AI AGENTS MORE AND MORE OFFENSIVE
(Tribute to Gérome Billois Wavestone)
During the UN recent session, the Australian Prime Minister revealed that an OpenAI agent had on June 18 accessed a Medicare statistics portal and reached non-public files. OpenAI only notified about it 84 days later… via an email sent to a generic inbox (small crisis communication win.
On the same day, Transluce published an analysis of traces left on urlquery.net: 6,467 scans strongly linked to agents since March 6, starting with Thai statistics, and three intrusion attempts against the University of New Mexico, Data USA, and the Australian health institute AIHW. More Details
On the regulation side, two approaches are emerging. At the UN, Australia co-signed with 26 countries, including Canada, Germany, and France, the call ‘A Call for Control of Frontier AI Models.’ On the industry side, Google, OpenAI, and Anthropic are preparing the SAFA, a self-regulatory body inspired by FINRA, for late 2026 or early 2027 (article ).
It’s a step forward, but the regulated would be shaping their own regulator… When it takes 84 days for an incident to be reported, the notification clearly can’t stay voluntary! In Europe, between GDPR, NIS2, the CRA, and the AI Act, we’ve already got what we need anyway …
BREVO TWICE HACKED
The French unicorn with 600,000 clients, expert in customer management, has just gone through two major security incidents, making it a weak link in the long list of supply chain attacks. The first incident coinerns a data leak from crypto-currencies customers. Through his Brevo account, an attacker was able to access contact data of crypto site users, including their email addresses and phone numbers, as well as identifying information (first and last names). Of course, data related to users’ wallets or tax status were not affected. But the leaked information is still sensitive, as it can be used to identify crypto owners.
The second incident relied on a compromised Cloudflare API key: an attacker managed to inject a malicious script for about five hours on September 14 some BREVO pages and three JavaScript files embedded by Brevo’s clients on their websites. This script prompted some users, under the pretense of verifying that they were human. Then he script would try to install a plugin on the websites of users logged in as WordPress admins, resulting in the compromission of more than 100 000 web pages.
DENMARK: HUGE DATA LEAK
“The administration of the Danish national registry (CPR) has found that unauthorized individuals have illegally accessed, among other things, the names, addresses, and CPR numbers [the equivalent of social security numbers] of about 8.8 million people registered (living, emigrated, deceased, etc.),” according to a statement. The total number of people in the register is 11 million. An investigation is underway, but at this stage, the authors of this intrusion (cupid criminals or some State services ?) have not been identified.
CISA AND FBI WARN INDUSTRIAL SYSTEMS OPERATORS
(Tribute to DataBreachToday)
U.S. authorities are warning companies that use operational technology to be cautious when granting online access to third-party integrators or consultants. They say foreign hackers are actively using such connections as a vector for cyberattacks. “Using third-party ICS integrators in critical infrastructure may inadvertently introduce security issues,” states a September 23 advisory from the Cybersecurity and Infrastructure Security Agency and the FBI. “Critical infrastructure owners and operators that rely on third-party integrators for system design face supply chain risks,” if they do not enforce clear security requirements, the advisory adds.
An expert gave an example, which is not that theoretical. “If you’re going to install a conveyor belt, you need to know how big the building is,” and what shape it is, he explained. “You need electrical diagrams: How are the sensors and the OT assets going to get power? And then of course you are sending [those assets] network traffic, so you need switches and routers and all that fun stuff.” “Taken together, those three types of diagrams provide a complete blueprint for the attacker”, he said, adding that the hacked company would also likely have exposed details of the make, model and software version of all the OT equipment they’d installed.
That kind of careful, advanced reconnaissance, hacking an integrator to lay the groundwork for downstream attacks against multiple critical power and transportation utilities, is the hallmark of “an extremely sophisticated actor, likely nation-state based,” commented a former CISA executive.
HACK OF THE FBI: NOW SAID TO BE WORSE THAN INITIALLY REPORTED
This Newsletter informed on the attack at the beginning of September. Now, according to several US Press reports, it is said the attack may have resulted in stealing important data on a large part of the agents, including … those working against IT hackers.
THE US DEFENSE DEPT HACKED
On September 28, the US Pentagon revealed a security flaw in a computer system,in the U.S. Department of Defense agency that manages military personnel data The default has allowed outsiders to access the data of millions of people. Discovered – and then patched – in July, the flaw, which had been active since October 2025, allowed “a small number” of “unauthorized” users to access millions of files, the data of some 2,7 million defense employees have been compromised.
FRENCH ADMINISTRATION TAKES STOCK OF THE RECENT SUCCESSFUL CYBER ATTACKS
The French Minister of Public Accounts has summarized the decisions in a letter to some Members of Parliament. Firstly, he insists on the systemic issue: the attack against the Tax Management system was possible after the credentials of an employee of another administration were stolen, such as happened for the Ministry of Interior which was attacked after a compromission in the Agriculture Ministry.
The first and important decision is that the CISO will directly report to the General Director of the said Administration. This new organization should allow the information systems security manager to have a slightly stronger voice, especially when it comes to budget decisions. The Security Operations Center will get more resources. and employees will have a reinforced double authentication system. Moreover, multiple attempts to access some files will be filtered.
