AI Security
NEWS ROUNDUP – 30th March 2026
F5 BIG-IP exploitation escalated after a flaw was reclassified to critical RCE, while a Fortinet FortiClient EMS bug also came under active attack. The European Commission confirmed a data breach after the Europa web platform incident, and UK sanctions targeted infrastructure tied to Cambodia-based scam operations. NCA’s 2026 assessment also linked cybercrime more closely with wider organised offending patterns overall.
NEWS ROUNDUP – 4th March 2026
UK NCSC urged organisations to tighten monitoring amid Middle East spillover risks, while Cloudflare reported session-token abuse. AkzoNobel confirmed a breach at a U.S. site after an extortion leak claim, and Russian government portals suffered a multi-vector DDoS. CISA warned VMware Aria Operations is being exploited, and California’s privacy regulator fined PlayOn Sports $1.1M. Supreme Court heard geofence warrant challenge.
NEWS ROUNDUP – 19th January 2026
This cycle reinforces a persistent operational truth: the “end” of an incident is rarely the end of its consequences. Threat actors keep pushing toward low-friction entry points—browser extensions, loader chains, and access-broker marketplaces—so prevention and detection must focus on control-plane hygiene and behavior telemetry. Evolving EU policy and AI-security baselines signal that assurance requirements will increasingly follow technology adoption globally.
NEWS ROUNDUP – 17th December 2025
DFM’s latest 48-hour roundup covers ransomware recovery updates, major platform breaches, and active exploitation alerts, alongside fraud investigations and law enforcement crackdowns. Policy signals include UK resilience legislation progress and rising phishing of public officials, while NIST advances AI-era security profiles. The edition also tracks consumer app exposure risks and third-party telemetry weaknesses shaping incident response.
NEWS ROUNDUP – 1st December 2025
In this 48-hour roundup we track insider-driven mega breaches, disrupted court and logistics systems, and fresh leaks from healthcare and consumer apps. New OT and backend vulnerabilities join the KEV list, while Europol’s Cryptomixer takedown and UK ransomware-reporting plans show growing pressure on the criminal business model and on unprepared boards, demanding faster, evidence-led response and genuinely risk-based cyber governance.
