The Desk · The Wire · Hacked Today? · Data Center RSS
The Perimeter Site

Who Actually Controls Belgium's eID?

Dana Kessler
2026-08-14
# Who Actually Controls Belgium's eID? Belgium's national eID authentication system has a hole that allows for remote code execution on citizen accounts. This isn't some theoretical academic paper or a low-impact bug. It's an RCE in the very mechanism used to prove who a person is to the state. When you compromise the identity layer, you don't just steal data; you steal the legal persona of every single user. It's surprising because we expect national infrastructure to have a baseline of competence. Instead, we have a systemic failure where the digital proxy for a citizen can be hijacked from the outside. This is an existential trust issue that no one in the Belgian government seems to have priced into their risk register. Then there's the 3am page. VMware vCenter is currently burning. CVE-2026-59310 is a directory traversal vulnerability that APT actors are leveraging for remote code execution. They aren't just popping shells; they're establishing reverse SSH access to maintain persistence. If you're running vCenter, your priority isn't the morning coffee. It's checking your logs for unauthorized SSH tunnels. The vendor severity is high, but that's an understatement. In a virtualized environment, vCenter is the keys to the kingdom. The claim from some architects is that segmented management networks mitigate this risk. They're wrong. Management planes are never truly isolated because they require updates and administrative access. That narrow window is exactly where these actors are sitting. Once an attacker controls the hypervisor, any security software running inside a guest VM is effectively a hallucination. You can have the most expensive EDR on your virtual servers, but it doesn't matter if the ground they're built on is owned by someone else. This rhymes with the SolarWinds disaster in the sense that we've placed blind trust in a central management tool, though this time it's a direct exploit rather than a poisoned update. Check your vCenter versions. Patch now. On the data side, Poland just had its medical records gutted. Roughly 19 million people are affected. To put that in perspective, DentaQuest recently reported a breach of 15 million records, which was touted as the largest US health breach of the year. Poland's hit is larger and more concentrated. The immediate focus is usually on the number of records exposed. That's the wrong metric. The real story is the second-order effect. A national medical database provides a goldmine for precision phishing. We aren't talking about generic "Dear Customer" emails. We're talking about attackers knowing your specific diagnosis, your medication, and your doctor. When an attacker knows your health history, they can craft lures that are almost impossible to ignore. Every insurance company and bank in Poland is now exposed to a decade of highly targeted fraud. Microsoft just dropped 398 patches for August. Among them are fixes for 42 critical vulnerabilities across Windows, Office, and Exchange Server. The "LegacyHive" zero-day was one of the highlights. For most shops, 398 is just noise. You can't patch everything without breaking something, so you triage. The problem is that attackers don't triage. They scan for anything that looks like an open door. We see this with the recent SharePoint authentication bypass (CVE-2026-55040). The PoC went public and the exploit attempts followed almost instantly. There's no longer a grace period between a researcher posting a proof-of-concept and a criminal using it to exfiltrate data. The gap is closing. We're seeing an odd trend in the sectors this week. Technology remains the top target with 379 stories, but government follows closely at #2 with 265. The targeting of national identity systems like Belgium's eID suggests a shift toward systemic infrastructure rather than just corporate theft. If you can compromise the tool that validates identity for an entire country, you don't need to breach ten thousand separate companies. You just breach the one place they all trust. The question is whether we actually want a centralized digital identity if the security is this brittle. Most of us are just waiting for the next CVE to tell us our passports aren't ours anymore.
◼
← More from the Desk Live Wire →

About · Methodology · Contact · Privacy

Tracking a CVE from this story? Hazard shows which vulnerabilities are confirmed exploited in the wild — and what the resulting breaches have cost UK organisations.

DISCLAIMER: Articles on this site are generated automatically from public security news feeds for educational and informational purposes. They may contain errors, and nothing here constitutes security, legal, or compliance advice. Verify details against original advisories and vendor bulletins before acting on them.