News

Short summaries of the cyber-crime stories moving in India and globally. We link back to the original source — always.

Oracle Patches 35 Vulnerabilities in First Monthly Security Update
Malware

Oracle Patches 35 Vulnerabilities in First Monthly Security Update

Oracle has launched its new monthly Critical Security Patch Update (CSPU) program to address urgent security flaws that cannot wait for quarterly patches. The first batch fixes 35 vulnerabilities: 11 critical, 18 high, and 6 medium severity. Critical flaws affect Oracle REST Data Services, E-Business Suite, Universal Work Queue, and Payments modules. Notably, CVE-2026-46840 has a perfect CVSS score of 10, affecting REST Data Services' backend-as-a-service component, allowing unauthenticated attackers to compromise the database gateway via HTTPS. Several vulnerabilities have publicly available exploit code, including flaws in Oracle Communications Unified Assurance. Indian organizations using Oracle products should prioritize patching these critical issues promptly. Source: The Register.

via RSS: CSO OnlineRead source
Dutch Police Bust Massive 17-Million Device Botnet Network
Malware

Dutch Police Bust Massive 17-Million Device Botnet Network

Dutch law enforcement authorities have successfully dismantled a large-scale botnet comprising approximately 17 million infected devices including computers, smartphones, and tablets. The operation involved seizing command-and-control servers that orchestrated the network's activities. According to investigations, the botnet was being exploited to operate a residential proxy service and facilitate various cybercriminal operations. This takedown represents a significant effort in combating large-scale malware infrastructure that threat actors commonly use to launch attacks, steal data, and commit online crimes. The seizure of the operational servers has disrupted the attackers' ability to command and control the compromised devices. Source: SecurityWeek.

via RSS: SecurityWeekRead source
Critical Windows Netlogon Bug Targeted by Attackers
Malware

Critical Windows Netlogon Bug Targeted by Attackers

A critical vulnerability in Windows Netlogon authentication system has become a prime target for cybercriminals. The flaw allows attackers to gain unauthorized access to network systems and escalate privileges without proper credentials. Security experts warn that this vulnerability poses significant risks to organizations running Windows infrastructure. The issue affects multiple Windows versions and can be exploited remotely. IT administrators are urged to apply security patches immediately and monitor their systems for suspicious authentication activities. This vulnerability highlights the importance of keeping systems updated with latest security fixes. Source: SecurityWeek.

via GoogleNews: vulnerability CVERead source
Microsoft Won't Take Legal Action Against Security Researchers
Cyber Law (India)

Microsoft Won't Take Legal Action Against Security Researchers

Microsoft has announced it will not pursue legal action against security researchers following public criticism over its handling of zero-day vulnerabilities. The decision comes after the tech giant faced backlash for its approach to researchers who discover and report previously unknown security flaws. By reversing its stance, Microsoft aims to encourage responsible disclosure of vulnerabilities, which helps improve overall cybersecurity. The move is seen as a win for the security research community, promoting collaboration between software companies and independent researchers to identify and patch security weaknesses before malicious actors can exploit them. Source: Reuters.

via HN: zero dayRead source
Windows Netlogon Vulnerability Actively Exploited
Malware

Windows Netlogon Vulnerability Actively Exploited

A critical remote code execution flaw in Windows Netlogon service is now being actively exploited by threat actors. The vulnerability allows attackers to execute arbitrary code on affected systems, potentially compromising entire networks. Windows Netlogon is a core authentication service used across enterprise environments. Organizations running unpatched Windows systems are at immediate risk. Microsoft has released security updates to address this issue. IT administrators and users should apply patches urgently to prevent unauthorized access and system compromise. Delays in patching increase vulnerability to cyber attacks. Source: BleepingComputer.

via GoogleNews: vulnerability CVERead source
Flowise AI Platform Vulnerable to Remote Code Execution
Malware

