npm
DFM News Roundup – 5th August 2026
This edition examines SharePoint compromise, AI agents exceeding test boundaries, malicious npm packages, counterfeit developer extensions and third-party data exposure. It also covers police investigations into impersonation and investment fraud, alongside new Australian AI governance guidance and Singapore’s proposed anti-scam legislation. The editorial focus is evidence preservation, source qualification, supply-chain visibility and defensible incident reconstruction across increasingly interconnected systems globally.
NEWS ROUNDUP – 25th February 2026
Australia’s ACSC released Azul, an open-source malware analysis tool, as defenders tracked vishing-driven access at Optimizely and extortion claims hitting Wynn Resorts and Air Côte d’Ivoire. Researchers detailed a GitHub Copilot prompt-injection chain and an NPM supply-chain campaign dubbed Sandworm_Mode. Spain arrested Anonymous Fénix suspects, while U.S. Treasury sanctioned a bulletproof hosting provider. NIST updated CSF guidance; CarGurus disclosed breach.
NEWS ROUNDUP – 26th December 2025
Digital Forensics Magazine’s 48-hour cybersecurity roundup tracks the most actionable developments across incident response, investigations, major disruptions, and emerging threats worldwide. This edition highlights ransomware and DDoS impacts, a WatchGuard Firebox zero-day under active exploitation, and supply-chain risk from compromised repositories and malicious npm packages. It also covers law-enforcement crackdowns, policy shifts affecting identity verification and privacy, plus new standards guidance for protecting tokens and assertions.
NEWS ROUNDUP – 10th September 2025
In the past 48 hours, defenders juggled Plex breach fallout, Microsoft’s Patch Tuesday triage, and npm supply-chain hijacks. Adobe Commerce shipped critical fixes, while healthcare and media breaches broadened impact. U.S. prosecutors charged a multi-ransomware administrator and posted rewards. Takeaways: accelerate credential resets, lock down publish keys, and run disciplined emergency patch cycles. Prioritize monitoring, SBOM mapping, and phishing verification.

