Cyber Resilience Act
NEWS ROUNDUP – 25th March 2026
From Trivy’s supply-chain compromise and Citrix’s new NetScaler memory leak to Mazda’s Thailand breach, Stryker’s recovery update, and US sentencing tied to ransomware access brokering, this DFM roundup tracks incidents, investigations, enforcement, and policy shifts. It also covers NIST’s CSF 2.0 workforce guide, a DevSecOps draft, and Treasury’s cyber insurance review alongside Crunchyroll and Infinite Campus breach disclosures this week.
NEWS ROUNDUP – 23rd March 2026
Google reported access-to-operator handoffs dropping to 22 seconds, while Trio-Tech disclosed ransomware at its Singapore unit and Oracle shipped an emergency patch for a critical Fusion Middleware flaw. Europol said 373,000 dark web sites were shut down, and U.S. authorities sentenced facilitators tied to North Korean remote-worker infiltration and a separate business email compromise scheme targeting victims across borders globally.
NEWS ROUNDUP – 9th March 2026
Australia warned on Cisco SD-WAN exploitation, U.S. investigators examined a suspected China-linked FBI network breach, LexisNexis and TriZetto disclosed major data exposures, and authorities disrupted LeakBase and Tycoon 2FA. The roundup also tracks Google’s 90 zero-day tally for 2025, White House cyber strategy priorities, and European Commission guidance for applying the Cyber Resilience Act across health, government, telecom, and sectors.
NEWS ROUNDUP – 6th March 2026
CISA added five newly exploited vulnerabilities to KEV as Cisco warned more Catalyst SD-WAN flaws are under active attack. Europol seized LeakBase and disrupted Tycoon 2FA, while Passaic County reported a malware outage and LexisNexis confirmed a data breach. Google challenged geofence warrants, and draft Cyber Resilience Act guidance signalled tougher product-security expectations for vendors and defenders globally this week.
NEWS ROUNDUP – 7th January 2026
Across regions, exploit-confirmed prioritization and identity-focused monitoring remain the quickest path to cutting incident volume. Public-sector resilience programs and privacy enforcement are tightening accountability, while third-party breaches keep fueling fraud. Strengthen evidence discipline: validate mail routing, inventory edge devices, and map vendor data flows. These seams are repeatedly exploited—and increasingly interrogated by regulators and boards in the next 48 hours.
