Supply Chain Security
NEWS ROUNDUP – 1st May 2026
Europol fraud and Black Axe actions, Signal phishing targeting German officials, Singapore contractor data exposure, Winona County ransomware leaks, Itron and Medtronic network intrusions, active cPanel exploitation, malicious SAP npm packages, UK breach survey findings, and agentic AI security guidance shape this DFM 48-hour roundup for investigators focused on evidence, attribution, audit trails, and cross-platform correlation readiness.
NEWS ROUNDUP – 29th April 2026
Backdoored WordPress plugin updates created unauthorised access across production sites, while investigators examined coordinated campaigns targeting enterprise messaging infrastructure and exposed administrative tooling. Enforcement activity linked to DDoS-for-hire disruption operations and regulatory developments around AI and crypto governance further illustrated how technical compromise, investigative response, and policy intervention continue to converge across operational security environments.
NEWS ROUNDUP – 13th April 2026
This DFM 48-hour roundup tracks the European Commission cloud breach linked to the Trivy supply-chain compromise, emergency Adobe Reader zero-day patching, healthcare disruption at Signature Healthcare, UNC6783 targeting outsourced support functions, Operation Atlantic freezing more than $12 million tied to crypto fraud, and new policy movement on enterprise connected device security and EU digital wallet certification efforts.
NEWS ROUNDUP – 7th April 2026
This edition tracks a cloud-breach attribution at the European Commission, emergency remediation for actively exploited FortiClient EMS systems, and CISA action on a TrueConf flaw. It also covers a cyberattack on a Massachusetts emergency communications centre, Microsoft’s warning on fast-moving Medusa intrusions, and Cambodia’s new cybercrime law aimed at scams, laundering, recruitment, and illicit data handling.
NEWS ROUNDUP – 3rd April 2026
CISA flagged active exploitation of a Langflow flaw, while researchers warned ShareFile bugs can deliver unauthenticated remote code execution. Mercor confirmed fallout from the LiteLLM supply-chain compromise, Hasbro investigated unauthorized network access, and CERT-EU widened the scope of the Europa platform breach. Policy and standards developments also moved, from China’s digital-human draft rules to ENISA’s digital wallet certification work effort.
