P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

SConnect was fixed in the app stores 55 days before its CVE, but the desktop host is a separate install

Thales published CVE-2026-18397 on 1 October, 55 days after the SConnect fix reached the Apple store on 7 August, a date the finders also give for Chrome. SWIFT's own notice says the store updates the browser extension only: the desktop host needs a separate install.

By Parminder Kumar Sharma · · 19 min read

A dark finance desk at night. A wide monitor shows a payment approval page made only of blank rounded shapes, with one solid indigo button. In the foreground a small plain USB hardware token sits plugged into an unmarked aluminium hub on a walnut desk.

55 days between the store fix and the CVE, and what they do not show

Apple's store data puts the SConnect fix on 7 August 2026 at 16:03 UTC. The CVE record for CVE-2026-18397 went public on 1 October at 21:49 UTC. That is 55 days and nearly six hours, derived here from Apple's public lookup interface for the UK Mac App Store and the datePublished field of the CVE.org record. The researchers at Bay Area Labs date the Chrome Web Store fix to the same day, 7 August, and the removal of the Edge copy to 13 September, which is 18 days before the CVE. Those two dates rest on their report alone, because the Chrome listing shows only its latest build, 2.16.1.2, updated 12 August.

What 55 days does not establish is most of what the coverage implies. It does not show that anyone exploited the flaw: CISA's coordinator recorded exploitation as none on 2 October at 19:40 UTC, and the CVE is not in CISA's Known Exploited Vulnerabilities catalogue (version 2026.10.02, read on 4 October). It does not show who was exposed, because no source read for this briefing counts the unpatched. And it is not, by itself, a delay. Fixing first and publishing later is the usual order of coordinated disclosure, and the finders say they reported the flaw to Thales on 29 June, 94 days before the CVE. Earlier briefings on the MCP Python SDK and on Zimbra showed the same shape: a fix that predates its paperwork.

The gap is worth reading for a narrower reason. SConnect is two programs: a browser extension, which the browser's store delivers, and a native host, a desktop program with its own installer. Dark Reading's account says Thales patched SConnect in the app stores in August. That is true of the extension. SWIFT's own notice says the desktop half needs a separate install, and the CVE record places the flaw in that desktop half.

A to-scale timeline from 26 June to 6 October 2026. Reported to Thales 29 June. CVE ID reserved 30 July. Thales lists 2.16.1.0 on 4 August. Store fix 7 August, Apple per Apple data and Chrome per the report. Chrome lists 2.16.1.2 from 12 August. Edge copy removed 13 September per the report. SWIFT's sunset of SConnect 30 September. CVE published 1 October, 55 days after the store fix and 18 days after the Edge removal.
Drawn to scale from the CVE.org record, Apple's lookup interface, the Chrome Web Store listing, SWIFT's 3SKey help pages and the Bay Area Labs report. Read 4 October 2026.

How each date was checked

Six of the ten dates below can be read from a first-party source. Four rest on the finders' own timeline, which is their account of a private exchange with Thales.

Each date, where it comes from and how it was checked. UTC where the source gives a time. Read 4 October 2026.

