Weekly Cybersecurity Digest [September, Week 4]
Posted on September 29, 2026
Dear Valued Clients,
Welcome to this week’s cybersecurity digest from Make Sense. Across Europe, several developments this week point to the same underlying challenge: organisations are increasingly exposed through the systems, connections and dependencies they already consider trusted.
From interconnected infrastructure and legacy platforms to external ICT providers and authenticated cloud environments, resilience increasingly depends on understanding where trust exists, what that trust allows, and how quickly it can be limited when something goes wrong. This week’s digest looks at how that challenge is appearing across European incidents, threat intelligence and regulatory scrutiny.
✅ Top Stories of the Week
i. Cyber Incident at Renfe Linked to Compromised Adif Systems
Spanish rail operator Renfe said a cybersecurity incident appears to have originated from previously compromised servers at infrastructure manager Adif that were interconnected with Renfe systems. Attackers may have accessed limited customer information, mainly names and email addresses, while Renfe said there was no evidence of access to banking, payment, identity-document or other especially sensitive data. Affected environments were isolated and rail services remained operational. The incident highlights how trusted interconnections between critical-infrastructure operators can extend the reach of a compromise. [Read more via Renfe]
ii. Lithuania’s Interior Ministry Reports Cyberattack on Archived Citizenship System
Lithuania’s Interior Ministry reported unauthorised access to EPEKIS, an information system that has not been actively used since 2018 and now functions as an archive containing data relating to foreign nationals who applied for Lithuanian citizenship. Newly introduced security measures detected the attack and prevented further malicious activity. Authorities said datasets were created inside the system, but had not established that data was downloaded. The case is a reminder that legacy and archival systems can remain attractive targets long after they stop supporting day-to-day operations. [Read more via Lithuanian Ministry of the Interior]
iii. Dutch Vulnerability-Disclosure Organisation Investigates Suspected Agentic-AI Attack
The Dutch Institute for Vulnerability Disclosure (DIVD) confirmed that its own infrastructure had been compromised and isolated affected systems while launching a forensic investigation with an external incident-response team. DIVD said the attacker’s modus operandi indicated a possible agentic-AI-powered attack, but stressed that the investigation remains ongoing and that it could not yet rule out other explanations. The incident demonstrates why claims around AI-driven attacks require careful technical verification even as more autonomous offensive capabilities begin to emerge. [Read more via DIVD CSIRT]
✅ Industry Trends & Insights
ENISA Warns Digital Dependencies Are Expanding Europe’s Attack Surface
ENISA’s 2026 Threat Landscape found that ransomware remains the most immediately impactful cyber threat to the EU, while public administration continues to be the most targeted sector. Seventy-three per cent of targeted organisations in the dataset were entities classified as essential or important under NIS2. ENISA also warns that the growing interconnectedness of digital ecosystems is increasing exposure and that emerging AI models are expected to play a larger role in malicious operations. [Read more via ENISA]
Actively Exploited Citrix Zero-Days Trigger Emergency Patching
European cybersecurity authorities issued urgent warnings after Citrix disclosed eight vulnerabilities affecting NetScaler ADC and Gateway products. Two critical flaws, CVE-2026-88771 and CVE-2026-88772, carry CVSS scores of 9.5 and have been actively exploited, potentially enabling unauthenticated remote code execution. CERT-EU recommended immediate updates and compromise assessments for internet-exposed systems. The incident reinforces why remote-access and perimeter appliances require both rapid patching and post-exploitation threat hunting when active attacks are confirmed. [Read more via CERT-EU]
Microsoft Disrupts AI-Enabled EvilTokens Platform Linked to 12,000+ Compromised Inboxes
Microsoft disrupted the EvilTokens phishing-as-a-service platform after linking it to more than 12,000 compromised email inboxes across over 10,000 organisations worldwide, with significant victim activity in the UK and France. The service combined device-code phishing with AI capabilities that could analyse compromised inboxes, identify trusted relationships and financial processes, and recommend fraud strategies. The findings show how AI can accelerate the progression from account compromise to highly targeted financial fraud. [Read more via Official Microsoft blog]
✅ Regulatory & Policy Updates
Sweden Fines Miljödata Over Security Failures Behind Major Data Breach
Sweden’s privacy regulator, IMY, fined IT provider Miljödata SEK 1.8 million after finding that its technical and organisational safeguards were insufficient for the personal data it processed. The underlying 2025 breach affected around 2.2 million people and exposed data including national identification details, contact information and sensitive records relating to sick leave, rehabilitation and school incidents. IMY found weaknesses including insufficient checks when installing new software and a lack of automated real-time monitoring for suspicious activity. [Read more via Swedish Authority for Privacy Protection (IMY)]
EU Supervisors Warn Cyber and ICT Dependencies Could Amplify Financial-Sector Risk
Europe’s three financial supervisory authorities have warned that growing dependence on external technology providers, particularly infrastructure outside the EEA, could amplify operational disruption and geopolitical risk across the EU financial system. The regulators also highlighted increasing cyber risks linked to more capable AI models. The warning reinforces the need for financial organisations to understand critical ICT dependencies and concentration risks as part of operational resilience. [Read more via ESMA]
✅ Cyber IQ Challenge + Proactive Security Hacks
Quick Quiz: Your organisation maintains a trusted system-to-system connection with a critical external provider. What provides the strongest protection if that provider is compromised?
A) Trust all traffic because the provider has passed a security assessment
B) Allow broad access but review activity once a month
C) Treat the connection as a security boundary by restricting privileges, segmenting access, continuously monitoring activity and maintaining the ability to isolate it
D) Rely on contractual cybersecurity clauses to ensure the provider prevents compromise
(Answer below)
Smart Security Moves of the Week:
- Map trusted interconnections: Identify systems connected to suppliers, infrastructure providers and other external environments, and document what each connection can actually reach.
- Review legacy and archival systems: Systems that are no longer operational can still hold valuable data. Remove unnecessary exposure, restrict access and securely decommission them when retention is no longer required.
- Prioritise internet-facing gateways: When active exploitation is confirmed, patch rapidly and investigate for compromise rather than assuming an update alone removes attacker access.
- Review device-code authentication risks: Monitor and restrict device-code sign-ins where appropriate, and ensure users understand that legitimate authentication prompts can still be abused.
- Match controls to data sensitivity: Monitoring, access controls and other technical safeguards should reflect both the volume and sensitivity of the personal information being processed.
Answer: C) Treat the connection as a security boundary by restricting privileges, segmenting access, continuously monitoring activity and maintaining the ability to isolate it.
A trusted connection is still a path between environments. The Renfe incident illustrates why organisations need to understand not only whether a partner is trusted, but what happens internally if that partner’s systems are compromised.
✅ Conclusion
This week’s developments point to a broader resilience challenge: organisations are increasingly dependent on systems, suppliers and connections they do not fully control.
The important question is therefore not only whether those dependencies are secure, but how much access they provide, how visible they are, and how quickly they can be isolated when trust breaks down. That applies equally to external providers, legacy platforms, internet-facing infrastructure and cloud identities.
For organisations, resilience increasingly depends on understanding those relationships before an incident exposes them.
Final reflection: If one of your trusted dependencies were compromised tomorrow, would you know exactly what it could reach and how to contain it?
At Make Sense, we help organisations translate cyber complexity into practical resilience across Europe’s evolving threat, technology, and regulatory landscape.
Stay secure,
The Make Sense SRL Team & CyberTania
