supply chain risk
NEWS ROUNDUP – 11th March 2026
Microsoft fixed two disclosed zero-days in March Patch Tuesday, SAP shipped critical NetWeaver and FS-QUO fixes, and Dutch agencies warned that Russia-backed operators are hijacking Signal and WhatsApp accounts. Reuters also reported a customer-data breach at Loblaw, while ENISA published package-manager security guidance and the European Commission updated AI Act standardisation FAQs for high-risk systems across Europe and North America.
NEWS ROUNDUP – 27th February 2026
Joint NSA-partner guidance and an NHS alert urge urgent hunting and hardening for actively exploited Cisco Catalyst SD-WAN flaws. Dutch telco Odido reports attackers publishing stolen customer data, while ManoMano notifies 38 million users after a third-party breach. Trend Micro patched critical Apex One console RCE. DOJ says scam-center crypto freezes exceeded $580m. EU advanced an undersea cable protection plan.
NEWS ROUNDUP – 23rd February 2026
Ransomware disrupted University of Mississippi Medical Center clinics while Japan’s Advantest investigated a network intrusion. CISA warned BeyondTrust CVE-2026-1731 is exploited in ransomware, and a critical Grandstream VoIP flaw enables root RCE. PayPal reported customer-data exposure from an application error, and an Android AI media editor leaked millions of files, alongside indictments for ATM jackpotting.
NEWS ROUNDUP – 7th January 2026
Across regions, exploit-confirmed prioritization and identity-focused monitoring remain the quickest path to cutting incident volume. Public-sector resilience programs and privacy enforcement are tightening accountability, while third-party breaches keep fueling fraud. Strengthen evidence discipline: validate mail routing, inventory edge devices, and map vendor data flows. These seams are repeatedly exploited—and increasingly interrogated by regulators and boards in the next 48 hours.
NEWS ROUNDUP – 10th December 2025
Ransomware, supply-chain breaches and zero-day exploits dominate this 48-hour DFIR roundup. Hospitals, telecoms and e-commerce platforms face data theft, while regulators tighten data-sovereignty and patching expectations in Europe and India. New Windows and React vulnerabilities, AT&T’s dark web fallout and fresh law-enforcement advisories underscore why robust logging, rapid patching and vendor risk management remain non-negotiable for security and leadership teams.
