DFIR
NEWS ROUNDUP – 9th February 2026
European Commission contained suspicious activity against its device management platform, while reports highlighted CERT-EU indicators on infrastructure. Microsoft warned of active exploitation of SolarWinds Web Help Desk flaws. Singapore’s telco sector investigated an alleged state-linked intrusion as Winter Olympics services faced disruption attempts. UK authorities examined cyber-sanctions compliance and NIS bill progress, and Substack and Coupang disclosed user data exposure.
NEWS ROUNDUP – 6th February 2026
CISA ordered U.S. agencies to remove unsupported edge devices as active exploitation of a GitLab flaw continues. Romania’s Conpet reported a cyberattack disrupting systems, while Flickr warned of member data exposure via a third-party email provider. The UK ICO opened investigations into X and xAI over Grok, as the European Commission advanced a cybersecurity package and NIST sought draft comments.
NEWS ROUNDUP – 1st February 2026
Ivanti Endpoint Manager Mobile zero-days drove urgent patching and forensic hunts, while US authorities seized the RAMP cybercrime forum and forfeited $400M tied to crypto laundering. Major incidents disrupted US municipal services, hosting infrastructure, and fintech platforms. Policy moved with a UK–Japan cyber partnership, alongside standards updates shaping vulnerability disclosure, random number generation assurance, and compliance expectations globally.
DFM Briefing on the UK Forensic Science Regulator Guidance [GUI-0004]
FSR-GUI-0004 sets clear expectations for how forensic evidence should be interpreted and communicated within the Criminal Justice System. This briefing explains the guidance’s scope, regulatory intent, and practical requirements, including evaluative reasoning, likelihood ratios, bias control, and competence. It assesses implications for digital forensics and incident response, highlighting operational challenges, risks, and areas where implementation discipline will determine credibility outcomes.
NEWS ROUNDUP – 30th January 2026
Nike investigated an extortion-linked breach claim, Rotterdam port operations faced hacktivist-driven DDoS disruption, and CISA added actively exploited Ivanti EPMM vulnerabilities to its KEV catalogue. Law enforcement seized the RAMP cybercrime forum, while NIST advanced its Cyber AI Profile consultation. Identity compromise, control-plane abuse, and data-only extortion dominated incident response priorities globally.

