Connect with us

Cybersecurity

‘We’re Losing Badly to Hackers’: EU Cyber Chief Sounds Alarm on Europe’s Digital Defences

Published

on

Europe is struggling to keep up with the scale and speed of modern cyber threats, and its current approach to digital security is no longer sufficient, the head of the European Union’s cybersecurity agency has warned. As cyberattacks grow more frequent and sophisticated, the gap between attackers and defenders is widening, leaving vital systems across the continent increasingly vulnerable.

Speaking from Brussels, the executive director of the EU Agency for Cybersecurity (ENISA) cautioned that Europe is “falling behind” hostile actors in cyberspace. He stressed that without a fundamental shift in strategy, the bloc risks losing control over the security of its digital infrastructure.

Rising Attacks, Real-World Consequences

The warning comes after a string of high-impact cyber incidents across Europe in recent years. Attacks have disrupted airport operations, interfered with democratic processes, and forced hospitals to suspend critical services, demonstrating that cyber threats now pose direct risks to public safety and economic stability.

Security analysts have recently highlighted an attempted breach of Poland’s power grid, reportedly linked to Russian actors. Meanwhile, Germany’s central bank has disclosed that it faces thousands of cyberattacks every minute, illustrating the relentless pressure on Europe’s financial institutions and government networks.

Cybersecurity Lagging Behind Geopolitical Reality

These challenges are unfolding amid a tense geopolitical environment. Europe is dealing with war on its eastern border, China’s expanding influence over global technology supply chains, and uncertainty surrounding long-term security cooperation with the United States. In response, many EU member states have committed to higher defence spending, while Brussels has increasingly prioritised strategic autonomy.

However, the ENISA chief warned that strengthening conventional defence without matching investment in cybersecurity leaves a dangerous blind spot. Cyber resilience, he argued, must be treated as a core element of Europe’s overall security architecture, not a secondary concern.

Push to Expand ENISA Falls Short

The comments follow a European Commission proposal to revise the EU’s Cybersecurity Act, which would give ENISA greater authority, a larger workforce, and a higher operational budget. Based in Athens, the agency currently employs roughly 150 staff, with modest expansion planned under the new proposal.

While welcoming the initiative, the agency’s leadership said the measures are insufficient given the scale of the threat. Comparisons were drawn with other EU bodies such as Europol and the border agency Frontex, which employ more than 1,400 and 2,500 personnel respectively and continue to receive substantial funding increases.

According to the ENISA chief, a simple upgrade will not close the gap. He argued that at minimum, the agency’s capacity should be doubled and supported by the creation of a robust, EU-level cyber infrastructure to counter years of underinvestment.

Threats Evolving Faster Than Defences

The pace of change in the cyber threat landscape has been dramatic. When the current ENISA leadership took office in 2019, around 17,000 software vulnerabilities were identified globally each year. By 2025, that number had climbed beyond 41,000.

More alarming is how quickly attackers now exploit these flaws. What once took weeks or months can now happen within a single day. The growing use of artificial intelligence by malicious actors has further accelerated their ability to detect, weaponise, and deploy attacks at scale.

Europe’s Dependence on External Cyber Infrastructure

Another concern raised was Europe’s long-standing reliance on US-based systems for managing and cataloguing software vulnerabilities. While these tools benefit European governments and companies, much of the responsibility and cost of maintaining them has fallen on American institutions.

The ENISA chief argued that Europe must assume a greater share of responsibility within the global cybersecurity ecosystem. In recent steps toward that goal, ENISA has begun operating its own vulnerability database and has taken on a more prominent technical role internationally.

A Narrow Window for Reform

Cybersecurity specialists warn that without rapid increases in funding, staffing, and coordination, critical sectors such as energy, healthcare, transportation, and finance will face escalating risks. As digital threats continue to evolve faster than defensive systems, the pressure on European institutions is only expected to grow.

The message from Europe’s top cyber official is clear: incremental changes are no longer enough. A comprehensive overhaul of the EU’s cybersecurity strategy is needed if the bloc hopes to defend itself effectively in an increasingly hostile digital world.

Continue Reading
Advertisement
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Cybersecurity

Hyderabad Cybercrime Police Summon Meta Over AI Deepfake Investment Scams

Published

on

By

Hyderabad Cybercrime Police have issued a notice to Meta seeking details about how its platforms detect and remove artificial intelligence-generated deepfake videos being used to promote fraudulent investment schemes.

The investigation follows a growing number of complaints from victims who say they were tricked by manipulated videos featuring well-known public figures allegedly endorsing fake trading platforms and investment opportunities. Authorities are examining how such content spreads across Facebook, WhatsApp, and Instagram and whether additional safeguards are needed to prevent financial fraud.

Fake Celebrity Videos Used to Lure Investors

Investigators have identified multiple cases where deepfake videos allegedly showed prominent personalities appearing to support fake financial schemes.

The probe includes manipulated content featuring Union Finance Minister Nirmala Sitharaman, actor Amitabh Bachchan, and Hyderabad MP Asaduddin Owaisi. Police said these videos were circulated online to create false credibility and encourage users to invest money through fraudulent platforms.

