OAuth abuse
NEWS ROUNDUP – 6th July 2026
This DFM 48h News Roundup covers AI-driven ransomware, browser data leakage, OAuth abuse, Mustang Panda activity, ransomware claims, SharePoint exploitation, Scattered Spider extradition, Japanese cybercrime enforcement, and policy developments from NIST and the European Parliament. The focus is digital investigations, evidential readiness, cross-platform artefacts, and the operational challenge of proving what happened.
NEWS ROUNDUP – 4th May 2026
Investigations span exposed property records in Tasmania, stolen Canvas student data, and a breach affecting Asian football organisations. Authorities warn of cyber-enabled cargo theft, while researchers link Shadow-Earth-053 to infrastructure targeting. Active cPanel exploitation and OAuth abuse campaigns expand attack surfaces, as new guidance highlights risks from autonomous AI systems and investigative challenges in evidence attribution.
NEWS ROUNDUP – 20th April 2026
Vercel traced a customer-impacting breach to a compromised OAuth app, while investigators in India linked abusive Google Drive activity to specific IP records. Police dismantled mule-account fraud networks, and a Scattered Spider member entered a guilty plea. Meanwhile, Bluesky faced DDoS disruption and UK officials advanced board-level cyber-resilience expectations across major organisations nationwide.

