Reading view

Dora Horjus programmamanager House of Cyber bij NCSC

Het Nationaal Cyber Security Centrum (NCSC) werkt samen met partners toe naar een fysiek ‘House of Cyber’. Hiermee zorgt het NCSC niet alleen voor een nieuw huis voor zijn medewerkers, maar ook voor een plek waar publieke en private partijen fysiek én actief kunnen samenwerken aan de cybersecurity van Nederland.
  •  

Oplichters klonen nu nieuwswebsites om je bankrekening te plunderen

Cybercriminelen misbruiken grote nieuwswebsites in het Verenigd Koninkrijk om mensen op te lichten. Aan de hand van artikelen op AI-klonen van o.a. The Guardian en de BBC lokken ze de lezers naar investeringsplatforms met als doel om hun rekening te plunderen. 

  •  

Beveilig je IP-camera’s om spionage van statelijke actoren te voorkomen

Russische statelijke actoren hacken IP-camera’s om (vitale) infrastructuur van NAVO-landen, waaronder Nederland, te bespioneren. Het NCSC ziet dat niet alleen statelijke actoren misbruik maken van deze camera’s, maar ook hacktivistische groeperingen en cybercriminelen. Daarom roept het NCSC organisaties en thuisgebruikers op om IP-camera’s beter te beveiligen door onder andere je apparaten up-to-date te houden, je netwerk te segmenteren en het aanvalsoppervlak te verkleinen. Lees hieronder ons uitgebreide handelingsperspectief.
  •  

Top 6 Managed Detection and Response Providers

There are several major managed detection and response (MDR) companies to choose from. We’ve compared the main offerings of the best MDR providers to help you decide which is right for your organisation. Maybe it was a near miss, or a security team stretched too thin and drowning in alerts from dozens of tools. Whatever […]

The post Top 6 Managed Detection and Response Providers appeared first on Heimdal Security Blog.

  •  

Cyber-Aware Customers Are Raising the Bar for MSPs and Other Vendors 

Your client is no longer just buying your security advice. They’re auditing whether you live by it.  That was a clear message from my exclusive interview with Heather MacDonald Alford, an MSP finance specialist and owner of Counting Creators.  Heather’s exactly the kind of customer MSPs should be paying attention to. She’s informed, commercially minded, and willing to challenge vendors to […]

The post Cyber-Aware Customers Are Raising the Bar for MSPs and Other Vendors  appeared first on Heimdal Security Blog.

  •  

Cyberbeveiligingswet en Wet weerbaarheid kritieke entiteiten vanaf 15 augustus 2026 van kracht

De Eerste Kamer heeft op 7 juli ingestemd met de Cyberbeveiligingswet (Cbw) en de Wet weerbaarheid kritieke entiteiten (Wwke). Hiermee zet Nederland een belangrijke stap in het versterken van de digitale en fysieke weerbaarheid van organisaties tegen toenemende dreigingen.
  •  

Versie 2.1 van STIX en TAXII per 1 juli 2026 verplicht voor de overheid

Vanaf 1 juli 2026 zijn de standaarden STIX en TAXII versie 2.1 toegevoegd aan de 'Pas toe of leg uit'-lijst. Dit betekent dat Nederlandse gemeenten, provincies, rijk, waterschappen en alle uitvoeringsorganisaties verplicht zijn om deze nieuwe versies toe te passen. Voor alle andere organisaties in de publieke sector geldt een dringend advies om STIX en TAXII versie 2.1 toe te passen. Ook is het functioneel toepassingsgebied bijgewerkt.
  •  

Wissel effectiever dreigingsinformatie uit met STIX/TAXI 2.1

Cyberaanvallen beperken zich zelden tot één organisatie. Kwaadwillenden vallen in veel gevallen meerdere organisaties tegelijk aan. Om te voorkomen dat meerdere organisaties slachtoffer worden, is snelle en gestandaardiseerde uitwisseling van dreigingsinformatie essentieel. Daarom heeft het Nationaal Cyber Security Centrum (NCSC) een aanvraag ingediend om versie 2.1 van STIX/TAXII, die effectieve en geautomatiseerde uitwisseling van dreigingsinformatie mogelijk maakt, op de 'Pas toe of leg uit'-lijst van Forum Standaardisatie op te laten nemen.
  •  

Eerste cyberaanval volledig door AI gedaan blijkt keerpunt in digitale veiligheid

Hackers zetten AI in om cyberaanvallen uit te voeren. Cloudbeveiligingsbureau Sysdig deelt dat zij een hack hebben onderschept, die waarschijnlijk volledig door AI werd gedaan. De AI blijkt hardnekkiger en effectiever dan menselijke hackers, waardoor dit moment als keerpunt voor cyberveiligheid kan worden gezien.

