News

Short summaries of the cyber-crime stories moving in India and globally. We link back to the original source — always.

FBI Dismantles India-Based Tech Support Scam Ring
Social Engineering

FBI Dismantles India-Based Tech Support Scam Ring

The Federal Bureau of Investigation has successfully shut down a major technical support scam operation based in India that defrauded victims of millions of dollars. The scam typically involved fraudsters posing as legitimate tech support representatives, contacting unsuspecting people and convincing them their devices were infected with malware or experiencing serious problems. Victims were then persuaded to grant remote access to their computers and transfer money for fake repairs. This operation targeted individuals across multiple countries, causing substantial financial losses. The FBI's action highlights the growing threat of tech support scams, which remain prevalent in India and internationally. Authorities advise citizens to verify support requests independently and avoid granting remote access to unknown parties. Source: News Arena India.

via GoogleNews: tech support scamRead source
Website Brand Hijacking Attack Exploits Content Delivery Systems
Malware

Website Brand Hijacking Attack Exploits Content Delivery Systems

Security researchers have identified an attack technique called Underminr that exploits domain-fronting vulnerabilities in content delivery networks. This method allows attackers to intercept and modify web requests while masking their malicious activity behind trusted websites. By leveraging legitimate domains, threat actors can hijack a website's brand and redirect users without detection. This attack poses significant risks to businesses and users who may unknowingly interact with compromised content. Organizations using content delivery services should review their security configurations and implement additional safeguards to prevent unauthorized request manipulation and brand misuse. Source: Cybersecurity Publication.

via RSS: Dark ReadingRead source
AI-Powered Ransomware Threats Growing in India: Check Point
Ransomware

AI-Powered Ransomware Threats Growing in India: Check Point

Cybersecurity firm Check Point has issued a warning about the increasing prevalence of artificial intelligence-driven ransomware attacks targeting Indian organizations. The threat assessment highlights how attackers are leveraging AI technologies to enhance ransomware capabilities, making attacks more sophisticated and harder to detect. This trend poses significant risks to businesses across various sectors in India. Organizations are advised to strengthen their defenses through updated security protocols, employee training, and robust backup systems. Check Point's warning underscores the need for Indian companies to remain vigilant against evolving cyber threats that combine ransomware with AI-powered tactics for maximum impact. Source: Express Computer.

via GoogleNews: ransomware IndiaRead source
FBI Busts India-Based Call Center Fraud Ring
Social Engineering

FBI Busts India-Based Call Center Fraud Ring

Law enforcement shut down a fraudulent call center operation involving five Indian nationals and two American businessmen. The operation targeted victims through deceptive telemarketing schemes, impersonating legitimate organizations to extract money and personal information. Investigators uncovered sophisticated social engineering tactics used to manipulate victims into transferring funds or divulging sensitive details. The coordinated operation between Indian and US authorities highlights the cross-border nature of organized cybercrime. This case demonstrates how criminal networks exploit call center infrastructure to conduct large-scale fraud targeting unsuspecting individuals across jurisdictions. Source: The Times of India.

via GoogleNews: tech support scamRead source
CISA Adds Two Active Exploited Vulnerabilities to Alert List
Malware

CISA Adds Two Active Exploited Vulnerabilities to Alert List

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified two vulnerabilities actively being exploited by attackers: CVE-2025-34291 in Langflow (origin validation flaw) and CVE-2026-34926 in Trend Micro Apex One (directory traversal issue). These flaws are now part of CISA's Known Exploited Vulnerabilities Catalog, a continuously updated list of security risks threatening critical systems. While U.S. federal agencies must patch these vulnerabilities immediately under directive BOD 22-01, CISA recommends all organizations—including Indian enterprises—prioritize fixing these issues to prevent cyberattacks. Organizations should integrate KEV Catalog monitoring into their vulnerability management strategies. Source: CISA.

via RSS: CISA AlertsRead source
India Faces Growing Ransomware Threat From AI-Enhanced Gangs
Ransomware

India Faces Growing Ransomware Threat From AI-Enhanced Gangs

India's ransomware landscape is shifting as criminal groups consolidate and leverage artificial intelligence to launch more sophisticated attacks. Instead of numerous scattered ransomware operations, fewer but better-organized cybercriminal syndicates are emerging with advanced capabilities. These groups are utilizing AI to automate attacks, improve targeting, and evade detection systems. The trend indicates a maturation of India's cybercriminal ecosystem, posing escalated risks to businesses and critical infrastructure. Organizations need enhanced security postures to counter these increasingly potent threats.

