Compliance
NEWS ROUNDUP – 8th December 2025
The latest 48-hour DFM cybersecurity roundup highlights major breaches, active zero-day exploitation and rising regulatory pressure across global sectors. Key developments include the Coupang megabreach, React2Shell exploitation, Android emergency patches, strengthened G7 incident-response expectations and new NIS2-driven compliance duties. DFIR teams face escalating operational, legal and supply-chain risks as attackers refine extortion tactics and exploit software weaknesses.
NEWS ROUNDUP – 1st December 2025
In this 48-hour roundup we track insider-driven mega breaches, disrupted court and logistics systems, and fresh leaks from healthcare and consumer apps. New OT and backend vulnerabilities join the KEV list, while Europol’s Cryptomixer takedown and UK ransomware-reporting plans show growing pressure on the criminal business model and on unprepared boards, demanding faster, evidence-led response and genuinely risk-based cyber governance.
An Analysis of The Planned National Digital Identity Scheme (UK)
The UK’s proposed national digital ID scheme represents a major shift in identity assurance, with significant implications for security, privacy, digital inclusion and investigative practice. Costed at £1.8bn, the system will integrate with GOV.UK One Login and Wallet, offering stronger identity verification while introducing new risks, legal complexities and cybersecurity challenges requiring careful governance and oversight.
NEWS ROUNDUP – 28th November 2025
A global surge in third-party breaches, emergency-service outages, and supply-chain malware defined this 48-hour cycle. OpenAI’s Mixpanel incident, Asahi’s major data leak, and widespread disruptions at London councils and CodeRED highlight escalating systemic risk. New exploits, regulatory actions, and ISO-27001 advances reinforce the need for evidence-ready DFIR processes, developer-pipeline security, and stronger vendor oversight.
NEWS ROUNDUP – 26th November 2025
The latest 48 hours saw coordinated attacks on London councils, a breach at Harvard, and ransomware disrupting US emergency alerts. Industrial firm Balkrishna Paper Mills and major banking vendor SitusAMC also reported compromises. Active exploitation of a FortiWeb zero-day, a revived npm worm campaign, and a huge Android fiction-app data leak round out a high-impact period.

