All Press

All Press Posts

Eye Security and The S-Unit Partner to Bridge the Gap Between Detection and Offensive Security

The Hague, April 7, 2026 – Eye Security, a European leader in 24/7 threat detection and incident response, today announced a strategic partnership with The S-Unit, a Netherlands-based specialist in offensive security, delivering penetration testing and red teamings to simulate advanced threat actors.

Dutch Researcher Ranked #1 on Microsoft’s Global Security Leaderboard

The Hague, Netherlands — 6th of January 2026 — Microsoft today announced that Vaisha Bernard, Chief Hacker at Dutch based Eye Security, has been ranked #1 worldwide on the Microsoft Security Response Center (MSRC) Security Researcher Leaderboard for Q4 2025, becoming the first researcher from the Netherlands to ever reach the top position.The MSRC leaderboard recognizes security researchers who responsibly disclose impactful vulnerabilities across Microsoft’s global technology stack. Bernard secured first place after submitting 52 critical and important vulnerabilities in a single quarter, contributing directly to the security of platforms used by millions of organizations worldwide.What makes the achievement exceptional is not just the ranking itself, but the path to get there. After years of methodical research, persistence, and deep technical work, Bernard’s first-place finish breaks a long-standing trend: over the past four years, the leaderboard has been dominated by researchers from China, with only a small number of first-place rankings attributed to the United States, India, and Serbia.

Dutch cybersecurity firm Eye Security turns AI attack method into protection tool

The Hague, The Netherlands, October 28th 2025 - Dutch cybersecurity company Eye Security has turned one of AI’s most discussed vulnerability into a defense mechanism. The company’s research team developed Prompt Injection for Good, a creative new concept to use prompt injection (a technique normally used by attackers), to protect sensitive data from leaving corporate environments.

SharePoint Attacks: Eye Security Publishes Victim Analysis of SharePoint Exploitation

The Hague, July 29 - European cybersecurity company Eye Security has released new victim data from the widespread exploitation of the recent Microsoft SharePoint vulnerability, offering one of the clearest windows yet into how the attacks unfolded and who was impacted.Based on a scan of over 27,000 SharePoint servers between July 18 and July 23, Eye Security confirmed 396 compromised systems across 145 unique organisations in 41 countries. Among these, the government sector accounted for 30% of confirmed infections and the education sector for another 13% worldwide - strongly suggesting targeted exploitation of entities typically pursued in intelligence-led operations.“From the data, it’s clear this wasn’t a random or opportunistic campaign. The attackers knew exactly what they were looking for,” said Lodi Hensen, VP of Security Operations at Eye Security.

Eye Security Detects Large-Scale Exploitation of Critical Microsoft SharePoint Vulnerability

Editor's Note: The vulnerabilities exploited during the attacks on July 17–19, 2025 seem not to be CVE-2025-53770/53771. Rather, this is the original ToolShell chain: CVE-2025-49706 (auth bypass) and CVE-2025-49704 (deserialisation RCE).The vulnerabilities we identified on July 18, 2025 seems to already been disclosed and patched on July 8, 2025, meaning this was an N-day exploitation, not a zero-day. Please find more details on our Tech Blog that is actively being maintained by our Research Team.  On Friday, July 25 at 11:00, our experts shared in a webinar how they discovered this vulnerability, what the impact is, and how organisations can protect themselves. Sign up here to watch the replay.  The Hague, July 21, 2025 – Last Friday, Eye Security’s research team, Eye Research, was the first to identify a critical vulnerability in Microsoft SharePoint, just as attackers began exploiting it at scale. Their findings have since been acknowledged globally, with organisations across sectors relying on Eye Security’s early warnings and support to recover within hours. The flaw allows attackers to take full control of vulnerable servers, giving them unrestricted access to sensitive business data, the ability to steal cryptographic material, install backdoors and move laterally through corporate networks. In many cases, this could result in data theft, ransomware attacks and prolonged breaches that remain undetected even after updates. Mass Exploitation Uncovered by Eye Research On the evening of July 18, Eye Research detected unusual activity on a customer’s on-premises SharePoint server. A malicious file had been uploaded, enabling exfiltration of cryptographic keys. These keys can be abused to bypass authentication and maintain persistent access to SharePoint environments, even after standard patching. During the triage, Eye Security learned it had stumbled upon a SharePoint 0-day used in the wild.Following the discovery, Eye Research scanned over 8,000 publicly accessible SharePoint servers worldwide. The team identified dozens of compromised systems, confirming that attackers are conducting a coordinated mass exploitation campaign. Eye Security has since issued responsible disclosures to affected organizations and national CERTs, while working closely with partners in the global cybersecurity community to help mitigate the threat.“This is not a theoretical risk. Attackers are already leveraging this vulnerability to deploy backdoors and steal sensitive data from SharePoint servers,” Eye Security said. “The potential consequences extend beyond SharePoint, as these servers often connect to core business systems such as email and file storage.” Microsoft Confirms Active Exploitation Microsoft has acknowledged the severity of the issue, named it a critical 0-day with identifier CVE-2025-53770. The company has published interim guidance to help organizations secure their environments. Eye Security urges organizations running on-premises SharePoint to act without delay. Immediate assessment for compromise, isolation of affected servers and rotation of potentially exposed cryptographic keys are critical to containing the threat. Organizations are advised to engage experienced incident response teams to investigate and remediate breaches. Rapid Response for Eye Security Customers For Eye Security customers, the attack was stopped before it could cause damage. Our 24/7 SOC acted immediately, isolating affected systems and mitigating the issue. Follow-up investigations confirmed no further intrusions, keeping customer environments secure.For further details and technical recommendations, see: Eye Research blog: SharePoint Under Siege – our detailed blog, cited by media outlets around the world Microsoft advisory on CVE-2025-53770 Washington Post BleepingComputer About Eye Security and Eye ResearchEye Research is part of Eye Security, a European cybersecurity company dedicated to protecting organizations against digital threats. The team includes seasoned cybersecurity professionals with extensive experience in both offensive and defensive operations, many with a background in national intelligence services. Their mission is to investigate emerging threats, analyze malware and vulnerabilities, and share real-world cyber incident insights through research publications. This work supports Eye Security’s 24/7 Managed Detection and Response (MDR) and incident response services, ensuring customers stay protected in an increasingly hostile digital landscape. To learn more about Eye Security and its services, visit eye.security.Note to journalistsFor more information, interviews or expert commentary, please contact:Mara Jochemmara.jochem@eye.security 

