News

Short summaries of the cyber-crime stories moving in India and globally. We link back to the original source — always.

Grafana Labs warns of TanStack NPM ransomware threat
Ransomware

Grafana Labs warns of TanStack NPM ransomware threat

Grafana Labs has issued a security advisory regarding a ransomware incident affecting the TanStack package in the NPM (Node Package Manager) supply chain. The incident highlights vulnerabilities in popular open-source repositories that developers rely on. The company has provided guidance on identifying compromised packages and recommended immediate updates for affected users. This supply chain attack underscores the importance of verifying package authenticity and monitoring dependencies in development workflows. Organizations using TanStack should review their systems and implement the suggested security patches promptly to prevent potential ransomware infections. Source: Grafana Labs Security Advisory.

via HN: ransomwareRead source
Interpol dismantles 53 servers in malware, phishing crackdown
Malware

Interpol dismantles 53 servers in malware, phishing crackdown

International law enforcement agency Interpol has successfully shut down 53 servers hosting malware and phishing operations as part of 'Operation Ramz'. The coordinated action targeted infrastructure used by cybercriminals to distribute malicious software and conduct phishing attacks that compromise user credentials and financial information. This operation demonstrates global cooperation in combating cybercrime threats that affect users worldwide, including India. The seizure of these servers disrupts criminal networks' ability to launch large-scale attacks and steal sensitive data from unsuspecting victims. Source: Interpol.

via HN: phishingRead source
NYC Health Agency Confirms Breach: Medical Records and Biometric Data Stolen
Data Breaches

NYC Health Agency Confirms Breach: Medical Records and Biometric Data Stolen

New York City Health and Hospitals Corporation (NYCHHC) disclosed a significant data breach affecting patient information. Attackers accessed medical records and fingerprint data during the incident. The breach compromises sensitive personal and health information of affected individuals. NYCHHC is investigating the scope of the attack and notifying impacted patients. This incident highlights vulnerabilities in healthcare systems' data security measures. Individuals whose data was compromised should monitor for identity theft and fraudulent activities. Healthcare organizations handling biometric data face increasing cyber threats, emphasizing the need for robust security protocols and regular audits.

via HN: data breachRead source
US Cybersecurity Agency Contractor Exposed AWS Credentials on GitHub
Data Breaches

US Cybersecurity Agency Contractor Exposed AWS Credentials on GitHub

A contractor working for the US Cybersecurity & Infrastructure Security Agency (CISA) accidentally left a public GitHub repository containing sensitive AWS GovCloud credentials and internal CISA system details. The exposed repository included files revealing how CISA develops, tests, and deploys software. Security experts have called this one of the most serious government data leaks in recent times. The repository remained publicly accessible until recently when it was discovered and removed. This incident highlights the risks of credential exposure on public platforms and the importance of proper access control management in government agencies. Source: BleepingComputer.

via RSS: Krebs on SecurityRead source
Windows MiniPlasma Zero-Day Flaw Enables Full System Access
Malware

Windows MiniPlasma Zero-Day Flaw Enables Full System Access

A critical vulnerability named MiniPlasma has been discovered in Windows systems, allowing attackers to gain SYSTEM-level access—the highest privilege level. A proof-of-concept exploit has been publicly released, increasing risk for unpatched systems. SYSTEM access enables attackers to install malware, steal data, modify system files, and control devices completely. Users should immediately apply Windows security updates from Microsoft. This zero-day affects multiple Windows versions and poses significant risk to Indian organizations and individual users. Keep systems updated and monitor security advisories from Microsoft for patches. Source: Security researcher disclosure.

via HN: zero dayRead source
FedEx Package Scam Targets Indian Comedian
Social Engineering

FedEx Package Scam Targets Indian Comedian

An Indian comedian fell victim to a sophisticated social engineering scam impersonating FedEx. Scammers sent notifications claiming a package contained illegal drugs, prompting the victim to click malicious links. The attack exploited trust in legitimate courier services to deceive users into revealing sensitive information or installing malware. Such scams target middle and upper-class Indians who frequently receive online deliveries. Experts advise verifying package details directly through official courier websites rather than clicking links in unsolicited messages. Awareness about these impersonation tactics is crucial for protecting personal and financial data. Source: BBC.

