Wednesday, April 29 2026

News Centre

Here you can access the latest 48hr Global News Roundups from DFM

We scour the internet to find the latest stories relating to:

DFIR, Cyber Investigations, Major Cyber Incidents, Exploits & Threat Intelligence, Law Enforcement, Policy, Standards & Compliance and Consumer App Data Leaks

We also provide an Editorial Perspective and a Reference List for further reading.

NEWS ROUNDUP – 29th April 2026

29/04/2026

Backdoored WordPress plugin updates created unauthorised access across production sites, while investigators examined coordinated campaigns targeting enterprise messaging infrastructure and exposed administrative tooling. Enforcement activity linked to DDoS-for-hire disruption operations and regulatory developments around AI and crypto governance further illustrated how technical compromise, investigative response, and policy intervention continue to converge across operational security environments.

NEWS ROUNDUP – 27th April 2026

27/04/2026

This 48-hour roundup covers FIRESTARTER on a Cisco ASA device, Signal phishing targeting German politicians, GopherWhisper activity against government targets, ADT and Medtronic data incidents, Breeze Cache exploitation, CISA KEV additions, Singapore and Telangana cybercrime arrests, and Cyber Essentials Danzell transition guidance, with emphasis on evidence integrity, platform records, vulnerability exposure, and cross-border investigative readiness.

NEWS ROUNDUP – 24th April 2026

24/04/2026

This 48-hour global roundup covers UK Biobank data appearing for sale in China, Eurail passport data exposure, Indonesian phishing-tool arrests, Toronto SMS-blaster seizures, France Titres breach claims, UMMC forensic review, China-nexus covert device networks, CrowdStrike LogScale vulnerability fixes, US scam-centre action, a BlackCat guilty plea, Japan’s financial cyber taskforce, and NCSC passkey guidance for consumer authentication.

NEWS ROUNDUP – 22nd April 2026

22/04/2026

French identity services faced potential data exposure, while New South Wales investigated unauthorised transfers of confidential Treasury files. Ukrainian police dismantled a Telegram bot farm supporting disinformation campaigns, and U.S. prosecutors secured guilty pleas in ransomware and phishing cases. Meanwhile, new .NET vulnerabilities and serial-to-IP device flaws highlighted ongoing exposure risks across connected infrastructure environments.

NEWS ROUNDUP – 20th April 2026

20/04/2026

Vercel traced a customer-impacting breach to a compromised OAuth app, while investigators in India linked abusive Google Drive activity to specific IP records. Police dismantled mule-account fraud networks, and a Scattered Spider member entered a guilty plea. Meanwhile, Bluesky faced DDoS disruption and UK officials advanced board-level cyber-resilience expectations across major organisations nationwide.

NEWS ROUNDUP – 17th April 2026

17/04/2026

Digital Forensics Magazine’s latest 48-hour roundup covers a WordPress plugin supply-chain compromise, espionage malware targeting Ukrainian emergency services, McGraw Hill’s reported 13.5 million-account breach, and Europol’s disruption of DDoS-for-hire infrastructure. It also tracks active exploitation of nginx-ui and Apache ActiveMQ flaws, UK crypto regulation proposals, and unauthorised access affecting Booking.com reservations and Inditex transaction databases across European retail systems globally.

NEWS ROUNDUP – 15th April 2026

15/04/2026

Microsoft fixed an exploited SharePoint zero-day among 165 flaws, Adobe patched critical Acrobat bugs, and Basic-Fit disclosed a breach affecting about one million members. Investigators traced mailbox compromises hitting Ukrainian prosecutors, while authorities froze stolen cryptocurrency in Operation Atlantic. Regulators and central bankers also escalated scrutiny of Anthropic’s Claude Mythos Preview and its cybersecurity implications for financial stability and resilience.

NEWS ROUNDUP – 13th April 2026

13/04/2026

This DFM 48-hour roundup tracks the European Commission cloud breach linked to the Trivy supply-chain compromise, emergency Adobe Reader zero-day patching, healthcare disruption at Signature Healthcare, UNC6783 targeting outsourced support functions, Operation Atlantic freezing more than $12 million tied to crypto fraud, and new policy movement on enterprise connected device security and EU digital wallet certification efforts.

NEWS ROUNDUP – 10th April 2026

10/04/2026

Ransomware at ChipSoft disrupted Dutch hospitals, while Signature Healthcare diverted ambulances after a cyberattack. UK authorities linked router hijacking to a Russian military unit, and Northern Ireland schools faced network outages. Treasury launched crypto threat sharing, the NCA froze $12 million in scam proceeds, and NIST advanced AI risk guidance for critical infrastructure operators amid rising supplier and mobile exposure.