  1. Date (2026)
    29 Jun
    Event
    Reported to Thales PSIRT
    Source and check
    Bay Area Labs report only. Not independently checkable.
  2. Date (2026)
    3 Jul
    Event
    Thales confirms; the report says a CVE was reserved
    Source and check
    Report only. The CVE.org record shows the ID reserved on 30 Jul, 27 days later.
  3. Date (2026)
    30 Jul
    Event
    CVE ID reserved
    Source and check
    CVE.org record, dateReserved 14:55 UTC.
  4. Date (2026)
    4 Aug
    Event
    Thales compatibility page for host 2.16.1.0 last updated
    Source and check
    Thales SConnect FAQ, read directly: Last Updated 2026/8/4.
  5. Date (2026)
    7 Aug
    Event
    Apple: two Safari builds at version 2.16.1
    Source and check
    Apple lookup, UK storefront: released 16:03 and 16:04 UTC. The release notes list native host hardening, security enhancements and SDK version matching, and name no vulnerability.
  6. Date (2026)
    7 Aug
    Event
    Chrome Web Store fix
    Source and check
    Report only. The listing now shows 2.16.1.2, updated 12 Aug.
  7. Date (2026)
    12 Aug
    Event
    Chrome lists 2.16.1.2
    Source and check
    Listing read 4 Oct. An Internet Archive capture of 2 Oct, 17:36 UTC, shows the same version and date.
  8. Date (2026)
    13 Sep
    Event
    Edge copy removed
    Source and check
    Report only. A search of Edge Add-ons on 4 Oct finds no SConnect, which is consistent with removal and is not proof.
  9. Date (2026)
    30 Sep
    Event
    SWIFT's sunset of SConnect for 3SKey tokens
    Source and check
    SWIFT Web Connect page, read directly.
  10. Date (2026)
    1 Oct
    Event
    CVE published
    Source and check
    CVE.org: 21:49 UTC. NVD lists it at 22:17 UTC.

The Apple row matters for a practical reason. A defender who read the store's release notes on 7 August would have seen "security enhancements", not a critical remote code execution fix. The CVE, the score and the word critical arrived 55 days later. A team that waits for a CVE before acting on an update to a security product has no ticket for those 55 days.

What the CVE record says, and who said it

The record carries two voices. Thales's product security team, Thales PSIRT, is the CNA, the body that assigned the ID, and it wrote the description, the 9.4 score and the weakness list. The second voice, CISA's ADP container (organisation ID 134c704f-9b21-4f2e-91b3-4a467353bcc0, which is CISA and not the vendor), adds only a triage entry. NVD carries no score of its own: its status was Deferred when read, and it lists Thales's score as secondary.

What CVE-2026-18397 carries, from the CVE.org record and the NVD API, read 4 October 2026

  1. Field
    Title
    Value
    SConnect: Native Host Unauthenticated Remote Code Execution Vulnerability
    Assigned by
    Thales PSIRT (CNA)
  2. Field
    Affected
    Value
    SConnect, every version from 0 up to but not including 2.16.1.0. The record gives no split by platform or component, though its description names the native host.
    Assigned by
    Thales PSIRT
  3. Field
    Score
    Value
    CVSS 4.0 base 9.4, Critical. Network, low complexity, no privileges, passive user interaction, high impact on the vulnerable and the subsequent systems.
    Assigned by
    Thales PSIRT
  4. Field
    Weaknesses
    Value
    CWE-347 improper verification of a cryptographic signature, CWE-130 length parameter inconsistency, CWE-457 use of an uninitialised variable, CWE-252 unchecked return value.
    Assigned by
    Thales PSIRT
  5. Field
    Triage
    Value
    SSVC: exploitation none, automatable no, technical impact total, stamped 2 Oct 2026 19:40 UTC.
    Assigned by
    CISA coordinator, in the CISA-ADP container
  6. Field
    Status
    Value
    NVD: Deferred, last modified 2 Oct 20:17 UTC. Not in the KEV catalogue.
    Assigned by
    NVD; CISA
  7. Field
    Reference
    Value
    One link, Thales's general PSIRT page, tagged vendor advisory.
    Assigned by
    Thales PSIRT

Two things stand out. First, the only reference in the record is a general page. When read on 4 October the Thales PSIRT page carried no SConnect advisory. Thales's dedicated advisories page answered with a bot check, which was not bypassed, and an Internet Archive capture of 15 September lists two advisories from May 2025 and nothing on SConnect. No Thales advisory text could therefore be read for this briefing. The fixed versions below come from SWIFT's page and from the affected range in the record.

