Blog

  • ARC Data Shield to be exhibiting at the Paris Air Show (SIAE) 2025

    ARC Data Shield to be exhibiting at the Paris Air Show (SIAE) 2025

    From 16 to 17 June 2025, at the Paris–Le Bourget Exhibition Centre (Hall 4, Stand E 167), come and discover how our Digital Air Gap solution and its various specialised versions ensure the resilience of your critical infrastructure and the protection of your backups against major cyber risks such as ransomware.

    Come and meet us at our stand so we can show you our innovative technology:

    How the ‘Backup’ version of our solution works, designed to protect your backups via offline transfer: essential for countering ransomware and EDR bypasses.

    How the ‘Transfer’ version works, designed to create isolated networks to protect your R&D, production equipment or any critical assets from attacks and data exfiltration.

    Discuss the many other detailed use cases and all the benefits of our solutions for safeguarding your business.

    In a context where every minute of downtime can cost tens of thousands of euros, our Digital Air Gap can be deployed either to protect your assets directly, or to ensure the availability of your backups by storing them physically offline, enabling you to implement your disaster recovery and business continuity plans with absolute certainty.

    Join us at SIAE to discuss your business continuity challenges in a relaxed setting and leave with an action plan that’s ready to implement straight away.

    SIAE

  • SentinelOne’s BDU out, Babuk in

    SentinelOne’s BDU out, Babuk in

    AON researchers demonstrated on May 7, 2025 how a hacker, after exploiting an application flaw, bypassed the SentinelOne EDR’s anti-tamper protection to uninstall the Windows agent and deploy a variant of the Babuk ransomware.
    By exploiting the agent’s unauthenticated upgrade/downgrade, the attacker neutralized all detection, leaving the compromised server at the mercy of malicious encryption.
    SentinelOne was quick to react: local passphrase activated by default, authentication of updates and reinforced installation authorization via its console.


    But, as Stroz Friedberg warns, these patches are no substitute for a defense-in-depth strategy.
    In the face of constantly evolving circumvention methods, regular, isolated (physically offline) backups remain the last bastion of business continuity.

    In addition to instant patches, investing in redundant solutions and frequently testing restoration procedures is now a must for controlling the risk of ransomware.

    https://www.lemondeinformatique.fr/actualites/lire-l-edr-de-sentinelone-neutralise-pour-installer-une-variante-du-ransomware-babuk-96790.html

    Credits : Le Monde Informatique ” SentinelOne’s EDR neutralized to install a variant of the Babuk ransomware” 

  • ARC Data Shield is returning to exhibit at the Forum In Cyber 2025 in Lille

    ARC Data Shield is returning to exhibit at the Forum In Cyber 2025 in Lille

    ARC Data Shield is delighted to announce that it will be exhibiting at the International Cybersecurity Forum (FIC) 2025, which will take place from 1 to 3 April 2025 at the Lille Grand Palais, France.

    We invite you to come and discover our innovative Digital Air Gap network gateway solutions at our stand F17-9. Our breakthrough solution is designed to effectively protect your critical assets against cyber threats. Our team of experts will be on hand to discuss current cybersecurity challenges and the solutions provided by our technologies.​

    Join us at FIC 2025 to explore together the best strategies for protecting your digital infrastructure.

    Accueil VF

  • Cyberattack on fintech firm Harvest: disruption and data breach

    Cyberattack on fintech firm Harvest: disruption and data breach

    In February 2025, the French fintech firm Harvest suffered a major ransomware cyberattack, which completely paralysed its digital services, including its official website and customer access via VPN. According to the specialist magazine LeMagIT, the incident began with a targeted intrusion exploiting a vulnerability in the company’s cloud infrastructure, causing a total outage of its systems for several days. Many of the financial services offered by Harvest, including its investment and wealth management platforms, were severely affected.

