Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Your Driverless Cab Is Spying on You

    October 2, 2026

    Microsoft’s X account hacked in crypto pump-and-dump scheme

    October 2, 2026

    Tether’s $190 billion USDT stablecoin is coming back to the Bitcoin network

    October 2, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Your Driverless Cab Is Spying on You
    • Microsoft’s X account hacked in crypto pump-and-dump scheme
    • Tether’s $190 billion USDT stablecoin is coming back to the Bitcoin network
    • California to Vote on Landmark Tribal Petitions for Coastal Protections
    • NBA closes sole Africa training academy in blow to young players | Basketball
    • First minister demands ‘new deal’ for Wales, before Plaid Cymru conference
    • Drumcree talks break up without agreement on fifth day of standoff | Northern Ireland
    • Health Care Workers Are Tired of Cleaning Up Palantir’s Mess
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, October 2
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Critical Flaws Discovered in Belgian eID Software Used by 2 Million People

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 10, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    DEF CON — A security researcher has revealed severe, now-resolved security vulnerabilities in the Connective digital identity system, a browser extension used by over two million users in Belgium. 

    Developed by Nitro Software Belgium, the software is used by eight of Belgium’s ten largest banks and over 60 government agencies to manage digital identity authentication and execute legally binding electronic signatures.

    James Arnott, security researcher and founder of cybersecurity firm Bay Area Labs, discovered that the software failed to verify which website was attempting to communicate with the user’s computer. Because these checks were missing, any website or embedded online ad could interact directly with the Connective application running on a victim’s machine without their knowledge or permission.

    According to Arnott, a malicious website could silently read connected electronic ID (eID) and payment card details. Furthermore, attackers could trick users into revealing their eID PIN by triggering official-looking authentication pop-ups. Because the software allowed web pages to customize the text inside these dialog boxes without displaying the domain making the request, users had no way to verify whether a prompt was legitimate or a phishing attempt.

    When a user entered their PIN into a prompt, the application transmitted it back to the requesting webpage. An attacker could then use the PIN to generate unauthorized approval tokens to forge legally binding electronic signatures whenever the victim’s physical eID card was inserted into a card reader.

    The compromise of the eID system severely impacted the trust model of Belgium’s broader digital ecosystem, including government portals like CSAM.be and third-party identity providers like Itsme. 

    Advertisement. Scroll to continue reading.

    While these service providers contained no flaws of their own, their reliance on eID signatures meant that an attacker with stolen signing capabilities could register or hijack digital identity accounts.

    In addition to identity theft, the researcher uncovered a remote code execution vulnerability that operated independently of whether an eID card was plugged in. By exploiting a flaw in how the application processed files on the local computer, a malicious website could force the software to execute attacker-controlled code at the user level.

    An attacker could execute this drive-by attack by tricking a user into downloading a file disguised as a standard document and visiting a webpage. Requiring no special permissions, the flaw also carried the risk of spreading like a self-propagating worm by hijacking user credentials to send malicious links to other potential victims.

    Nitro fully remediated the issues 146 days after the initial report and awarded a $200 bug bounty. The company deployed updates to block unauthorized origin requests and secure PIN handling, with final security enforcement completed in late July. No CVEs appear to have been assigned.

    Nitro has not responded to SecurityWeek’s request for comment. 

    Arnott publicly disclosed the findings at DEF CON and released a blog post with additional technical details. 

    Related: Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

    Related: How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones

    Related: Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix

    Belgian critical discovered eID flaws Million People software
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Microsoft’s X account hacked in crypto pump-and-dump scheme

    Rolling the cyber dice with open-source and open-weight AI models

    Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action

    Microsoft says threat actors are ahead in the early AI race

    Autonomous AI agents tried to hack US, Canadian government websites

    OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Your Driverless Cab Is Spying on You

    October 2, 2026

    Microsoft’s X account hacked in crypto pump-and-dump scheme

    October 2, 2026

    Tether’s $190 billion USDT stablecoin is coming back to the Bitcoin network

    October 2, 2026

    California to Vote on Landmark Tribal Petitions for Coastal Protections

    October 2, 2026
    Latest Posts

    Max Miller Continues to Resist Pressure to Drop Out as Deadline Looms

    August 7, 2026

    Houthi attacks kill at least 10 in Yemen as rebels target oil-rich Marib

    August 8, 2026

    Scientists find unexpected life on Ötzi the Iceman’s 5,300-year-old body

    August 8, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Your Driverless Cab Is Spying on You

    October 2, 2026

    Microsoft’s X account hacked in crypto pump-and-dump scheme

    October 2, 2026

    Tether’s $190 billion USDT stablecoin is coming back to the Bitcoin network

    October 2, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.