Second, the SSVC entry is a judgement at a point in time. CISA's SSVC guide defines exploitation none as no evidence of active exploitation and no public proof of concept, and says answers should be time-stamped because the state changes. It defines automatable as whether an attacker can reliably automate the steps from reconnaissance to exploitation. CISA's coordinator answered no. The finders describe a visit-a-page attack that completed end to end in six to ten seconds in their testing. Both can be true: one is about reliable automation at scale, the other about a demonstration. Neither is evidence about what has happened in the wild.

Who is telling us what

Bay Area Labs describes itself as an independent security company. Its product is Am I Being Pwned?, a browser extension security service for organisations, and the SConnect report is published on that product's blog, where the extension catalogue also rates SConnect high risk with a note that its page is AI-generated and may contain errors. The finders therefore have a commercial interest in extension risk being taken seriously. That does not make the findings wrong. The CVE record, SWIFT's notice and Thales's own FAQ independently confirm the flaw, the fixed version and the update path.

What rests on the report alone: the 29 June report date, the 7 August Chrome date, the 13 September Edge removal, the 89,000 Edge users at removal, the statement that updated extensions can no longer reach the old host, and the six to ten second demonstration. The finders also had no 3SKey or eID to test with, and they tested only the Chrome Web Store build. Their own text says this "is not a story of incompetence"; coverage quotes harsher language. This briefing does not grade Thales's engineering. It grades what the record establishes. Dark Reading reported on 2 October that Thales had not yet responded to its request for comment, and no Thales statement was found.

Where the flaw sat in the chain

The shape is the one the finders flag as risky: any site, then an extension, then a native host. A page sends a message to the extension. The extension, whose content script runs in every frame, forwards it with the page's origin to a native host, a desktop program outside the browser's sandbox. The host decides whether the site is approved and, if so, lets the page drive the token and install add-ons. According to the report, approval depends on a token, signed by Thales, that the host fetches from the site and verifies.

The CVE record's wording is an "unrestricted messaging interface" between an attacker-controlled web page and the native host, combined with cryptographic and memory handling weaknesses that let malicious input bypass security checks. The report puts the weakness in an in-house implementation of the signature check that mishandled a failure case, and says that once the check was defeated the same routine also vouched for an add-on, which the host then loaded into its own process. This briefing stops at that level of detail on purpose.

Five stages left to right: any web page or iframe, the SConnect browser extension, the SConnect native host, the hardware token, and the system being signed into. The flaw sat in the native host, the separate desktop program, in how it verified a signed token from the site. The store updates the extension; a separate installer updates the host. The researchers had no token, so that stage was not tested.
Drawn from the CVE.org record, SWIFT's 3SKey SConnect page, Thales's SConnect FAQ and the Bay Area Labs report. Read 4 October 2026.

What the finders showed was code running inside the signed Thales host process on the workstation, reached from a web page, and invisible to the user in their account. Thales's FAQ describes an Origin Access dialog that asks the user to allow a site that has not been approved before. Whether that dialog would have appeared in the demonstrated flow is not stated. They had no 3SKey or eID, so they did not test what an attacker could do with a token present. The researcher told Dark Reading that relaying challenges to sign documents, stealing a session or moving money could follow, and that he could not prove it for lack of a token. That is a hypothesis from the finder, not a finding.

Hardware MFA protects the credential, not the program that brokers it

A hardware token is a control on a credential: it keeps a private key out of reach and makes a stolen password worthless. Nothing in this story defeats that. The token was not in the path of what was shown. What was shown was a web page talking a desktop program into running code, and the weak point was the software that sits between the page and the token. A FIDO-grade authenticator would be the same kind of control on the same part of the chain: it vouches for the credential, not for whatever software brokers it. Nothing read here describes 3SKey or the national eID cards as FIDO2 devices. SWIFT calls 3SKey "a multi-bank and multi-network personal digital identity solution".

