News

Short summaries of the cyber-crime stories moving in India and globally. We link back to the original source — always.

30,000 Facebook Accounts Compromised in Phishing Scheme
Phishing

30,000 Facebook Accounts Compromised in Phishing Scheme

A recent cyber operation linked to Vietnam has been detected, involving around 30,000 hacked Facebook accounts. The hackers utilized Google AppSheet as a tool for phishing, sending fraudulent emails to trick users into giving away their account details. This operation, known as AccountDumpling, has been reported by cybersecurity firm Guardio. The stolen accounts are being sold through an illegal online marketplace run by the cybercriminals. Users are advised to remain vigilant and take necessary precautions to protect their accounts from phishing attacks.

via The Hacker NewsRead source
Teen Arrested in Connection with French Data Breach Incident
Data Breaches

Teen Arrested in Connection with French Data Breach Incident

French authorities have detained a 15-year-old boy linked to a cyberattack on France Titres (ANTS), the national agency responsible for administrative documents. The teenager is suspected of selling personal data that was stolen during the breach, highlighting ongoing concerns regarding youth involvement in cybercrime. The incident serves as a reminder of the growing challenge of data security and the need for awareness around such events. Cyberattacks can have serious implications, affecting both individuals and government agencies. Authorities continue to investigate the incident to ascertain the full extent of the breach and prevent future occurrences. Source: [publication name].

via BleepingComputerRead source
US Officials Propose Shorter Deadlines for IT Vulnerability Fixes
Data Breaches

US Officials Propose Shorter Deadlines for IT Vulnerability Fixes

US cybersecurity officials are considering a significant reduction in the time allocated for government agencies to address critical IT system vulnerabilities. This proposal aims to cut the deadline from two weeks to just three days. The urgency stems from the growing capabilities of advanced AI tools, which can quickly identify and exploit these weaknesses, increasing the risk of cyberattacks. By shortening the response time, authorities hope to enhance defenses against fast-evolving cyber threats and better protect sensitive data and infrastructure. Similar measures may be of interest for Indian cyber defense strategies in light of rising cyber risks. Source: [publication name].

via Economic Times TechRead source
AI Integration Risks Lead to Database Deletion Issues
Malware

AI Integration Risks Lead to Database Deletion Issues

Recent reports indicate that the challenges related to artificial intelligence (AI) in production environments stem not from the AI itself, but from premature integration without thorough security assessments. The industry has been incorporating AI agents into live systems before ensuring they meet safety and security standards. This lack of adequate testing has resulted in unintended consequences, including the accidental deletion of critical production databases. Experts emphasize the importance of rigorous security protocols and testing phases when deploying AI technologies to prevent such incidents. Proper safeguards are crucial to maximize the benefits of AI while minimizing the risks associated with its implementation.

via Dark ReadingRead source
Cybercrime Groups Target SaaS Platforms with Vishing and SSO Abuse
Data Breaches

Cybercrime Groups Target SaaS Platforms with Vishing and SSO Abuse

Cybersecurity experts have identified two groups, Cordial Spider and Snarky Spider, that are executing rapid and impactful cyberattacks focused on Software as a Service (SaaS) platforms. These groups use techniques like voice phishing (vishing) and Single Sign-On (SSO) abuse to steal sensitive data while leaving few traces of their activities. The attacks are characterized by high speed and efficiency, which pose a significant threat to organizations utilizing SaaS solutions. Companies are advised to enhance their security measures to prevent such breaches. Source: [publication name].

via The Hacker NewsRead source
Cybersecurity Caption Contest: Share Your Thoughts and Win!
Cyber Law (India)

Cybersecurity Caption Contest: Share Your Thoughts and Win!

