Latest Stories

Stay up-to-date with everything at Approach

Blog article

Weekly Digest Week 26 – 2024

Publication date

28.06.2024

Featured Story

Adoption of the NIS2 Royal Decree

The Royal Decree implementing the Law of 26 April 2024 establishing a framework for the cybersecurity of networks and information systems of general interest for public security (the « NIS2 Law ») has been published in the Belgian Official journal: Moniteur belge / Belgisch Staatsblad.

SOC Analysis:
As cybersecurity experts, we are pleased to see the formal implementation of the NIS2 Directive in Belgium. For SMBs, this is both a challenge and an opportunity to align with EU-wide standards, boost cyber resilience, and benefit from a centralized governance model led by the CCB.

Other Stories

Fake Facebook account and competition in the name of Partenamut

Partenamut reports on a Facebook page that copies its identity and organises a competition to deceive the public.

SOC Analysis:
These scams replicate real campaigns to mislead users. Always verify such competitions on official platforms, avoid suspicious links, and use multi-factor authentication where possible.

CISOs Reveal Firms Prioritize Savings Over Long-Term Security

A third of security leaders believe companies sacrifice security for savings, according to Bugcrowd’s latest CISO report. 87% are hiring, but many report being understaffed and underprepared for breach risks.

SOC Analysis:
Skimping on security budgets leads to long-term risk. CISOs should champion forward-looking investments and strong governance to handle rising threats—especially as AI changes the security landscape.

Fresh MOVEit Bug Under Attack Mere Hours After Disclosure

Progress Software’s MOVEit Transfer flaw (CVE-2024-5806) is being actively exploited just hours after disclosure. The vulnerability allows attackers to bypass authentication and access internal systems.

SOC Analysis:
This vulnerability has a CVSS score of 9.1 and is actively exploited. Patch immediately and apply all mitigation steps to block RDP access and secure the perimeter.

Polyfill.io Supply Chain Attack Smacks Down 100K+ Websites

The polyfill.io domain used by over 100,000 websites has been compromised and is now serving malicious JavaScript payloads. The issue began after the domain was sold to a Chinese organization.

SOC Analysis:
This is a classic example of a supply chain risk. Remove all references to polyfill.io and consider self-hosting scripts to prevent malicious injection.

Want to enhance your organization’s cyber awareness or compliance strategy?
Contact the Approach Cyber SOC team for tailored support and training programs.

OTHER STORIES

Contact us to learn more about our services and solutions

Our team will help you start your journey towards cyber serenity

Do you prefer to send us an email?