Eye Underwriting B.V. Appoints Dr. Kenneth Otto as Chief Underwriting Officer

Strategic hire strengthens Eye’s position as a next-generation cyber insurance provider across Europe Berlin/Duisburg, July 1, 2025 – Eye Underwriting B.V., the insurance arm of Eye Security, has appointed Dr. Kenneth Otto as Chief Underwriting Officer (CUO). In his new role, Dr. Otto will oversee underwriting, portfolio management, pricing, product development, and regulatory affairs. The appointment marks a significant milestone in Eye's expansion strategy, reinforcing its position as an innovative player in the European cyber insurance market, with a particular focus on Germany. Dr. Otto joins Eye from Willis Towers Watson, where he advised insurers, reinsurers, and corporates on complex cyber risk exposures. With direct access to key players and solutions across the European insurance landscape, he brings a rare blend of market intelligence and technical expertise. Dr. Otto previously served as Chief Insurance Officer at a leading German MGA, where he was responsible for cyber underwriting, pricing, and portfolio management. Technology-first risk management "What sets Eye apart is a fundamental shift in thinking," says Dr. Otto. "We do not start with the policy. We start with the risk. Our technical security solution measurably reduces both the likelihood and impact of cyber incidents. This is the foundation on which we build insurance products, even for high-exposure clients." "At Eye Underwriting, we go beyond offering an insurance product. We deliver an integrated security model. Active risk mitigation is at the heart of our approach, enabling data-driven insurability," Otto adds. "It is a paradigm shift: we view cyber insurance not as a standalone transfer instrument, but as part of a holistic, proactive risk management system. This is what differentiates us from the rest of the market." A cross-functional team driving Eye's next growth phase "With Dr. Kenneth Otto, we gain a key leader to help drive our next phase of growth," says Job Kuijpers, CEO of Eye Security. "Together with our broader insurance team, we are executing on our vision for a fully integrated, technology-powered European cyber insurance platform. At the core of that vision is trust. Our partners trust us to protect their clients, and that trust is earned through the seamless interplay of technology, risk management, and underwriting. This is exactly what our team structure and expertise are built to deliver." "The creation of this new role underlines our commitment to deepening our technical underwriting capabilities," adds Ronan Gerety, Chief Insurance Officer at Eye Security. "Dr. Otto’s in-depth market knowledge and hands-on experience in the commercial and industrial segments are vital to our growth strategy. His appointment marks a key step in professionalising our underwriting operations and enhancing our technical excellence." Dr. Otto joins a growing team of senior experts including Ronan Gerety (CIO, Eye Security), Maarten de Jonge (Head of Cyber Insurance Development), and Arjan Halma (Managing Director, Eye Underwriting). Together, they form a unique leadership group combining deep cyber risk expertise with technical insurance capabilities, a rare combination in the European market. About Eye Underwriting B.V. Eye Underwriting and Eye Security are scaling across key European markets with an integrated model that combines managed detection and response (MDR) and incident response capabilities with data-driven cyber insurance. The focus is on mid-sized businesses and affinity groups that have traditionally struggled to access effective and affordable cyber coverage. By offering operational and financial protection under the hood, Eye delivers stable, cost-efficient solutions in a volatile risk landscape.      {{ include_custom_fonts({"Silka":["Black","Bold","Extra Light","Light","Medium","Regular","Semi Bold"]}) }}

Eye Security Warns: BEC Incidents Surge in 2024, Driving Up Insurance Costs

Business Email Compromise (BEC) attacks have surged dramatically this year, accounting for 73% of all reported cyber incidents in 2024 — a sharp increase from 44% in 2023, according to research conducted by Eye Security based on its client data. This alarming 64% rise underscores the growing cyber threat landscape and its impact on businesses, including a significant escalation in cyber insurance claims and premiums. 

Eye Security launches security portal to simplify cyber data for every business

The Hague, Netherlands – August 13th, 2024 – In an era where cyber threats are increasingly sophisticated and pervasive, many businesses find themselves in the dark about their security status. Eye Security tackles this issue by integrating a new portal into its comprehensive cyber security services, providing businesses of all sizes with the insights they need to improve their cyber security posture by highlighting critical metrics in a simple and understandable format.