News

Short summaries of the cyber-crime stories moving in India and globally. We link back to the original source — always.

Six arrested in Rs 24 crore Bengaluru digital arrest scam
Social Engineering

Six arrested in Rs 24 crore Bengaluru digital arrest scam

Bengaluru police have arrested six individuals involved in a massive Rs 24 crore fraud scheme operating under the guise of 'digital arrest'. The scam involved impersonating law enforcement and financial officials to deceive victims into transferring money. Perpetrators used social engineering tactics, claiming victims had violated financial regulations or were involved in illegal activities. They pressured victims to move funds to fake secure accounts controlled by the criminals. The operation targeted multiple victims across the city, demonstrating the sophistication of cyber-fraudsters exploiting citizens' fear of legal consequences. Authorities recovered substantial amounts during the arrests and are investigating the network's full extent. Source: MSN.

via GoogleNews: digital arrest scamRead source
Windows Server 2016 Domain Lookup Issue After Security Update
Cyber Law (India)

Windows Server 2016 Domain Lookup Issue After Security Update

Microsoft has identified a bug in Windows Server 2016 systems following installation of the KB5087537 May 2026 security patch. The issue prevents domain controller lookups from functioning properly, potentially disrupting network authentication and directory services. Affected organizations may experience connectivity problems within their Active Directory infrastructure. Microsoft is investigating the matter and working on a resolution. Administrators managing Windows Server 2016 environments should monitor system performance and consider delaying the update deployment until a fix is released. This known issue highlights the importance of testing security patches in non-production environments before full rollout. Source: Microsoft.

via RSS: BleepingComputerRead source
Iranian hackers target aviation, software sectors with malware
Malware

Iranian hackers target aviation, software sectors with malware

A state-sponsored Iranian hacking group known as Nimbus Manticore has launched a new cyber campaign using phishing emails and search engine manipulation. The attackers impersonate legitimate organizations in aviation and software industries to target users across the United States, Europe, and Middle East. The campaign deploys malware variants called MiniFast and MiniJunk V2. Security researchers attribute this activity to geopolitical tensions following military operations in late February 2026. The group uses deceptive tactics to trick victims into downloading malicious files. Indian users should remain cautious of suspicious emails claiming to be from aviation or software companies and verify sender authenticity before opening attachments. Source: Cybersecurity News.

via The Hacker NewsRead source
7-Eleven breach exposes data of 185,000 customers
Data Breaches

7-Eleven breach exposes data of 185,000 customers

Cybercriminal group ShinyHunters compromised 7-Eleven's systems in April, stealing personal information of over 183,000 individuals, according to Have I Been Pwned, a data breach notification service. The convenience store chain fell victim to the extortion-focused gang, which gained unauthorized access to customer records. Affected individuals may face identity theft and fraud risks. 7-Eleven customers should monitor their accounts for suspicious activity and consider placing fraud alerts with credit bureaus. The breach highlights ongoing security vulnerabilities in retail sector databases, emphasizing the need for stronger cybersecurity measures among major corporations handling sensitive customer data. Source: Have I Been Pwned.

via RSS: BleepingComputerRead source
Zero-Knowledge Encryption May Not Prevent Server Hack Password Theft
Data Breaches

Zero-Knowledge Encryption May Not Prevent Server Hack Password Theft

Zero-knowledge encryption, a security method designed to protect user privacy, may fail to prevent password theft during server breaches. Even with this advanced encryption technique, if attackers gain unauthorized access to servers, they could potentially extract stored passwords. Security experts warn that zero-knowledge encryption alone is insufficient protection. Organizations must implement multi-layered security measures including strong authentication protocols, regular security audits, and immediate breach response procedures. Users are advised to enable two-factor authentication and use unique passwords across platforms. This highlights the importance of comprehensive cybersecurity strategies beyond encryption alone. Source: Original publication.

via HN: zero dayRead source
LMS Vulnerability Exploited to Deploy Malware
Malware

LMS Vulnerability Exploited to Deploy Malware

A high-severity flaw in Digital Knowledge's KnowledgeDeliver Learning Management System (CVE-2026-5426, CVSS 7.5) was exploited by attackers before being patched. The vulnerability, caused by hard-coded ASP.NET machine keys, allowed attackers to deploy the Godzilla web shell and subsequently launch Cobalt Strike Beacon malware. The LMS is widely used in educational institutions, particularly in Japan. Organizations running affected versions should apply patches immediately to prevent unauthorized access and malware installation. Source: Cybersecurity News.

