Supply Chain Security
NEWS ROUNDUP – 1st April 2026
Europe’s Commission disclosed data theft from cloud infrastructure, while CISA ordered urgent Citrix patching for active exploitation. U.S. prosecutors charged a suspect over the $50 million Uranium Finance hacks, and researchers linked the axios npm supply-chain compromise to North Korean actors. The roundup also tracks UK scam-centre sanctions, Italy’s Intesa breach fine, and Lloyds’ mobile banking data exposure this week.
NEWS ROUNDUP – 23rd March 2026
Google reported access-to-operator handoffs dropping to 22 seconds, while Trio-Tech disclosed ransomware at its Singapore unit and Oracle shipped an emergency patch for a critical Fusion Middleware flaw. Europol said 373,000 dark web sites were shut down, and U.S. authorities sentenced facilitators tied to North Korean remote-worker infiltration and a separate business email compromise scheme targeting victims across borders globally.
NEWS ROUNDUP – 18th March 2026
Intuitive disclosed a phishing-linked breach of internal business applications, CISA added a Wing FTP flaw to its exploited catalog, and investigators traced GlassWorm fallout into compromised GitHub-hosted Python repositories. INTERPOL warned that AI-enhanced financial fraud is scaling globally, while NIST advanced cryptographic validation automation and the UK ICO pressed technology firms to strengthen age checks and protect children’s data better.
NEWS ROUNDUP – 16th March 2026
Poland’s nuclear research centre blocked a cyberattack while Albania’s parliament isolated email systems during a separate incident. The FBI is tracing victims linked to malware distributed through Steam games, and U.S. prosecutors allege a responder assisted BlackCat ransomware actors. Telus and Stryker reported cyber disruptions, while authorities dismantled the SocksEscort proxy service and INTERPOL seized 45,000 malicious IPs.
NEWS ROUNDUP – 25th February 2026
Australia’s ACSC released Azul, an open-source malware analysis tool, as defenders tracked vishing-driven access at Optimizely and extortion claims hitting Wynn Resorts and Air Côte d’Ivoire. Researchers detailed a GitHub Copilot prompt-injection chain and an NPM supply-chain campaign dubbed Sandworm_Mode. Spain arrested Anonymous Fénix suspects, while U.S. Treasury sanctioned a bulletproof hosting provider. NIST updated CSF guidance; CarGurus disclosed breach.
