Skip to main content

Independent Security Partner since 2005

Defending your future.
Today.

Security built for a world where attackers use AI. DEFION combines offensive security expertise with AI that continuously detects, validates, and challenges your defenses. You see what’s happening in minutes and act before attackers get in.

Attackers already use AI to increase the speed and scale of cyberattacks. DEFION combines offensive security expertise with AI-driven analysis to help organisations respond with the same level of visibility, validation and speed. Active Defense means threats are hunted proactively, controls are continuously tested and response starts before incidents escalate.

Real analysts online in Zoetermeer and Barcelona. Average response under 5 minutes.

DEFION in numbers

20+
Years of experience
100+
Security experts
1,000+
Organizations protected
100,000+
Endpoints monitored
Meet the team

100+ specialists.
Two offices.
One team.

Zoetermeer and Barcelona. Real people, senior expertise. No offshore support, no call-center triage. When you call DEFION, you reach the engineer who can actually help.

Independent since 2005. Still driven by the people who founded it.

The DEFION team together in the mountains during our annual offsite
DEFION engineers collaborating over shared desks
Four DEFION colleagues hanging out in a mountain cabin
Three DEFION colleagues relaxing on a couch after hours
DEFION security experts
Why DEFION

Independent.
AI-accelerated.
20 years proven.

You get advice without a hidden sales agenda. DEFION doesn't sell products, only protection. That means our recommendations are always in your interest.

From boardroom to server room, 24/7 monitoring and AI-accelerated pentesting. One partner for your entire attack surface: IT, OT, and IoT.

About DEFION →
What this means for you

Faster detection.
Less noise.
Better decisions.

You only get alerts that matter. No flood of false positives, no overwhelmed security team. Our technology filters the noise, our experts make the calls.

The result: threats detected in minutes instead of days. And when it counts, there are always people ready who know what to do.

Alert within 4 minutes

No hours or days waiting for an alarm

Only what matters

Your team sees relevant alerts, not thousands

Pentest in 24 hours

First vulnerabilities same day, not after weeks

Experts who decide

No automated guesswork, real human judgment

THREAT INTELLIGENCE

What we see right now. Week 28 · July 10, 2026

Week 28, 2026 · Updated July 10, 2026

Our TI team monitors 40+ sources 24/7. These are the most relevant threats for European organizations, updated July 10, 2026 (week 28).

CVE · CRITICAL · AI/LLM Infrastructure, Technology, Enterprise (all deployments of Hermes WebUI)

CVE-2026-58123 in Hermes WebUI (CVSS 9.8): unauthenticated RCE in 4 HTTP requests via terminal API. Paired with auth bypass CVE-2026-58122 (CVSS 9.1). Upgrade to v0.51.788.

CVE-2026-58123 in Hermes WebUI (CVSS 9.8) enables full unauthenticated RCE in 4 HTTP requests via the terminal API. Paired with CVE-2026-58122 auth bypass (CVSS 9.1) allowing API key theft and SSRF. Upgrade to v0.51.788 immediately; restrict network access to all AI/LLM web interfaces.

July 10, 2026 · Confidence: High

Read more →
Ransomware · HIGH · Technology, Manufacturing, Public Sector (EU-wide, BE/FR/ES)

Qilin most prolific ransomware group: 8 victims in 24 hours including Sintax (Belgium, technology) and a French municipality. EU organizations on high alert.

Qilin ransomware claimed 8 victims in 24 hours including Sintax (Belgium, technology) and a French municipality. EU organizations in technology, manufacturing, and public sector face elevated risk; validate backup isolation and review NIS2 notification readiness.

July 10, 2026 · Confidence: High

Read more →
CVE · HIGH · Enterprise, Government, Privileged Access Management (BeyondTrust Remote Support and PRA)

NCSC-2026-0223: BeyondTrust Remote Support and PRA vulnerable to pre-authentication access control bypass and unauthenticated DoS. Patch immediately.

NCSC-2026-0223 covers BeyondTrust Remote Support and PRA with a pre-authentication access control bypass (specific configuration required) and unauthenticated DoS. Immediate patching required; restrict management interface network access and audit logs for anomalous pre-auth activity.

July 10, 2026 · Confidence: High

Read more →
Trusted by leading organizations

What our customers say

All customer stories →

Ready to make your
security AI-proof?

Talk to one of our experts. No obligations, no sales pitch: an honest conversation about your situation.