Incident Response
NEWS ROUNDUP – 17th October 2025
Microsoft dismantles Rhysida ransomware infrastructure and CISA issues 13 new ICS advisories, while breaches hit Sotheby’s and Malaysia’s Regency Hospital. California enforces a 30-day breach notification rule as ISO refreshes privacy standards. DFIR teams face renewed scrutiny of trust stores, industrial systems, and rapid-response readiness amid tightening global regulatory and law-enforcement actions.
NEWS ROUNDUP – 13th October 2025
Ransomware, data leaks, and zero-days dominated the past 48 hours. Qantas confirmed customer data was posted online, while Texas officials battled a municipal network breach. Healthcare ransomware rose 30%, and Apple doubled its top bug bounty. Germany’s rejection of EU “chat control” rules underscores encryption’s central role as DFIR teams confront escalating third-party and exploit risks.
NEWS ROUNDUP – 8th October 2025
CISA expands its Known Exploited Vulnerabilities list as Microsoft investigates active GoAnywhere MFT attacks. Japan’s Asahi Group faces a ransomware claim, while UK police arrest teens behind the Kido Nurseries breach. New NCSC guidance urges observability and proactive threat hunting. Global DFIR teams should prioritise patching, token hygiene, and compliance readiness amid rising cross-sector intrusions.
NEWS ROUNDUP – 6th October 2025
Oracle E-Business Suite zero-day (CVE-2025-61882) is being actively exploited, prompting global CERT advisories and extortion attempts linked to Clop. Asahi resumes operations after a ransomware-driven week-long outage. CISA adds a Meteobridge flaw to KEV. Europol spotlights cross-border data access gaps, while ETSI and ISO open security conferences shaping future compliance standards.
Crisis communication and real-world harm after security incidents
Silence after a crisis is never neutral. This analysis of Southport and Liverpool shows how delays in communication fuel rumours, conspiracy theories, and unrest, while timely, transparent disclosure can contain escalation. For DFIR teams, the lesson is clear: strategic, evidence-based communication is as vital as technical response in safeguarding trust.

