def con2 articles
Belgian eID Software Had Holes Big Enough to Sign Away Your Life
Security researcher James Arnott discovered critical vulnerabilities in Belgium's Connective eID software, used by over two million people across major banks and government agencies, which failed to verify which websites could communicate with the application. The flaws allowed malicious websites to silently read card details, trick users into revealing their PINs via spoofed prompts, forge legally binding electronic signatures, and even execute remote code on victims' machines without any special permissions. Nitro Software Belgium fully patched the vulnerabilities 146 days after the initial report and awarded a $200 bug bounty, with no CVEs assigned.
PLCs on the public internet are an open goal for attackers, says ex-NSA chief
Retired General and former NSA chief Paul Nakasone has warned that water system controllers should not be connected to the internet, following suspected Iranian cyberattacks on water facilities across at least 12 US states. Speaking at DEF CON, he highlighted the enormous attack surface posed by around 50,000 underfunded and understaffed water municipalities, calling for higher cybersecurity standards and a collaborative defence approach. While neither the FBI nor the Trump administration has officially attributed the attacks to Iran, security researchers and Nakasone himself consider Iranian involvement highly likely given the country's history and demonstrated capability in targeting such infrastructure.