Incident Response
NEWS ROUNDUP – 26th December 2025
Digital Forensics Magazine’s 48-hour cybersecurity roundup tracks the most actionable developments across incident response, investigations, major disruptions, and emerging threats worldwide. This edition highlights ransomware and DDoS impacts, a WatchGuard Firebox zero-day under active exploitation, and supply-chain risk from compromised repositories and malicious npm packages. It also covers law-enforcement crackdowns, policy shifts affecting identity verification and privacy, plus new standards guidance for protecting tokens and assertions.
NEWS ROUNDUP – 15th December 2025
In the past 48 hours, responders tracked macOS infostealer lures and a ransomware decryptor weakness, while regulators opened probes into UK mobile outages and Seoul investigators intensified action over Coupang. Major breach disclosures include 700Credit impacts, alongside React2Shell/KEV patch pressure. Enforcement operations targeted SIM and laundering networks. Consumer risks rose from exposed AI imagery, fiction-app records leaks, and fake apps.
NEWS ROUNDUP – 12th December 2025
This 48-hour DFM roundup tracks global cyber risk across DFIR, investigations, major incidents, exploitation and governance. Highlights include government email compromise, large-scale consumer breach fallout, OT and Windows patch triage, and enforcement actions disrupting hostile infrastructure. The meta theme is evidence readiness: deception telemetry, standardized baselines, supplier controls and rapid remediation are now inseparable from incident response and regulatory defensibility for teams.
When AI Becomes the Hacker
The first fully autonomous AI-driven cyber-espionage campaign marks a turning point in national-level cyber operations. Anthropic’s investigation into the state-aligned GTG-1002 group reveals how AI executed up to 90% of the intrusion lifecycle—reconnaissance, exploitation, lateral movement, and data theft—at machine speed. DFIR teams now face a new era of AI-orchestrated, high-velocity attacks.
NCSC Annual Review 2025
The NCSC Annual Review 2025 highlights a decisive year for UK cyber resilience, with record incident volumes and major strides in AI security, critical supplier oversight, and automation. Yet ransomware and supply-chain vulnerabilities persist. For DFIR professionals, the Review underscores urgency around governance accountability, rapid patching, dependency mapping, and post-quantum preparedness across critical national sectors.


