News

Short summaries of the cyber-crime stories moving in India and globally. We link back to the original source — always.

US Agencies Ordered to Patch Oracle WebLogic Critical Flaw
Malware

US Agencies Ordered to Patch Oracle WebLogic Critical Flaw

US Cyber Security and Infrastructure Security Agency (CISA) has directed all federal agencies to patch a critical vulnerability in Oracle WebLogic Server. The flaw poses significant security risks and could be exploited by threat actors to compromise government systems. WebLogic Server, widely used for business applications, requires immediate patching to prevent potential attacks. The directive mandates agencies complete patching within specified timeframes as part of critical infrastructure protection measures. Organizations running WebLogic Server deployments should prioritize applying available security updates to mitigate exploitation risks. Source: SC Media.

via GoogleNews: vulnerability CVERead source
Password Stealer Attacks Surge 20%, Threatening Indian Business Data
Malware

Password Stealer Attacks Surge 20%, Threatening Indian Business Data

Kaspersky reports a concerning 20% increase in password stealer attacks targeting Indian businesses, putting corporate credentials at significant risk. These malicious tools are designed to extract login information from employees' systems, enabling unauthorized access to sensitive business accounts and data. The surge highlights growing threats to organizational cybersecurity infrastructure across India. Businesses are advised to implement robust security measures, including multi-factor authentication, regular password updates, and employee security awareness training. IT teams should monitor network activity for suspicious behavior and deploy advanced threat detection solutions. This trend underscores the importance of proactive credential protection strategies for enterprises operating in India's digital ecosystem. Source: Deccan Herald.

via GoogleNews: ransomware IndiaRead source
US Agencies Warn of Cyber Attacks on Tank Gauge Systems
Malware

US Agencies Warn of Cyber Attacks on Tank Gauge Systems

US cybersecurity authorities, including CISA, FBI, NSA, and other agencies, have identified malicious cyber activity targeting automatic tank gauge (ATG) systems used across energy, chemical, food, agriculture, and transportation sectors in America. These systems monitor fuel levels, temperature, and detect leaks in storage tanks. Attackers are exploiting vulnerabilities through authentication bypass, hardcoded credentials, and command execution to compromise internet-exposed ATG systems. The agencies recommend operators secure systems with strong passwords and disconnect them from the internet to minimize exposure. The attack source remains unattributed to any specific nation-state or threat group. Source: CISA.

via RSS: CISA AlertsRead source
CISA Lists Two Active Exploited Vulnerabilities
Malware

CISA Lists Two Active Exploited Vulnerabilities

The US Cybersecurity and Infrastructure Security Agency (CISA) has identified two vulnerabilities actively exploited by attackers: CVE-2022-0492 affecting Linux Kernel authentication and CVE-2025-48595 impacting Android Framework. These have been added to CISA's Known Exploited Vulnerabilities catalog, which tracks threats to critical infrastructure. While mandatory remediation applies to US federal agencies under Binding Operational Directive 22-01, CISA recommends all organizations prioritize patching these vulnerabilities to reduce cyberattack exposure. The catalog serves as a living resource for vulnerability management practices globally. Source: CISA.

via RSS: CISA AlertsRead source
Android Zero-Day Flaw Used in Active Device Takeover Campaign
Malware

Android Zero-Day Flaw Used in Active Device Takeover Campaign

Security researchers have identified an unpatched vulnerability in Android devices that is being actively exploited by attackers to gain complete control over affected smartphones. The zero-day flaw allows threat actors to bypass security protections and take over devices remotely. Users may experience unauthorized access to personal data, applications, and device functions without their knowledge. Google has been notified and is reportedly working on a patch. Meanwhile, Android users are advised to exercise caution with suspicious links and downloads, enable automatic security updates, and consider using mobile security applications for enhanced protection. Source: gbhackers.com.

via GoogleNews: vulnerability CVERead source
WordPress Plugin Flaw Allows Admin Account Creation
Malware

WordPress Plugin Flaw Allows Admin Account Creation

A critical vulnerability (CVE-2026-8732) in the WP Maps Pro WordPress plugin enables unauthenticated attackers to create administrative accounts on vulnerable websites. This security defect could lead to complete site takeover, allowing malicious actors to modify content, steal data, or inject malicious code. WordPress site administrators using this plugin are advised to update immediately to patched versions. This vulnerability highlights the importance of keeping plugins updated and using security measures to protect WordPress installations from unauthorized access. Source: SecurityWeek.

via RSS: SecurityWeekRead source
Oracle Patches 35 Vulnerabilities in First Monthly Security Update
Malware

