Eye Security Blog

What we see across European incidents. Threat analysis, case findings, and practical defence.

All Blog Posts

Log poisoning in AI agents: The OpenClaw case

For the full technical analysis, please visit the Eye Research website.AI assistants with deep system access are rapidly moving into production environments. Tools like OpenClaw connect to email, cloud platforms and local machines, and can take action on behalf of users. That level of autonomy changes the security model.

Cyber Incidents in Europe 2026: Identity-based Attacks and the Impact of MDR

Cyber incidents across Europe are accelerating. They are happening more often, unfolding more quickly, and causing greater business impact than in previous years. An analysis of 630 cyber incidents that Eye Security handled across the Benelux region and Germany over the past three years shows a consistent shift in how threat actors operate and where organisations remain vulnerable.

The State of Incident Response 2026: Insights from 630 Investigations

Eye Security analysed 630 anonymised cybersecurity incidents across Europe between January 2023 and November 2025, drawing insights into detection, dwell time, root causes, and operational outcomes. From ransomware to business email compromise, the incident data shows how threat actors exploit trust, time, and technology, and how Managed Detection and Response (MDR) changes the outcome.

From Helper To Risk Factor: Why AI Canvases Deserve Executive Attention

Eye Research demonstrated that a shared AI canvas can convincingly imitate legitimate business content, such as an HR survey or internal login page. When these canvases are distributed via email or messaging platforms, they appear trustworthy because we associate them with well-known AI service domains. And trust is the currency of modern attacks. Read more in the full technical writeup. 

AI Agents in Cybersecurity: What’s Real, What’s Hype, and What’s Next

Artificial intelligence is everywhere in cybersecurity conversations right now. From phishing emails that read flawlessly to automated reconnaissance at machine speed, AI is already reshaping how cyberattacks are launched and defended against. Yet alongside real progress comes real confusion. Headlines shift between promises of fully autonomous security operations centres and warnings of unstoppable AI-driven cybercrime.

The Cyber Threat Landscape 2026: Building Resilience, Acting Fast

Cyber defence is entering a race measured in minutes, not days. As we move into 2026, threat actors are faster and quieter than ever before. Breakout times have dropped below an hour, identity abuse has overtaken malware as the primary intrusion path, and AI is accelerating phishing, fraud, and reconnaissance at industrial scale. What once required specialist skills can now be bought, automated, and deployed by almost anyone.

Microsoft 365 AitM Phishing Protection: Free Browser Extension

Adversary-in-the-Middle (AitM) phishing is a rapidly growing threat that can bypass MFA and capture session tokens in real time. Even careful users and organisations with strong security policies are at risk. To help protect users, Eye Security has developed Microsoft AitM Phishing Block, a free browser extension for Chrome and Edge. Curious about the technical details? Read our technical blog on Microsoft AitM phishing block.

Insights from the SOC: Why Analysts Still Matter in the Age of AI

Every week, vendors announce new AI tools promising autonomous defence and detection pipelines that operate faster than any human team. For many mid-sized businesses, especially those under pressure to reduce costs and address talent shortages, these promises are tempting. If AI can classify threats, prioritise alerts, and even initiate containment, do we even still need human analysts?

Battling Shadow AI: A Practical Tool for CISOs

Generative AI is transforming how businesses operate. Tools such as ChatGPT, Copilot, and DeepSeek enable teams to move faster, automate tasks, and innovate in ways that were hard to imagine just a year ago. But with this innovation comes a new, largely invisible risk known as Shadow AI.This is why our research team at Eye Security invented a concept to turn prompt injection into a compliance and end-user awareness tool for security teams and CISO offices. 👉 Try out the prompt generator

Top Cyber Threats in Logistics and How to Defend Against Them

For decades, transport and logistics operators have focused primarily on physical security, guarding cargo, facilities, and vehicles, often underestimating the digital dimension of risk. That mindset is evolving. As operations become connected, the sector has emerged as a lucrative target for a wide spectrum of threat actors: from financially motivated cybercrime groups to politically driven hacktivists and state-sponsored attackers.Despite their differing motives, the outcomes tend to converge: disruption of operations, financial losses, reputational damage, erosion of public trust, and, in severe cases, impacts on critical infrastructure and safety. The shifting security paradigm in transport and logistics The ENISA Threat Landscape 2025 report (covering July 2024 – June 2025) confirms that the transport sector remains one of the EU’s top three cyber targets, accounting for 7.5% of all recorded incidents. Within the sector, air transport suffered the majority of attacks, representing 58.4% of cases, followed by logistics at 20.8%. This trend reflects continuity. In the previous reporting period (June 2023 – July 2024), transport accounted for 11% of global attacks, alongside public administration (19%) and finance (9%). Hacktivism Hacktivist activity continues to exert disproportionate pressure on the sector. In 2025, transport ranked among the top three sectors targeted, trailing public administration at 63.1% but ahead of finance at 11.7%. This pattern mirrors 2024, when the sector consistently attracted hacktivist attention. Leading threat actors, including Noname 057, Lockbit, Black Basta, and Cyber Dragon, dominated these campaigns, with Noname 057 responsible for the largest share. DDoS attacks were the primary method of disruption, accounting for 87.6% of transport-related hacktivist activity in 2025. Notably, NoName057(16) orchestrated 36.4% of these attacks, DarkStorm Team 15.4%, and Mysterious Team Bangladesh 6.2%. In 2024, DDoS attacks similarly drove targeted activity across sectors, with transport among the top three targets (21% of all DDoS incidents), alongside public administration (33%) and banking (12%). Cybercrime Cybercrime targeting the EU transport sector represented 8.4% of all recorded incidents, with ransomware comprising 83.9% of these cases and data breaches making up the remaining 16.1%. The sector’s top three ransomware strains in 2025 are Akira (12.9%), followed by INC Ransom and Cl0p, each accounting for 9.7% of incidents. The operational impact of these attacks remains significant. In 2024, 12% of all incidents reported under the NIS Directive with major consequences originated from the transport sector. Together, these trends highlight the sector’s vulnerability. Transport’s reliance on digital systems for logistics, scheduling, and operational coordination makes it an enduringly attractive target for both hacktivists and cybercriminals. The persistence of attacks, combined with their operational and economic impact, highlights the urgent need for continuous monitoring, proactive threat mitigation, and strategic collaboration to protect the EU’s transport infrastructure. Below, we break down the top threats and outline concise, actionable playbooks to detect, mitigate, and respond.