consumer data leak
NEWS ROUNDUP – 4th February 2026
CISA warned on Avation Light Engine Pro OT risk as CERT-FR prioritised weekly patches. Investigators tracked Notepad++ updater hijacking and coercive Scattered Lapsus ShinyHunters tactics. Major incidents included Coinbase contractor misuse, NationStates breach downtime, and an Iron Mountain data-theft claim. CISA added SolarWinds Web Help Desk RCE to KEV while Metro and Office exploits circulated across Europe, Americas, and APAC.
NEWS ROUNDUP – 12th January 2026
This cycle reinforces a DFIR reality: exposure risk often stems from basics—overshared cloud content, weak identity controls, and stale permissions—rather than exotic zero-days. APT credential-harvesting keeps accelerating through cheap infrastructure, so defenders should treat identity telemetry and web artifacts as primary evidence. Cross-border fraud arrests also show why disciplined logging and financial tracing matter during incident response and prosecutions worldwide.