Owaisi had earlier approached Hyderabad Police after his identity was allegedly misused in a fake investment promotion. Similar deepfake-based scams have also targeted other public figures, including business leaders and celebrities, as fraudsters increasingly use trusted faces and voices to convince victims.

Fraud Pattern Follows a Common Method

Cybercrime investigators said many investment scams follow a similar approach. Criminals first use deepfake videos or fake advertisements to attract victims, then move conversations to private messaging platforms such as WhatsApp or Telegram.

Victims are often shown fake trading dashboards displaying artificial profits. When they attempt to withdraw funds, scammers demand additional payments in the form of taxes, processing charges, or verification fees.

Authorities have warned that the realistic appearance of AI-generated videos makes these scams more difficult for ordinary users to identify.

Meta Asked to Explain Detection Measures

A Meta representative has already appeared before investigators, who presented details of cases involving significant financial losses. Police have now requested technical experts from the company to explain the systems used to identify, monitor, and remove AI-generated fraudulent content.

The investigation reflects a broader effort by Telangana cybercrime authorities to examine the responsibilities of major technology platforms in preventing online fraud.

Officials are also reviewing whether social media companies and digital platforms are taking sufficient preventive measures rather than responding only after victims report losses.

Growing Pressure on Technology Platforms

The action against Meta follows similar scrutiny of other technology companies. In a separate investigation, Cyberabad Police questioned processes related to fraudulent stock-trading applications that allegedly caused financial losses after appearing on an app marketplace.

Together, these cases indicate a stronger focus by law enforcement agencies on the role of digital platforms in enabling cybercrime through advertisements, applications, and user-generated content.

Authorities are also examining the impact of updated Indian technology regulations that increase obligations for online platforms regarding synthetic media, harmful content detection, and user safety.

Experts Warn of Rising AI Fraud Threat

Cybersecurity experts have described AI-generated deepfakes as one of the fastest-growing threats in the online fraud landscape.

Experts warn that criminals can now create convincing videos and voice recordings of trusted individuals, making victims more likely to believe false investment claims.

Authorities have advised users to verify investment opportunities through official sources, avoid transferring money based solely on online promotions, and remain cautious of offers promising unusually high returns.

Investigation Continues

Hyderabad Cybercrime Police said the investigation will focus not only on identifying scam operators but also on understanding how fraudulent content reaches large audiences.

Officials believe cooperation between law enforcement agencies and major technology companies will be essential to reducing organized cyber fraud and improving digital safety for users.

Continue Reading

Cybersecurity

AI-Powered Cyber Threats Put India’s Financial Sector Under Growing Pressure, Report Warns

Published

on

By

New security assessment highlights deepfakes, identity attacks, supply-chain risks and weaknesses beyond traditional compliance systems

India’s banking, financial services and insurance (BFSI) sector is facing a rapidly changing cyber threat environment as attackers increasingly use artificial intelligence, deepfake technology, identity manipulation and advanced digital techniques to target financial systems.

A new Digital Threat Report 2025-26 developed by SISA, CERT-In and CSIRT-Fin warns that cyber risks are evolving faster than many organisations can strengthen their defences. The report highlights that modern attacks are no longer limited to stealing information but are increasingly focused on disrupting transactions, compromising trust and exploiting digital infrastructure.

The assessment notes that several cyber trends predicted in the previous edition of the report have already become widespread, showing that the time between emerging threats and real-world attacks is becoming significantly shorter.

Deepfakes and AI Increase Sophistication of Financial Fraud

Artificial intelligence has become a major factor behind the growth of sophisticated cyber fraud campaigns. The report identifies AI-driven impersonation, deepfake videos, automated phishing and advanced social engineering as key challenges for financial institutions.

Criminal groups are increasingly using realistic fake identities, manipulated communications and AI-generated content to deceive employees and customers. Traditional verification methods based only on visual or voice recognition are becoming less reliable as attackers improve their ability to imitate trusted individuals.

The report also highlights rising risks from business email compromise, credential theft and session hijacking. Attackers are using stolen access details and legitimate user sessions to bypass security measures instead of directly breaking authentication systems.

Cyber incidents affecting India’s BFSI sector are estimated to be significantly higher than the global average, with reported incidents increasing substantially in recent years. The report stresses that organisations must focus on analysing user behaviour, device activity and transaction patterns rather than relying only on passwords or authentication checks.

Identity Protection Becomes a Critical Security Challenge

Cybercriminals are increasingly targeting digital identities after successful login attempts. The report warns that attackers are focusing on session tokens, application programming interface (API) keys, service accounts and cloud-based permissions.

In these situations, security systems may not detect a traditional authentication failure because attackers are operating through valid sessions or stolen credentials. Financial institutions are therefore being urged to strengthen identity monitoring and continuously review access privileges.

The report recommends improved management of non-human identities, stronger credential protection and better visibility into digital activity across applications and cloud environments.

Compliance Alone Cannot Guarantee Cyber Resilience

The report highlights a growing gap between meeting regulatory requirements and achieving real-world cybersecurity readiness.

