On February 2nd, 2026, the common text editor, Notepad++, shared an update to its initial announcement in December 2025 that it was the target of a software supply chain attack. According to the announcement, starting in June 2025, bad actors intercepted and redirected requests for updates to malicious infrastructure. These bad actors were then able to deliver malware through a software update channel that users trusted.
We have been notified of a recent phishing email campaign impersonating FINRA. Multiple firms have reported receiving emails that appear to be from FINRA, reference regulatory reporting requirements, and include attachments.
The compliance deadline for larger advisers (those with $1.5B or more in AUM) is less than two weeks away (Dec. 3, 2025). While much of what the previous administration proposed has been tossed or postponed, the SEC has made it clear that Amended Reg S-P is not only here to stay, but it’s also a key focus area.
SonicWall, a popular network security company that advisers and other financial institutions use for its firewall or router products, recently confirmed a security incident resulting in unauthorized access to configuration backup files for customers using its cloud backup service.
On September 30th, the SEC Division of Investment Management gave an answer to the most challenging question for crypto assets: What entities are qualified custodians for crypto assets? Since qualified custodians must meet the definition of a banking institution for both the Adviser Act’s Custody Rule and the Investment Company Act’s.