Home Archive by category Security Services

Security Services

More Than 12 Million Users Affected by Cyberattack on Japan’s KDDI

Japanese telecommunications operator KDDI has confirmed that more than 12 million users were affected by a cyberattack that took place in June this year. The incident was discovered on June 17, after unknown attackers exploited a so-called zero-day vulnerability in third-party software to gain access to an email system operated by KDDI for five Japanese internet service providers. The company stated that its mobile and fixed-line email services were not affected by the attack, as they operate on separate infrastructure.

According to available information, the email addresses of approximately 12.2 million users were compromised, while the passwords of around 7.6 million accounts also fell into the hands of the attackers. KDDI says the vulnerability was likely exploited as early as May and that the software vendor is currently working on a security patch. In cooperation with the affected internet service providers, the company has already launched a password reset process for users, while the mandatory reset of all compromised accounts is expected to be completed in the coming days.

KDDI claims that the attackers were removed from its systems immediately after the incident was discovered and that there is currently no evidence of any additional suspicious activity. The company has also announced a thorough security review of the affected software and plans to transition to more secure communication technologies in order to prevent similar incidents in the future.

Konica Minolta Croatia: The Importance of Encryption at the Source

In today’s business environment, video surveillance systems represent a key element in protecting assets, employees, and operational processes. However, the level of security provided by such systems depends not only on their functionality, but also on the way they manage the data they collect. This raises an important question: Are your data protected from the very moment they are created?

In the event of the physical theft of a device or storage medium, unprotected data can become easily accessible to unauthorized persons, exposing organizations to security, legal, and reputational risks.

Integrated Security Without Compromise

To ensure complete protection, it is essential to implement a security approach that covers the entire data lifecycle, from the moment the data are created to their storage. Such an approach includes:

Encryption at the source – Data are encrypted immediately at the moment of recording. This ensures that all records are protected from the very beginning, regardless of any potential loss or theft of the device.

Secure data transmission and storage – During transmission across the network and storage in archival systems, data remain continuously protected, without exposing any unencrypted segments.

Compliance with regulatory requirements – The implementation of advanced security standards enables organizations to meet the requirements of the GDPR and other relevant regulations more easily, while simultaneously preserving business integrity.

Privacy as the Foundation of Trust

Data protection is no longer merely a technical issue, but a key component of responsible business practices. Organizations that systematically approach data security protect not only their resources, but also the trust of their clients, partners, and employees.

In this context, encryption at the source is not an additional option, but an essential standard.

Ensure comprehensive data protection, from the moment data are created to their storage.

Comtrade Opens Security Operations Center in Sarajevo

As cyberattacks become increasingly sophisticated, organizations are more frequently faced with a critical question they cannot answer: Is our IT infrastructure under attack right now? To help companies achieve continuous security monitoring and faster incident response, Comtrade System Integration has opened a new Security Operations Center (SOC) in Sarajevo.

The new center provides organizations in Bosnia and Herzegovina with 24/7 cybersecurity monitoring, supported by a team of experts who understand the local market and can respond rapidly to security incidents. The Sarajevo SOC is part of a regional network that also includes operational centers in Belgrade and Ljubljana, combining local support with regional expertise.

According to the company, an increasing number of organizations are turning to managed cybersecurity services, as building and operating an in-house Security Operations Center requires significant investments in skilled personnel, processes, and advanced technologies. Instead of developing and maintaining complex internal infrastructure, companies can benefit from continuous monitoring, rapid threat detection, and expert support through an established SOC.

One of the key advantages of the Sarajevo center is that customers can immediately reach a team that understands their business environment, speaks their language, and can respond without the delays often associated with cross-border coordination or communication barriers.

Today, Comtrade System Integration ranks among the top 15 managed cybersecurity service providers in Europe and the top 75 worldwide. The company operates in accordance with the ISO 27001 standard and maintains the highest partnership levels with leading global cybersecurity vendors, underscoring its expertise in protecting business-critical systems.

Hytera: How Smart Body-Worn Cameras Are Transforming Adriatic Security

The private security sector across the Adriatic region is undergoing a critical operational transformation. For years, on-site security personnel, event stewards and facility managers have relied on voice-only two-way radios for team coordination. However, as client expectations rise and security scenarios grow increasingly complex, Adriatic security stakeholders are facing higher standards for faster response, on-site transparency and verifiable accountability.