  •  

How to scale your patches without scaling your team (the patch wave)

Most breaches don’t start with a vulnerability nobody knew about. They start with one nobody patched in time. Vulnerability exploitation is now the single biggest way attackers get into a network. It has overtaken stolen credentials for the first time in the 19-year history of Verizon’s Data Breach Investigations Report, with 31% of breaches now […]

The post How to scale your patches without scaling your team (the patch wave) appeared first on Heimdal Security Blog.

  •  

AI didn’t break patching. It showed us patching was already broken.

Claude Mythos, an AI model from Anthropic, has found 23,019 software vulnerabilities in the past month. Fewer than 1% of them have been patched. That gap is the story. Finding a vulnerability used to be the hard part, the thing that limited how fast software got fixed. AI just closed that gap to almost nothing. […]

The post AI didn’t break patching. It showed us patching was already broken. appeared first on Heimdal Security Blog.

  •  

Heimdal Launches MSP Onboarding Wizard to Help Partners Onboard Microsoft CSP Customers in 2 Minutes

COPENHAGEN, Denmark, 1 July 2026 – Heimdal today announced the launch of MSP Onboarding Wizard, a new capability that helps managed service providers onboard Microsoft Cloud Solution Provider (CSP) customers inside the Heimdal platform faster and with less manual work. Built for MSPs managing multiple Microsoft tenants, MSP Onboarding Wizard reduces customer onboarding from around […]

The post Heimdal Launches MSP Onboarding Wizard to Help Partners Onboard Microsoft CSP Customers in 2 Minutes appeared first on Heimdal Security Blog.

  •  

De Cyberbeveiligingswet in laatste fase van vaststelling

Op 6 en 7 juli 2026 vergadert de Eerste Kamer over de Cyberbeveiligingswet (Cbw). Dan zal er ook over het wetsvoorstel worden gestemd. Als de Eerste Kamer het wetsvoorstel aanneemt, treedt de Cbw naar verwachting op 15 augustus 2026 in werking. Organisaties die onder de wet vallen, krijgen dan te maken met nieuwe verplichtingen op het gebied van digitale weerbaarheid.
  •  

How Dynamic Defense shuts an attacker out without shutting down the business

AI has handed hackers a resource advantage. Winning it back means spending your own resources far more precisely, and that’s the strategy we call Dynamic Defense. The principle is simple. Contain the threat just enough, for just long enough, until the risk is removed. This piece shows how that works as a five-stage loop that […]

The post How Dynamic Defense shuts an attacker out without shutting down the business appeared first on Heimdal Security Blog.

  •  

Static security has run out of road. The case for Dynamic Defense

AI has flipped the economics of cybersecurity in the attacker’s favor. For most of the last decade, defenders held the cost advantage, buying down their risk with a stack of largely static controls. That advantage is gone, and winning it back is the central problem facing every security team in 2026. I think the answer […]

The post Static security has run out of road. The case for Dynamic Defense appeared first on Heimdal Security Blog.

  •  

Breaking the MSP Echo Chamber: The Power of Community

MSPs spend too much time talking to other MSPs and not enough time talking to the people they’re supposed to serve.  That’s Paul Croker’s view of some of the channel’s biggest growth problems.   While most industry events bring technology professionals together, they rarely put them in the same room as the business leaders making […]

The post Breaking the MSP Echo Chamber: The Power of Community appeared first on Heimdal Security Blog.

  •  

How attackers built a RAT on a Windows machine using its own .NET compiler

In May 2026 an attacker compromised a UK medical practice endpoint without delivering a single malicious file. They used PowerShell and the .NET compiler built into Windows to build a Remcos remote access trojan on the machine itself, so signature antivirus had no known sample to match. The thing that caught it was DNS filtering, […]

The post How attackers built a RAT on a Windows machine using its own .NET compiler appeared first on Heimdal Security Blog.

  •  

Attacker enables RDP, creates admin, erases evidence in ten seconds

At 06:34am on 2 June 2026, an attacker logged on to a customer’s network. In a single automated burst, they switched on remote desktop and created a rogue administrator account. And deleted the evidence behind them.  The intrusion reached 34 endpoints and was over in under ten seconds.  Heimdal Extended Threat Protection (XTP) and Ransomware […]

The post Attacker enables RDP, creates admin, erases evidence in ten seconds appeared first on Heimdal Security Blog.

  •  
❌