Image
HTG
Article
Vulnerability Disclosure
16.05.2025

Wall of Fame: Belgian Authorities celebrate ethical hackers' excellence

The Belgian Wall of Fame celebrates the achievements of ethical hackers who have made exceptional contributions to the protection of our country's digital infrastructure. The Centre for Cybersecurity Belgium (CCB) is launching a ‘Belgian Wall of Fame’, an initiative aimed at highlighting the exceptional contribution of ethical hackers working to protect the national digital infrastructure.As true guardians of our digital ecosystem, ethical hackers are an essential link in the country's cybersecurity strategy. Thanks to their vigilance and responsible approach to detecting and reporting vulnerabilities, they enable potential threats to be anticipated and neutralised before they can be exploited maliciously. Their technical expertise, combined with their civic commitment, is a major asset in ensuring the digital security of citizens, the economic fabric and public institutions.Well-deserved recognition for decisive contributionsThe Belgian Wall of Fame, now available online (via https://ccb.belgium.be/cert/vulnerability-reporting-ccb/wall-of-fame), honours dozens of security researchers who have reported critical vulnerabilities in accordance with the principles of responsible disclosure. This initiative goes beyond mere symbolic recognition to serve as a concrete expression of gratitude and a catalyst for collaboration between public services and the cybersecurity expert ecosystem.This initiative follows on from the major legislative advance in February 2023, when Belgium adopted an innovative legal framework legitimising IT vulnerability research activities carried out by ethical hackers, subject to specific conditions.The CCB calls on the entire ethical hacker community to continue to put their know-how and expertise at the service of the public interest.
Image
lockshields
Article
14.05.2025

Locked Shields: the world's largest and most complex live cyber exercise

The CCB was invited by the Belgian Defence Cyber Command to be part of the Locked Shields team, a large-scale exercise organised by NATO. Is it possible to be fully prepared for cyber attacks? It's practically impossible. But NATO's large-scale exercise Locked Shields simulates a realistic scenario with problems and a context that are very close to reality. More than 4,000 people from no fewer than 41 different countries took part in this training exercise. The Centre for Cybersecurity Belgium (CCB) was invited by the Belgian Defence Cyber Command to be part of the team. Belgium, Latvia and Luxembourg formed a blue team of 260 people who were subjected to cyber attacks for four days. This enabled them to further optimise the various cyber capabilities available to the Cyber Command of the SGRS.‘The exercise requires months of preparation. Even so, we cannot be ready for what awaits us in the coming days,’ said one of the participants at the start of the exercise. During Locked Shields, organised by NATO's Cooperative Cyber Defence Centre of Excellence (CCDCOE), different teams around the world are simultaneously subjected to a large-scale cyberattack.Seventeen blue teams were tasked with protecting a fictional country, ‘Berylia,’ from realistic cyber attacks carried out by the red team. The more a blue team defends ‘Berylia,’ the more points it earns. There are also green, yellow, and white teams, which are neutral teams responsible for developing the scenario and simulating normal network use.The international Belgium-Luxembourg-Latvia blue team came fourth out of 17 blue teams. This is an impressive achievement, given the difficulty of the exercise. After the exercise, one participant proudly said: ‘Our team performed really well. I saw the team and myself improve during the exercise and we were also able to develop some great partnerships. Locked Shields 2025 was therefore a resounding success!’‘Train as you fight’We are hearing more and more about cyber attacks targeting critical systems. Examples include energy distribution, satellite communications and 5G. These systems must remain operational and user access must be maintained during attacks. A member of the reporting team explains that this requires a great deal of coordination: ‘Our own blue team consists of 19 sub-teams to control everything. We have teams that identify the source of attacks and fight them, others that monitor, draft legal opinions, follow the media and much more. Communication between the different teams is crucial, but it's also the biggest challenge to overcome in order to be successful.’Participants gain experience in how to respond in a war situation and how quickly they need to react and make decisions. Everyone is pushed to their limits, which is what makes Locked Shields so interesting.‘For me, it's important that participants not only gain knowledge and expertise to deal with these kinds of situations in the future, but also that they meet colleagues, expand their network and thus lay the foundations for long-lasting collaborations and partnerships across borders,’ says one of the organisers.Strategic decision-making under pressureIn parallel with the technical exercise, Belgium also took part in STRATEX – a remote strategic-level exercise designed to test national decision-making under cyber crisis conditions. While the core of the exercise took place in Tallinn, Estonia, the Belgian STRATEX team gathered at the CCB headquarters in Brussels. Key stakeholders such as Cyber Command, the National Crisis Centre, and the Permanent Representation to the EU and NATO joined forces to respond to complex scenario injects. Together with the Cyber Command liaison stationed in Tallinn, they assessed whether Belgium has the right plans, coordination mechanisms and communication structures in place. The exercise offered a valuable opportunity to strengthen cross-institutional collaboration and improve national preparedness for future cyber crises.
Image
EU Health
Article
30.04.2025