A clear operational gap has emerged within traditional security workflows – voice communication enables teams to describe incidents, but cannot visually document what happens on-site. This long-standing limitation has gradually undermined response efficiency, dispute resolution credibility and overall service professionalism for local security companies.

Modern commercial security operations demand far more than voice communication and basic dispatch. Private security firms across the Adriatic region are under growing pressure to boost operational transparency, resolve on-site disputes fairly, protect staff from unfounded accusation, and deliver solid, tamper-proof evidence for insurance claims, liability audits and commercial dispute settlement.

This industry evolution — shifting from voice-only coordination to integrated visual evidence capture — is no longer a discretionary upgrade. It has become an inevitable necessity to elevate professional service standards, mitigate operational risks and meet regional regulatory compliance requirements for private security providers.

Legacy radio devices are designed purely for voice transmission, lacking visual recording and evidence retention capabilities. They cannot document on-site interactions, record theft, de-escalate operational conflicts, or support real-time remote supervision. With tightening data privacy regulations, rising client accountability demands and increasingly sophisticated commercial security scenarios, relying solely on voice-centric devices leaves security teams vulnerable to he-said-she-said disputes, incomplete incident records and insufficient liability protection. Upgrading to unified, evidence-driven communication devices has become essential for modern private security operations.

Hytera’s professional smart Body-Worn Camera portfolio — SC880, SC780, SC580 and GC550 — is purpose-built to empower this industry transition. By integrating reliable mission-critical communication with high-definition recording, Hytera Body-Worn Camera redefines on-site efficiency, operational accountability and personnel protection for commercial security teams across the Adriatic region and wider European markets.

As the flagship 5G body camera for high-end security scenarios, the Hytera SC880 delivers ultra-low-latency 4K real-time video streaming over public 5G networks, enabling command center to obtain instant, high-resolution on-site visuals and support faster, more accurate emergency responses. The device also supports native Push-to-Talk over Cellular (PoC) functionality, unifying real-time voice communication and visual surveillance within one portable device. Equipped with advanced distortion correction, 6-axis electronic image stabilization and high-power infrared illumination, the SC880 captures clear, detailed footage even during moving patrols and low-light night shifts, ensuring no critical on-site information is missed.

The Hytera SC780 serves as a high-performance 4G workhorse for daily commercial security operations. It supports up to 120-second pre-recording, fully capturing incident precursors that manual activation may miss. Paired with stable, high-definition video output and rich on-site detail restoration, the device eliminates recording blind spots during sudden emergencies. Integrated seamlessly with Hytera’s unified security platform, the SC780 supports HD live streaming, encrypted audio and video transmission, and real-time situational awareness, empowering supervisors with reliable remote field visibility at all times.

Balancing lightweight ergonomics and powerful performance, the Hytera SC580 features an ultra-slim, uniform-friendly design for all-day comfortable wear. Despite its compact form factor, it delivers stable 4G real-time streaming, enhanced starlight night vision and AI-powered image stabilization, consistently producing clear, evidence-grade footage even during high-intensity patrols and dynamic on-site operations.

The Hytera GC550 ultra-compact body camera is engineered for discreet, all-scenario evidence collection. Its 150° ultra-wide-angle lens captures comprehensive on-site details, delivering objective, unbiased video and photo evidence for daily facility patrols, retail security and low-profile on-site supervision. The combination of optimized hardware and intelligent software significantly improves the transparency of on-site security interactions and safeguards the legitimate rights and safety of frontline security personnel.

Beyond on-site recording capabilities, the true value of Hytera Body-Worn Camera ecosystem lies in standard and secure evidence management. Video footage is only credible when full data integrity and a complete chain of custody are guaranteed. Supported by Hytera’s Digital Evidence Management platform, all recorded files are automatically uploaded, fully encrypted and systematically archived once devices are docked. The automated, closed-loop evidence workflow ensures full traceability and data security, perfectly adapting to evolving European data privacy and evidence management regulations.

