Threat-informed security

Real attacks continuously improve our audit.

The Pain Test is not static. Documented incidents, CERT-FR advisories, CNIL decisions and European cyber requirements are translated into new or stronger controls while clearly separating public evidence from checks that require authorised internal access.

REFERENCE / UPDATED 2026-09-30

Changes currently integrated.

Each reference below may change the audit engine, Pain Test, paid diagnosis or remediation guidance. A news item never makes a client vulnerable by itself: only evidence actually observed is used.

VULNERABILITY / HIGH / 2026-09-28

Citrix NetScaler ADC/Gateway — active exploitation before patches

Audit impact: Adds a pre-patch exposure-window concept and separates two states: current vulnerability remediation and historical compromise assessment. When an authoritative source documents exploitation before patches, an asset exposed during that period should be flagged for compromise assessment without claiming that compromise occurred.

Boundary: The external scan may only report a technology or version when genuinely observable. No PoC, RCE, authentication bypass or active CVE validation. Reconstructing the exposure window and reviewing logs/IOCs requires client authorisation and internal evidence.

Official source: CERT-FR — CERTFR-2026-ALE-011 ↗

TECHNOLOGY-DEBTEXTERNAL-SURFACEPRE-PATCH-EXPOSURE-WINDOWCOMPROMISE-ASSESSMENTREMOTE-CODE-EXECUTIONDETECTION-GAP
INCIDENT / HIGH / 2026-09-03

Hôpital Privé de la Loire — compromised account, excessive privileges and late detection

Audit impact: Strengthens paid controls for MFA, authorisation scope, least privilege, abnormal-access detection and bulk consultation/extraction detection. Blast Radius should measure how much data one compromised account can reach.

Boundary: MFA, authorisation scope, SIEM and internal blast radius are not inferred from a public scan: authorised internal evidence is required.

Official source: CNIL ↗

IDENTITYMFALEAST-PRIVILEGEDETECTION-GAPBULK-ACCESSBLAST-RADIUS
VULNERABILITY / HIGH / 2026-09-03

SPIP — critical vulnerabilities before 4.4.23

Audit impact: Adds passive SPIP fingerprinting. If a reliable version below 4.4.23 is observed, the detailed audit should correlate it with the CERT-FR advisory. Without reliable version evidence: detect the technology but do not claim vulnerability.

Boundary: No administration-console probing, brute force or exploitation attempt.

Official source: CERT-FR — CERTFR-2026-AVI-1109 ↗

TECHNOLOGY-DEBTSPIPVERSION-EXPOSUREREMOTE-CODE-EXECUTIONPRIVILEGE-ESCALATION
REGULATION / HIGH / 2026-08-01

Cyber Resilience Act — reporting obligations from 11 September 2026

Audit impact: Adds a paid Vulnerability & Incident Reporting Readiness module for applicable manufacturers: product owner, reporting channel, 24h/72h workflow, affected versions, corrective measure and notification evidence.

Boundary: An Internet scan must never claim CRA compliance. The module is enabled only after confirming that the client is in scope.

Official source: Commission européenne ↗

CRAVULNERABILITY-REPORTINGINCIDENT-REPORTING24H72HPRODUCT-SECURITY
STRATEGIC / MEDIUM / 2026-09-03

ANSSI / G7 — prepare the transition to post-quantum cryptography

Audit impact: Adds a progressive crypto inventory: TLS, signature algorithms, key type/size, certificate chain and observable dependencies. Show “Crypto agility: review recommended” without score penalty at this stage.

Boundary: Standard pre-quantum cryptography is not presented as a current vulnerability. This is a readiness and crypto-agility indicator.

Official source: ANSSI ↗

CRYPTOGRAPHYCRYPTO-AGILITYPQCTLSCERTIFICATE-INVENTORY
INCIDENT / HIGH / 2026-08-14

DGFiP — stolen credentials, authorised third-party account and data extraction

Audit impact: Strengthens review of trust paths associated with authorised third-party accounts, the access scope of a compromised identity and the ability to revoke external access quickly. The subsequent suspension of external SPDC access illustrates the importance of an operational containment mechanism.

Boundary: The external scan may identify a publicly observable portal or identity provider, but cannot infer third-party privileges, MFA coverage or actual revocation capability. No credential testing, MFA bypass or partner-access testing is performed without explicit authorisation.

Official source: Ministère de l’Économie et des Finances ↗

IDENTITYCREDENTIAL-ABUSETHIRD-PARTY-TRUSTEXTERNAL-ACCESSDATA-EXPOSUREACCESS-REVOCATIONBLAST-RADIUS
INCIDENT / HIGH / 2026-02-18

FICOBA — compromised authorised account and banking-data access

Audit impact: Reinforces measurement of the authorisation scope associated with one compromised account in the authorised internal audit.

Boundary: Actual authorisation scope requires authorised internal access.

Official source: Ministère de l’Économie et des Finances ↗

IDENTITYPRIVILEGED-ACCESSDATA-EXPOSUREBLAST-RADIUS
INCIDENT / MEDIUM / 2026-07-13

ANSSI — Turla targeting and compromise of French entities

Audit impact: Strengthens external-surface inventory and technology-debt assessment without turning the public audit into an intrusive penetration test.

Boundary: No exploitation, persistence or intrusive action is reproduced.

Official source: ANSSI ↗

RECONNAISSANCEEXTERNAL-SURFACETECHNOLOGY-DEBTPERSISTENCE
PAIN TEST / SIX AXES

From technical weakness to business exposure.

The free score remains external and non-intrusive. Internal dimensions remain explicitly undetermined until authorised evidence is provided.

01

Identity

Public authentication, session and third-party access signals. MFA, access context, actual privilege scope and partner rights require internal review.

02

Attack surface

Internet-visible services, technologies, subdomains and entry points. Internal or partner trust paths are assessed only with authorisation.

03

Data exposure

Signals of public data, APIs and sensitive business functions.

04

Technology debt

Visible technologies, reliable versions and correlation with authoritative advisories.

05

Detection gap

Logging, SIEM, behavioural detection and bulk-extraction detection require internal evidence.

06

Blast radius

Paid measurement of the data, resources and business actions one compromised account can reach or trigger.

INTERNAL REVIEW / PAID OPTION

What an Internet scan cannot prove.

With explicit authorisation and client-provided evidence, the detailed assessment can cover external-access MFA, access context, authorised third-party accounts, partner trust paths, revocation/containment capability, least privilege, authorisation scope, logging, SIEM, abnormal-access detection, bulk-extraction detection, compromised-account blast radius and reconstruction of a pre-patch exposure window when active exploitation is documented.

01MFA / ACCESS CONTEXT
02THIRD-PARTY / TRUST PATHS
03REVOCATION / CONTAINMENT
04LOGGING / SIEM
05EXPOSURE WINDOW / IOC
06DATA + ACTION BLAST RADIUS
CRA / READINESS

Prepare reporting without pretending to certify compliance.

For manufacturers in scope of the Cyber Resilience Act, Interface Trust can qualify a reporting-readiness module: product owner, notification channel, 24h / 72h workflow, affected versions, corrective measure and notification evidence. This module is never inferred from an Internet scan.

01CRA SCOPE
02PRODUCT OWNER
0324H EARLY WARNING
0472H NOTIFICATION
05AFFECTED VERSIONS
06CORRECTIVE MEASURE / EVIDENCE