The NetScaler zero-days raise a question that reaches beyond Citrix: when a national CSIRT warns some organisations before others, who decides who is worth protecting first?
Two NetScaler zero-days have Dutch hospitals and government taking their remote access offline, six years after the first Citrix-file. The patch is the easy part. The real question is why one appliance can hurt this much.
A response to the NCSC Community piece on ‘open source, unless’, and why one line about transparency needing a watcher deserves more scrutiny than it got.
The Odido breach did not end when the systems were patched. It continued wherever abandoned domains, forgotten mailflows, and expired infrastructure were still trusted.
The European Commission ran its infrastructure on AWS while writing sovereignty frameworks for everyone else. Now 350GB is gone. This was not a surprise.
Een waarschuwing voor organisaties: in de zomer neemt mentale vermoeidheid toe, waardoor security-risico’s stijgen, ondanks dat systemen operationeel blijven.
A decade of Dutch digital sovereignty surrendered through procurement. From the failed Rijkscloud to the CLOUD Act, and now a state secretary who confirms it in writing and presses on anyway.
Mobile authenticator vulnerabilities expose a fundamental truth. Securing the endpoint OS while leaving the phone untouched is security theater. Here is what actually works.