via RSS: The Hacker NewsRead source
Italian Telecom Firm BASE Hit by SpaceBears Ransomware
Ransomware

Italian Telecom Firm BASE Hit by SpaceBears Ransomware

Italian telecommunications company BASE S.p.A. has fallen victim to a ransomware attack attributed to the SpaceBears threat group. The attackers encrypted the company's systems and likely exfiltrated sensitive data. BASE S.p.A. is one of Italy's major mobile network operators serving millions of customers. This incident highlights the growing threat ransomware poses to critical infrastructure and telecom providers across Europe. Organizations are advised to maintain robust backup systems, implement multi-factor authentication, and develop incident response plans to mitigate ransomware risks. Source: DeXpose.

via GoogleNews: ransomware globalRead source
WhatsApp Removes 9,400 Digital Arrest Scam Accounts
Social Engineering

WhatsApp Removes 9,400 Digital Arrest Scam Accounts

WhatsApp has banned approximately 9,400 accounts involved in digital arrest scams operating across India, according to information presented to the Supreme Court. These fraudulent accounts were being used to deceive users through fake police impersonation and threats of legal action. The messaging platform's action represents efforts to curb the growing menace of digital arrest scams that have victimized thousands of Indians. The government highlighted these enforcement measures during court proceedings, demonstrating coordinated responses between tech platforms and authorities to combat organized online fraud targeting vulnerable citizens. Source: MSN.

via GoogleNews: WhatsApp scamRead source
Government Alerts India AI Summit 2026 Attendees of Phishing Threats
Phishing

Government Alerts India AI Summit 2026 Attendees of Phishing Threats

Indian government authorities have issued a warning to participants of the India AI Impact Summit 2026 regarding an active phishing scam targeting attendees. Cybercriminals are sending fraudulent emails and messages impersonating summit organizers to steal personal information and credentials from participants. The scam attempts to trick recipients into clicking malicious links or revealing sensitive data. Attendees are advised to verify communications directly with official summit channels, avoid clicking suspicious links, and report any phishing attempts to authorities. This warning highlights the growing threat of cyber attacks during major events and conferences in India. Source: News On AIR.

via GoogleNews: phishing IndiaRead source
Six arrested in ₹24 crore Bengaluru 'digital arrest' scam
Social Engineering

Six arrested in ₹24 crore Bengaluru 'digital arrest' scam

Police in Bengaluru have arrested six individuals involved in an elaborate 'digital arrest' scam that defrauded victims of approximately ₹24 crore. The scheme involved fraudsters impersonating law enforcement officers through video calls, convincing victims they were under investigation for financial crimes. Perpetrators then coerced targets into transferring substantial sums under the guise of 'verification' procedures. This social engineering tactic has increasingly targeted Indian citizens, exploiting fear and authority. The arrests follow complaints from multiple victims across the city. Authorities urge the public to verify claims directly with official police channels and avoid sharing sensitive information with callers. Source: MSN.

via GoogleNews: digital arrest scamRead source
Google flags security concerns in lawful-access proposal
Cyber Law (India)

Google flags security concerns in lawful-access proposal

Google has raised significant cybersecurity concerns regarding a proposed lawful-access bill, warning that the legislation could introduce major security vulnerabilities. The tech giant argues that granting government backdoor access to encrypted systems would weaken overall data protection standards and create exploitable gaps that cybercriminals could leverage. Such backdoors, Google contends, could compromise user privacy and data integrity across platforms. The company emphasizes that mandatory weakening of encryption standards poses risks not just to individual users but to critical infrastructure and financial systems. Security experts generally align with these concerns, noting that backdoors designed for law enforcement could be misused or exploited by malicious actors. The debate highlights the ongoing tension between government surveillance demands and cybersecurity best practices in the digital age. Source: Google Official Statement.

via HN: cybersecurityRead source
Anthropic's Claude Mythos Model May Get Wider Release
Malware

Anthropic's Claude Mythos Model May Get Wider Release

Anthropic is preparing to expand access to its Claude Mythos model, which was unveiled in April as a restricted artificial intelligence system flagged for significant security vulnerabilities. The model poses potential risks to both private and public software systems. The planned rollout through Claude Code represents a major shift from its initially limited availability. Security experts remain concerned about the implications of broader access to a system with known restrictions and vulnerability issues. This development highlights ongoing challenges in balancing AI innovation with cybersecurity safeguards. Source: TechCrunch.

via RSS: BleepingComputerRead source