Such decisions come after the report issued by ANSSI, the French cybersecurity Agency. Among others, it notes that the cumulative volume of requests that the attackers have generated to orchestrate the data exfiltration should have triggered alerts. And it proposes an action plan – largely endorsed by the Minister covering the following areas: strengthening the supervision of the DGFiP and extending coverage to all business applications; limiting the exposure of login credentials and implementing strong authentication; reducing the attack surface and the exposure of business resources on third-party networks, including setting thresholds on data that can be accessed to prevent mass extractions. Moreover, the Agency recommends that the administration step up awareness on: ‘the separation of professional and personal uses should be technically enforced and encouraged to ensure that professional credentials are not compromised from environments not managed by the DGFiP’. In addition, the report recommends to set up a fine tuned mapping of legitimate IT connections within the State Interdepartments Network, this echoing the number of external connections by subcontractors.
Finally, ANSSI has published its first statement on the attacks against Public IT systems.
NEVERTHELESS THE PUBLIC WATCHDOG ITSELF WAS COMPROMISED
According to a recent report, on August 6, 2026, Metabase, a Business Intelligence and data analysis platform, reported a breach of its systems. A now-fixed vulnerability was used as an entry point, allowing hackers to gain access to accounts belonging to ANSSI, the national French cybersecurity Agency, and to DINUM, the Interministerial Directorate of Digital Affairs.
Thanks to 120 compromised accounts (including 118 linked to ANSSI) about thirty of which belonged to external users some data were exfiltrated, the agency announced in a report made public on September 30.
THE EU WILL SET UP A NEW SECURE TELECOM NETWORK BETWEEN PUBLIC KEY ENTITIES
To ensure the confidentiality of data exchanges across the continent, the EU is going to set up a new private IT backbone, isolated from the internet and highly secure. The new infrastructure “will ensure secure connectivity from the start, high availability (99.999%), and strong resilience between sites and multicloud environments;”
Orange Business, the B2B branch of the French operator, has been chosen as the ‘trusted partner’.
ESET TO ENHANCE ITS CYBERSECURITY OFFERING THANKS TO AI
In a recent post, Michal Jankech, VP of Enterprise, SMEs and MSSP business at ESET, states: “Modern cyberattacks aren’t just malicious files someone accidentally downloads. They are AI-accelerated, operating at unprecedented speed, and mimicking complex hands-on-keyboard behavior in real time. Threats moving at this pace can no longer be stopped by human effort alone. AI is essential.
Which brought us to a critical question:
If AI is becoming central to cybersecurity, how much responsibility should we hand over? Should cybersecurity become fully autonomous? Or remain supervised?
Our answer is clear: Cybersecurity for the AI era must be both effortless and supervised.
- AI provides the speed, scale, and real-time intelligence.
- Skilled experts remain accountable and firmly in control.
That belief has shaped our biggest leap forward yet. We’ve expanded our security operations, embedded cutting-edge AI innovation, and completely redesigned our commercial offering.
Our goal is simple: Every business not just the largest enterprises deserves simple, accessible, and uncompromising security”.
ECA COMMENT: this vision is close to that also expressed by the French SEKOIA. See in NEWS FROM OUR MEMBERS;
AN INTERESTING EXAMPLE OF INFILTRATION, SOME WAYS TO STOP IT
(We here reproduce a Post by BizSecure APAC)
TRUSTED TOOL. UNTRUSTED ACCESS.
What happens when a legitimate remote-management tool becomes the attacker’s backdoor?
A recent intrusion targeting Thailand’s 3BB broadband infrastructure offers a clear example.
Investigators found that attackers deployed MeshCentral – a legitimate remote-management platform – as a hidden backdoor to maintain remote control over compromised systems.
Some systems were running with root privileges.
The attackers then attempted to:
→ Password-spray more than 55 internal systems
→ Harvest credentials and SSH keys
→ Target internal applications
→ Access sensitive authentication infrastructure
→ Remove logs and other traces while keeping their persistence mechanism alive
The attacker didn’t just gain access. They built a way to stay inside. And that’s where security architecture matters. Before access:
Continuously monitor your external attack surface and identify exposed assets, vulnerabilities and changes across your organisation and critical third parties.
After access:
Control privileged identities, restrict what they can reach, secure remote access and maintain visibility over privileged sessions.
With Board of Cyber, security teams can continuously assess external cyber exposure and monitor the posture of their ecosystem.
With WALLIX Group, organisations can enforce least-privilege access, secure privileged credentials and monitor privileged sessions across IT, OT and cloud environments.
Because cybersecurity isn’t only about stopping the first intrusion.
It’s about making sure that one compromised access doesn’t become unlimited access.
SWITZERLAND: LAKE GENEVA DIGITAL TRUST ECOSYSTEM MEETS
A vibrant meeting where Public Authorities, researchers and private stake holders have discussed on AI and cybersecurity.
More details here
IN CYBER FORUM: THE SELECTION OF INNOVATIVE STARTUPS IS OPEN
Start-ups have until November 30, 2026 to apply and compete for one of the prizes, including the INCYBER Start-up Grand Prize, which offers outstanding visibility and a partnership package for 2028.
Are you an ambitious start-up? This is your chance to shine click here



