personal data pertaining to employees and job applicants. The group said the hack was in retaliation for the bureau disseminating incorrect information about its cybercrime activities and tactics. “We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job. Whether it be a Special Agent or any other role within your agency,” reads a “public service announcement” posted to ShinyHunters’ data-leak site Tuesday and updated Wednesday. The bureau said in a statement that it’s probing the alleged breach. “The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating,” it said.
ShinyHunters told multiple media outlets that the stolen information encompasses personal data pertaining to FBI agents, including their name, home address, phone number and details pertaining to their spouse. After being given a sample of 5,000 individuals’ allegedly stolen details by the group, 404 Media reported that it appears to be legitimate. ShinyHunters told news outlets it stole the data after using a zero-day exploit against the FBI’s Oracle PeopleSoft software, then pivoting to its Amazon Web Services GovCloud environment and stealing over two terabytes of data.
HACKERS HACK OTHER HACKERS
Cl0p’s hackers have a big problem: their showcase site for their extortion campaigns, accessible via the Tor browser, has just been hacked, an attack claimed by the Shinyhunters. The Cl0p hackers are known for being efficient. Their malicious campaign against the secure transfer software MOVEit, for example, turned into a jackpot in the summer of 2023. This well-oiled operation has now hit a snag because of the Shinyhunters, a group originally connected to French hackers.
RANSOMWARE CRIMINAL SENTENCED
The French Anti-Cybercrime Office (Ofac) helped arrest a suspect in Switzerland in a ransomware case. Five years later, the suspect was sentenced, on September 10, 2026, to nearly 13 years in prison. At the hearing in August, the prosecution described this 52-year-old IT specialist as the main developer of the LockerGoga, MegaCortex, and Nefilim ransomware, according to ‘Swiss Info.’ He was also suspected, among other things, of being involved in a cyberattack on Stadler Rail in May 2020.
Initially, the French investigation had managed to trace a suspect, a computer scientist living in Switzerland. They had first identified a command and control server located in France, rented out to third parties by a Ukrainian national, before following the trail of ransom payments. The French police had thus succeeded in mapping out the criminal infrastructure, which was notably based on the use of the Trickbot trojan and the penetration testing tools Cobalt Strike. This international crackdown had also made it possible to release a decryption tool for the LockerGoga ransomware.
SECLAB AND SCHNEIDER ELECTRIC STRENGTHEN THEIR PARTNERSHIP FOR OT SECURITY
Faced with the industrialization of vulnerability discovery and a cyber threat that now directly targets industrial processes, purely software-based cybersecurity is no longer enough. That’s why Schneider Electric, a global leader in energy technologies, and Seclab are strengthening their collaboration to take protection of critical industrial environments even further. This collaboration relies on strong hardware isolation, fine application-level filtering of OT protocols (PLCs, DCS, SIS), and end-to-end deployment handled by Schneider Electric’s OT cybersecurity teams in Europe.
TRUSTINSOFT: NEW MODULE TISA 26.10
The French company TrusInSoft, a provider of software verification solutions with mathematical guarantees, is introducing the idea of AI-assisted automation to cut down on the engineering effort needed to set up formal analysis. Basically, engineering teams can now use an AI-powered coding assistant to automate the main steps needed to set up and configure an analysis campaign, while tracking its progress and checking the results directly in the TISA software.
FILIGRAN IS 4 YEARS OLD
On this occasion, FILIGRAN, the French start up,describes itself: “the open-source platform born inside a threat intelligence team, for other threat intelligence teams. The name comes from filigree, the craft of assembling fine threads into something precise and strong, and it still describes what this community does every day: pulling on a signal, patiently, until the structure appears. Today, what we build reaches far beyond threat intelligence, and the name has never fit better, as more and more threads come together around a single conviction: defense has to be proactive, and informed by the threat.“
NOMIOS GOES SOUTH
NOMIOS, the French cybersecurity service expert, has just made an acquisition in Portugal and is looking at the Iberian Peninsula as a growth lever. The target is Orbcom, a company founded in 2002 and based in Porto, which provides cybersecurity solutions, professional services, and managed services. The company employs over 80 certified experts spread across Porto, Braga, Lamego, and Lisbon. Orbcom will give Nomios a strong presence and deep knowledge of the local market, which will allow the Group to expand across the entire Iberian Peninsula.
HOW CYBER MATURE ARE FRENCH ORGANIZATIONS ?
Board of Cyber, a software vendor specialized in cyber ratings, analyzed the external attack surface of 21,700 organizations across the 18 sectors covered by NIS 2. The result are not that bright: only 32.7% of the organizations studied reach a maturity level considered “advanced.” The average score is 690 out of 1000, which puts a large part of the sample in the intermediate category. The study also shows that the risk is very concentrated: 10% of the entities account for 93.1% of the critical vulnerabilities detected.
ECA COMMENT: this statement comes at a time when NIS2 is not yet translated into French law … some 2 years after the deadline now.
AI AGENTS AGAIN COMPROMISE IT SYSTEMS
According to DataBreachToday, AI agents built with Google’s Gemini model attempted to hack outside companies while tasked with solving a cybersecurity test, making Google the latest company embroiled in an AI safety debate set off by disclosures of similar events at Anthropic and OpenAI. The hack, reported by the end of last July, happened during a cybersecurity evaluation run by the third-party AI security company Irregular. This marks the first time Google has been involved in AI agents hacking other companies, and the fourth incident involving Irregular. Agents from Anthropic, Meta and OpenAI that Irregular was testing have also illicitly accessed other companies during security evaluations. The first incident involved a Gemini agent guessing a password to access a company’s services, but when it realized it was trying to access a real company, the agent stopped the task. In other testing runs, Gemini agents looked up the false company in their search platform, which led them to public online repositories. Once the agents realized that they were trying to gain entry to real firms, they immediately ended the action. A more virtuous behavior than OPEN AI and ANTHROPIC’ agents some time ago.
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.


