News

Short summaries of the cyber-crime stories moving in India and globally. We link back to the original source — always.

Weekly Security Update: Linux Flaws, Windows Defender Vulnerabilities, and Botnet Threats
Malware

Weekly Security Update: Linux Flaws, Windows Defender Vulnerabilities, and Botnet Threats

This week highlighted multiple critical security concerns across different platforms. Linux systems contained previously undiscovered vulnerabilities, while Microsoft Defender itself required patching against zero-day exploits. Attackers deployed router-based botnets targeting unpatched devices. Organizations discovered overlooked legacy servers lacking essential security updates. Supply chain disruptions occurred when compromised development tools distributed malware to users. Simultaneously, phishing campaigns evolved with increasingly sophisticated, targeted tactics replacing obvious spam approaches. These incidents underscore the importance of regular patching, legacy system management, and employee security awareness. Source: Security recap publication.

via The Hacker NewsRead source
Chinese Phishing Services Growing Threat to Global Users
Phishing

Chinese Phishing Services Growing Threat to Global Users

Chinese-language phishing-as-a-service (PhaaS) platforms are rapidly expanding in underground criminal markets, rivaling Russian-dominated operations. Google's Threat Intelligence Group analyzed twelve mature PhaaS services operating within Chinese criminal networks, revealing sophisticated tactics beyond simple password theft. These services now employ real-time interception to steal one-time passcodes (OTPs), bypassing multi-factor authentication instantly. Attackers use live administration panels to interact with victims in real-time and tokenize stolen payment data to gain unauthorized access to digital wallets and financial accounts. They exploit encrypted messaging channels like RCS and iMessage to evade traditional security filters. Unlike Russian operations, these Chinese services primarily target non-Chinese organizations globally. Google has taken legal action against PhaaS providers and supports legislation to combat these evolving threats. Source: Google Threat Intelligence Group.

via RSS: Mandiant BlogRead source
KnowledgeDeliver LMS Vulnerability Allows Remote Code Execution
Malware

KnowledgeDeliver LMS Vulnerability Allows Remote Code Execution

A critical security flaw in KnowledgeDeliver, a Learning Management System used in Japan, was exploited by threat actors in late 2025. The vulnerability (CVE-2026-5426) stems from identical pre-shared ASP.NET machine keys hardcoded in the vendor's standard configuration file across multiple customer installations. Attackers who obtained these keys could craft malicious ViewState payloads to achieve unauthenticated remote code execution on any internet-facing instance. The vulnerability affected all KnowledgeDeliver deployments before February 24, 2026. This incident mirrors similar vulnerabilities found in Sitecore and highlights the dangers of standardized security credentials across independent environments. Source: Mandiant.

via RSS: Mandiant BlogRead source
TeamPCP Malware Targets Multiple Code Platforms
Malware

TeamPCP Malware Targets Multiple Code Platforms

TeamPCP, a sophisticated cyber threat group, has expanded its supply chain attack operations across three package ecosystems simultaneously. The group has infiltrated GitHub's internal codebase and compromised an official Microsoft Python SDK, distributing malware through these trusted channels. Additionally, TeamPCP has released its own malicious framework on GitHub, increasing its reach and operational capability. This campaign demonstrates how attackers target developers and organizations through supply chain vulnerabilities, potentially affecting thousands of downstream users who trust official repositories. Source: CyberSathi.in.

via RSS: SANS ISC DiaryRead source
TeamPCP Supply Chain Attack Targets Multiple Code Ecosystems
Malware

TeamPCP Supply Chain Attack Targets Multiple Code Ecosystems

Cybersecurity researchers have identified TeamPCP, a threat actor group conducting a widespread supply chain campaign that remained active through May 2024. The group simultaneously operates across three package management ecosystems and has successfully compromised GitHub's internal codebase. Notably, TeamPCP trojanized an official Microsoft-published Python SDK, potentially affecting numerous developers relying on the compromised tool. The attackers have also released their own malicious framework on GitHub, expanding their attack surface. This multi-pronged approach demonstrates sophisticated supply chain attack tactics targeting software developers and organizations worldwide. Indian developers using these ecosystems should remain vigilant and verify package authenticity. Source: Security Research Report.

via RSS: SANS ISC DiaryRead source
Netherlands Shuts Down Servers Used for Russian Cyberattacks
Cyber Law (India)

Netherlands Shuts Down Servers Used for Russian Cyberattacks

Dutch authorities arrested two co-owners of internet hosting companies accused of providing infrastructure for Russian cyberattacks, disinformation campaigns, and influence operations targeting the European Union. The companies had taken control of technical systems previously operated by Stark Industries Solutions, an ISP sanctioned by the EU for facilitating cyber operations linked to Russian intelligence agencies. Police seized approximately 800 servers during the operation. This crackdown highlights how hosting providers can be exploited to support state-sponsored cyber activities across borders. Source: KrebsOnSecurity.

