Wednesday, September 23 2026
DFM News Roundup Golden Template V7.3

DFM News Roundup — 23rd September 2026

48-hour roundup 21-09-2026 09:33 to 23-09-2026 09:33 UTC

What’s in this roundup?

Both headline highlights from each existing section. Select a section to jump to and open it.

[AMER] Boston Scientific said CrowdStrike’s completed investigation found the 25 August intrusion began through an external-facing network device before reaching a limited portion of its on-premises IT environment, with no evidence of continued attacker activity after containment. Investigators found no evidence that cloud, manufacturing, product, medical-device, human-resources or SCADA systems were compromised, and no evidence that customer or patient data was accessed, staged or exfiltrated.

[APAC] Western Australia Police reported results from the first three months of its overt live facial-recognition trial, covering 77 deployments at 36 locations and 905,117 face scans that generated 209 alerts and eight incorrect alerts. The update provides measurable investigative-performance data for evaluating identification workflows, including how facial-recognition alerts are converted into officer action and how false matches must be documented and reviewed before being relied upon operationally.

[EMEA] Dutch police arrested a 21-year-old man in Groningen after a Limburg cybercrime investigation into services allegedly supporting bank-helpdesk fraud, including call-centre software, phishing websites, number spoofing and stolen-data checking. Officers seized data carriers for further examination, while investigators said the broader inquiry is intended to identify facilitators and potentially trace customers who acquired the criminal services through online marketplaces.

[APAC] Indore police arrested a 25-year-old man after tracing more than ₹906,000 in suspected cryptocurrency-investment fraud proceeds through a bank account that investigators linked to complaints in Karnataka and Dewas. Police said the inquiry used data from India’s national cybercrime reporting systems and is continuing to examine an alleged associate and other mule accounts, making transaction records and account relationships central to reconstructing the wider fraud network.

[GLOBAL] BigCommerce said attackers used compromised credentials for third-party Ribon applications to inject malicious scripts into a small number of merchant storefronts and access customer records, while the ecommerce platform itself was not breached. SecurityWeek reported that affected data at UK retailer Master of Malt included names, email addresses, telephone numbers and postal addresses, with BigCommerce revoking the application access and providing logs to support further investigation.

[GLOBAL] Microsoft disrupted EvilTokens after linking the AI-enabled phishing service to more than 12,000 compromised email inboxes across over 10,000 organisations worldwide, seizing 50 websites and disabling more than 150 supporting domains. Microsoft said investigators combined reverse engineering, legal action and intelligence sharing with UK police, who had arrested two suspected administrators, while wider public coverage corroborated the service’s global scale and device-code phishing model.

[GLOBAL] ReversingLabs identified a malicious npm package posing as an authorised Twilio security-research tool that checked for Twilio development environments and, in some versions, exfiltrated ACCOUNT_SID and AUTH_TOKEN credentials through a webhook. Researchers found eleven versions published on 14 August with changing behaviours, and said npm removed the package after notification, providing defenders with package-level indicators for repository and developer-environment investigations.

[AMER] Canada’s Cyber Centre warned that CVE-2026-94127, a heap-based buffer overflow affecting configured F5 BIG-IP Access Policy Manager deployments, is being exploited in the wild and urged administrators to apply available updates. The alert identifies the affected version ranges and configuration conditions, giving investigators a concrete basis for checking appliance versions, access-policy settings, exploitation indicators and relevant logs when assessing possible compromise.

[AMER] A US federal court sentenced Armenian national Karen Vardanyan to 24 months in prison and ordered $1,219,106 in restitution for his role in a conspiracy that deployed Ryuk ransomware against organisations in the United States and elsewhere. The Justice Department said the FBI investigation and Ukrainian cooperation supported his extradition, with the case documenting cryptocurrency-enabled extortion activity and cross-border evidential work spanning attacks conducted between 2019 and 2020.

[AMER] The Georgia Bureau of Investigation arrested and charged a 19-year-old Ellijay man with sexual extortion and unlawful surveillance offences following a police request for assistance in an investigation involving the alleged sextortion of a woman. The GBI said the inquiry remains active and will be referred to prosecutors when complete, leaving digital communications, devices and any surveillance evidence central to establishing the sequence and scope of the alleged conduct.

[EMEA] Sweden’s privacy regulator fined Miljödata SEK1.8 million after finding that inadequate technical and organisational safeguards preceded a 2025 intrusion in which personal data relating to about 2.2 million people was exposed and later published online. The regulator cited insufficient checks when installing new software and a lack of automatic real-time monitoring, turning the enforcement decision into a concrete benchmark for security controls, detection capability and evidential accountability under GDPR.

[AMER] NIST released an initial public draft of SP 800-82 Revision 4, updating guidance for operational-technology security across sectors including water, transport, building automation, maritime systems and industrial IoT. The draft aligns more closely with Cybersecurity Framework 2.0, expands asset-management and network-monitoring guidance, and adds zero-trust and enterprise-risk considerations that can improve the logs, inventories and architectural context available when investigating OT incidents.

Editorial Perspective

This cycle repeatedly shows that investigative confidence depends on reconstructing access paths rather than treating an incident label as evidence. Boston Scientific’s completed work narrows both the initial access route and the systems apparently left untouched, while the BigCommerce and npm cases show why third-party credentials, package provenance and application logs must be preserved alongside host evidence. The Dutch and Indian investigations similarly demonstrate the value of linking devices, accounts, transaction records and service infrastructure across organisational boundaries. Strong evidence handling therefore increasingly requires correlation across identity, network, application, financial and platform records.

Readiness also depends on collecting evidence before an incident becomes a retrospective reconstruction exercise. The F5 exploitation alert and NIST’s revised OT guidance both reinforce the need for accurate asset inventories, configuration records and monitoring data, while Sweden’s Miljödata decision shows the regulatory consequences when preventive controls and real-time detection are inadequate. Facial-recognition deployments add another evidential requirement: automated matches need traceable thresholds, error handling and human verification before they support operational decisions. Across the roundup, the common requirement is defensible provenance from detection through attribution, enforcement and regulatory review.

Reference Reading

Tags: digital investigations, cybercrime investigations, supply-chain compromise, EvilTokens, CVE-2026-94127, npm security, operational technology, live facial recognition, ransomware prosecution, GDPR security, evidence provenance

Share this roundup