The era of voice-only communication in private security is fading. Modern private security requires a unified system that enables efficient team coordination while securing admissible, objective on-site evidence. Hytera’s Body-Worn Camera portfolio delivers robust reliability, regulatory compliance and actionable operational intelligence, helping security firms reduce disputes, protect frontline staff, strengthen liability defence and upgrade overall service quality.

For forward-thinking private security providers across the Adriatic region and Europe at large, this is far more than simple equipment replacement. It represents a strategic upgrade of operational models – transforming traditional security guards into connected, tactical, data-backed security professionals fully prepared for the complex security challenges of 2026 and beyond.

Mercury AI: Digital Shield of the Future

The Mercury AI next-generation digital shield demonstrates how AI technology is redefining the security of our environment.

In a world changing faster than most ever imagined, the issue of security has ceased to be a question without an answer or something beyond our influence; it has become a part of our daily lives in an environment full of challenges. To properly address one of the most vital concerns for every individual—their safety and the safety of their loved ones—it is necessary to utilize the latest modern achievements. This includes not only traditional “hard security,” such as armed police and physical barriers, but also the “soft,” almost invisible hand of security that utilizes cameras, smart software, and Artificial Intelligence. At the center of this new technology, which helps us feel safer than ever before, is the company The Mercury AI, specialized in the latest digital advancements in the field of security with its “digital shield.”

Most people do not think about security until they have to. However, the environment in which we live and work is changing so rapidly that one must react quickly to new challenges, while the reality unfortunately remains that most security systems still operate under the old rule—react only after something has already happened. But if we already possess technology that can recognize a problem early, why should we wait for it to become an incident? That is why we created the digital shield—a weapon detection platform that uses artificial intelligence to identify potential threats before they turn into problems. Security should come through prevention, not reaction.

A Watchful Eye That Never Blinks

What exactly is the digital shield? The core of this system is not just in “recording the environment,” but in understanding what is happening in real-time. While the human factor is naturally subject to fatigue, loss of concentration, or a limited field of vision, The Mercury AI platform offers constant surveillance that knows no breaks and functions 24 hours a day, seven days a week.

The main advantage of this technology over existing ones is the specialized AI algorithm. Unlike ordinary security cameras that merely transmit an image, this system performs a constant analysis of every video frame. It establishes instantaneous visual contact with any form of weaponry—whether it be firearms or bladed weapons like knives.

But that is not all. What sets this system apart in the market is its incredible accuracy. Namely, the biggest problem with automated systems is “false alarms” that can cause panic and unnecessary costs. Our platform, however, makes a precise distinction in a fraction of a second between a dangerous object and harmless everyday items like phones, keys, or tools. This achieves a dual goal: maximum vigilance while eliminating unnecessary stress.

Silent Guard: Discretion as a Priority

As we have started to grow accustomed to relaxed and safe work environments, one of the greatest challenges in introducing high-security measures into public spaces is maintaining a pleasant atmosphere. No one wants to feel like they are in a high-security “prison” with an “all-seeing eye” at every turn in a shopping mall or school. Although citizens know that surveillance cameras are all around, it is natural that they do not want them to be intrusive. This is where silent and discreet monitoring comes into play.

The system functions almost invisibly, operating in the background of existing video infrastructure. It does not require bulky installations that would disturb the public or ruin the aesthetics of the space. While life goes on normally, the AI silently scans the surroundings 24/7. This continuous security support provides a level of protection that the human eye, no matter how well-trained, simply cannot maintain at every moment and on every square meter of a facility.

Automation That Saves Lives

The greatest advantage of such a system is, of course, in crisis situations, where every second is literally a matter of life and death. Statistics show that the highest number of casualties in incidents occurs during those crucial minutes spent waiting for emergency services to be called and for them to arrive on the scene. The digital shield solves this problem through automated rapid response.

The moment the algorithm detects a threat, the system does not wait for someone to press a button. It automatically triggers a series of predefined protocols:

Instant Notifications: Security teams and police receive an alarm with the exact location and visual evidence of the threat in real-time. Smart Locking: The system can automatically lock strategic doors to isolate the attacker, preventing movement through the facility. Lockdown Protocols: Procedures for evacuation or moving people to safety are automatically initiated.

