Category: News cyber

  • The director of the NSA has confirmed that Mythos, Anthropic’s AI model, has penetrated ‘almost all’ US classified systems. In a matter of hours.

    The director of the NSA has confirmed that Mythos, Anthropic’s AI model, has penetrated ‘almost all’ US classified systems. In a matter of hours.

    Senator Mark Warner revealed on 11 June that General Joshua Rudd, who heads both the NSA and Cyber Command, had told him directly: Mythos “had breached almost all our classified systems, not in weeks, but in hours.” The information, reported by The Economist, has not been officially confirmed by the agencies concerned.

    The test was an authorised red team exercise on the NSA’s networks. It was not a real attack. However, the speed and scale of the breach are said to have exceeded anything previously observed using conventional methods.

    This revelation puts the 12 June decision to cut off access to Fable 5 and Mythos 5 into context. It may not have been just a simple jailbreak. It was a demonstration that a commercial AI model could autonomously compromise the world’s most heavily protected systems.

    The official trigger remains the jailbreak reported by Amazon to the Department of Commerce. Facebook’s former head of security, Alex Stamos, says he examined the data and shared Anthropic’s view: ‘valid results but no unique capability justifying a response of this scale. ”

    But if Rudd’s account is accurate, it changes everything. An AI model built by a San Francisco start-up, capable of breaching the NSA’s defences in a matter of hours. Not using a known exploit. Through autonomous reasoning.

    We’ve gone from ‘AI could become dangerous one day’ to ‘AI has just hacked the NSA during a test’. The question is no longer a theoretical one.

    👉 Follow DisruptionMedia to stay up to date with the latest AI news

    🚀 THE free newsletter to understand AI, technology and the transformations reshaping the world in less than 5 minutes a day: https://lnkd.in/eN6-tGKB

    https://www.linkedin.com/posts/le-directeur-de-la-nsa-a-confirm%C3%A9-que-share-7474927693105532928-1pm8/?utm_source=share&utm_medium=member_desktop&rcm=ACoAAEtvOeUBqYHeE35nWzjFlbI5EsqJ1uzg1QM

    Credit : DisruptionMedia

  • SentinelOne’s BDU out, Babuk in

    SentinelOne’s BDU out, Babuk in

    AON researchers demonstrated on May 7, 2025 how a hacker, after exploiting an application flaw, bypassed the SentinelOne EDR’s anti-tamper protection to uninstall the Windows agent and deploy a variant of the Babuk ransomware.
    By exploiting the agent’s unauthenticated upgrade/downgrade, the attacker neutralized all detection, leaving the compromised server at the mercy of malicious encryption.
    SentinelOne was quick to react: local passphrase activated by default, authentication of updates and reinforced installation authorization via its console.


    But, as Stroz Friedberg warns, these patches are no substitute for a defense-in-depth strategy.
    In the face of constantly evolving circumvention methods, regular, isolated (physically offline) backups remain the last bastion of business continuity.

    In addition to instant patches, investing in redundant solutions and frequently testing restoration procedures is now a must for controlling the risk of ransomware.

    https://www.lemondeinformatique.fr/actualites/lire-l-edr-de-sentinelone-neutralise-pour-installer-une-variante-du-ransomware-babuk-96790.html

    Credits : Le Monde Informatique ” SentinelOne’s EDR neutralized to install a variant of the Babuk ransomware” 

  • Cyberattack on fintech firm Harvest: disruption and data breach

    Cyberattack on fintech firm Harvest: disruption and data breach

    In February 2025, the French fintech firm Harvest suffered a major ransomware cyberattack, which completely paralysed its digital services, including its official website and customer access via VPN. According to the specialist magazine LeMagIT, the incident began with a targeted intrusion exploiting a vulnerability in the company’s cloud infrastructure, causing a total outage of its systems for several days. Many of the financial services offered by Harvest, including its investment and wealth management platforms, were severely affected.

    Cette cyberattaque a entraîné une fuite de données de clients et de salariés. Face à cette situation critique, Harvest a immédiatement mobilisé ses équipes techniques et fait appel à des experts externes pour contenir l’attaque et restaurer progressivement ses systèmes informatiques. Conformément à la réglementation européenne RGPD, les entreprises clientes ont dû rapidement notifier la CNIL afin de signaler cette violation de données.

    https://www.lemagit.fr/actualites/366620441/Cyberhebdo-du-7-mars-2025-une-semaine-exceptionnellement-violente

    Crédit : LeMagIT.fr, « Cyberhebdo du 7 mars 2025 : une semaine exceptionnellement violente ».

  • NIS 2 Directive: an opportunity to strengthen resilience in the face of growing cyber threats

    NIS 2 Directive: an opportunity to strengthen resilience in the face of growing cyber threats

    The NIS 2 Directive, which aims to strengthen the cybersecurity of thousands of French public authorities and businesses, comes into force today. The draft bill for its transposition into national law has been presented to the Council of Ministers and will shortly be debated in Parliament. This directive broadens the scope of entities covered, now including around 15,000 organisations in France, and increases the requirements for securing information systems.

