Cyber Resilience Act
NEWS ROUNDUP – 6th March 2026
CISA added five newly exploited vulnerabilities to KEV as Cisco warned more Catalyst SD-WAN flaws are under active attack. Europol seized LeakBase and disrupted Tycoon 2FA, while Passaic County reported a malware outage and LexisNexis confirmed a data breach. Google challenged geofence warrants, and draft Cyber Resilience Act guidance signalled tougher product-security expectations for vendors and defenders globally this week.
NEWS ROUNDUP – 7th January 2026
Across regions, exploit-confirmed prioritization and identity-focused monitoring remain the quickest path to cutting incident volume. Public-sector resilience programs and privacy enforcement are tightening accountability, while third-party breaches keep fueling fraud. Strengthen evidence discipline: validate mail routing, inventory edge devices, and map vendor data flows. These seams are repeatedly exploited—and increasingly interrogated by regulators and boards in the next 48 hours.
NEWS ROUNDUP – 19th December 2025
In the last 48 hours, breaches and recoveries hit healthcare and retail, while investigators disrupted fraud marketplaces and laundering services. Major incidents affected oil logistics and UK government systems. Active exploitation warnings targeted React2Shell and SonicWall SMA, alongside new CISA ICS advisories. Policy and standards moved on UK cyber legislation, EU CRA reporting, and NIST’s Cyber AI profile this week.
NEWS ROUNDUP – 3rd December 2025
Ransomware-hit fintechs, leaked university staff records and a massive Coupang customer data exposure headline this 48-hour DFM roundup. Investigators crack camera-hacking and “digital arrest” scams, while Akira and other gangs push fresh victims onto leak sites. Meanwhile governments tighten ransomware and CRA policy, and insecure consumer apps spill highly sensitive personal data worldwide, raising pressure on boards, regulators and responders.