This proactivity drastically shortens reaction time, leaving an attacker with minimal room to act while simultaneously providing life-saving seconds to those inside the building. The reaction time compared to traditional methods is dramatically reduced.

Versatility and Application

Due to the versatility and adaptability of this platform, its application is possible in almost any place where large numbers of people gather or where there is a need for property protection:

Educational Institutions and Public Places: Schools must be the safest places in the world. By implementing The Mercury AI detection in schools, malls, and stadiums, we raise the level of security to a standard generations before us could not have imagined. Transport Hubs: Airports, bus terminals, and railway stations are the “lifeblood” of every city, but also potential targets. The Mercury AI system enhances the security of key points without slowing down passenger flow. Critical Infrastructure: Administrative centers and energy facilities require a special level of protection. The Mercury AI detection ensures that vital state systems remain intact and safe from external threats. Business Sector: Workspaces are where we spend half our day. Protecting employees from potential threats is not just a legal obligation, but an ethical imperative for every modern employer.

The Future is Proactive

The time when we relied solely on luck or post-incident reaction is behind us. The future has arrived. The digital shield offered by The Mercury AI is not just a technological novelty—it is a necessary evolution in preserving human lives and property. Investing in such a system is an investment in the peace of mind of parents, the safety of workers, and the stability of the entire community.

We at The Mercury AI team leave nothing to chance. We do not gamble with security; we raise safety to the maximum level enabled by technology and provide an environment truly dedicated to preserving vital interests and values. That is why we work daily on implementing new solutions and keeping pace with the latest technologies—all so our clients can fully relax and not worry so much about security, knowing the digital shield is around them, protecting them.

Cyberattack Disrupts French Postal Operations as Pro-Russian Group Claims Responsibility

France’s national postal service, La Poste, experienced a significant disruption to its digital infrastructure this week after a large-scale cyberattack temporarily disabled key systems during the peak holiday delivery period. A pro-Russian hacking collective later claimed responsibility for the incident, according to French authorities.

The attack, identified as a distributed denial-of-service (DDoS) operation, forced central IT systems offline on Monday, preventing postal employees from tracking parcels and causing interruptions to online payment services linked to La Poste’s banking division. As of Wednesday morning, parts of the system had not yet been fully restored.

Responsibility for the attack was claimed by the hacker group Noname057, which has previously been linked to a series of cyber operations targeting European institutions. Following the claim, France’s domestic intelligence service, DGSI, assumed control of the investigation, the Paris prosecutor’s office confirmed.

The disruption comes at a critical time for La Poste, which handles billions of mail items and parcels annually and employs more than 200,000 people nationwide. The outage coincided with one of the busiest logistics periods of the year, amplifying its operational impact.

French authorities view the incident within a broader pattern of hostile cyber activity attributed to Russia-aligned actors. France and its European partners argue that such attacks form part of a wider “hybrid warfare” strategy aimed at destabilizing public services, exhausting security resources, and weakening political support for Ukraine. In recent years, European investigators have documented hundreds of similar incidents involving cyberattacks, disinformation campaigns, and acts of sabotage across the region.

SoundCloud Confirms Cyberattack, User Data Partially Compromised

SoundCloud has confirmed it was the target of a cyberattack in which hackers gained unauthorized access to data belonging to approximately 20% of the platform’s users. The company said the incident was detected after suspicious activity was identified within an ancillary administrative system, prompting the immediate activation of internal incident response protocols. An investigation carried out with the support of external cybersecurity experts found that the attackers accessed a limited set of data, including email addresses and information already visible on public user profiles.

SoundCloud emphasized that sensitive information such as passwords or financial data was not exposed. Nevertheless, users have been advised to remain vigilant for potential phishing attempts that could follow the incident. With the platform estimated to have more than 100 million users, the breach could affect tens of millions of accounts.

The company stated that the attackers have been removed from its systems, although the platform subsequently faced DDoS attacks, two of which temporarily disrupted the web version of the service. Issues with VPN access reported by users in recent days were linked to security-related configuration changes introduced in response to the incident, and SoundCloud said it is actively working to resolve those problems.

