Snapshot Summary
| Sector / Section | Headline Highlights | Count |
|---|---|---|
| Digital Investigations | Edge forensics and device correlation | 2 |
| Cyber Investigations | Cross-border tracing and breach evidence | 2 |
| Major Cyber Incidents | Payroll ransomware and fintech exposure | 2 |
| Exploits & Threat Intelligence | AsyncOS and Vite exploitation | 2 |
| Law Enforcement | Courier fraud and identity theft | 2 |
| Policy & Standards | Platform safeguards and cyber decoys | 2 |
Digital Investigations
[EMEA] Brevo’s 17 September post-mortem said attackers used a stolen, long-lived Cloudflare API key to create an edge Worker that altered company pages and embedded customer scripts for roughly five and a half hours. Investigators found the key had been hardcoded in application source, while origin files remained unchanged, helping explain why standard integrity checks did not detect the manipulation (Source: BleepingComputer, 17-09-2026).
[APAC] New Zealand Police said Operation Jacaranda linked a series of North Shore offences after detectives reviewed extensive CCTV, social-media material and forensic examinations of mobile phones. The combined evidence allowed investigators to associate further alleged incidents with the same group, demonstrating how device artefacts and open-platform content can be correlated to extend an inquiry beyond the offence that originally triggered it (Source: New Zealand Police, 17-09-2026).
Cyber Investigations
[APAC] Delhi Police said five people were arrested after investigators traced 317 unauthorised transactions that removed about ₹12.84 crore from Hero FinCorp and allegedly routed proceeds through mule accounts connected to handlers in China and Dubai. The inquiry identified a bank relationship manager accused of helping establish accounts used in the transfers, adding financial records and account-opening evidence to the cross-border investigative trail (Source: ThePrint, 17-09-2026).
[APAC] Victoria Police charged two CFMEU officials as Taskforce Hawk and Cybercrime Squad detectives continued investigating an alleged data breach involving personal information and intimate images of a former member. Officers executed a search warrant at a St Albans Park address and seized a mobile phone, while investigators continue assessing information and previously seized devices to establish the distribution pathway and responsibility for the alleged disclosures (Source: Victoria Police, 17-09-2026).
Major Cyber Incidents
[APAC] Singapore’s MUIS said investigations into the ransomware incident affecting Avelogic’s HR and payroll platform currently show no evidence that a large amount of data was taken, although checks remain ongoing. The affected community organisations include 48 mosques and four madrasahs; data was recovered, alternative payroll arrangements are operating, no ransom was paid, and the system will remain offline until safeguards and security checks are completed (Source: MUIS, 17-09-2026).
[EMEA] Revolut is facing a reported $3 million extortion demand after attackers obtained information relating to about 680 cryptocurrency customers through fraudulent requests sent from a compromised Italian government email system. Revolut has confirmed the data exposure but says its internal systems and customer funds were not compromised; the ransom demand remains an attacker claim, while law-enforcement and regulatory investigations continue across affected jurisdictions (Source: The Guardian, 17-09-2026).
Exploits & Threat Intelligence
[GLOBAL] Cisco updated its Secure Email Gateway advisory on 17 September after CVE-2026-76461, a critical AsyncOS SQL-injection flaw, was reported under active exploitation. A crafted email can allow an unauthenticated remote attacker to execute SQL statements and ultimately commands with root privileges; Cisco has issued fixed software, provides no workaround, and recommends reviewing mail logs for suspicious SQL activity that may indicate attempted exploitation (Source: Cisco, 17-09-2026).
[GLOBAL] Singapore’s Cyber Security Agency warned that CVE-2026-39364 in Vite development servers is being actively exploited to retrieve restricted system and configuration files over HTTP. The unauthenticated file-read and access-list bypass affects Vite 7.1.0 through 7.3.1, Vite 8.0.0 through 8.0.4 and Vite-plus 0.1.15 and earlier, with administrators advised to update affected deployments to current fixed versions (Source: Cyber Security Agency of Singapore, 17-09-2026).
Law Enforcement
[EMEA] West Midlands Police charged two Birmingham men with conspiracy to commit fraud after an investigation into courier fraud that has cost nine local victims more than £100,000 since April. Police allege offenders posed as officers, persuaded victims to surrender bank cards as part of a fictitious investigation, and then used the cards for fraudulent transactions; both defendants were remanded for a further hearing next month (Source: West Midlands Police, 17-09-2026).
[AMER] A former Ohio bank employee was sentenced to ten years in prison after a federal jury convicted him of bank fraud, aggravated identity theft and money laundering involving elderly customers. Prosecutors said he created email accounts in victims’ names, enrolled them in online banking without permission and redirected funds to accounts he controlled, with the FBI investigation attributing about $2 million in unauthorised transfers to the scheme (Source: US Department of Justice, 17-09-2026).
Policy & Standards
[EMEA] The European Commission adopted the proposed EU KIDS Act on 17 September, setting new online-safety requirements intended to restrict social-media access for children and place greater responsibility on providers. The proposal introduces an EU-wide minimum age framework and requires services to demonstrate that they are age-appropriate and safe by design, creating new compliance and evidence expectations for platforms operating across Member States (Source: European Commission, 17-09-2026).
[AMER] CISA published new guidance on using cyber decoys alongside Zero Trust controls to improve detection of intruders using legitimate credentials, native tools and living-off-the-land techniques. The guidance describes tripwires, breadcrumbs, honeytokens and other decoy assets as mechanisms for generating high-fidelity alerts and collecting threat information, while stressing that organisations should plan, test and refine deployments using MITRE Engage and ATT&CK concepts (Source: CISA, 16-09-2026).
Editorial Perspective
Across this cycle, the strongest investigative theme is the need to preserve and correlate evidence across systems that no longer share a single trust boundary. Cloud-edge manipulation, mobile-device examination, transaction tracing and third-party service dependencies each create different records, but useful conclusions depend on establishing timelines that connect those records without overstating what they prove. Investigative readiness therefore rests on dependable logging, retained access history and clear ownership of evidence held by providers or intermediaries. Where those records are incomplete, attribution and scope can remain uncertain even after technical recovery.
The coverage also shows why evidential integrity increasingly matters beyond the immediate investigation. Regulators, courts, affected organisations and law-enforcement teams may all need to rely on the same artefacts while asking different questions about responsibility, impact and compliance. That makes provenance, timestamps, chain of custody and documented analytical assumptions central to defensible conclusions, particularly when attacker claims or automated detections are involved. Organisations that design those requirements into systems before an incident will be better placed to reconstruct events and distinguish confirmed facts from plausible but unverified explanations.
Reference Reading
Tags
Cloudflare Workers, digital evidence, ransomware, mule accounts, CVE-2026-76461, CVE-2026-39364, courier fraud, identity theft, online safety, cyber decoys