What code on the workstation can do next is not shown. As inference, a compromised host or a stolen session sits after the token has done its job, so the token cannot stop either, and the approval a token gives is only as trustworthy as the machine asking for it. That is why a treasury team should care about the workstation as much as the token. Two earlier briefings make the same point from other directions: a rogue external MFA provider can simply ask for the password again, and device code phishing is a phish that MFA cannot stop.

The native host: who updates it, according to the people who ship it

This is the practical crux for defenders, and the primaries speak to it more clearly than the coverage does. Thales's own FAQ describes installing SConnect as separate steps, the extension from the browser's store and then a separate extension host installer, and describes uninstalling as two steps as well, with the host removed from the operating system's list of installed programs.

Stated and not stated about the desktop host, from SWIFT's pages, Thales's FAQ, the CVE record, the CISA entries, the Apple and Chrome listings and the Bay Area Labs report. Read 4 October 2026.

  1. Question
    Does the store update reach the desktop host?
    Stated
    No automatic path is described. SWIFT tells users to download host 2.16.1.0 and run its installer. Thales's FAQ lists the host as its own installed program.
    Not stated
    Any automatic or silent host update.
  2. Question
    New extension, old host?
    Stated
    SWIFT: SConnect is disabled until the host is upgraded. The report: updated extensions "no longer were able to communicate with the old native host".
    Not stated
    Whether the old host stays on disk, and whether anything else can still reach it.
  3. Question
    Which extension copies got the fix?
    Stated
    Chrome and Edge users through the Chrome store (SWIFT). Two Safari builds on 7 Aug (Apple). Firefox users install by hand (SWIFT).
    Not stated
    Edge installs that predate the 13 Sep removal: the report "cannot confirm" they were uninstalled. Any platform beyond the tested Chrome build.
  4. Question
    Which versions are affected?
    Stated
    Below 2.16.1.0 (CVE record). Version 2.16.0 and earlier (SWIFT). 2.16.0.0 demonstrated (report).
    Not stated
    A split by platform or component. A statement on the Safari, macOS or Linux hosts.
  5. Question
    Any sign of use against victims?
    Stated
    CISA triage: exploitation none (2 Oct). Not in the KEV catalogue (4 Oct). The report names no victim.
    Not stated
    Telemetry from Thales, SWIFT or any bank. Indicators of compromise. How many hosts are still unpatched.
  6. Question
    Has Thales said anything?
    Stated
    A host download page, and a CVE record that credits the finder.
    Not stated
    A dated advisory. Any statement on Edge copies. A comment to the press: none had arrived when Dark Reading published on 2 Oct.

Three practical consequences follow, and the first two are why the gap matters.

A stale host beside a current extension fails closed. According to SWIFT and the report, SConnect stops working rather than carrying on with the old host. That protects the browsers that updated. It leaves the extension copies that did not: Firefox installs, an Edge copy that was never removed and, as inference, managed or offline browsers where extension updates are held back. The primaries do not list that last group. It is a place to look, not a finding.

SWIFT's own installer button starts a workstation inside the affected range. On 4 October, SWIFT's token software page says the Install SConnect button "installs SConnect Host 2.13 and provides a link to update to SConnect Host 2.16.1.0". Version 2.13 is below the CVE's fixed version. A machine built from that button stays there until someone follows the link.

Removing the extension removes only the browser half. Thales's FAQ gives host removal as a separate step. An endpoint that dropped the extension may still carry a host below 2.16.1.0. Whether that host is reachable without an extension is not stated, but it is an affected version on the record and the one thing no store will ever update.

End of life is SWIFT's date, and the same vendor's replacement is not assessed

Dark Reading says SConnect reached end of life the month before it wrote. SWIFT's pages say something narrower. The SConnect page says SWIFT "plans to end support for SConnect in September 2026". The Web Connect page says "The vendor has announced the sunset of SConnect on 30 September 2026", after which SWIFT will not support SConnect with 3SKey tokens. That is a date for one use. Thales's updater page still offers eGovernment and eBanking variants beside the SWIFT one, and the Chrome listing was updated on 12 August. The CVE was published one day after SWIFT's date. The sources say nothing about a connection, so treat it as a coincidence of dates.