    Vincent Strubel, Director-General of ANSSI, has announced a three-year period for regulated entities to comply with the new obligations, whilst emphasising the importance of starting immediately. The obligations include carrying out risk assessments, reporting security incidents to ANSSI, strengthening the resilience of IT systems, and promoting a culture of cybersecurity within organisations. Significant financial penalties are envisaged in the event of non-compliance.

    Faced with the growing wave of cyber-attacks that potentially threaten the survival of businesses, the introduction of NIS 2 should be seen as an opportunity to strengthen their resilience. Solution providers and software vendors are ready to support organisations through this transition, offering services and technologies to improve their resilience. Thus, whilst 17 October may seem like a symbolic date, it marks the beginning of a new era of vigilance and proactivity in cybersecurity.

    https://www.lemondeinformatique.fr/actualites/lire-dma-dsa-data-act-ai-act-un-foisonnement-de-textes-clefs-de-la-legislation-europeenne-94855.html

    Credits : Le Monde Informatique

  • Cyberattack in Germany: the need for robust network segmentation

    Cyberattack in Germany: the need for robust network segmentation

    On 1 September, the German Air Navigation Services (DFS) fell victim to a cyberattack targeting its internal communications system. Although air traffic was not affected and the consequences appear to be limited for the time being, this attack has highlighted a critical vulnerability. The pro-Russian hacker group APT 28, suspected of being behind the attack, is known for its cyber-espionage activities and is believed to have links to Russian military intelligence (GRU).

    This incident highlights the need to implement a strict system of segregation between critical infrastructure and office systems. Such a separation would provide better protection for vital air traffic control functions against malicious intrusions, by restricting access to sensitive systems and minimising the risk of an attack spreading. By strengthening these defences, it would be possible to prevent more serious consequences, such as disruption to air traffic or the exfiltration of sensitive data.

    https://www.lemondeinformatique.fr/actualites/lire-controle-aerien-allemand-pirate-un-cybergang-russe-soupconne-94641.html

    Credits: Le Monde Informatique

  • Ransomware: a growing threat to businesses in 2023

    Ransomware: a growing threat to businesses in 2023

    Ransomware affected three in four businesses in 2023, posing a serious cybersecurity problem. According to the Veeam 2024 Ransomware Trends Report, only 57 per cent of compromised data is restored, leaving 43 per cent irrecoverable.

    These attacks cause system failures and downtime, having a significant impact on businesses. The pressure on IT and security teams is mounting, with 45 per cent of professionals reporting increased stress and 26 per cent a loss of productivity. Despite the need for an effective cyber defence strategy, 63 per cent of companies regret the lack of coordination between backup and cyber risk teams.

    A majority of 81 per cent of businesses paid ransoms, but a third did not recover their data after payment. Cyber insurance, taken out by 86 per cent of companies, covers only 62 per cent of the costs associated with attacks. Data stored in the cloud is just as vulnerable as on-premises data, highlighting the need to improve IT infrastructure to prevent cyberattacks.

    https://itsocial.fr/enjeux-it/enjeux-securite/cybersecurite/les-entreprises-continuent-a-etre-fortement-impactees-par-les-ransomwares/

    Credit: IT Social

  • "Black hat AI" versus "White hat AI" – which will win?

    "Black hat AI" versus "White hat AI" – which will win?

    Given the capabilities of AI, which are a double-edged sword – equally powerful for launching attacks as for defence – should we take preventive measures or continue to leave our critical assets exposed?

    "Black hat AI" versus "White hat AI" – which will win?

    Is it a matter of urgency to stop leaving critical or sensitive assets accessible, protected solely by software security, or should we wait and hope that the positive uses of AI will outweigh the negative ones?

    An excellent article by OnePoint, written in collaboration with EGE’s business intelligence experts on this topic.

    https://www.groupeonepoint.com/fr/nos-publications/intelligence-artificielle-et-cybersecurite-risques-ou-opportunites/

    Credit: Onepoint

  • The new recommendations regarding backup policy: moving away from the 3-2-1 strategy, which is no longer sufficient, towards the robust 3-2-1-1-0 strategy.

    The new recommendations regarding backup policy: moving away from the 3-2-1 strategy, which is no longer sufficient, towards the robust 3-2-1-1-0 strategy.

    The 3-2-1 rule recommended three copies of data across two different media types, with one copy stored off-site. Originally proposed by Peter Krogh, this rule needs to be adapted to reflect current risk trends. In an ever-expanding and interconnected digital landscape, more advanced backup strategies are emerging to meet these needs. Veeam promotes the 3-2-1-1-0 rule, which fulfils the objective of ensuring data recovery through the diversification of storage copies. By incorporating these principles into their practices, organisations can guarantee the security and availability of their data in a dynamic digital environment.

    Recommendations 3-2-1-1-0:

    – 3 copies of the data

    – Across two different media

    – Including 1 off-site copy

    – And a physical copy that is offline

    – And no errors during the restoration tests

    https://www.veeam.com/blog/321-backup-rule.html

    Credit: Veeam