News

Short summaries of the cyber-crime stories moving in India and globally. We link back to the original source — always.

NIST to Cease Rating Lower-Priority Vulnerabilities
Cyber Law (India)

NIST to Cease Rating Lower-Priority Vulnerabilities

The National Institute of Standards and Technology (NIST) announced it will no longer assign severity scores to lower-priority vulnerabilities. This decision comes in response to an overwhelming increase in the number of submissions, which has made it challenging for the agency to assess and manage all reported flaws effectively. By focusing on higher-priority issues, NIST aims to streamline its processes and better allocate resources. This change may impact how organizations prioritize their cybersecurity measures, as they will need to independently assess these lower-priority vulnerabilities. Source: cybersecurity publication.

via BleepingComputerRead source
Regulations Shape Growth of Razorpay, Says CEO Harshil Mathur
Cyber Law (India)

Regulations Shape Growth of Razorpay, Says CEO Harshil Mathur

Harshil Mathur, CEO of Razorpay, discussed the positive impact of regulations on business growth during his talk at YC Startup School. He pointed out that despite initial hurdles, such as losing bank support, the company has thrived in India's payments sector, which has surpassed $180 billion in transaction volume. Mathur credited the startup's adaptability, particularly its adoption of the Unified Payments Interface (UPI), for its success, especially during the rise of direct-to-consumer businesses amid the pandemic. These insights emphasize the balance between regulatory challenges and the potential for significant growth in a structured market environment. Source: [publication name].

via Economic Times TechRead source
Coast Guard's Cybersecurity Guidelines Provide Insights for CISOs
Cyber Law (India)

Coast Guard's Cybersecurity Guidelines Provide Insights for CISOs

The Maritime Transportation Security Act (MTSA) outlines new cybersecurity regulations for maritime operations, focusing on the protection of Operational Technology (OT) systems. These regulations mandate that organizations create comprehensive cybersecurity plans and undergo audits by independent third parties. Additionally, the Act emphasizes the importance of a hybrid security role that combines both IT and OT security responsibilities. Indian Chief Information Security Officers (CISOs) can draw valuable lessons from these guidelines to enhance their own cybersecurity frameworks and risk management strategies. Adopting a proactive approach in safeguarding critical infrastructure is essential for combating emerging cyber threats. Source: [publication name].

via Dark ReadingRead source
NIST Updates CVE Processing Due to Surge in Submissions
Cyber Law (India)

NIST Updates CVE Processing Due to Surge in Submissions

The National Institute of Standards and Technology (NIST) has revised its approach to handling cybersecurity vulnerabilities. Due to a significant increase of 263% in submissions for Common Vulnerabilities and Exposures (CVEs), NIST will now only enhance those entries that meet specific criteria. While all CVEs will still be recorded in the National Vulnerability Database (NVD), only some will receive detailed enrichment. This decision comes as part of an effort to manage the growing volume of submissions and ensure that critical vulnerabilities are effectively prioritized. Such changes aim to improve overall cybersecurity measures and awareness. Source: [publication name].

via The Hacker NewsRead source
India's Space Sector Gets New Cybersecurity Guidelines
Cyber Law (India)

India's Space Sector Gets New Cybersecurity Guidelines

The Space Industry Association India and CERT-In have jointly released comprehensive cybersecurity guidelines to protect India's space ecosystem. These guidelines establish security standards and best practices for organizations operating in the space sector, addressing vulnerabilities and cyber threats specific to space infrastructure. The initiative aims to strengthen India's space security posture as the sector expands its capabilities and commercial activities. The joint effort between the industry body and the government's cybersecurity authority represents a coordinated approach to safeguarding critical space assets and data from cyber attacks. Source: PIB.

via GoogleNews: cyber attack IndiaRead source
India's Cyber Deterrence Strategy: Challenges and Risks
Cyber Law (India)

India's Cyber Deterrence Strategy: Challenges and Risks

A new analysis examines India's approach to cyber deterrence and the complexities involved in establishing credible defensive postures against digital threats. The study explores constraints India faces in developing effective cyber deterrence mechanisms, including technical limitations, attribution challenges, and the credibility of response measures. It also assesses escalation risks that could arise from cyber conflicts in the South Asian context. The research highlights how India's cyber deterrence strategy must balance national security interests with international norms and the potential for unintended consequences in an increasingly connected digital environment. Source: NatStrat.

via GoogleNews: cyber attack IndiaRead source
Windows Administrator Protection Bypassed Through UI Access Flaws
Cyber Law (India)

Windows Administrator Protection Bypassed Through UI Access Flaws

A security researcher discovered nine vulnerabilities in Windows' Administrator Protection feature by exploiting UI Access implementation issues. The flaws stem from longstanding problems with User Interface Privacy Isolation (UIPI) in Windows UAC. Historically, Windows Vista introduced UIPI to prevent privilege escalation attacks where low-privilege users could manipulate windows created by high-privilege processes. The researcher identified root causes affecting five of the nine bypasses, highlighting how accessibility features can be abused to circumvent security boundaries. All discovered vulnerabilities have been patched by Microsoft. The findings underscore ongoing challenges in balancing security with system accessibility in Windows environments.

via RSS: Google Project ZeroRead source
India's Strategy Against Deepfakes and Financial Cyber Threats
Cyber Law (India)

India's Strategy Against Deepfakes and Financial Cyber Threats

India is implementing a comprehensive approach to combat deepfakes and financial cybercrime. The multi-layered response involves coordination between government agencies, regulatory bodies, and law enforcement to address the growing threat of synthetic media fraud and digital financial crimes. Authorities are focusing on detection mechanisms, public awareness, and legal frameworks to protect citizens from deepfake-based scams and financial exploitation. The strategy emphasizes both preventive measures and swift response protocols to mitigate risks in the digital economy. Source: Observer Research Foundation.

via GoogleNews: deepfake scamRead source