SWIFT's advice complicates the obvious fix. Its Web Connect page says that if you use SConnect to sign in to a treasury or bank application, do not uninstall it, because the application provider will say when it has moved to Web Connect, and the two can sit on one machine. So removal needs the provider's word, and the migration target is a product from the same vendor: the page names it Gemalto Web Connect and says installing it needs administrator rights. No source read here assesses it. A replacement is a migration plan, not a finding about its safety.

Who uses it, as far as the primaries go

Where SConnect use is evidenced, with the kind of source. Read 4 October 2026.

  1. Context
    SWIFT 3SKey portal; treasury and bank applications
    What the source says
    SConnect is "a browser extension that can be used to access the 3SKey portal"; do not uninstall it if a treasury or bank application uses it.
    Source
    SWIFT help pages, first-party
  2. Context
    Qatar national authentication
    What the source says
    An SConnect FAQ is hosted on a Qatar government domain, nas.gov.qa.
    Source
    Qatar page; named by the report
  3. Context
    Swedish Tax Agency
    What the source says
    Its page on the e-ID on its ID card says users need the SConnect browser plug-in.
    Source
    Agency page; Dark Reading names the agency
  4. Context
    Banking and insurance
    What the source says
    The report names BNP Paribas corporate banking, banks using Gemalto Ezio card readers and, "potentially historically", AG Insurance.
    Source
    Report only, not checked
  5. Context
    Product variants
    What the source says
    Thales's updater offers eGovernment, eBanking and eBanking Swift variants.
    Source
    Thales updater page
  6. Context
    How many users
    What the source says
    Chrome: 1,000,000 shown. Edge: 89,000 at removal. Apple: no count.
    Source
    Chrome listing; report

The report says outright that it does not know how many banks used SConnect. Neither does any other source read here. Bay Area Labs and Dark Reading call SConnect a main route into the SWIFT banking system; the SWIFT pages read describe the 3SKey portal and applications that use 3SKey tokens. Whether those are the same thing for a given bank is a question for that bank.

The UK angle: no UK name in the primaries, UK-named sibling extensions on the same store

No source read names a UK bank, treasury team or public body as an SConnect user. Both Apple builds are listed on the UK storefront, which says nothing about use. What a UK security lead can say today is narrower: the exposure is whichever endpoints carry the extension and the host, and the only way to know is to look.

There is one more place to look. A Chrome Web Store search for Gemalto Web Signer on 4 October returns extensions published under Thales names and titled for UK banks.

Thales-published Web Signer extensions with UK bank names on the Chrome Web Store, read 4 October 2026. A different product line from SConnect.

  1. Listing
    Gemalto Web Signer for NatWest
    Version and update date
    2.4.89, 16 July 2026
    Users shown
    None shown
  2. Listing
    Gemalto Web Signer for Lloyds Banking Group
    Version and update date
    2.4.92, 2 September 2026
    Users shown
    None shown
  3. Listing
    Web Signer for Barclays
    Version and update date
    2.3.1.7, 5 September 2026
    Users shown
    100,000
  4. Listing
    Gemalto Web Signer for Sign online CYBG
    Version and update date
    2.3.1.40, 22 January 2026
    Users shown
    None shown

No source read ties these to CVE-2026-18397, and none says whether they carry a native component. The finders say they have more digital signing extensions with similar weaknesses than they can report, and they name none. The listings are a prompt to inventory and to ask the vendor, not a finding. For a suspected compromise, the NCSC runs a cyber incident reporting service, and a regulated firm should tell its supervisor.

