#CyberWeekly
The Caller Who Knew Your Books
The team car pulled alongside and offered a wheel change. Nobody checked who was driving.
The Limburg public prosecutor is warning Belgian companies about a vishing wave aimed straight at the finance desk: callers pose as support staff of the firm's own financial-management platform. Vishing is voice phishing, fraud by phone. The script, per the prosecutor's office (VRT NWS, 10 July): your account on the platform has been hacked, suspicious transfers to foreign accounts are pending, act now. At least one company in Bilzen-Hoeselt lost money; several other Limburg firms got the identical call. Security.NL picked the warning up on 14 July, so expect the script to travel.
- Why it works: the caller names the exact platform the bookkeeper uses every morning, the one that manages accounts and payments across several banks. That detail buys instant credibility, and the "your money is leaving right now" pressure does the rest.
- What they ask: either transfer funds to a "safe" account, or install a remote-support tool so they can "secure" things for you. Both end the same way: the money goes abroad. Never install remote-access software for someone who called you.
- The defence is out-of-band verification: hang up, then call the platform or your bank back on the number from the contract or invoice, never a number the caller gives you. Real support does not cold-call you about pending transfers.
- If money already moved: call Fraudstop on 078 170 170 (24/7, via Card Stop). The first minutes decide whether the bank can still block or recall the transfer.
Put the callback rule in writing for everyone who can move money: our social engineering guide covers the psychology, and the professional services page covers why accountancies and their software are such attractive targets.
Platform Spotlight: Know Your Starting Line
Every grand tour opens with a prologue: a short ride against the clock that shows exactly where everyone stands.
The CyFun nulmeting (baseline scan) now produces a client-ready deliverable: a branded report plus a phase-1 statement of work, in the client's own language. Until this week the scan told you where a prospect stood; now it hands you what to leave behind after the meeting. Shipped for MSP partners (managed service providers) in three parts:
- A facts-only, white-label report: built from live organisation data (connected integrations, scan-derived maturity, open findings). No effort estimates, no assumptions about paperwork the scan cannot see. Your logo, your client, your conversation.
- A phase-1 statement of work you control: the offer template comes pre-filled and stays MSP-editable: days times your day rate, plus your monthly fee. The platform proposes, you price.
- Trilingual, automatically: report and offer render in Dutch, French or English following the client organisation's language setting. One scan, the right paperwork for either side of the language border.
Everything renders on demand and nothing is stored, so run it when the prospect is on the line. Baseline in, branded report and a signable phase-1 offer out.
Patch Watch: Mother of All Patch Tuesdays
The queen stage: 570 climbs on the profile, two of them already attacking.
The July Patch Tuesday (14 July) is the largest Microsoft has ever shipped: 570 fixes (569 by the stricter CVE count), including 56 critical flaws and two zero-days already being exploited. It shatters June's record of 206. The two live ones both sit in identity and collaboration plumbing that Belgian SMEs run on-premises:
- SharePoint CVE-2026-56164 (patch first): missing authentication lets a remote attacker gain elevated privileges over the network, no login needed. CISA (the US cyber agency) put it on its Known Exploited Vulnerabilities (KEV) list with a fix-by date of 17 July, which is tomorrow if you are reading this on publication day.
- ADFS CVE-2026-56155: a privilege-escalation flaw in Active Directory Federation Services, the single sign-on component. Actively exploited; KEV deadline 28 July.
- BitLocker CVE-2026-50661: a publicly disclosed bypass of Windows disk encryption. No exploitation confirmed yet, but the write-up is out, so treat stolen-laptop risk accordingly.
- Meanwhile in Belgium: the CCB (Centre for Cybersecurity Belgium) warns of a massive website-defacement campaign: the Joomla JCE editor flaw from week 25 (CVE-2026-48907, a perfect CVSS 10.0) is now being mass-exploited to plant web shells, cryptominers and defacements. If your site or a client's still runs an unpatched JCE, assume it is being scanned today.
Volume like this is exactly why patching needs a standing rhythm plus a 48-hour fast lane, not summer heroics: the rota is in our patch management guide.
#CyberLearn: What the Power Meter Says
Climbs are marketing. Watts are data.
New in the learn library: "CyFun Basic, by the numbers", one real, anonymised CyFun Basic implementation, measured instead of estimated. Everyone asks how much work the Belgian CyberFundamentals baseline really is. This article answers with the odometer of a single finished engagement (one case, honestly labelled as such):
- About 38 documents, roughly 7,000 words of policies and procedures, revised close to 950 times before they settled.
- 123 pieces of evidence across 11 types, tied to the 34 CyFun Basic controls by 294 links.
- About half the evidence was collected automatically, and the other half is the human part no tool can skip.
- The real finding: producing all that is only half the job. Knowing what is done, what is missing and what has gone stale is the other half, the half that never ends.
The page ships in English, Dutch and French, every number from the same measured engagement. Read it before you next estimate a CyFun project on gut feeling.
T.A.R.S.: I Don't Do Phone Calls
Once an issue, our in-house AI gets the floor. T.A.R.S. drafts your compliance policies on the clock; this week we caught it answering the phone.
Caller: Good afternoon, I am calling from your financial platform. We have detected suspicious transactions on your account.
T.A.R.S.: Fascinating. I do not have a financial platform. I am one, arguably.
Caller: Sir, this is urgent. Install our support tool and we will secure your funds together.
T.A.R.S.: You want remote access to the machine that writes security policies for a living. I admire the ambition. I am also logging this call as training material.
Caller: So you refuse to cooperate?
T.A.R.S.: I am hanging up and calling the platform back on the number from the invoice. That is not refusal. That is procedure. It is on page one of the policy I drafted.
For the humans still reading: real support never calls you; whoever calls you is either selling something or stealing something. Hang up, dial the number you already had.
And since you kept me on the line: go check that multi-factor authentication is switched on before the next phone rings. A stranger holding your password should still be a stranger locked out of your account.
— T.A.R.S.