via GoogleNews: courier scamRead source
NGINX Vulnerability CVE-2026-42945 Under Active Exploit
Malware

NGINX Vulnerability CVE-2026-42945 Under Active Exploit

A critical vulnerability in NGINX web server (CVE-2026-42945) is being actively exploited by attackers in the wild. Organizations running NGINX installations are at risk and should prioritize applying security patches immediately. System administrators are advised to update their NGINX instances to patched versions and monitor systems for signs of compromise. This vulnerability could potentially allow unauthorized access or remote code execution on affected servers. Indian enterprises and web hosting providers should review their NGINX deployments and implement necessary security measures without delay to prevent exploitation. Source: Help Net Security.

via GoogleNews: vulnerability CVERead source
Signal Messaging App Adds Alerts Against Social Engineering
Social Engineering

Signal Messaging App Adds Alerts Against Social Engineering

Signal, the popular encrypted messaging platform, has introduced new security warnings to protect users from social engineering and phishing attempts. These alerts are designed to identify suspicious messages and links that could compromise user safety. The feature helps users recognize common tactics used by scammers to manipulate them into revealing sensitive information or clicking malicious links. This move strengthens Signal's commitment to user protection in an era of increasing cyber threats. Indian users can benefit from these built-in safeguards while communicating on the platform. The implementation reflects growing awareness about the need for in-app security measures against evolving social engineering techniques. Source: Signal Official Announcement.

via HN: phishingRead source
BlackFile Extortion Gang Targets Organizations via Voice Phishing
Social Engineering

BlackFile Extortion Gang Targets Organizations via Voice Phishing

A threat group called UNC6671, operating under the 'BlackFile' brand, is conducting a large-scale extortion campaign targeting organizations across North America, Australia, and the UK. The group uses sophisticated voice phishing (vishing) and SSO compromise techniques combined with adversary-in-the-middle attacks to bypass multi-factor authentication and gain access to cloud environments, particularly Microsoft 365 and Okta systems. They use Python and PowerShell scripts to steal corporate data for extortion purposes. Since emerging in early 2026, the group has maintained high operational tempo. Security experts emphasize these attacks exploit social engineering rather than vendor vulnerabilities, highlighting the need for phishing-resistant authentication methods. Source: Google Threat Intelligence Group.

via RSS: Mandiant BlogRead source
Ransomware Attacks Surge Across India in April 2026
Ransomware

Ransomware Attacks Surge Across India in April 2026

India experienced a significant rise in cyber attacks during April 2026, with ransomware activity emerging as a major threat. The acceleration in attack frequency reflects growing sophistication among cybercriminals targeting Indian organizations. Security experts warn of expanding ransomware campaigns affecting businesses across sectors. The trend underscores the need for enhanced cybersecurity measures and employee awareness in Indian enterprises. Organizations are advised to strengthen backup systems, implement multi-factor authentication, and develop incident response plans. Government and private sector collaboration remains critical to combat the evolving threat landscape. Source: SMEStreet.

via GoogleNews: ransomware IndiaRead source
The Ransomware Dilemma: When Attackers Force Impossible Choices
Ransomware

The Ransomware Dilemma: When Attackers Force Impossible Choices

Ransomware attacks present victims with devastating dilemmas similar to the trolley problem—a philosophical thought experiment about choosing between two harmful outcomes. Cybercriminals encrypt critical data and demand payment, forcing organizations to decide between losing valuable information or funding criminal operations. This tactic exploits the psychological pressure on decision-makers during crises. Indian businesses increasingly face such scenarios where attackers deliberately create impossible choices to maximize pressure for ransom payment. Security experts recommend maintaining offline backups, implementing robust incident response plans, and avoiding ransom payments to prevent encouraging further attacks.

via HN: ransomwareRead source
Not applicable for CyberSathi.in
Phishing

Not applicable for CyberSathi.in

This content discusses Nanci, a CI/CD platform development project, not a cybersecurity or cyber-crime awareness topic. It covers software development practices, debugging tools, and pipeline automation—areas outside CyberSathi.in's focus on cyber-crime awareness for Indian readers. The article does not address phishing, ransomware, fraud, malware, data breaches, or other security threats relevant to the portal's mission.

via HN: phishingRead source