SECLAB OFFERS A WIDER RANGE OF OT SECURITY FEATURES
In the world of industrial systems’s cyber protection, SECLAB makes one’s way
Seclab has just been ranked top of the “Progressive Companies” quadrant by MarketsandMarkets™ in its study on the OT cybersecurity market!
This quadrant evaluates emerging companies in the sector across two dimensions: product footprint and market performance: Seclab achieves the highest position
Since acquiring Seckiot in 2025, Seclab covers the full range of industrial cybersecurity needs: network and USB segmentation, asset mapping, intrusion detection.
MAILINBLACK LAUNCHES A NEW PRODUCT TO TRAIN STAFF
Mailinblack launches Smart Simulation! The first French AI that plays the role of a hacker.
For each employee, it generates attack simulations based on their real habits — Forget static models: Smart Simulation trains your team on ultra-contextual and ultra-personal scenarios!
Smart Simulation runs on Néréus, our AI that spans the entire Mailinblack suite Protect, Coach, Academy, Sikker Integrated with Coach, automatic deployment, no configuration needed and this is just the first in a series of innovations!
To learn more here
AISLE: A NEW START UP FROM CZECHIA, BETTER THAN LARGE AI PLATFORMS ?
AISLE is a startup specialized in AI-based vulnerability management. Some of the best open-source project managers know it well and really appreciate it. Why? Because, reportedly, Aisle detects real bugs that other, much more well-known AI coding programs like Anthropic’s Mythos and OpenAI’s Codex fail to catch.
For example, Aisle recently announced that its security analysis system uncovered six previously unknown vulnerabilities in Curl, which the open-source project managers verified and even assigned CVE (Common Vulnerabilities and Exposures) numbers to.
“We tested whether low-cost models with sufficient throughput could detect real bugs without manual intervention. The answer is yes: models smart enough, systematically deployed across an entire codebase, can detect real bugs without manually selected code snippets.”
According to AISLE, the results of an AI-based security product depend less on the raw power of its underlying base model than on the system around it — how its agents are orchestrated, the context of the codebase, its vulnerability assumptions, the validation loops, and the workflows that allow potential issues to be reproduced and fixed.
ECA COMMENT: in the work that the ECA has started with some of the best European cybersecurity vendors, we had the pleasure to welcome AISLE. The above results comfort this choice.
EXEIN THE ITALIAN OT SECURITY VENDOR BECOMES A UNICORN
Exein has raised $270 million at a $1.7 billion valuation, making it Europe’s most valuable cybersecurity startup. Founded in 2018 and at the time backed by UNITED VENTURES, an Italian investment fund, Exein’s technology today protects more than two billion devices. The company is now extending the security layer for Physical AI, from robots and autonomous vehicles to critical infrastructure. Outside Italy, EXEIN has a presence in Tokyo, Taipei and Americas.
ECA COMMENT: As EXEIN becomes a unicorn, this achievement pledges for the recognition of the importance of securing industrial systems, and for the role that European vendors can play in this so important domain.
HACKUITY ARISES A SECOND ROUND OF FUNDING
HACKUITY announces a 2nd round of funding of 19 M€, doubling its financial basis.
The round was led by Forgepoint Capital, alongside Bright Pixel Capital, Bpifrance, and Seventure Partners.
The company delivers smart vulnerability intelligence, allowing users to better plan their journey to resilience. Not another dashboard with hundreds of thousands of findings, but clarity on what actually puts the business at risk, and the right teams moving on it, fast.
More details here
ANTHROPIC EXPOSES AI BASED CYBER ATTACKS
(Tribute to DATABREACHTODAY)
Anthropic’s Threat Intelligence team identified a series of attempted attacks using its artificial intelligence models by malicious actors. The company focused not on how fast AI systems develop exploits at scale, but on how broader, deeper attacks can emerge with just a few resources. “Sophisticated and persistent threat actors continuously test our safeguards and try to circumvent the technical measures we use to detect and prevent misuse,” the company said. Anthropic said the majority of the operations it found “were enabled by AI via direct execution or orchestration.” “The use of AI went beyond simple questions and responses from a chatbot but rather involved the use of multi-agent frameworks executing reconnaissance, exploitation and data exfiltration,” the company said.
