News

Short summaries of the cyber-crime stories moving in India and globally. We link back to the original source — always.

Key Cybersecurity Threats Expected in 2026
Malware

Key Cybersecurity Threats Expected in 2026

Security experts have identified several emerging cybersecurity threats that individuals and organizations should prepare for in 2026. These trends include evolving attack methods targeting both personal and corporate data, increased sophistication in malware development, and new vulnerabilities in digital infrastructure. As cyber threats continue to advance, staying informed about these emerging patterns helps users strengthen their defenses. Indian internet users are particularly advised to maintain updated security practices, enable multi-factor authentication, and remain cautious of suspicious digital activities. Organizations should conduct regular security audits and employee training to combat these anticipated threats effectively. Source: Simplilearn.com.

via GoogleNews: cyber attack IndiaRead source
TrapDoor Malware Found in Popular Code Libraries
Malware

TrapDoor Malware Found in Popular Code Libraries

Security researchers discovered a coordinated attack called TrapDoor targeting three major software package repositories: npm, PyPI, and Crates.io. The campaign distributed malicious code across 34 packages with over 384 versions designed to steal user credentials. Attackers published these packages in waves starting May 22, 2026, exploiting the trust developers place in open-source libraries. This supply chain attack demonstrates how cybercriminals can compromise software development tools to reach thousands of potential victims. Developers using affected packages are at risk of credential theft and system compromise. Source: Security Research Publication.

via RSS: The Hacker NewsRead source
Wireshark 4.6.6 Update Patches Security Flaw
Malware

Wireshark 4.6.6 Update Patches Security Flaw

Wireshark, the widely-used network analysis tool, has released version 4.6.6 with important security updates. The latest release addresses one vulnerability and fixes eleven bugs to improve stability and security. Wireshark is commonly used by IT professionals and cybersecurity experts for monitoring network traffic and diagnosing connectivity issues. Users are advised to update to this version to benefit from the security patch and bug fixes. Keeping network analysis tools updated helps organizations maintain better visibility into their network activities and identify potential threats more effectively. Source: Wireshark.

via RSS: SANS ISC DiaryRead source
Elderly Bengaluru Woman Loses Rs 24 Crore in Digital Arrest Scam
Social Engineering

Elderly Bengaluru Woman Loses Rs 24 Crore in Digital Arrest Scam

A 74-year-old woman from Bengaluru fell victim to a digital arrest scam, losing Rs 24 crore. Scammers impersonated law enforcement officials and convinced the victim that she was involved in illegal activities, pressuring her to transfer large sums of money. This social engineering tactic exploits fear and urgency to manipulate vulnerable individuals, particularly elderly citizens, into surrendering their savings. Authorities advise citizens to verify official communications directly through official channels and remain skeptical of unsolicited demands for money or personal information. Such scams continue to target senior citizens across India. Source: NDTV.

via GoogleNews: digital arrest scamRead source
LiteSpeed cPanel Plugin Flaw Allows Root Access Attacks
Malware

LiteSpeed cPanel Plugin Flaw Allows Root Access Attacks

A critical vulnerability (CVE-2026-48172) has been discovered in the LiteSpeed cPanel plugin that enables attackers to gain root-level privileges on affected systems. Security researchers report active exploitation of this flaw in the wild. System administrators running LiteSpeed with cPanel should immediately apply available patches to prevent unauthorized access. This vulnerability poses significant risk to web hosting infrastructure and server security across India. Users are urged to update their installations urgently and monitor systems for suspicious activity indicative of compromise. Source: Rescana.

via GoogleNews: vulnerability CVERead source
Retired Teacher Lost ₹24 Crore in Digital Arrest Scam
Social Engineering

Retired Teacher Lost ₹24 Crore in Digital Arrest Scam

A retired teacher in India fell victim to a digital arrest scam, losing ₹24 crore to fraudsters. The scam involved criminals impersonating law enforcement officials and tricking the victim into believing they were under digital arrest. Police arrested six individuals involved in the scheme. Digital arrest scams have become increasingly common, targeting vulnerable individuals through phone calls and online platforms. Victims are coerced into transferring large sums of money under the false pretext of legal action. Authorities urge citizens to verify official communications directly with police departments and never transfer money based on unverified claims. Source: The Hindu.

via GoogleNews: digital arrest scamRead source
Half of Gen Z job seekers targeted by recruitment scams
Social Engineering

