News

Short summaries of the cyber-crime stories moving in India and globally. We link back to the original source — always.

Drupal SQL Injection Flaw Added to Active Threat List
Malware

Drupal SQL Injection Flaw Added to Active Threat List

India's cybersecurity teams should note that CISA, the US Cybersecurity and Infrastructure Security Agency, has added CVE-2026-9082, a critical SQL injection vulnerability in Drupal Core, to its Known Exploited Vulnerabilities catalog. This designation indicates active exploitation by threat actors. While CISA's mandate applies to US federal agencies, the agency recommends all organizations globally prioritize patching this vulnerability as part of standard security practices. SQL injection flaws remain favored attack vectors for cybercriminals targeting enterprise systems. Organizations running Drupal should apply available patches immediately to prevent potential compromise. Source: CISA.

via RSS: CISA AlertsRead source
Chinese Hackers Target EU Governments Using Discord, Microsoft Tools
Malware

Chinese Hackers Target EU Governments Using Discord, Microsoft Tools

An advanced persistent threat group linked to China has conducted cyberattacks against European government agencies using legitimate platforms like Discord and Microsoft Graph APIs as command-and-control channels. The attackers employed SOCKS proxies including SoftEther VPN to mask their activities and establish secure tunneling between compromised systems and attacker infrastructure. This sophisticated approach allowed the group to evade detection by blending malicious traffic with normal communications. Security researchers identified this campaign as part of a broader espionage operation targeting sensitive government networks across the EU region. Source: Cybersecurity publication.

via RSS: Dark ReadingRead source
India shifts focus from cyber deployment to operations
Cyber Law (India)

India shifts focus from cyber deployment to operations

India's cybersecurity landscape is evolving beyond initial implementation phases toward mature operational management. Organizations across the country are moving past the deployment stage to focus on continuous monitoring, threat detection, and response capabilities. This shift reflects growing organizational maturity in handling security infrastructure. Industry experts highlight that Indian enterprises must now prioritize skilled personnel, efficient incident response procedures, and regular security audits. The transition underscores challenges in maintaining robust defenses against evolving threats while managing existing systems effectively. Companies need to invest in training and automation to bridge the gap between deployment and sustainable security operations.

via GoogleNews: cyber attack IndiaRead source
Shira: Employee Training Against Phishing Attacks
Phishing

Shira: Employee Training Against Phishing Attacks

Shira is a dedicated anti-phishing training platform designed to help organizations educate employees about phishing threats. The platform provides interactive training modules that teach users to recognize suspicious emails, fraudulent links, and social engineering tactics commonly used in phishing campaigns. By simulating real-world phishing scenarios, Shira enables employees to practice identifying threats in a safe environment before encountering actual attacks. Such training platforms are crucial for Indian businesses and institutions seeking to strengthen their cybersecurity defenses, as phishing remains a primary entry point for data breaches and financial fraud. Awareness and employee training significantly reduce an organization's vulnerability to phishing-based attacks. Source: Shira.

via HN: phishingRead source
Ottawa Man Arrested for Operating Kimwolf IoT Botnet
Malware

Ottawa Man Arrested for Operating Kimwolf IoT Botnet

A 23-year-old from Ottawa has been arrested by Canadian authorities for allegedly developing and running Kimwolf, a rapidly spreading botnet targeting Internet-of-Things devices. The malicious software compromised millions of devices to launch large-scale DDoS attacks over six months. The suspect faces criminal hacking charges in both Canada and the United States after launching DDoS, doxing, and swatting attacks against security researchers and journalists. The arrest follows public identification of the accused in early 2026 following these coordinated cyber attacks. Source: KrebsOnSecurity.

via Krebs on SecurityRead source
Google API Keys Remain Accessible After Deletion
Data Breaches

Google API Keys Remain Accessible After Deletion

Security researchers have identified a concerning vulnerability in Google's API key deletion process. When users delete API keys from Google Cloud, the keys reportedly remain functional for up to 23 minutes despite Google's claims of immediate deactivation. This delay creates a security window where attackers who have compromised the keys could potentially continue accessing services. The vulnerability poses risks for developers and organizations relying on Google Cloud services for sensitive operations. Users should be cautious about API key management and consider implementing additional security measures such as rotation policies and monitoring for unauthorized access attempts during this critical timeframe. Source: Security Research.