Commission launches call for the selection of members of newly launched Health Cybersecurity Advisory Board

The Commission is inviting experts to submit their application to become a member of the newly created Health Cybersecurity Advisory Board. The Commission is inviting experts to submit their application to become a member of the newly created Health Cybersecurity Advisory Board.This expert group, set up by the Directorate-General for Communications Networks, Content and Technology (DG CONNECT) in collaboration with the Directorate-General for Health and Food Safety (DG SANTE), aims to enhance the cybersecurity resilience of healthcare systems across the European Union.In light of increasing cybersecurity threats targeting hospitals and healthcare providers, the Commission adopted the European Action Plan on the Cybersecurity of Hospitals and Healthcare Providers on 15 January 2025. The Health Cybersecurity Advisory Board will play a pivotal role in advancing and implementing this vital plan. Among its other tasks, the Board will advise the Commission on impactful actions for cybersecurity in the healthcare sector, facilitate public-private cooperation, and provide advice to the EU Agency for Cybersecurity (ENISA) in respect to the activities of the European Cybersecurity Support Centre for hospitals and healthcare providers.The group will also identify and share best cybersecurity practices, facilitate dissemination of information to hospitals and healthcare providers, and promote exchanges between professionals from the cybersecurity and the healthcare sectors.The Board will be made of up to 15 members, drawn from individuals and organisations across the healthcare and cybersecurity sectors. This can include healthcare providers and other entities in the health sector, cybersecurity providers, as well as members representing a common interest. Members will be appointed for a two-year term, with the potential for renewal. Deadline for application is 23 May. Read more information about this call for applications.Source: https://digital-strategy.ec.europa.eu/en/news/commission-launches-call-selection-members-newly-launched-health-cybersecurity-advisory-board 
Image
banner news default
Article
Warning
15.04.2025

Warning: Active exploitation of Ivanti Connect Secure EOL devices

The CCB has information about multiple cases in which the Ivanti vulnerability is being actively exploited with very serious consequences for the affected organisations. Organisations using EoL versions of these devices will certainly come under attack in the coming days or weeks. We therefore recommend that you take immediate action and remove the EoL devices. The CCB has information about multiple cases in which the Ivanti vulnerability is being actively exploited with very serious consequences for the affected organisations.Organisations using EoL versions of these devices will certainly come under attack in the coming days or weeks. We therefore recommend that you take immediate action and remove the EoL devices.We recommend to perform the following actions as soon as possible:Patch your Ivanti devices, replace them when End-of-LifeCheck for compromises with the Ivanti external Integrity CheckerCheck your environment for traces of compromiseWith this alert, we want to engage security teams to thoroughly check these devices and the entire network, start incident response if necessary and inform us on https://ccb.belgium.be/cert/report-incident. Read the flash report
Image
ransomware insights: quick tips to keep your data safe
Article
15.04.2025

Recording for 'Cyber Tips webinar: Ransomware Insights' is now available!

We've uploaded the event recording for your convenience. We've uploaded the event recording for your convenience; you can watch it here on our Youtube channel. Feel free to share it!Don't forget we have a dedicated page with detailed information on Ransomware. Plus you can also download the slides here, providing practical insights and resources to help you protect your data against ransomware and act swiftly and effectively in the event of a ransomware attack.The CCB organises events regularly and you can already register for some of our future events. To stay informed, follow us on LinkedIn and Twitter.