What to do, in the order worth doing it

Take this with you

Treasury and government portal endpoints, in order

  • Inventory both halves on every endpoint that touches SWIFT 3SKey, bank portals or government portals: the SConnect extension (Chrome Web Store ID mjhbkkaddmmnkghdnnmkjcgpphnopnfk, the two Safari apps from Thales DIS Czech Republic s.r.o., any Firefox or Edge copy) and the SConnect Host entry in the installed programs list. Record both versions. Include user-space installs, virtual desktop images and gold builds.
  • Confirm the fixed versions: host 2.16.1.0 or later and extension 2.16.1.1 or later, per SWIFT. Treat anything below 2.16.1.0 as affected, per the CVE record. Chrome listed 2.16.1.2 on 4 October 2026.
  • Find extension copies that cannot update: Firefox installs, extension versions pinned or blocked by policy, offline or non-persistent images. Update or remove these first, because an old extension is the route to an old host.
  • Check for an Edge copy and compare its version with the Chrome listing. No Thales statement on Edge installs already in place was found, and the finders could not confirm they were removed.
  • Ship your own host installer at 2.16.1.0 or later. SWIFT's Install SConnect button lays down version 2.13 first, so do not build new workstations from it.
  • Restrict who may install extensions and native hosts. Allow-list extensions by ID. In Chrome and Edge, set the native messaging block list to deny all hosts and allow only the host you name, and disable user-level native messaging hosts so that only system-level installs are honoured. Both browsers document these policies.
  • Review what each token or signing extension may talk to. The researchers' catalogue lists SConnect 2.16.0.0 as declaring access to all sites, to tab details and to native messaging. Ask every vendor of a token or signing extension which origins it accepts and how its host verifies them.
  • Treat treasury and government portal workstations as a tier of their own: a dedicated browser or profile used only for those portals, no general browsing or mail, extension and host allow-lists, application control on the host's folder, and outbound access limited to the portals. The demonstrated attack needed only a page visit.
  • Do not uninstall SConnect on a machine whose treasury or bank application still depends on it until the application provider confirms its move to Web Connect. SWIFT says so. Update it instead, and ask the provider for its date.
  • Hunt, then report. Look back as far as your logs allow for the SConnect host process starting child processes or writing libraries outside its install folder. That is a hunt idea, not an indicator: none has been published. Report a suspected compromise to the NCSC, to your supervisor if you have one, to your bank and to SWIFT.

The question that exposes the gap

The browsers were told on 7 August, by a store note that said "security enhancements". The desktop programs were told, if at all, by a SWIFT notice that users had to find, a ZIP they had to download and an EXE that somebody had to be allowed to run. Which of your treasury workstations is running SConnect host 2.16.1.0 today, and who told you?