via RSS: Dark ReadingRead source
European Police Shut Down VPN Used by Ransomware Gangs
Ransomware

European Police Shut Down VPN Used by Ransomware Gangs

European law enforcement authorities have successfully dismantled a VPN service that was reportedly used by approximately 24 ransomware criminal groups for conducting cyberattacks. The VPN provider had marketed itself as offering complete anonymity to users. However, Europol managed to identify and notify the service's users about their exposure. This operation represents a significant blow to organized cybercriminals who relied on this infrastructure for concealing their malicious activities. The shutdown demonstrates growing international cooperation in combating ransomware threats that increasingly target businesses and critical infrastructure globally. Source: Europol

via RSS: TechCrunch SecurityRead source
Two Americans Guilty in India-Based Tech Support Scams
Social Engineering

Two Americans Guilty in India-Based Tech Support Scams

Two American citizens have pleaded guilty to assisting tech support scam operations based in India. These scam centers typically target unsuspecting victims through deceptive pop-ups and cold calls, convincing them that their computers are infected with malware. Once victims are manipulated into providing remote access, scammers steal personal information and financial data. The Americans' involvement in facilitating these operations highlights the transnational nature of cybercrime networks. Such tech support scams remain prevalent in India and globally, affecting thousands of people annually. Authorities continue cracking down on individuals who knowingly support these fraudulent operations across borders. Source: The Record from Recorded Future News.

via GoogleNews: tech support scamRead source
AI Model Used to Discover macOS Kernel Vulnerability
Malware

AI Model Used to Discover macOS Kernel Vulnerability

Researchers utilized Anthropic's Mythos AI model to identify and exploit a kernel memory corruption vulnerability in Apple's M5 processor. The discovery highlights emerging risks where advanced AI systems can be leveraged to uncover critical security flaws in operating systems. Kernel-level vulnerabilities are particularly dangerous as they can grant attackers complete system control and bypass security protections. Apple users running M5-based devices should monitor for security patches addressing this issue. This incident underscores the dual-use nature of AI technologies and the importance of responsible disclosure practices in cybersecurity research. Source: News Article.

via RSS: Schneier on SecurityRead source
Microsoft Releases May 2026 Security Updates
Malware

Microsoft Releases May 2026 Security Updates

Microsoft has announced new security updates designed to enhance visibility, control, and protection across interconnected systems. The updates focus on addressing emerging threats as organizations increasingly adopt artificial intelligence. These enhancements aim to provide comprehensive security coverage for expanding digital ecosystems. The improvements are part of Microsoft's ongoing commitment to securing enterprise environments against evolving cyber threats. Organizations are encouraged to review the latest security features and implement them to strengthen their defensive posture. Source: Microsoft Security Blog.

via RSS: Microsoft SecurityRead source
AI Agents Reshape Enterprise Identity Security Spending
Identity Theft

AI Agents Reshape Enterprise Identity Security Spending

Organizations deploying AI agents across operations face new identity security challenges requiring different budgeting approaches than traditional systems. According to Omdia research, AI agent identities demand specialized management, security protocols, and governance frameworks distinct from conventional identity and access management (IAM) projects. As enterprises expand AI agent deployment, security teams must adapt budget allocation strategies to address emerging identity risks specific to autonomous AI systems. This shift reflects growing recognition that AI agents operate under different threat models compared to human users or traditional applications.

via RSS: Dark ReadingRead source
Microsoft Alerts Users to New Defender Security Flaws
Malware

Microsoft Alerts Users to New Defender Security Flaws

Microsoft has issued a warning about previously unknown vulnerabilities in its Windows Defender security software that are being actively exploited by attackers. These zero-day flaws allow threat actors to bypass security protections and potentially compromise affected systems. The vulnerabilities represent a significant risk to users who rely on Defender as their primary antivirus solution. Microsoft is urging users to apply security updates and implement additional protective measures. The company is actively investigating the scope of attacks and working on patches to address these critical security gaps. Users should remain vigilant and monitor their systems for suspicious activity. Source: Microsoft Security Advisory.

via HN: zero dayRead source