One operation involved a Russian-speaking operator using the name “JackPoterz” who targeted military intelligence within the Ukrainian and European governments. The attacks used custom AI workflows that automated development, infrastructure acquisition, phishing and data exfiltration. Another Russian-speaking actor exfiltrated around 26 gigabytes of data from hotel and financial technology platforms and tried the same trick of injecting malicious prompts into sandboxes. A group of “low-level” hacktivists leveled up their attacks using AI capabilities, and Anthropic said that while the group was small, it was able “to achieve significant goals due to the integration of AI in their operations.”
Anthropic said AI models and agents have enabled democratized malicious actions, and the adoption of the technology “threatens to quickly and easily subvert” increased costs defenders direct to adversaries. The company said more traditional cyber espionage attacks required adversaries to build specific tools to evade detection, and defenders could detect and block them, creating higher costs. AI agents erase that.
CONSOLIDATION (IN THE USA): PROOFPOINT PROPOSES TO ACQUIRE VARONIS
Varonis brings together data, artificial intelligence, and threat detection within a complete security platform; PROOFPOINT, which took over HORNET Security and hence VADE SECURE in 2025, provides cybersecurity for data, for persons in their collaboration, finally for AI processes. Proofpoint, which belongs to the investment fund THOMA BRAVO, has a valuation of more than 12 B$, while VARONIS’s valuation amounts to some 5 B$.
EU CYBER RESILIENCE ACT NOW APPLICABLE
As of September 11, the article #14 of the CRA is applicable. Manufacturers of products that include digital components now have to report actively exploited vulnerabilities to ENISA (the EU Agency for Cybersecurity) and their national CSIRT (Computer Security Incident Response Team), and they have to do it within 24 hours of finding out.
CRYPTO CURRENCY OPERATOR SUFFERS DATA LEAK, BREVO EXPOSED
Cold cryptocurrency storage provider Trezor says roughly 347,000 of its customers received phishing emails after a third-party marketing platform used by the company was hacked. The incident involved the marketing platform Brevo, a French scale up which has recently been names a unicorn, which Trezor uses for newsletters. Brevo said an attacker exploited how it handles SAML Single Sign-On (SSO) to access 138 accounts.
“The attacker created a Brevo account and enabled single sign-on (SSO) on it, then invited legitimate Brevo users into that SSO configuration. Using their own identity provider, they were able to sign in as those invited users, which by itself is expected behavior for SSO,” Brevo explained. “This access was not properly scoped: instead of being limited to the single organization where SSO was enabled, it wrongly granted the attacker access to all organizations those users could reach,” it added.
According to the company, the attacker sent phishing messages to the email addresses stored under six of the compromised accounts. In addition, the threat actor exfiltrated contacts from 43 accounts. One of the customers whose email list was abused for a phishing campaign appears to be Trezor, which informed customers on Thursday that the attacker sent phishing messages to 347,000 email addresses stored in the Brevo account.
THE FINTECH REVOLUT HACKED
Revolut, the British leading online bank, said on Wednesday, September 16 it was the victim of identity theft., that this led them to share some customers’ information with ‘an unauthorized third party,’ who pretended to be a government agency. It is reported that 680 customers were affected across several European countries. ‘Customer funds are not affected,’ the bank clarified. Revolut described it as ‘a sophisticated scam,’ where ‘an unauthorized third party used the email domain of a legitimate government agency to submit false information requests.’
AND THE FRENCH AGENCY IN CHARGE OF ADULTS’ TRAINING
AFPA, the public organization in charge of organizing training for adults, often for unemployed people, has just announced that it was the target of a major cyberattack, which could compromise the personal data of 1.7 million people. The intrusion didn’t come directly from the agency’s internal servers, but from an external tool managed by a third-party provider for hosting management. According to the Agency, no banking info or Social Security numbers were on the affected app. However, first and last names, postal addresses, and phone numbers could be out there. ONce more, the real danger is phishing.