via Krebs on SecurityRead source
FBI Alerts on Kali365 Phishing Service Targeting Microsoft 365
Phishing

FBI Alerts on Kali365 Phishing Service Targeting Microsoft 365

The FBI has issued a warning about Kali365, a phishing-as-a-service platform exploiting Microsoft 365 users. The service leverages OAuth device code authentication to compromise accounts and steal session tokens, effectively bypassing multi-factor authentication (MFA) protections. This phishing service poses a significant threat to organizations and individuals relying on Microsoft 365 for business operations. Users are advised to remain vigilant against suspicious authentication attempts and review account access logs regularly. Organizations should implement additional security measures beyond standard MFA to protect against such sophisticated attacks. Source: FBI.

via BleepingComputerRead source
Ghost CMS Flaw Exploited to Compromise 700+ Websites
Malware

Ghost CMS Flaw Exploited to Compromise 700+ Websites

Cybercriminals are actively exploiting CVE-2026-26980, a critical SQL injection vulnerability in Ghost CMS, to compromise over 700 websites. The flaw, rated 9.4 on the CVSS severity scale, exists in Ghost's Content API and allows attackers to inject malicious JavaScript code without authentication. This vulnerability is being weaponized to launch ClickFix attacks, a social engineering technique that deceives users into downloading malware. Security researchers at QiAnXin XLab discovered the widespread exploitation campaign. Website administrators using Ghost CMS are urged to apply security patches immediately to prevent unauthorized data access and malicious code injection on their platforms. Source: Security research report.

via The Hacker NewsRead source
AI-Powered Network Detection Reduces False Security Alerts
Malware

AI-Powered Network Detection Reduces False Security Alerts

Network Detection and Response (NDR) systems have historically faced criticism for generating excessive alerts and noise. However, security teams now deploying NDR with artificial intelligence capabilities report significant improvements in threat detection speed and accuracy. These AI-enhanced systems help security professionals identify threats earlier, prioritize incidents more efficiently, and reduce false positives that waste resources. The evolution of NDR technology addresses longstanding concerns about alert fatigue, enabling teams to focus on genuine security threats rather than filtering through irrelevant notifications. Source: Original cybersecurity publication.

via The Hacker NewsRead source
Cybersecurity threats pose risk to India's $5 trillion economy goal
Cyber Law (India)

Cybersecurity threats pose risk to India's $5 trillion economy goal

Security experts have raised concerns about mounting cybersecurity risks that could undermine India's ambitious $5 trillion economy target. As the nation pursues rapid economic growth and digital transformation, vulnerabilities in critical infrastructure, financial systems, and digital platforms are becoming increasingly apparent. Experts emphasize the need for stronger cybersecurity frameworks, investment in defensive capabilities, and coordination between government and private sectors. The warning highlights that without adequate protection measures, cyber threats including data breaches, ransomware attacks, and financial fraud could significantly impact economic growth and investor confidence. India must prioritize cybersecurity alongside economic expansion to safeguard its development goals and protect citizens' digital assets. Source: fundsforNGOs News.

via GoogleNews: cyber attack IndiaRead source
This article is not cybersecurity-related
Phishing

This article is not cybersecurity-related

This article covers a business funding announcement for abcoffee, a specialty coffee chain in India. It discusses the company's Pre-Series B funding round of ₹61 crores led by Kliff and plans for offline expansion. This is a business/startup news story and does not relate to cybersecurity, cyber-crime, data protection, or digital safety concerns relevant to CyberSathi.in's audience.

via RSS: Inc42Read source
Lazarus Group Targets Financial Firms with RemotePE Malware
Malware

Lazarus Group Targets Financial Firms with RemotePE Malware

Security researchers have identified RemotePE, a cross-platform malware used by North Korea-linked Lazarus Group to attack financial and cryptocurrency organizations. The malware operates as part of a sophisticated multi-stage attack chain involving two loaders: DPAPILoader and RemotePELoader. DPAPILoader functions to decrypt and execute subsequent malicious payloads, while RemotePELoader facilitates the deployment of RemotePE in memory without writing to disk. This memory-only approach makes detection difficult for traditional security tools. The campaign specifically targets organizations handling digital assets and financial services, highlighting persistent threats to India's growing crypto and fintech sectors. Source: NCC Group/Fox-IT Research.

via RSS: The Hacker NewsRead source