Major Cloudflare Outage Temporarily Disrupts Internet Worldwide

A large portion of the global internet experienced significant slowdowns today after Cloudflare, one of the key infrastructure providers behind thousands of popular websites, suffered a major technical outage. The disruption affected numerous online services — including X (formerly Twitter), Substack, Canva and others — with users encountering a “500 internal server error” message instead of the expected content.

Interestingly, some platforms that were impacted by a similar worldwide outage earlier this month remained stable this time, likely because they have since reduced their reliance on Cloudflare’s infrastructure. Among those unaffected was ChatGPT.

This is the second major incident in less than three weeks, once again highlighting the complexity and vulnerability of the global internet ecosystem. Cloudflare provides essential services that act as a “bridge” between websites and their users, accelerating page loading and protecting sites from overload. As a result, any disruption within Cloudflare’s systems can quickly trigger a chain reaction that brings down numerous unrelated services across the internet.

Although the interruption was relatively brief, it underscored how dependent the global digital landscape has become on a handful of key technology providers — and how their technical issues can instantly become a worldwide problem.

 

Germany Launches Major NIS2 and DORA Offensive: The Strictest Era of Cyber Compliance Begins for Companies

At the end of November 2025, Germany initiated the most far-reaching cybersecurity reform of the past decade, following the Bundesrat’s adoption of the NIS2 implementation law. As a result, regulatory obligations effectively entered into force immediately, without any transitional periods — a development legal experts are calling a “compliance shock” for the business sector. At the same time, European supervisory authorities activated a key mechanism of the DORA regulation and published the first list of critical IT third-party providers, who now fall under direct EU oversight.

The Federal Network Agency (BNetzA) has already presented a draft of a new security catalogue, introducing stricter requirements for safeguarding the telecommunications supply chain. The law firm Dentons reminds that all obligations apply the moment the law takes effect, including mandatory registration with the BSI and the implementation of comprehensive cyber risk-management measures. The scope of regulated entities is expanding dramatically — from around 4,500 to almost 30,000 companies — now including logistics, food supply, and digital service providers.

DORA further tightens supervision over cloud providers, analytics companies, and software vendors serving the financial sector, introducing mandatory on-site inspections and new channels for reporting IT incidents. The common priority of both regulations is strengthened third-party risk management, meaning that suppliers can no longer rely on simple declarations of conformity but must provide evidence of their security reliability.

Regulators stress that the era of postponements is over, and companies that were counting on extended deadlines now face severe penalties and increased personal liability for management. All indicators suggest that the period leading into early 2026 will be a race to close compliance gaps across all sectors.

Amazon blames Iran for combining cyber espionage with physical attacks

Amazon has released details on two cases in which Iranian threat actors combined digital espionage with physical attacks, a practice the company refers to as “cyber-enabled kinetic targeting.” The first case involves the group Imperial Kitten (also known as Tortoiseshell), linked to Iran’s IRGC, which over a two-year period progressed from cyber reconnaissance to a physical strike. According to Amazon, the group compromised a ship’s AIS system in December 2021 and, by August 2022, had gained access to additional maritime platforms and onboard CCTV cameras to collect real-time visual intelligence. In January 2024, they searched AIS location data for a specific vessel, which just days later, on February 1, became the target of a Houthi missile attack. Amazon says the link between the cyber reconnaissance and the subsequent strike is “unmistakable,” even though the attack itself was unsuccessful.

The second case concerns MuddyWater, a group tied to Iran’s MOIS, which in May 2025 prepared a server for cyber operations and, by June 17, used the same infrastructure to access a compromised CCTV server streaming live footage from Jerusalem. Researchers believe the footage was used to support the planning of a June 23 missile attack, after which Israeli authorities warned citizens to immediately disconnect internet-exposed cameras. Amazon stresses that existing terms such as “cyber-kinetic operations” or “hybrid warfare” lack precision, and proposes a new definition for campaigns where cyber activities directly support physical strikes. The company warns that this type of operation will become increasingly common as nation-states recognize the strategic advantage of combining digital reconnaissance with kinetic attacks.

Amazon urges companies to adjust their security strategies and expand threat models, noting that even entities that previously considered themselves uninteresting to attackers may now be targeted for tactical intelligence collection.