|
As an antidote to historical siloed risk management methods, we investigate the Ten Domains of Risk framework, which all organizations should consider incorporating into their risk management plans.
Risk Nodus Weekly Intelligence Brief
|
|
LiteLLM Supply-Chain Attack Exposes $10B AI Trainer's Data
AI data training startup Mercor, valued at $10 billion after its $350 million Series C six months ago, is facing mounting operational and legal pressure following its March 31 disclosure of a data breach. A hacker group claims to have stolen 4TB of data, including candidate profiles, employer information, source code, and API keys, though Mercor has not verified the dataset. The company attributed the intrusion to compromised credentials linked to the open-source tool LiteLLM. Reported fallout includes Meta pausing contracts, OpenAI reviewing exposure, and at least five contractor lawsuits.
|
|
|
Secret Service Trainee Arrested for Hidden-Camera Surveillance of Fellow Recruit
The U.S. Secret Service is facing a fresh insider risk incident after trainee Joel Lara Canvasser was arrested on April 8, 2026, at the Federal Law Enforcement Training Center in Glynco, Georgia, on a felony eavesdropping charge. Police allege Canvasser used a hidden camera concealed in a phone charger to record his suitemate and sent harassing messages implying continuous surveillance. The agency said his access to Secret Service sites and systems has been revoked, and his clearance has been suspended. The case raises renewed concerns around vetting, conduct, and internal monitoring controls.
|
|
|
Brazil's Labor Ministry Flags Chinese BYD Over Forced Labor
Brazil’s Labor Ministry has placed Chinese automaker BYD on its registry of employers linked to slavery-like labor conditions, extending reputational and financing pressure in its largest market outside China. The decision follows a 2024 case involving 163 Chinese workers hired by contractor Jinjiang Group for BYD’s Bahia plant, where inspectors alleged abusive contracts, overcrowded housing, and degrading living conditions. Inclusion on the list restricts access to certain Brazilian bank loans for two years unless overturned by a court order, though plant operations and vehicle production remain unaffected.
|
|
|
Iran-Nexus Actors Hit 300+ Israeli Organizations in M365 Password-Spray Campaign
A suspected Iran-linked threat actor conducted a password-spraying campaign against Microsoft 365 environments in three waves on March 3, 13, and 23, 2026, according to Check Point. The activity reportedly affected more than 300 organizations in Israel and over 25 in the U.A.E., with limited targeting also observed in Europe, the United States, the United Kingdom, and Saudi Arabia. Sectors hit included government, municipalities, technology, transportation, energy, and private industry. The campaign underscores persistent credential-based cloud risk and suggests continued overlap between regional geopolitical tensions and disruptive cyber operations.
|
|
|
Measles Sparks Emergency Vaccination Drive: 100+ Bangladeshi Children Dead
Bangladesh has launched an emergency measles-rubella vaccination campaign in 18 high-risk districts after an outbreak killed more than 100 children in less than a month. Official data cited on April 7, 2026, showed more than 900 confirmed measles cases among 7,500 suspected cases reported since March 15. The campaign, supported by the World Health Organization, UNICEF, and Gavi, is targeting children aged 6 months to 5 years and is set to expand nationwide in phases from May. Officials linked the outbreak to vaccine stock shortages, disrupted immunization efforts, and persistent coverage gaps.
|
|
|
FTC Warns PayPal, Stripe, Visa, and Mastercard for Denying Services Over Politics
The U.S. Federal Trade Commission widened the “debanking” debate on March 26, 2026, when Chairman Andrew Ferguson sent warning letters to PayPal, Stripe, Visa, and Mastercard stating that denying or facilitating the denial of payment services to law-abiding customers for political or religious reasons could violate Section 5 of the FTC Act. The letters cited President Donald Trump’s August 7, 2025, executive order and warned of potential investigations or enforcement, despite not alleging any specific violations by the four companies. The move increases compliance and policy risk across payment infrastructure and merchant access decisions.
|
|
|
Air BP Italia Shortage Triggers Jet Fuel Rationing Across Italian Airports
Northern Italy’s aviation network is facing a short-term fuel supply disruption after Milan Linate, Bologna, Venice, and Treviso introduced refueling restrictions, which were published on April 6, 2026. According to airport notices, priority is being given to ambulances, state flights, and flights longer than 3 hours, while other short-haul services are capped at 2,000 liters per aircraft until at least April 9. Operators said the issue is linked to constrained stock levels at a supplier rather than a full-system shortage, but the measures highlight Europe’s exposure to energy logistics stress tied to broader tensions in the Middle East.
|
|
|
U.S. Campaign Security Spending Tops $41M in 2024 Cycle - A Fivefold Rise in a Decade
A new report from the nonpartisan Public Service Alliance shows U.S. congressional and presidential campaigns spent more than $40 million on expenses explicitly labeled as security during the 2023–24 cycle, a fivefold increase from a decade earlier. The findings reflect a sustained rise in threats against public officials, from doxing and cyber harassment to assassination attempts and attacks at private homes. Digital security spending rose from $50,000 in 2015–16 to $900,000 in 2023–24, while home security costs approached $1 million, underscoring higher barriers to candidacy and a growing burden of protection.
|
|
|
Operation Skip Trace Dismantles $267M Medi-Cal Fraud Ring Built on Stolen Identities
California authorities on April 9, 2026, announced a major enforcement action against an alleged Los Angeles hospice fraud network accused of submitting $267 million in bogus Medi-Cal charges. Attorney General Rob Bonta said the scheme involved stolen identities, straw owners, and 14 hospice companies that allegedly billed for services never provided. Five people were arrested, 21 suspects were charged, and officials said additional arrests are expected. The case, part of Operation Skip Trace, also prompted broader scrutiny: state officials said more than 300 hospices are under investigation for possible license revocation.
|
|
|
Satellite Images Suggest Haftar Forces Acquired Combat Drones Despite UN Embargo
Satellite imagery reviewed by Reuters indicates eastern Libyan commander Khalifa Haftar’s forces may have acquired combat drones despite the longstanding UN arms embargo on Libya. Images taken between April and December 2025 reportedly show at least three drones at Al Khadim airbase, including one assessed by experts as likely a Chinese-made Feilong-1 drone and two resembling Turkish Bayraktar TB2s. Analysts said the systems could strengthen Haftar’s leverage over eastern and southern Libya, including key oil areas, while raising fresh questions about foreign support, the enforcement of the embargo, and who may be operating the aircraft.
|
Organizations must stay vigilant and adopt proactive methods to predict and manage risk across various domains. By understanding and addressing the Ten Domains of Risk, organizations can not only protect themselves from potential threats but also position themselves for growth and success in a competitive marketplace.
The Risk Nodus Pulse delivers cross-domain intelligence on emerging threats and strategic shifts. Speak with our team about how Presage Global leverages predictive risk intelligence services to help you expect the unexpected and make well-informed decisions. Contact us today.
Know someone who would be interested in subscribing to Risk Nodus? Forward this email and invite them to join.
|
|
|
Edward V. Marshall, Founder & CEO
Presage Global
|
|
|