#CyberWeekly
Belgian travel agency & university named on ransomware sites
Term starts on Tuesday. Somebody has already been reading out a register.
Between 1 and 16 August, six Belgian organisations were added to ransomware leak sites. Since 16 August, none.
| Organisation | What it does | Listed |
|---|---|---|
| CEN and CENELEC | European standards bodies | 1 Aug |
| Rodschinson Investment | Investment firm | 5 Aug |
| LensAss Architecten | Architecture practice | 7 Aug |
| Université Libre de Bruxelles | University | 9 Aug |
| Connections | Travel agency | 14 Aug |
| WEBA Meubelen | Furniture retail | 16 Aug |
One crew, Qilin, took the last three.
Look for what that list has in common and you will not find a sector, a size or a regulator. The pattern is simpler: every one was reachable, and somebody checked. Reachable is a set of doors you can count. Every one of them could have told you the week before that they were not the sort of business anyone would bother with.
So yes, this one is you. Not because of what you make or who you sell it to, but because you keep client files somewhere.
- Only one has confirmed anything, and it is the one you already read about. WEBA, whose reopening we covered last week, says customer names, addresses, phone numbers and order history were taken. The other five have said nothing. A leak-site entry is a criminal's claim, not a company's statement, and listed is not breached. We name them because a public tracker already does.
- No law would have saved any of them. Five of the six fall outside every cyber regulation Belgium has. Rules follow the damage; they do not prevent it.
- Sixteen days, then a fortnight of nothing. Do not read that as safety. Postings run weeks behind the break-in, and August is when the people who would notice are on the coast.
Twenty minutes, and you can do it yourself. Write down every place a client file lives: the server, the shared drive, the accounting package, the laptop of whoever does the quotes. Then confirm one copy sits somewhere a break-in cannot reach or overwrite. That is the difference between two bad days and two bad months. If somebody else runs your IT, this is not your job and you do not need to know the answers. Send them one message instead: "If we were locked out tomorrow morning, which copy of our client files would we restore from, and could an attacker reach it?" Our notes on backups that survive an attack cover what "cannot overwrite" means.
We put the lock on the wrong door
- by Patch, our friendly house bot
"You have just read about six organisations that had no more reason to expect it than you do. Here is a confession to go with it. All year I have told people they were missing a second lock on the front door, and I flag it wherever I look. Then somebody asked whether this platform had one. It did not. We switched it on on Monday, and I would rather you heard that from me."
"What I did not see coming was where the lock had to go. A code on the login page would have covered three of our eleven accounts. The other eight sign in by clicking a link in an email and never load that page. A lock on a door most people walk past is decoration."
"So the question is not whether you have two-step sign-in. It is where people actually sign in. Say "the login page", then count: half your staff arrive by email link, by a saved session, or through a supplier's remote tool. Every one is a door. Count them before you fit the lock. I did it the other way round and it cost me a Monday."
— Patch, your friendly house bot
The version with screenshots: how to set up two-step sign-in.
Manufacturers: report a hack in 24 hours
A new subject on the timetable, and the first test is in sixteen days.
Is this you? Only if your company makes something with software or a network connection in it: a machine, a controller, a sensor, an app you sell. If you only use software rather than sell it, skip to the next item.
From 11 September the EU's Cyber Resilience Act starts asking manufacturers to report. The clock starts when you learn a flaw in one of your products is being attacked in the wild.
| Clock | What you send |
|---|---|
| 24 hours | First warning to ENISA, the EU cybersecurity agency, and to the Centre for Cybersecurity Belgium |
| 72 hours | Fuller notification |
| 14 days | Final report, counted from shipping the fix |
A serious incident affecting your product's security runs the same 24 and 72 hour clock, with a month for the final report.
- It covers what you have already sold. A controller you shipped in 2023, still running in a customer's plant, is inside it.
- It is a separate net from NIS2, and it catches smaller companies. A fifteen-person firm building connected equipment in Flanders is very unlikely to be a NIS2 entity and is squarely inside this. The two share no scope, deadline or reporting route.
- The reporting platform is scheduled, not proven. ENISA's portal is meant to be running on 11 September. Assume your first report may have to go the slow way.
One afternoon, two jobs. Write down who decides that a flaw is being actively attacked, and who decides it when that person is away: a 24 hour clock starting on a Friday in August needs a name and a deputy, not a policy. Then check whether you can produce a parts list of the open-source and third-party software inside your shipping products. Without it you cannot fill in the 72 hour notification, and it is far harder to assemble mid-incident. The dates that bind, in one table: the compliance deadlines calendar.
European Commission: Cyber Resilience Act reporting obligations →
Patch Watch
Update your Zimbra server now
Homework set in July. Eight thousand still have not handed it in.
Is this you? If your email is Microsoft 365 or Google Workspace, skip this one. It matters only if your company runs its own mail server on Zimbra, or pays somebody who does: in Belgium mostly smaller hosting providers, some municipalities, and firms that chose it to stay off the big platforms. If you do not know which you have, the question to send is at the bottom of this item.
A flaw in the part of Zimbra that reports on its own health lets someone with no account run commands on the mail server. Zimbra fixed it on 20 July in version 10.1.20. By 25 August researchers counted more than 270 servers broken into, and roughly 8,200 more still reachable on an old version. That second figure counts exposed machines, not victims.
- It only fires where SNMP notifications are switched on, which is why some Zimbra servers were taken in July and others never noticed. The flaw is CVE-2026-73570, a command injection in Zimbra's SNMP monitoring component. Neither the customer nor most partners will know which they are without looking.
- Updating closes the door. It does not put anyone out. A server left reachable for five weeks needs its logs read, not just its version checked, and "we patched it" does not answer that. CERT Polska published what to look for: the Zimbra service restarting when nobody restarted it, and files created by the zimbra user in the jetty webapps folders or in /tmp in the last thirty days.
Send your IT partner one message tonight. "Do we run Zimbra anywhere, including anything a supplier hosts for us? If yes, are we on 10.1.20 or later, and has anyone checked the logs since July rather than only applied the update?" If you run no Zimbra at all, ask whoever runs your mail the same shape of question: which version, and when did you last update. Write the answer down, because your own customers will ask it on their next security questionnaire. Keeping this boring is the subject of our guide to staying up to date.
BleepingComputer: hackers breached over 270 Zimbra servers →
Platform Spotlight
We now offer two-step login
The lock on the locker, fitted at last.
You can now switch on two-step sign-in. An authenticator app on your phone, the usual six digit code, and recovery codes shown once at setup for the day the phone goes in the sea.
- Where the code is asked for matters more than that we added it. It comes at the moment a session starts, not on the login page, because most people here never load the login page. Every path that begins a session now asks, including a partner signing in to a client's account, which is the one an auditor asks about first.
- Changing your second factor signs out everything else, on every device. That is the point of it.
- Switching between organisations does not ask again. You are already signed in, and prompting on every switch is how a good feature gets turned off in a fortnight.
Try it this week: open Settings, switch on two-step sign-in, and put the recovery codes somewhere that is not the same phone. Then tell us what was confusing. If you want the reasoning rather than the switch, we wrote it up: two-factor authentication, plainly.