What’s in this roundup?
Both headline highlights from each existing section. Select a section to open it.
Digital Investigations
IU Health vendor access confirmed
Merrimack County investigation continues
→Cyber Investigations
Belnet breach enters investigation
WhatsApp student impersonation scams
→Major Cyber Incidents
Luminis restores MyChart services
CCQ widens breach protection
→Exploits & Threat Intelligence
Firefox 157 fixes high-risk flaws
WatchGuard AP flaws disclosed
→Law Enforcement
Cyber-intrusion pair sentenced
ShinyHunters suspect arrested
→Policy & Standards
UK cyber skills gaps widen
Australia proposes enforceable telco rules
→Indiana University Health said a vendor-managed legacy system used by a Southern Indiana imaging centre was accessed without authorisation after the vendor identified exposure to a previously unknown software vulnerability. IU Health said its core network and electronic medical record were unaffected, while its review found limited radiology files could contain names, dates of birth, health-plan identifiers and treatment information.
Merrimack County in New Hampshire said systems affected by a September network security incident are contained and there is no active threat, while an investigation into the disruption remains open. County officials are still determining whether personal information was involved, making preservation of access records, affected-system images and restoration evidence important for establishing scope and supporting any later notification decisions.
Belgium’s Belnet said the vulnerability behind a security and privacy incident on its BAMS infrastructure has been corrected and the breach contained after the issue was detected on 24 September. The national research and education network has now moved into a detailed investigation, with people who emailed Belnet between 22 July and 25 September directed to its data-protection contact over possible personal-data concerns.
Singapore Police warned that compromised WhatsApp accounts are being used to impersonate students and solicit payments from parents for fictitious youth exchange programmes or courses. At least eight cases involving losses of at least S$18,000 have been reported since September, with investigators linking the fraud to account compromise, impersonation, fabricated consent forms and PayNow payment requests that victims discovered were false after independent verification.
Luminis Health said MyChart and telephone services have been restored as recovery continues from its cybersecurity incident across the Maryland health system. Some patient notes, laboratory results and imaging records may still be unavailable in the portal while information created during downtime is scanned back into systems, leaving restoration sequencing and reconciliation of clinical records central to confirming completeness and continuity.
Quebec’s construction commission said operations have returned to normal after its cyberattack, while analysis has widened protection to additional former workers whose social insurance numbers may have been affected by stolen data. The CCQ is contacting those people for two years of credit and identity monitoring, while a police investigation and the organisation’s own analysis continue to determine the incident’s full scope.
Mozilla released Firefox 157 with fixes for multiple high-impact vulnerabilities, including use-after-free conditions, privilege escalation and several sandbox-escape flaws across navigation, process sandboxing and content processes. The advisory does not state that these flaws are being exploited, so investigation and remediation should distinguish exposure from confirmed compromise while retaining browser version, crash, endpoint and application telemetry where exploitation is suspected.
Canada’s Cyber Centre issued an advisory for WatchGuard AP vulnerabilities affecting versions before 3.4.8, including unauthorised API access and command-injection flaws in management interfaces. The notice urges administrators to review vendor guidance and apply updates, while any investigation of exposed appliances should preserve management logs, configuration changes, authentication records and network telemetry before remediation alters evidence of attempted or successful exploitation.
Two Delaware men were sentenced in Iowa to a combined 189 months in federal prison for roles in an international cyber-intrusion and business-email-compromise scheme targeting organisations across the United States. Prosecutors said phishing and spoofed email enabled theft of employee credentials and redirected payments, with the FBI and Air Force Office of Special Investigations supporting a case built around account access, fraudulent communications and money movement.
Dutch police said a 24-year-old Amsterdam man arrested on 15 September is suspected of participating in the ShinyHunters hacking group and separately of attempting to solicit two murders. Investigators seized data-storage devices for further examination, and police said additional arrests remain possible; wider reporting corroborates the arrest while attribution to specific ShinyHunters activity remains an allegation under investigation rather than an established finding.
The UK government’s 2026 cyber security labour-market study found that 57% of businesses reported a basic technical skills gap and that 47% of businesses and charities lacked confidence in managing a cyber breach. The findings also show a workforce of about 145,900 and increased use of artificial intelligence, providing policy evidence on the capability gaps that can affect evidence preservation, investigation and recovery when incidents occur.
Australia’s communications regulator opened consultation on a draft Telecommunications Consumer Protections Industry Standard intended to replace the existing industry-developed code with directly enforceable obligations. The proposed rules cover sales practices, credit assessments, payment options, service disconnection and remedies, giving investigators and compliance teams a clearer future framework for assessing provider conduct, consumer harm and records relevant to disputes involving phone and internet services.
Editorial Perspective
Across this cycle, the common investigative requirement is reliable evidence that survives containment, restoration and third-party remediation. Several organisations are moving from immediate control into deeper analysis, which makes preserved authentication records, system images, application logs and change histories essential to reconstructing access and data movement. The cases also show why investigators need evidence from suppliers and hosted services, not only from an organisation’s own network. Without that cross-platform correlation, scope and attribution can remain provisional long after services are restored.
Investigative readiness therefore depends on retention policies and access arrangements being established before an incident, particularly where healthcare, public services or managed platforms are involved. Vulnerability disclosures should be linked to observed telemetry rather than treated as proof of compromise, while actor or group attribution should remain qualified until device, account, infrastructure and communications evidence converge. Regulatory and workforce developments add another dimension because organisations need both competent people and defensible records to explain what happened. The strongest investigations will be those that preserve evidence while operational recovery is still under way.
Reference Reading
- NIST SP 800-86 — Guide to Integrating Forensic Techniques into Incident Response
- NIST SP 800-61 Rev. 3 — Incident Response Recommendations and Considerations
- NIST Cybersecurity Framework 2.0
- NCSC — Technical response capabilities: logs, evidence and analysis
- NCSC — Logging and protective monitoring guidance
- ICO — Personal data breaches: a guide