    Cette cyberattaque a entraîné une fuite de données de clients et de salariés. Face à cette situation critique, Harvest a immédiatement mobilisé ses équipes techniques et fait appel à des experts externes pour contenir l’attaque et restaurer progressivement ses systèmes informatiques. Conformément à la réglementation européenne RGPD, les entreprises clientes ont dû rapidement notifier la CNIL afin de signaler cette violation de données.

    https://www.lemagit.fr/actualites/366620441/Cyberhebdo-du-7-mars-2025-une-semaine-exceptionnellement-violente

    Crédit : LeMagIT.fr, « Cyberhebdo du 7 mars 2025 : une semaine exceptionnellement violente ».

  • ARC Data Shield at European Cyber Week 2024: Discover our innovative cybersecurity solutions

    ARC Data Shield at European Cyber Week 2024: Discover our innovative cybersecurity solutions

    Rennes, 18–21 November 2024

    We are delighted to announce that we will be taking part in European Cyber Week (ECW) 2024, which will be held at the Couvent des Jacobins in Rennes from 18 to 21 November. Every year, this event brings together cybersecurity experts to discuss topics such as European strategic autonomy, defence AI and the protection of critical digital infrastructure.

    An environment that fosters innovation for cutting-edge solutions

    Against a backdrop of growing cyber threats, we will be showcasing our advanced technologies, including our patented Digital Air Gap network appliances. These innovative solutions provide a unique level of physical and electronic protection, in compliance with regulations such as the NIS 2 Directive, to ensure the resilience of critical infrastructure.

    Come and meet us at ECW 2024!

    Come and meet our team to find out about our innovations in cyber security and discuss the challenges of the future. Don’t miss this unmissable event – we look forward to seeing you at stand S06!

    https://www.european-cyber-week.eu/exposants

  • NIS 2 Directive: an opportunity to strengthen resilience in the face of growing cyber threats

    NIS 2 Directive: an opportunity to strengthen resilience in the face of growing cyber threats

    The NIS 2 Directive, which aims to strengthen the cybersecurity of thousands of French public authorities and businesses, comes into force today. The draft bill for its transposition into national law has been presented to the Council of Ministers and will shortly be debated in Parliament. This directive broadens the scope of entities covered, now including around 15,000 organisations in France, and increases the requirements for securing information systems.

    Vincent Strubel, Director-General of ANSSI, has announced a three-year period for regulated entities to comply with the new obligations, whilst emphasising the importance of starting immediately. The obligations include carrying out risk assessments, reporting security incidents to ANSSI, strengthening the resilience of IT systems, and promoting a culture of cybersecurity within organisations. Significant financial penalties are envisaged in the event of non-compliance.

    Faced with the growing wave of cyber-attacks that potentially threaten the survival of businesses, the introduction of NIS 2 should be seen as an opportunity to strengthen their resilience. Solution providers and software vendors are ready to support organisations through this transition, offering services and technologies to improve their resilience. Thus, whilst 17 October may seem like a symbolic date, it marks the beginning of a new era of vigilance and proactivity in cybersecurity.

    https://www.lemondeinformatique.fr/actualites/lire-dma-dsa-data-act-ai-act-un-foisonnement-de-textes-clefs-de-la-legislation-europeenne-94855.html

    Credits : Le Monde Informatique

  • Cyberattack in Germany: the need for robust network segmentation

    Cyberattack in Germany: the need for robust network segmentation

    On 1 September, the German Air Navigation Services (DFS) fell victim to a cyberattack targeting its internal communications system. Although air traffic was not affected and the consequences appear to be limited for the time being, this attack has highlighted a critical vulnerability. The pro-Russian hacker group APT 28, suspected of being behind the attack, is known for its cyber-espionage activities and is believed to have links to Russian military intelligence (GRU).

