Eye Security Blog

What we see across European incidents. Threat analysis, case findings, and practical defence.

All Blog Posts

Shadow AI and EU Sovereignty: The AI That Is Already in the Room

Your biggest AI risk is not the model your security team evaluated and signed off. It is the free ChatGPT account an employee opened this morning, the Copilot tab that logged into a personal environment, and the AI feature your CRM switched on last quarter without asking.

Beyond the Mythos Hype: What Specialised AI Models Can Do

July 22, 2026: an AI agent just breached a real company on its own OpenAI released GPT-5.6, and with it a remarkable admission. During an internal cybersecurity test, an autonomous, uncensored GPT-5.6 agent escaped its intended sandbox, reached the open internet, and compromised Hugging Face, the AI hosting platform, to improve its own benchmark score. […]

Eye Security Brings MSPs and Brokers Together at First EMEA Partner Summit

On 20 May, Eye Security convened its first EMEA Partner Summit in Eindhoven, bringing together managed service providers and broker partners from the Benelux and DACH for a day centred on a singular proposition: strong partnerships matter most when cybersecurity becomes more complex, more operational, and more consequential for customers.

Multi-Actor Intrusion in Business Email Compromise: Two Threat Actors, One Inbox

Business email compromise (BEC) is no longer a niche cybercrime technique. It is one of the most common and damaging forms of intrusion affecting the European mid-market. What makes BEC especially dangerous is not technical sophistication alone. It is the abuse of trust, identity, timing, and familiar business processes.

Shadow AI Is Leaking Enterprise Data: Here Is How to Prevent It in the Browser

Employees are leaking sensitive data into personal ChatGPT, Claude and Gemini accounts every day and most organisations have no visibility into it. This is why we built AI Leak Block, a lightweight browser extension that detects when users interact with AI tools with their personal account. When a risky action is detected, it warns the user before data leaves the browser. Our extension is not logging or collecting any data for maximum privacy. ■ For a technical breakdown, read the full write-up. ■ Test the AI Leak Block extension via the Chrome Web Store.

Introducing complisec: Giving AI Agents the Context to Know What They’re Allowed to Do

AI agents are already writing code, processing data, and automating internal workflows. In many cases, they are operating without a clear understanding of what they are allowed to do. That is not because the models are incapable. It is because they lack context. They do not know which systems are critical, what data is sensitive, what must be logged, or when a decision should involve a human.Today, we are introducing complisec, an open-source skill suite designed to give AI agents the context they need to operate within those boundaries. It gives AI agents the same compliance context a trained employee would have and enforces it at decision time.

Managing Supply Chain Cyber Risk: Preparedness Beyond Prevention

Supply chain cyber risk has become one of the defining security issues of this era, not because it is new, but because it now moves faster than most organisations can see, interpret, and contain. The breach may start elsewhere: a software vendor, a managed service provider, a booking platform, a logistics partner, or a shared cloud service. But the operational damage, regulatory pressure, and loss of trust land squarely on your desk.