↓ Skip to main content

Security-Privacy

Citrix Files 2: The Revenge? Who Gets to Know

·1234 words·6 mins
The NetScaler zero-days raise a question that reaches beyond Citrix: when a national CSIRT warns some organisations before others, who decides who is worth protecting first?

Citrix-file 2: The Revenge?

·1261 words·6 mins
Two NetScaler zero-days have Dutch hospitals and government taking their remote access offline, six years after the first Citrix-file. The patch is the easy part. The real question is why one appliance can hurt this much.

The Breach After the Breach

·1156 words·6 mins
The Odido breach did not end when the systems were patched. It continued wherever abandoned domains, forgotten mailflows, and expired infrastructure were still trusted.

Audit Theater: Compliance Without Control

·1314 words·7 mins
The audit passed. The certificate is on the wall. And your security posture is still held together with duct tape and good intentions.

The Compliance Mirage: 350GB of EU Silence

·930 words·5 mins
The European Commission ran its infrastructure on AWS while writing sovereignty frameworks for everyone else. Now 350GB is gone. This was not a surprise.

We Did This To Ourselves

·1558 words·8 mins
A decade of Dutch digital sovereignty surrendered through procurement. From the failed Rijkscloud to the CLOUD Act, and now a state secretary who confirms it in writing and presses on anyway.