Critical Infrastructure
NEWS ROUNDUP – 2nd March 2026
CISA updated hunting guidance for RESURGE malware lingering on Ivanti appliances, while Juniper warned of a critical PTX router takeover flaw. Reuters tracked cyber operations hitting Iranian apps and sites after strikes, as Sophos monitored Iran-linked hacktivist claims. In the US, UH Cancer Center reported SSN exposure affecting up to 1.15 million people. Substack disclosed stolen emails and phone numbers.
NEWS ROUNDUP – 27th February 2026
Joint NSA-partner guidance and an NHS alert urge urgent hunting and hardening for actively exploited Cisco Catalyst SD-WAN flaws. Dutch telco Odido reports attackers publishing stolen customer data, while ManoMano notifies 38 million users after a third-party breach. Trend Micro patched critical Apex One console RCE. DOJ says scam-center crypto freezes exceeded $580m. EU advanced an undersea cable protection plan.
NEWS ROUNDUP – 26th January 2026
Microsoft issued out-of-band Windows fixes for Outlook freezes and probed post-update boot failures as investigators tracked Cambodia-based scam networks repatriated to South Korea. ESET tied Sandworm to a DynoWiper power-sector attempt, while Fortinet and CISA warned on FortiCloud SSO abuse and exploited vCenter flaws. Policy moves spanned NHS supplier assurance, Australian smart-device rules, and Korean breach scrutiny in this window.
NEWS ROUNDUP – 23rd January 2026
Cisco patched a Unified Communications RCE (CVE-2026-20045) amid active exploitation, while CSA Singapore urged urgent updates. CISA issued a batch of ICS advisories for OT operators. Investigators tracked the Telegram-linked Tudou Guarantee marketplace and authorities tied suspects to Black Basta. Policy moved on Ireland’s spyware law, EU high-risk vendor phase-out, and UK NIS Bill progress. Chainlit flaws threatened cloud apps.
NEWS ROUNDUP – 21st January 2026
Over the past 48 hours, responders tracked UK warnings on Russia-aligned DDoS activity, Ingram Micro’s disclosure affecting 42,000 people, and a brief hijack of Iranian state television feeds. Investigations detailed LinkedIn-delivered malware and Gemini prompt injection, while policymakers advanced EU cybersecurity reforms, new UK fraud reporting, and Singapore issued fresh vulnerability advisories impacting cloud deployments, broadcast resilience, and response planning.