via GoogleNews: ransomware IndiaRead source
FBI Dismantles India-Based Tech Support Scam Operation
Social Engineering

FBI Dismantles India-Based Tech Support Scam Operation

US Federal Bureau of Investigation has shut down an India-based call centre involved in a widespread tech support scam targeting elderly citizens. The operation deceived victims by posing as legitimate technical support providers, convincing them their devices were compromised and extracting money through fake repair services. This investigation highlights how cybercriminals exploit senior citizens through social engineering tactics and remotely access their systems. Indian authorities continue collaborating with international law enforcement to identify and prosecute scammers. Citizens, especially elderly individuals, should verify support requests independently and avoid sharing remote access to their devices with unverified callers. Source: The420.in.

via GoogleNews: tech support scamRead source
FBI Dismantles India-Based Tech Support Scam Targeting US Seniors
Social Engineering

FBI Dismantles India-Based Tech Support Scam Targeting US Seniors

The FBI has shut down a tech support scam operation linked to India that primarily targeted elderly Americans. The fraudsters posed as legitimate technical support representatives, convincing victims their computers had serious problems. They then gained remote access to systems and either installed malware or extracted personal financial information. This type of scam exploits trust and technical knowledge gaps among vulnerable populations. Authorities emphasized that legitimate tech companies rarely initiate unsolicited support calls. Indian cyber-crime investigators have been intensifying efforts against such international fraud rings operating from Indian soil. Source: Mathrubhumi English.

via GoogleNews: tech support scamRead source
Majority of Indian firms hit by identity breaches
Identity Theft

Majority of Indian firms hit by identity breaches

A significant majority of organizations operating in India have experienced at least one identity breach during the past year, according to recent findings. This alarming statistic underscores the growing threat landscape that Indian businesses face from cybercriminals targeting sensitive employee and customer identity data. Identity breaches can lead to unauthorized access, financial losses, and reputational damage. Organizations are increasingly vulnerable due to weak authentication mechanisms, poor access controls, and inadequate identity management practices. Experts recommend implementing robust identity verification systems, multi-factor authentication, regular security audits, and employee awareness training to mitigate these risks. Source: ETCISO.in.

via GoogleNews: ransomware IndiaRead source
AI Essential for Defending Against Cyber Attacks in India
Malware

AI Essential for Defending Against Cyber Attacks in India

As cyber threats intensify across India, artificial intelligence has become crucial for effective defense mechanisms. Organizations and individuals must adopt AI-powered security solutions to combat evolving attack vectors. Traditional security measures alone are insufficient against sophisticated cyber threats that target Indian businesses and citizens. AI enables real-time threat detection, automated response systems, and predictive analytics to identify vulnerabilities before exploitation. Experts emphasize that without AI integration in cybersecurity infrastructure, Indian organizations face significant risks of data breaches, financial loss, and operational disruption. Implementing AI-driven security frameworks is now considered essential rather than optional for protecting critical digital assets. Source: Whalesbook.

via GoogleNews: cyber attack IndiaRead source
Malicious npm Packages Steal CI/CD Credentials from Developers
Malware

Malicious npm Packages Steal CI/CD Credentials from Developers

Hackers compromised @antv npm packages to distribute malware called Mini Shai-Hulud, targeting developers' automation systems. The malicious code activates during package installation and extracts sensitive credentials from popular platforms including GitHub, AWS, Kubernetes, Vault, npm registry, and 1Password. This attack specifically impacts Linux-based development environments and poses significant risk to organizations relying on automated software deployment pipelines. Developers should immediately review their npm dependencies and update to verified versions. Source: Microsoft Security Blog.

via RSS: Microsoft SecurityRead source
Measuring AI Security: Beyond Benchmarks and Standards
Cyber Law (India)

Measuring AI Security: Beyond Benchmarks and Standards

Securing artificial intelligence systems requires more than benchmark scores, according to security experts. Traditional software security approaches—from penetration testing to architectural risk analysis—may offer valuable lessons for AI security measurement. However, AI's deeper business impact demands adapted strategies. Rather than seeking a single security metric, organizations should focus on establishing robust assurance processes and risk management frameworks. The evolving field of AI security must learn from decades of software security development while recognizing AI's unique challenges. Experts emphasize continuous vigilance and proper process management remain essential, as no single security measurement can guarantee AI safety.

via RSS: Schneier on SecurityRead source