Europol
NEWS ROUNDUP – 20th March 2026
Microsoft Intune hardening guidance followed the Stryker breach, while ConnectWise patched a critical ScreenConnect flaw. Investigators tied Russian operations to a Zimbra breach and iPhone exploitation in Ukraine. Europol’s Operation Alice shuttered 373,000 dark-web sites, CISA flagged active SharePoint exploitation, and NIST issued final guidance on secure DNS deployment and 5G security design.
NEWS ROUNDUP – 6th March 2026
CISA added five newly exploited vulnerabilities to KEV as Cisco warned more Catalyst SD-WAN flaws are under active attack. Europol seized LeakBase and disrupted Tycoon 2FA, while Passaic County reported a malware outage and LexisNexis confirmed a data breach. Google challenged geofence warrants, and draft Cyber Resilience Act guidance signalled tougher product-security expectations for vendors and defenders globally this week.
NEWS ROUNDUP – 6th February 2026
CISA ordered U.S. agencies to remove unsupported edge devices as active exploitation of a GitLab flaw continues. Romania’s Conpet reported a cyberattack disrupting systems, while Flickr warned of member data exposure via a third-party email provider. The UK ICO opened investigations into X and xAI over Grok, as the European Commission advanced a cybersecurity package and NIST sought draft comments.
NEWS ROUNDUP – 12th January 2026
This cycle reinforces a DFIR reality: exposure risk often stems from basics—overshared cloud content, weak identity controls, and stale permissions—rather than exotic zero-days. APT credential-harvesting keeps accelerating through cheap infrastructure, so defenders should treat identity telemetry and web artifacts as primary evidence. Cross-border fraud arrests also show why disciplined logging and financial tracing matter during incident response and prosecutions worldwide.
NEWS ROUNDUP – 8th October 2025
CISA expands its Known Exploited Vulnerabilities list as Microsoft investigates active GoAnywhere MFT attacks. Japan’s Asahi Group faces a ransomware claim, while UK police arrest teens behind the Kido Nurseries breach. New NCSC guidance urges observability and proactive threat hunting. Global DFIR teams should prioritise patching, token hygiene, and compliance readiness amid rising cross-sector intrusions.