Half of Gen Z job seekers targeted by recruitment scams

Nearly 50% of young Indian professionals have encountered or almost fallen victim to fraudulent online recruitment scams. These deceptive schemes target job seekers through fake job postings, promising unrealistic salaries and benefits. Scammers typically request upfront payments for processing fees, training materials, or documentation. Gen Z workers, eager to secure employment, are particularly vulnerable to these social engineering tactics. The scams often involve convincing fake websites, forged company credentials, and impersonation of legitimate recruiters. Experts recommend verifying company details independently, avoiding advance payment requests, and using official job portals. Awareness and caution during the job search process are essential to avoid financial losses and identity theft. Source: The Times of India.

via GoogleNews: job scam IndiaRead source
Gujarat police arrests 13 in Rs 632 crore cyber mule racket
UPI Fraud

Gujarat police arrests 13 in Rs 632 crore cyber mule racket

Gujarat Police dismantled a major cyber mule network operating across four cities—Ahmedabad, Surat, Vadodara, and Rajkot. The operation resulted in 13 arrests and uncovered fraudulent transactions worth Rs 632 crore. Cyber mules are individuals who receive stolen or laundered money into their bank accounts and transfer funds to criminal networks, often unaware they're facilitating crime. This bust highlights how organized cybercriminal gangs exploit innocent citizens as unwitting accomplices. The coordinated operation demonstrates law enforcement's growing focus on combating the financial infrastructure supporting online fraud schemes across India. Source: The Times of India.

via GoogleNews: investment scam IndiaRead source
Security modes in Apple, Google, Meta phones guard against spyware
Malware

Security modes in Apple, Google, Meta phones guard against spyware

Major tech companies have introduced dedicated security modes to protect users from targeted spyware attacks. Apple, Google, and Meta offer enhanced protection features that strengthen device defenses against sophisticated threats. These modes implement stricter security protocols and limit certain functionalities to reduce vulnerability. Users can activate these protective settings through their device preferences. Understanding how these security modes function and when to enable them is crucial for preventing unauthorized surveillance and protecting personal data from malicious actors attempting spyware installation. Source: Security publication.

via RSS: TechCrunch SecurityRead source
Ransomware Gang's VPN Service Shut Down in Global Operation
Ransomware

Ransomware Gang's VPN Service Shut Down in Global Operation

Law enforcement agencies worldwide have successfully dismantled a VPN service that was widely used by ransomware actors to conceal their identities and coordinate attacks. The operation targeted the infrastructure used by cybercriminals to launch ransomware campaigns against organizations globally. This coordinated crackdown involved multiple countries working together to disrupt the service that provided anonymity to threat actors. The takedown is expected to disrupt ongoing ransomware operations and make it harder for attackers to hide their tracks. Authorities continue investigating individuals who used the service for malicious purposes. Source: [Original Publication].

via HN: ransomwareRead source
AI-Powered Bug Scanning Tools Reveal New Linux Vulnerabilities
Malware

AI-Powered Bug Scanning Tools Reveal New Linux Vulnerabilities

Recent security research has identified three critical vulnerabilities in Linux systems—Dirty Frag, Copy Fail, and Fragesia—discovered through AI-assisted code analysis tools. These findings highlight an emerging trend where artificial intelligence is uncovering previously undetected bugs in widely-used operating systems. The vulnerabilities pose potential security risks for servers and systems relying on Linux infrastructure. Security experts warn that as AI scanning tools become more sophisticated, attackers may also leverage similar technology to identify exploitable flaws. Organizations running Linux systems should monitor security advisories and apply patches promptly to mitigate exposure to these newly-discovered threats. Source: Original publication.

via RSS: The Register SecurityRead source
Cyber Warfare: Global Threats and Legal Gaps
Cyber Law (India)

Cyber Warfare: Global Threats and Legal Gaps

Cyber warfare poses significant global security challenges amid inadequate legal frameworks. Nations face growing threats from state-sponsored attacks, but international laws remain underdeveloped. The absence of clear regulations complicates response mechanisms and attribution of attacks. Countries struggle to balance national security with privacy rights. Solutions include strengthening international cooperation, establishing unified cyber laws, and developing rapid response protocols. India and other nations must adopt comprehensive cyber security policies while respecting international norms. Building technical capacity and promoting diplomatic dialogue are essential to address this evolving threat landscape. Source: INSIGHTS IAS.

via GoogleNews: cyber attack IndiaRead source