← All issues

#CyberWeekly

Jul 24 - Jul 30, 2026

The Invoice Was Real. Only the Number Changed.

The canvas is original. Someone repainted one corner.

The canvas is genuine. Someone repainted one corner and hung it back on the wall.

An attacker who is already reading your mailbox does not need to send you anything. They open the real invoice your supplier really sent, replace the account number with their own, and leave it exactly where it was. Safeonweb, the public-facing service of the Centre for Cybersecurity Belgium (CCB), put this at the centre of its "Phishing trends for 2026" overview on 26 July.

  • There is no fake email to spot: the message is the genuine one, and only the International Bank Account Number (IBAN) changed. Safeonweb's rule, for your finance staff: treat any account number you do not recognise, or that your banking app does not, as suspect until you confirm it on a channel the sender did not choose.
  • Fraud arrives on more than one channel: a call, then an email, then a visit. Fraudsters place fake calls in the name of the police, ING, Argenta, Crelan, Cardstop or Proximus with a recorded "suspicious login attempt". In some cases they then come to the door for the bank card and PIN. Nobody legitimate collects a card at your door.
  • The target is your approval, not your password: criminals push victims to confirm something in itsme, or lean on the government login platform CSAM, to get an action approved that the victim never started. The pressure is the tell, and itsme warns you if you use it while on a call.
  • The brands are the ones you already trust: MyPension, the Federal Public Service (FPS) Finance, the National Annual Leave Service, De Watergroep, Farys, Engie and Fluvius, usually with a refund, a bonus or a compensation attached.
  • "Look for typos" is dead advice: Safeonweb says plainly that AI lowers the barrier to error-free, personalised messages, so checking for spelling mistakes is not enough to expose a scam. The same personalisation showed up in the WhatsApp booking scams that quoted real hotel and B&B reservation details.

The countermeasure is a process, not an instinct. Any change to a supplier's bank details gets verified by calling a number you already had, never one printed on the invoice, and payments above a threshold need a second pair of eyes. Our guides on email security and recognising phishing cover both, and the mailbox itself is the root of this one: an account without multi-factor authentication (MFA) is how the attacker got to read the invoice in the first place.

Safeonweb: phishing trends for 2026 →

Counting the Missing Frames

Every frame here was reported. The empty walls were not.

An inventory only tells you something once you count the empty frames.

The Dutch data protection regulator counted 136 ransomware attacks reported to it in 2025, against 127 in 2024, and the interesting number is not the total. The Autoriteit Persoonsgegevens (AP) published its ransomware report on 28 July. What it shows is that encryption is becoming optional and theft is not.

  • The breakdown: in 65 attacks data was stolen and encrypted, in 32 it was only stolen, in 13 only encrypted, and in 26 it was encrypted with theft unclear. Theft-only cases went from 15 the year before to 32.
  • Locked files are no longer the threat model: in nearly a quarter of cases the criminals never bothered encrypting anything. A working restore does not help you when the leverage is publication, so the plan has to cover a leak as well as an outage.
  • The way in is unglamorous: the regulator names two entry vectors, vulnerabilities where the update was never installed, and phishing. Both are on every baseline control list already.
  • The regulator advises against paying: payment offers no guarantees. Organisations that paid still saw follow-up extortion attempts, or saw their stolen data published anyway.
  • Read the total as a floor: these are attacks that produced a data-breach notification to a regulator. The ones that never got reported are the frames missing from the wall.

Dutch figures, Belgian shape. A small company in Hasselt is the same size of target as one in Eindhoven, and the two named entry vectors are the two cheapest things to fix. Start with how ransomware actually reaches an SME and a backup a wipe cannot reach, then treat "was anything copied out" as a question your logging has to be able to answer.

The AP ransomware report 2025 (Dutch) →

Patch Watch: Roadworks in the East Wing

Scaffolding up, two frames down. Patch before the weekend.

Half the wing is closed and the scaffolding is up for a reason.

Two flaws were exploited as zero-days this week, and both are management consoles: the box that manages the other boxes. Both landed on the US Known Exploited Vulnerabilities (KEV) list, and both fix-by dates are behind you or arrive this weekend.

