European Cyberdefense, GPT-6 Astra and Data Leaks: The ECA Update

AGREEMENT BETWEEN SWEDEN AND THE NETHERLANDS

The Netherlands and Sweden announce they have agreed on a collaboration program in cybersecurity.

Another example of regional inter-States collaboration in a domain where the EU institutions  seem unable to set the  tone.

AI FOR CYBER: 

OPEN AI LAUNCHES ASTRA

OpenAI has unveiled GPT-6 Astra, ‘the smartest and most advanced model ever released’ and ‘the one that best follows users’ intents and instructions.’ It’s also the most powerful when it comes to cybersecurity and defense. OpenAI thus assures cybersecurity professionals that Astra’s enhanced capabilities in this area can help defense teams identify and fix vulnerabilities, while requiring stricter protective measures. It is reported that Astra reaches the “critical” level in cybersecurity within the Preparedness Framework. OpenAI is strengthening its protections against malicious use and is starting to offer, through its Daybreak program, less restrictive access to a first group of trusted actors, especially for work on vulnerability validation, malware analysis, and detection engineering. So OpenAI is setting up a two-tier access: a limited version for the general public and advanced features reserved for authorized players. At the same time, critics expose the fact that the new model’s action decisions are more difficult to explain, leading to a governance issue.

ENISA TO EVALUATE MYTHOS and GPT-6-ASTRA 

After some delay, the EU Cybersecurity Agency ENISA has been authorized to join the circle of actors entitled to evaluate MYTHOS (or FABLE), the ANTHROPIC system dedicated to vulnerability detection. OPEN AI had already authorized the same evaluation by ENISA for ASTRA.

MISTRAL AI WILL HELP THE FRENCH STATE

The first domain of the agreement is Cybersecurity, which became a critical issue after a large-scale data leak hit the Directorate General of Public Finances this summer, compromising the information of 678,000 users. The other two areas focus on detecting complex tax fraud and automating the handling of legal disputes at the Ministry of Justice to relieve the courts.

From a technical architecture perspective, deployments will be adapted to the sensitivity of the data being processed. Projects can rely on the provider’s own infrastructure, the state’s internal data centers, or the certified sovereign cloud offering from Outscale.

At the same time, the Minister Roland Lescure has insisted: “If European AI boils down to Mistral, then we’re screwed,” he said.

The minister stressed the urgency of building a diverse industrial base to face the American and Chinese blocs, pointing out, “We can’t put all our eggs in one basket: we need to develop an entire ecosystem.”

SOPRA STERIA COMPLETES ITS EUROPEAN CYBERSECURITY PARTNERS LIST

The ECA is glad to here reproduce an announcement by SOPRA STERIA, a major integrator with a large cybersecurity practice:

Sopra Steria strengthens its European cybersecurity ecosystem with a new partnership with VMRay.

Cyberattacks no longer arrive one at a time. Bot-orchestrated campaigns now generate and mutate malware faster than most security teams can analyse it, changing the nature of the threat as much as its volume. And when attacks are machine-generated, analysis becomes the bottleneck. To meet that shift, we’re partnering with VMRay, a European reference in advanced malware and phishing analysis. 

We’re also glad to announce that, with Sekoia, HarfangLab, Egerie, Glimps, Memority, Filigran, CryptoNext Security, and now VMRay, sovereign solutions now cover up to 30% of our cybersecurity offering, all integrated and operated by our own experts in Europe.

Discover the partnership here

THE FRENCH SENATE ON THE BIG TAX MANAGEMENT CYBERSECURITY INCIDENT

The first hiccup noted by the senators: the growing number of access channels to the applications and data of the General Directorate of Public Finances. As exchanges increase between the directorate and its partners, the memo emphasizes the need to ‘find a better balance between data flow and securing access’.

Another flaw noted: the absence of systems to automatically detect a high volume of database consultations or extractions. This is particularly relevant when an authorized account generates massive database extractions – something common in the missions of the DGFiP, given the volume of data handled by this administration. “We believe that such systems should be quickly rolled out, in a way that’s proportionate to the level of risk,” the senators said, adding that the Minister of Action and Public Accounts, David Amiel, told them that the deployment of such systems would be sped up, prioritizing the most sensitive applications.

Finally, Senators are pointing out the lack of an active two-factor authentication system on one of the accounts that was compromised during the incident, “even though the accessible data was covered by tax secrecy.” Two-factor authentication, which is actually one of the key measures in the state’s national cybersecurity strategy presented last February, is one of the main points of tension in recent cyberattacks, most of which have been made possible through compromised accounts.

DATA LEAK AT JINKO

The French platform Jinko, specialized in supporting people with cancer, confirmed a data breach after unauthorized access to its systems. More than 3,500 accounts are believed to be affected. Jinko confirmed that it experienced unauthorized access to its systems as well as data exfiltration. The number of accounts affected is said to be around 3,550. The claimed information therefore includes standard identity and contact data, like names, email addresses, phone numbers, dates of birth, or postal addresses, but also information directly related to the medical history. Messages and conversations with the doctors may also have been stolen. All this could pave the way to targeted phishing.

Share:

More Posts