Cybersecurity News
NEWS ROUNDUP – 3rd November 2025
BADCANDY reinfection warnings, telecom resilience failures, and new DDoS alerts dominated the last 48 hours. The Philippines DICT warned of a possible 5 November cyberattack, while Australia’s Optus outage review exposed change-control gaps. Global DFIR teams are urged to verify router hygiene, review vendor trust chains, and monitor evolving breach-reporting rules shaping future compliance.
NEWS ROUNDUP – 31st October 2025
ACSC and CISA released synchronized Exchange Server hardening guidance as new KEV entries and ICS advisories highlight active exploitation across IT and OT systems. Major incidents hit Ribbon Communications and Conduent, while U.S. prosecutions target Conti and insider espionage cases. DFIR teams should prioritize patch validation, supplier risk reviews, and Exchange baseline enforcement.
NEWS ROUNDUP – 29th October 2025
Qilin ransomware tactics evolve, commercial spyware resurfaces, and municipal services face fresh extortion pressure. A Lanscope zero-day and BIND 9 risks demand swift patching, while Singapore tackles SIM-fraud networks on the ground. New supply-chain ransomware guidance and crypto-finance sanctions signal policy tightening. Plus, standards shifts in ICMPv6 and hashing preview changes coming to defensive stacks.
NEWS ROUNDUP – 27th October 2025
Qilin ransomware tactics evolve, commercial spyware resurfaces, and municipal services face fresh extortion pressure. A Lanscope zero-day and BIND 9 risks demand swift patching, while Singapore tackles SIM-fraud networks on the ground. New supply-chain ransomware guidance and crypto-finance sanctions signal policy tightening. Plus, standards shifts in ICMPv6 and hashing preview changes coming to defensive stacks.
NEWS ROUNDUP – 15th October 2025
Microsoft’s October Patch Tuesday, new CISA KEVs, and Oracle’s emergency ERP fixes headline a high-intensity 48-hour cycle. Law enforcement advanced with major crypto-fraud indictments and the UK ICO’s £14 million Capita fine. Global advisories from the NCSC and ISO refreshed defence and privacy standards, underscoring the convergence of regulatory accountability, ERP exploitation risk, and industrial system resilience.