Sources

  1. PrimaryThe CVE.org record for CVE-2026-18397, read in full: CNA, dates reserved and published, description, affected range, CVSS 4.0 score and vector, weaknesses, credit, and the CISA-ADP SSVC containerCVE Program, record assigned by Thales PSIRT as CNAaccessed 2026-10-04
  2. PrimaryThe NVD record for the same CVE, read through the NVD API at 10:58 UTC on 4 October 2026: status Deferred, last modified 2 October, Thales score carried as secondaryNIST National Vulnerability Databaseaccessed 2026-10-04
  3. PrimaryThe finders' own report of 2 October 2026, read in full: the flow, the timeline, the affected version, the Edge user count and the statement about the updated extension. Technical exploitation detail deliberately not reproducedBay Area Labs (Am I Being Pwned?)accessed 2026-10-04
  4. PrimarySWIFT's SConnect page, read in a browser: what SConnect is, the critical update to host 2.16.1.0 and extension 2.16.1.1, how the extension and host are updated, and the end of support planSWIFT 3SKey helpaccessed 2026-10-04
  5. PrimarySWIFT's Web Connect page: the sunset date of 30 September 2026, the advice not to uninstall SConnect, and the replacementSWIFT 3SKey helpaccessed 2026-10-04
  6. PrimarySWIFT's token software installation page: the Install SConnect button that installs host 2.13 and links to 2.16.1.0SWIFT 3SKey helpaccessed 2026-10-04
  7. PrimaryThe 3SKey home page: how 3SKey describes itself and its September 2026 notice that Web Connect replaces SConnectSWIFT 3SKeyaccessed 2026-10-04
  8. PrimaryThales's official SConnect FAQ: separate extension and extension host installation, two-step uninstall, the Update Native Host dialog, the Origin Access dialog, and the compatibility page for 2.16.1.0 last updated 2026/8/4Thales Groupaccessed 2026-10-04
  9. PrimaryThales's official SConnect updater page: eGovernment, eBanking and eBanking Swift variants and the instruction to download the host from SwiftThales Groupaccessed 2026-10-04
  10. PrimaryThe SConnect listing read on 4 October 2026: version 2.16.1.2, updated 12 August 2026, 1,000,000 users, developer Thales DIS Czech Republic s.r.o.Google Chrome Web Storeaccessed 2026-10-04
  11. PrimaryA capture of the Chrome Web Store listing at 17:36 UTC on 2 October 2026, showing the same version, update date and user countInternet Archiveaccessed 2026-10-04
  12. PrimaryApple's public lookup interface for the UK storefront: two Safari web extension apps by Thales DIS Czech Republic s.r.o., version 2.16.1, current version released 7 August 2026 at 16:03 and 16:04 UTC, with release notesAppleaccessed 2026-10-04
  13. PrimaryA search of the Edge Add-ons store for sconnect on 4 October 2026, which returned three unrelated extensionsMicrosoft Edge Add-onsaccessed 2026-10-04
  14. PrimaryThe Known Exploited Vulnerabilities catalogue, version 2026.10.02 released 2 October 2026, 1,733 entries: CVE-2026-18397 is not listedCISAaccessed 2026-10-04
  15. PrimaryThe CISA SSVC guide, used for the definitions of the exploitation and automatable values and the advice to time-stamp answersCISAaccessed 2026-10-04
  16. PrimaryThales's PSIRT page, the only reference in the CVE record: a general page that carries no SConnect advisoryThales Groupaccessed 2026-10-04
  17. PrimaryA capture of Thales's product security advisories page from 15 September 2026, listing two advisories dated May 2025 and none for SConnect. The live page answers with a bot check, which was not bypassedInternet Archiveaccessed 2026-10-04
  18. PrimaryAn SConnect FAQ page hosted on a Qatar government domain, supporting the report's statement that Qatar's national authentication system uses SConnectQatar National Authentication Systemaccessed 2026-10-04
  19. PrimaryThe agency's page on the e-ID carried by its ID card, which says users need the SConnect browser plug-inSkatteverket (Swedish Tax Agency)accessed 2026-10-04
  20. PrimaryA store search for Gemalto Web Signer on 4 October 2026, returning Thales-published Web Signer extensions named for UK banks, with version, update date and user figures read from each listingGoogle Chrome Web Storeaccessed 2026-10-04
  21. PrimaryChrome's documentation of the native messaging block list, allow list and user-level hosts policiesGoogle Chrome Enterpriseaccessed 2026-10-04
  22. PrimaryMicrosoft Edge's documentation of the equivalent native messaging policiesMicrosoft Learnaccessed 2026-10-04
  23. PrimaryThe NCSC's service for reporting a cyber security incidentNational Cyber Security Centreaccessed 2026-10-04
  24. PrimaryThe finders' own description of themselves and of their product, Am I Being Pwned?, a browser extension security service for organisationsBay Area Labsaccessed 2026-10-04
  25. Reported byNews coverage of 2 October 2026 by Nate Nelson, the pointer to the story. Its claims were checked against the primaries above; the researcher's speculation about wider attacks and the statement that Thales had not responded rest on this article aloneDark Readingaccessed 2026-10-04

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

How often

Every new briefing in one email, at 7am, or at 7am, 12:30pm and 6pm. Nothing is sent when nothing is new. Unsubscribe any time.