While compliance frameworks help organisations establish security standards, they may not always reveal weaknesses that appear during active attacks. The report identifies issues such as outdated security practices, incomplete monitoring and gaps between designed controls and their actual operation.

For example, encryption may protect stored information but may not secure data while it is being processed. Multi-factor authentication can confirm identity but may not stop attackers who have already gained access through stolen sessions.

The report advises financial organisations to treat compliance as a starting point rather than a complete security solution. Continuous testing, threat simulations, behavioural monitoring and regular security reviews are recommended to strengthen resilience.

Business Logic Attacks and Hidden Threats Expand Risk

Modern attackers are increasingly exploiting weaknesses in how financial systems operate rather than simply attacking technical vulnerabilities.

The report warns that payment systems, transaction limits and verification workflows can be manipulated through unusual sequences of legitimate actions. Attackers may abuse authorised functions in ways that developers never intended, making such activities difficult to detect.

It also highlights threats from fileless malware, encrypted communication channels and incomplete monitoring systems. These techniques can allow attackers to remain hidden while moving through networks or extracting sensitive information.

Report Calls for Continuous Cyber Defence Strategy

The assessment outlines several major security challenges expected to shape the future threat landscape, including AI-powered fraud, identity compromise, payment manipulation, supply-chain attacks and risks affecting critical financial infrastructure.

To address these challenges, the report recommends an 18-month security improvement roadmap focused on strengthening basic protections, expanding monitoring capabilities and redesigning security architecture.

The report concludes that cybersecurity must become an ongoing business priority for financial organisations. In an environment where cyberattacks can scale rapidly through automation and AI, periodic security checks are no longer enough. Continuous protection, testing and adaptation will be essential to maintaining trust and stability in the financial sector.

Continue Reading

Cybersecurity

Dell BIOS Flaw Lets Hackers Recover Admin Passwords Within Seconds

Published

on

By

Firmware vulnerability allows rapid password recovery on affected Dell devices, raising concerns over enterprise hardware security

A newly disclosed security vulnerability in the BIOS firmware of several Dell devices could allow attackers to recover administrator and user BIOS passwords within seconds, according to cybersecurity researchers.

The flaw, identified as CVE-2026-40639 and documented in Dell’s security advisory DSA-2026-197, is linked to an insecure password storage method inside certain firmware components. Rather than exploiting weak passwords, attackers can take advantage of how BIOS credentials are encrypted and stored.

Although exploitation generally requires physical access to the affected device or low-level system access, successful attacks could bypass important firmware security protections that help secure the boot process.

Faulty Encryption Method Exposed BIOS Credentials

Researchers found that some Dell systems stored BIOS passwords using a weak repeating-key XOR encryption method instead of a stronger cryptographic protection mechanism.

The affected passwords are stored in the Dell Variable (DVAR) section of the SPI flash memory, where firmware settings are maintained. According to researchers, weaknesses in the encryption design allow sensitive key information to be recovered from stored password data.

The problem is particularly serious for shorter passwords because unused storage space in the encrypted password field can reveal portions of the encryption key. This enables attackers to recover passwords directly instead of attempting traditional password-cracking methods.

Even longer passwords may remain vulnerable because the system’s key-generation process relies on limited device-specific information, reducing the complexity required for recovery.

Researchers Identify Affected Dell Platforms

The vulnerability was discovered by security researchers Craig S. Blackie of MDSec and Darren McDonald of AmberWolf during an investigation into Dell UEFI firmware.

Their analysis identified issues in the SystemPwSmm firmware component, which is used across multiple Dell client systems. Testing confirmed exposure on devices including:

  • Dell Latitude E7250
  • Dell Latitude 7490
  • Dell XPS 15 9560
  • Dell Wyse 5070 thin client

Researchers noted that newer Dell platforms using the Security Information Vault Block design with SHA-256-based protection were not affected during testing.

The difference highlights that Dell has already implemented stronger firmware security methods on newer hardware, although some older systems remain dependent on the vulnerable design.

Attack Requires Access, But Impact Could Be Significant

The vulnerability is not considered a remote attack because hackers typically need physical access to a device or the ability to obtain a firmware image from the system.

However, once attackers gain access, recovering BIOS passwords can reportedly be performed without user interaction or authentication. This creates risks for corporate laptops, shared devices and systems used in environments where physical security cannot always be guaranteed.

BIOS passwords often protect settings related to Secure Boot, boot order changes and other pre-operating system controls. If compromised, attackers could potentially weaken security protections or interfere with systems protected by disk encryption technologies.

Security experts warn that firmware-level weaknesses are particularly dangerous because they operate beneath the operating system and can affect multiple layers of device security.

Dell Releases Updates and Advises Security Measures

The vulnerability was privately reported to Dell in March 2026. After reviewing the findings, Dell published its security advisory and began releasing firmware updates for affected product lines.

Initial updates covered several platforms, including Precision systems, Rugged Latitude devices, Embedded PCs and Edge Gateway products. Additional fixes for other affected models were expected as part of Dell’s broader remediation effort.

Continue Reading

Trending

Copyright © 2022 420 Reports Marijuana News & Information Website | Reefer News | Cannabis News