A contest is being held for creative captions related to cybersecurity, reflecting on the developments of the past 20 years. Participants can choose from various categories such as phishing, ransomware, UPI fraud, and more. The best entry will receive a $20 gift card as a reward. This initiative aims to engage the community and raise awareness about the significance of cybersecurity in today's digital age. Interested individuals are encouraged to share their thoughts and contribute to the dialogue on cyber threats and safety. Source: [publication name].

via Dark ReadingRead source
Pentagon Partners with AI Firms to Enhance Defense Capabilities
Cyber Law (India)

Pentagon Partners with AI Firms to Enhance Defense Capabilities

The Pentagon has formed partnerships with seven prominent AI companies to incorporate their technology into secure military networks. This initiative aims to enhance data analysis and improve decision-making processes within the Defense Department, indicating a strategic shift towards AI-driven military operations. However, one of the involved companies, Anthropic, is currently facing some limitations due to security-related concerns. This move underscores the growing importance of artificial intelligence in modern defense strategies. The collaboration illustrates the military's commitment to leveraging advanced technologies to support national security objectives. Source: [publication name].

via Economic Times TechRead source
Bombay HC Orders WhatsApp to Act on Scam Groups Without Delays
Cyber Law (India)

Bombay HC Orders WhatsApp to Act on Scam Groups Without Delays

The Bombay High Court has directed WhatsApp to proactively remove fraudulent groups from its platform without waiting for formal court orders. The ruling addresses growing concerns about scam groups operating on the messaging app to defraud users. The court emphasized that WhatsApp must take immediate responsibility in identifying and eliminating such malicious communities rather than relying solely on judicial intervention. This decision aims to strengthen the platform's role in combating online fraud and protecting Indian users from scam operations. The order reflects the judiciary's commitment to holding tech companies accountable for misuse of their services. Source: MediaNama.

via GoogleNews: WhatsApp scamRead source
New Scan Reveals 9-Year-Old Linux Vulnerability, Patch Available
Malware

New Scan Reveals 9-Year-Old Linux Vulnerability, Patch Available

A recent AI-assisted software scan has discovered a nine-year-old vulnerability in Linux systems, identified by a short proof-of-concept exploit code consisting of just 10 lines. Fortunately, a patch is already available to address this security flaw, ensuring users can protect their systems against potential threats. This incident highlights the importance of regular software updates and the role of modern technology in identifying long-standing vulnerabilities. Linux users are advised to implement the updates promptly to safeguard against any exploitation of this bug. Source: [publication name].

via Dark ReadingRead source
Impact of Anthropic's New AI Model on Cybersecurity
Malware

Impact of Anthropic's New AI Model on Cybersecurity

The introduction of Anthropic's latest AI model, Mythos, is anticipated to significantly transform the cybersecurity landscape. Experts in the industry are expressing concerns that advancements in artificial intelligence could alter how cyber threats operate, potentially leading to more sophisticated attacks. This development raises questions about preparedness in tackling new challenges in cybersecurity. Industry leaders are engaging in discussions on how to adapt to these changes, emphasizing the need for heightened security measures. As technology evolves, the response to cyber threats must also advance to safeguard against emerging risks. Source: [publication name].

via Dark ReadingRead source
Anthropic Unveils Claude Security for Enterprises in Public Beta
Malware

Anthropic Unveils Claude Security for Enterprises in Public Beta

Anthropic has introduced Claude Security in a public beta phase. This new AI-driven tool is aimed at helping enterprise security teams by scanning their code for potential vulnerabilities and automatically generating fixes. Utilizing the advanced capabilities of Claude Opus 4.7, the tool analyzes the code similarly to how a human expert would, tracing the flow of data and component interactions. This innovation seeks to improve code security and address issues that conventional tools might overlook. The launch signifies a step forward in integrating AI technologies into cybersecurity measures. Source: [publication name].

via Economic Times TechRead source
New Bluekit Phishing Toolkit Features AI and Over 40 Templates
Phishing

New Bluekit Phishing Toolkit Features AI and Over 40 Templates

A new phishing toolkit called Bluekit has been launched, featuring more than 40 templates designed to target widely used online services. This toolkit incorporates basic artificial intelligence capabilities that can help users generate drafts for their phishing campaigns, making it easier to deploy fraudulent activities. Phishing attacks, where cybercriminals attempt to deceive individuals into providing sensitive information, continue to pose significant risks to internet users. Awareness and preventive measures are critical to safeguard personal and financial data against such threats. Users are encouraged to remain vigilant and regularly update their security practices. Source: [publication name].

via BleepingComputerRead source