Our digital defense is crumbling: why our CISOs are burning out
Our digital defense is crumbling, not because of attackers but because of the pressure on our CISOs. Five developments from research and practice.
Insights on cybersecurity trends, threat intelligence, compliance updates, and technical deep dives from the DEFION team.
Our digital defense is crumbling, not because of attackers but because of the pressure on our CISOs. Five developments from research and practice.
From our pentests and cloud security reviews: misconfigurations in Active Directory and Microsoft 365 are still the easiest way in for attackers.
DEFION analyzes a Magecart skimmer that stores its code in smart contracts on a public blockchain and delivers payloads via encrypted WebRTC, invisible to classic defenses.
DEFION and NCSC-NL warn of a growing trend: attackers increasingly route their traffic through residential proxy networks to evade detection. How they work, how to detect them, and how to reduce your risk.
CVE-2026-35273 is a CVSS 9.8 pre-authentication RCE in Oracle PeopleSoft PeopleTools, exploited as a zero-day for two weeks by ShinyHunters. Patching is step two. Here is what to check first.
Hundreds of publicly accessible AI agent dashboards found, sometimes protected only by a four-digit PIN. Research into agentic AI security risks by DEFION Offensive Security Specialist Jean de Cuba.
Threat actors increasingly use OSINT, public metadata, and psychological pressure to fabricate convincing cyber breach claims without proving compromise. Learn how these extortion tactics work.
A real-world IR case study: an attacker used an intern account with Domain Admin rights to compromise 26 systems, exfiltrate 175 GB of sensitive data, and nearly deploy ransomware across an educational institution.
A pentest (penetration test) is a controlled cyberattack on your own systems. Learn what a pentest is, when you need one, and what it costs.
NIS2 is the EU cybersecurity directive applying across Europe. Learn which sectors are covered, what obligations apply, and how to prepare your organization.
MDR is an outsourced 24/7 cybersecurity monitoring service. Learn what MDR is, how it works, and how it differs from SIEM, SOC, and MSSP.
Step-by-step action plan for the first 24 hours of a cyber incident. Learn what to do, what to avoid, and when to notify regulators.
Our experts respond personally to your message.
Thank you for reaching out. We will get back to you as soon as possible.
Call immediately during a security incident. Our DFIR experts are available around the clock.
DEFION Netherlands
+31 (0)88 733 13 38
DEFION Spain
+34 932 546 277
We use cookies to analyze traffic and improve your experience. Essential cookies are always active.
®