Skip to content

other

Netherlands National Cyber Security Centrum

The Netherlands' national cyber security agency, which monitors threats, coordinates incident response, and issues advisories on vulnerabilities.

Known aliases

  • Dutch National Cyber Security Center
  • Dutch National Cyber Security Centre
  • Dutch officials
  • Nationaal Cyber Security Centrum
  • National Cyber Security Centre Netherlands
  • National Cyber Security Centre (Netherlands)
  • National Cyber Security Centre of the Netherlands
  • NCSC Netherlands
  • NCSC-NL
  • Netherlands National Cyber Security Centre

Relationships

No evidence-backed relationships are recorded.

Current stories

security8 publishers

DIVD traces its breach to two chained zero-days in its own Zammad helpdesk

DIVD, the Dutch volunteer disclosure group, was breached through two chained zero-days in its own Zammad helpdesk that took an attacker to root in seconds. Zammad claims over 2,000 customers, and DIVD wants every older install upgraded to version 7 or taken offline.

Perspective Coverage

8 publishers
Builder
Builder 27%
Operator
Operator 64%
Investor
Investor 9%

Reality

Evidence68
Adoption35
Hype gap+25
Incentives40
Confidence66
security21 publishers

NetScaler attackers tunnel into internal networks with a new Python proxy

Mandiant and Google traced a September 2026 campaign exploiting NetScaler bug CVE-2026-88772, CVSS 9.5, to root on appliances with no login. From there the intruders drop web shells and a Python tunneler that reaches into victims' internal networks to steal credentials.

Perspective Coverage

21 publishers
Builder
Builder 29%
Operator
Operator 56%
Investor
Investor 15%

Reality

Evidence88
Adoption82
Hype gap−8
Incentives60
Confidence86
build3 publishers

Default NetScaler Gateway configurations meet the conditions for both exploited pre-auth RCE bugs

Citrix confirmed attackers are exploiting two CVSS 9.5 pre-auth RCE flaws in NetScaler ADC and Gateway, one of them present in default configurations. Self-managed appliances need the fixed build, installed after evidence is saved, since an upgrade can erase signs of intrusion.

Publishers:dev.tothestack.technologywatchtowr.com

Perspective Coverage

3 publishers
Builder
Builder 20%
Operator
Operator 68%
Investor
Investor 12%

Reality

Evidence70
Adoption
Insufficient
Hype gap+5
Incentives35
Confidence72
security3 publishers

Attackers are exploiting two unpatched NetScaler RCE flaws, watchTowr says

watchTowr says attackers exploited two remote code execution flaws in Citrix NetScaler ADC and Gateway before any fix existed. The August patch for CVE-2026-19490 fixes a different bug, so every operator now has to decide whether to keep the box online and whether to assume it is breached.

Perspective Coverage

3 publishers
Builder
Builder 15%
Operator
Operator 73%
Investor
Investor 12%

Reality

Evidence55
Adoption
Insufficient
Hype gap+10
Incentives35
Confidence60
product5 publishers

Apple's quiet Screen Sharing fix is now a same-day job: CVE-2026-65400 is under active abuse

Dutch officials report root access and Monero miners on Macs with port 5900 open to the internet. Sonoma, Sequoia and Tahoe all need the update Apple shipped as an important security fix.

Perspective Coverage

5 publishers
Builder
Builder 22%
Operator
Operator 70%
Investor
Investor 8%

Reality

Evidence70
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence68
security6 publishers

macOS Screen Sharing bug exploited in the wild: if port 5900 was open, assume root was taken

The Dutch NCSC says CVE-2026-65400 was abused within two weeks of Apple's fix, with root access and Monero miners in every reported case. Patching closes the door; it does not evict anyone.

Perspective Coverage

6 publishers
Builder
Builder 22%
Operator
Operator 72%
Investor
Investor 6%

Reality

Evidence60
Adoption
Insufficient
Hype gap+20
Incentives40
Confidence62
security6 publishers

Check Point patches a Security Management zero-day it saw exploited on July 23

The advisory confirming attacks on a Security Gateway VPN flaw three days after its September 9 fix also carries the first patch for a management path traversal that was used in targeted attacks in late July.

Perspective Coverage

6 publishers
Builder
Builder 21%
Operator
Operator 70%
Investor
Investor 9%

Reality

Evidence72
Adoption
Insufficient
Hype gap+5
Incentives60
Confidence70
security3 publishers

Public exploit code for CVE-2026-62911 is outpacing patching on 21,899 exposed Exchange servers

Microsoft patched the Exchange authentication bypass on August 11. Shadowserver's September 1 scan still counts 21,899 internet-facing servers unpatched, and NCSC-NL says working exploit code for full mailbox takeover is circulating.

Perspective Coverage

3 publishers
Builder
Builder 20%
Operator
Operator 68%
Investor
Investor 12%

Reality

Evidence72
Adoption30
Hype gap+18
Incentives70
Confidence68