    This incident highlights the need to implement a strict system of segregation between critical infrastructure and office systems. Such a separation would provide better protection for vital air traffic control functions against malicious intrusions, by restricting access to sensitive systems and minimising the risk of an attack spreading. By strengthening these defences, it would be possible to prevent more serious consequences, such as disruption to air traffic or the exfiltration of sensitive data.

    https://www.lemondeinformatique.fr/actualites/lire-controle-aerien-allemand-pirate-un-cybergang-russe-soupconne-94641.html

    Credits: Le Monde Informatique

  • The new version of the HardBit 4.0 ransomware: A growing threat to corporate cybersecurity

    The new version of the HardBit 4.0 ransomware: A growing threat to corporate cybersecurity

    Cybersecurity researchers have discovered a new version of the HardBit ransomware, known as HardBit 4.0, which uses password protection to evade detection. Unlike previous versions, this variant requires a password to run properly, making analysis more difficult for security researchers. HardBit, which first appeared in October 2022, is notable for the absence of a data leak site, instead threatening victims with further attacks to force them to pay.

    The initial access vector is unclear, but may involve brute-forcing RDP and SMB services. Once access has been gained, the attackers use tools such as Mimikatz to steal credentials and move laterally via RDP. HardBit disables antivirus software and Microsoft Defender services, and encrypts files on the infected host. It also offers a ‘wiper’ mode to permanently delete files. In 2024, ransomware attacks are on the rise, with significant activity from the LockBit, Akira and BlackSuit groups.

    https://thehackernews.com/2024/07/new-hardbit-ransomware-40-uses.html

    Source: The Hacker News

  • Cyberattacks: the ransomware that is crippling hospitals

    Cyberattacks: the ransomware that is crippling hospitals

    Several healthcare facilities have been hit by recent attacks: in February, the Armentières facility had 18 GB of data published after its servers were encrypted, and in May, the Simone Veil Hospital in Cannes suffered a similar attack, with 61 GB of data leaked. In 2023, reports of ransomware attacks increased, with healthcare organisations accounting for 10 per cent of victims, according to ANSSI.

    A report by CERT Santé records 32 ransomware attacks in 2023, which caused serious disruption to certain organisations. France is the European country most affected by these cyber threats, but only 27 per cent of healthcare organisations have a ransomware protection programme in place.

    The consequences are severe, with medical data being sold on the dark web. Pierre-Antoine Failly Crawford of Varonis states that a single patient record can fetch 300 euros. However, an increasing number of organisations are refusing to pay ransoms, preferring to restore their systems from backups. CERT Santé notes that healthcare organisations are stepping up their cybersecurity efforts, with a commitment to strengthening their defences.

    https://www.lemondeinformatique.fr/les-dossiers/sommaire-lire-cyberattaques-ces-ransomwares-qui-terrassent-les-hopitaux-260.html

    Credit: Le Monde Informatique

  • Ransomware: a growing threat to businesses in 2023

    Ransomware: a growing threat to businesses in 2023

    Ransomware affected three in four businesses in 2023, posing a serious cybersecurity problem. According to the Veeam 2024 Ransomware Trends Report, only 57 per cent of compromised data is restored, leaving 43 per cent irrecoverable.

    These attacks cause system failures and downtime, having a significant impact on businesses. The pressure on IT and security teams is mounting, with 45 per cent of professionals reporting increased stress and 26 per cent a loss of productivity. Despite the need for an effective cyber defence strategy, 63 per cent of companies regret the lack of coordination between backup and cyber risk teams.

    A majority of 81 per cent of businesses paid ransoms, but a third did not recover their data after payment. Cyber insurance, taken out by 86 per cent of companies, covers only 62 per cent of the costs associated with attacks. Data stored in the cloud is just as vulnerable as on-premises data, highlighting the need to improve IT infrastructure to prevent cyberattacks.

    https://itsocial.fr/enjeux-it/enjeux-securite/cybersecurite/les-entreprises-continuent-a-etre-fortement-impactees-par-les-ransomwares/

    Credit: IT Social