Oracle Patches 35 Vulnerabilities in First Monthly Security Update

Oracle has launched its new monthly Critical Security Patch Update (CSPU) program to address urgent security flaws that cannot wait for quarterly patches. The first batch fixes 35 vulnerabilities: 11 critical, 18 high, and 6 medium severity. Critical flaws affect Oracle REST Data Services, E-Business Suite, Universal Work Queue, and Payments modules. Notably, CVE-2026-46840 has a perfect CVSS score of 10, affecting REST Data Services' backend-as-a-service component, allowing unauthenticated attackers to compromise the database gateway via HTTPS. Several vulnerabilities have publicly available exploit code, including flaws in Oracle Communications Unified Assurance. Indian organizations using Oracle products should prioritize patching these critical issues promptly. Source: The Register.

via RSS: CSO OnlineRead source
Dutch Police Bust Massive 17-Million Device Botnet Network
Malware

Dutch Police Bust Massive 17-Million Device Botnet Network

Dutch law enforcement authorities have successfully dismantled a large-scale botnet comprising approximately 17 million infected devices including computers, smartphones, and tablets. The operation involved seizing command-and-control servers that orchestrated the network's activities. According to investigations, the botnet was being exploited to operate a residential proxy service and facilitate various cybercriminal operations. This takedown represents a significant effort in combating large-scale malware infrastructure that threat actors commonly use to launch attacks, steal data, and commit online crimes. The seizure of the operational servers has disrupted the attackers' ability to command and control the compromised devices. Source: SecurityWeek.

via RSS: SecurityWeekRead source
Critical Windows Netlogon Bug Targeted by Attackers
Malware

Critical Windows Netlogon Bug Targeted by Attackers

A critical vulnerability in Windows Netlogon authentication system has become a prime target for cybercriminals. The flaw allows attackers to gain unauthorized access to network systems and escalate privileges without proper credentials. Security experts warn that this vulnerability poses significant risks to organizations running Windows infrastructure. The issue affects multiple Windows versions and can be exploited remotely. IT administrators are urged to apply security patches immediately and monitor their systems for suspicious authentication activities. This vulnerability highlights the importance of keeping systems updated with latest security fixes. Source: SecurityWeek.

via GoogleNews: vulnerability CVERead source
Windows Netlogon Vulnerability Actively Exploited
Malware

Windows Netlogon Vulnerability Actively Exploited

A critical remote code execution flaw in Windows Netlogon service is now being actively exploited by threat actors. The vulnerability allows attackers to execute arbitrary code on affected systems, potentially compromising entire networks. Windows Netlogon is a core authentication service used across enterprise environments. Organizations running unpatched Windows systems are at immediate risk. Microsoft has released security updates to address this issue. IT administrators and users should apply patches urgently to prevent unauthorized access and system compromise. Delays in patching increase vulnerability to cyber attacks. Source: BleepingComputer.

via GoogleNews: vulnerability CVERead source
Flowise AI Platform Vulnerable to Remote Code Execution
Malware

Flowise AI Platform Vulnerable to Remote Code Execution

Security researchers at Obsidian Security discovered a critical vulnerability in Flowise, an open-source AI platform used by enterprises for self-hosted AI applications. The flaw, tracked as CVE-2026-40933, allows attackers to execute arbitrary commands through malicious Model Context Protocol (MCP) configurations. The vulnerability can be triggered with a single click via importing a malicious chatflow, requiring only post-authentication access. Flowise, commonly used for building AI assistants, chatbots, and autonomous agents, is vulnerable when stdio MCP is enabled. Flowise Cloud users are unaffected as the feature is disabled there. The official patch has proven insufficient, as attackers can bypass input validation. Organizations using self-hosted Flowise deployments should review their MCP server configurations immediately to mitigate risks. Source: SecurityWeek.

via RSS: CSO OnlineRead source
Hackers Exploit Palo Alto VPN Security Flaw in Network Attacks
Malware

Hackers Exploit Palo Alto VPN Security Flaw in Network Attacks

Palo Alto Networks has alerted organizations about active exploitation of a critical authentication bypass vulnerability in its PAN-OS GlobalProtect VPN service, identified as CVE-2026-0257. Threat actors are leveraging this flaw to bypass login protections and gain unauthorized access to corporate networks. The vulnerability allows attackers to circumvent standard authentication mechanisms, potentially enabling them to infiltrate sensitive systems and data. Organizations using Palo Alto's GlobalProtect VPN are advised to apply security patches immediately and monitor their networks for suspicious access attempts. This active exploitation underscores the importance of timely security updates for enterprise infrastructure. Source: Palo Alto Networks.

via RSS: BleepingComputerRead source