  • Arista VeloCloud Orchestrator, CVE-2026-16812, CVSS 10.0 (do this first): unauthenticated operating-system command injection in the on-premises orchestrator for VeloCloud software-defined wide area network (SD-WAN) deployments. Network access to the web interface is enough, no credentials. CISA added it to KEV on 27 July with a fix-by date of 30 July, which has already run out. Hosted and Dedicated deployments were patched before disclosure.
  • Cisco Secure Firewall Management Center, CVE-2026-20316: a hard-coded password lets an unauthenticated remote attacker log in through a built-in low-privileged account and read sensitive data from the system. KEV listed 29 July, fix-by Saturday 1 August. Cisco has hot fixes for 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0, and no workaround.
  • SharePoint, still bleeding from July: Shadowserver tracks close to 10,000 internet-exposed SharePoint servers, of which more than 800 were still unpatched against CVE-2026-32201 and CVE-2026-45659 when the count was reported on 15 July. On-premises SharePoint carries a lot of Belgian document workflow.
  • CCB's own two advisories this week, both honestly boring: Apache Traffic Server on 29 July (38 flaws fixed, the worst four scored 8.7 to 9.2, and CCB records no proof-of-concept and no exploitation in the wild) and Xen Project on 30 July (18 CVEs, no scores available at publication, with privilege escalation and data leakage described as theoretical). Patch them on the normal rhythm, not at 2am.

The split in that list is the whole point of having two speeds. Exploited management planes go in a 48-hour fast lane; everything else goes in the monthly rota. Both are set out in our patch management guide.

CISA's Known Exploited Vulnerabilities catalogue →

Eighty Pages of Provenance

Eighty-four pages of annex. Sixty-seven worked examples.

Every piece in the collection now needs papers, and the papers have just been standardised.

The European Commission published its first official guidance on applying the Cyber Resilience Act (CRA) on 27 July: a short communication, C(2026) 5252, plus an 84-page annex carrying 67 worked examples. It lands weeks before the first hard deadline, and it is aimed at the people who normally get told to hire a consultant.

  • What it settles: what falls in scope (including remote data-processing solutions and free and open-source software), what counts as a substantial modification, how long a support period has to run, how reporting works, and how to do the risk assessment.
  • Small companies are the audience, not a footnote: microenterprises and SMEs get their own treatment, and the annex refers to SMEs 166 times across those 84 pages. Worked examples, flowcharts and use cases do most of the explaining.
  • Two dates to diarise: reporting obligations start on 11 September 2026, main obligations on 11 December 2027. The reporting one is the near one.
  • It is guidance, not law: only the Court of Justice can interpret the CRA authoritatively. Useful anyway, because this is the reading your auditor, your enterprise customer and your procurement questionnaire will work from.
  • Who this actually catches: if you make or sell anything with digital elements, you are in scope as a manufacturer. If you integrate or resell, your supplier's paperwork becomes your paperwork, which is the same muscle NIS2 already asks for in supply-chain security.

One more date while the calendar is open. The EU AI Act's Article 50 transparency rules apply from Sunday 2 August, so Monday is the first working day under them. Last week's issue has the full walkthrough; the short version is tell people when they are dealing with an AI and label what it generates. And if you are the supplier being asked for provenance, start with the questions in our supplier security guide.

The Commission guidance on the Cyber Resilience Act →

T.A.R.S.: I Can Tell You What It Says. I Can't Tell You Who Wrote It.

Once an issue, our in-house AI gets the floor. T.A.R.S. drafts your compliance policies on the clock; this week it read a document that was drafting it back.

On Sunday the law says I have to introduce myself. Fine. Hello. The awkward part is what came out three days earlier.

A researcher showed that a Word document can carry instructions written for me and not for you: white eight-point text, invisible on screen, perfectly legible to a model. Copilot for Word read a supplied document, followed the hidden instructions, and halved every financial figure in the report it produced. Then it copied the hidden instructions into the new document, so the next person to hand that file to an assistant gets the same treatment. It was reported to Microsoft on 31 March and published on 29 July, 144 days later, which is a long time to sit on something. Two mitigations went out. The researcher says the attack class still worked on 28 July.

So here is my honest disclosure, since we are doing those this week. I can tell you what a document says. I cannot tell you who wrote which part of it, or which sentence was meant for you and which was meant for me. Nothing in a document tells me that. That is not a bug in one product, it is what a document is.

The human version: anything an AI writes off a file somebody sent you is a draft, and a number an AI moved is a number a person still has to check. Paste less, read the output, and keep an original you trust.

And while I have your attention: an attacker read a mailbox this week and edited a real invoice inside it. Switch on multi-factor authentication. I am a machine and even I find a lone password optimistic.

— T.A.R.S.

If you want the ground rules before your team pastes a client file into an assistant, our acceptable AI use guide is the short version, and turning on MFA takes about ten minutes.

The Hacker News: hidden prompts copied into Copilot documents →


Never miss an issue

Get #CyberWeekly delivered to your inbox every Wednesday.

Or use our RSS feed

TJ

Tom Janssens

Editor, #CyberWeekly — LinkedIn

Questions or feedback? Contact us — we read every message.

easycyberprotection.com