CNC A.I CyberSecurity Scoring
CNC
Company Information
Website:http://www.connective.eu
Employees number:8
Number of followers:0
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:connective.eu
CNC Risk Score (AI oriented)
Between 750 and 799
CNCIT Services and IT Consulting
Updated:
10/08/2026
10/08/2026
799/1000
Fair
Baa
CNC Global Score (TPRM)
xxxx
CNCIT Services and IT Consulting
Score locked

CNCFair
Current Score
799Baa (FAIR)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
799
AUGUST 2026
799
JULY 2026
799
JUNE 2026
799
MAY 2026
798
APRIL 2026
798
MARCH 2026
798
Vulnerability
17 Mar 2026 • CNC
Nitro Software Belgium: Connective eID Extension Flaws Let Attackers Steal Belgian ID PINs and Trigger Drive-By RCE
Critical Vulnerabilities in Belgium’s Connective Signing Extension Exposed Millions to Fraud and RCE
798
CRITICAL0
CON1786357491
Critical Vulnerabilities in Belgium’s Connective Signing Extension Exposed Millions to Fraud and RCE
Security researchers uncovered severe flaws in the Connective Signing Extension, a browser component used by over 2 million people in Belgium for accessing electronic identity (eID) cards and Maestro payment cards. The now-patched vulnerabilities could have enabled attackers to steal eID PINs, harvest card data, forge signing requests, and execute malicious code on Windows devices all with minimal user interaction.
### How the Flaws Worked
The extension acts as a bridge between websites, a browser plugin, and a native application that communicates with smart-card readers. However, researchers from Have I Been Pwned identified multiple critical weaknesses:
1. Token Replay Attacks – The extension failed to properly validate the origin of requests, allowing malicious websites to replay tokens issued to legitimate services. This could let attackers interact with the native host and extract data from connected eID or Maestro cards without the user’s knowledge.
2. PIN Phishing via Fake Dialogs – Attackers could display native-looking PIN prompts with custom titles and messages, impersonating trusted banking or government services. The stolen PIN, combined with access to an eID card, could enable unauthorized authentication or document signing.
3. Drive-By Remote Code Execution (RCE) – A command in the native host could load a library from an attacker-controlled path. By tricking users into downloading a malicious file, attackers could execute arbitrary code at the current user’s privilege level, even without an eID card connected.
### Broader Impact
Belgium’s eID system is integral to banking, public services, and legally binding electronic signatures under the EU’s eIDAS regulation. A compromised signing capability could facilitate account takeovers, fraudulent identity verification, or large-scale identity theft. Researchers demonstrated an account takeover involving Belgium’s CSAM (Child Abuse Material) reporting system, though impacts on other platforms depended on additional security controls.
### Remediation Timeline
Nitro Software Belgium, the company behind Connective and an EU-listed Qualified Trust Service Provider, deployed fixes in stages:
- Disabled the risky library-loading feature.
- Modified PIN-token handling to prevent decryption by malicious sites.
- Enforced origin checks for all requests.
The final patch was released 146 days after the initial report, though no CVEs were assigned at the time of disclosure. The vulnerabilities highlight the risks of third-party identity and payment integrations, particularly in high-trust environments like government and financial services.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
798
JANUARY 2026
798
DECEMBER 2025
798
NOVEMBER 2025
798
OCTOBER 2025
798
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for CNC ??
What was CNC's A.I Rankiteo Cyber Score in August 2026 ??
What was CNC's A.I Rankiteo Cyber Score in July 2026 ??
What was CNC's A.I Rankiteo Cyber Score in June 2026 ??
What was CNC's A.I Rankiteo Cyber Score in May 2026 ??
What was CNC's A.I Rankiteo Cyber Score in April 2026 ??
What was CNC's A.I Rankiteo Cyber Score in March 2026 ??
What was CNC's A.I Rankiteo Cyber Score in February 2026 ??
What was CNC's A.I Rankiteo Cyber Score in January 2026 ??
What was CNC's A.I Rankiteo Cyber Score in December 2025 ??
What was CNC's A.I Rankiteo Cyber Score in November 2025 ??
What was CNC's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on CNC's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with CNC ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view CNC's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?