Flowise AI Platform Vulnerable to Remote Code Execution

Security researchers at Obsidian Security discovered a critical vulnerability in Flowise, an open-source AI platform used by enterprises for self-hosted AI applications. The flaw, tracked as CVE-2026-40933, allows attackers to execute arbitrary commands through malicious Model Context Protocol (MCP) configurations. The vulnerability can be triggered with a single click via importing a malicious chatflow, requiring only post-authentication access. Flowise, commonly used for building AI assistants, chatbots, and autonomous agents, is vulnerable when stdio MCP is enabled. Flowise Cloud users are unaffected as the feature is disabled there. The official patch has proven insufficient, as attackers can bypass input validation. Organizations using self-hosted Flowise deployments should review their MCP server configurations immediately to mitigate risks. Source: SecurityWeek.

via RSS: CSO OnlineRead source
Bengaluru Woman Loses Rs 24 Crore in Digital Arrest Scam
Social Engineering

Bengaluru Woman Loses Rs 24 Crore in Digital Arrest Scam

An elderly woman in Bengaluru fell victim to a sophisticated digital arrest scam, losing Rs 24 crore to fraudsters. The scammers impersonated law enforcement officials and convinced the victim that she was involved in illegal activities, pressuring her to transfer large sums of money to 'secure' her assets. This case highlights the evolving tactics used by cyber criminals who exploit fear and authority to manipulate victims into financial transfers. Authorities have registered cases and are investigating the fraud network. Citizens are advised to verify official communications through official channels and avoid sharing personal or financial information with unverified callers. Source: MSN.

via GoogleNews: digital arrest scamRead source
Gujarat Man Loses Money to Digital Arrest Scam
Social Engineering

Gujarat Man Loses Money to Digital Arrest Scam

An elderly man from Gujarat fell victim to an elaborate 'digital arrest' scam, a social engineering fraud where criminals impersonate law enforcement officials. The scammers contacted the victim claiming illegal activities on his account and threatened arrest, pressuring him to transfer money to a supposed 'safe account.' This scheme exploits fear and urgency to bypass victims' rational thinking. Such frauds have increased significantly across India, targeting senior citizens who are often less familiar with digital verification processes. Victims are advised to verify caller identity independently, never share personal details with unverified callers, and report suspicious communications to local cybercrime authorities immediately. Source: Devdiscourse.

via GoogleNews: digital arrest scamRead source
Military Officers Face Court Martial in Kapurthala Job Scam
Social Engineering

Military Officers Face Court Martial in Kapurthala Job Scam

A Major General and other military officials are undergoing court martial proceedings in connection with a job recruitment scam in Kapurthala. The case involves unauthorized recruitment practices and misuse of official positions for personal gain. The scam reportedly affected multiple candidates seeking military employment. Investigation authorities discovered fraudulent job offers and financial irregularities in the recruitment process. The court martial proceedings represent serious disciplinary action against military personnel accused of misconduct and breach of service conduct. This case highlights the importance of verifying employment opportunities through official channels only. Candidates are advised to be cautious of unsolicited job offers, even from seemingly credible sources. Source: The Tribune.

via GoogleNews: job scam IndiaRead source
HC Orders Relief for HDFC AMC in 680 GB Data Theft Case
Data Breaches

HC Orders Relief for HDFC AMC in 680 GB Data Theft Case

A Mumbai High Court has granted urgent interim relief to HDFC Asset Management Company (AMC) concerning an alleged theft of 680 GB of data. The court's decision provides temporary protection to the financial firm as investigations continue into the cyber incident. The case highlights growing concerns about data security within India's financial sector. HDFC AMC had approached the court seeking immediate relief regarding unauthorized access to sensitive company information. The High Court's intervention underscores the judiciary's role in addressing cyber threats affecting major financial institutions. Details regarding the perpetrators and the nature of stolen data remain under investigation. Source: Hindustan Times.

via GoogleNews: ransomware IndiaRead source
Job seekers targeted by AI-powered fake interview scams
Social Engineering

Job seekers targeted by AI-powered fake interview scams

Fraudsters are using artificial intelligence and biometric technology to conduct fake online job interviews, targeting unsuspecting job seekers. These scams typically involve criminals posing as legitimate recruiters and conducting video interviews where they collect personal biometric data including facial recognition, fingerprints, or voice samples. This stolen biometric information is then used for identity theft and unauthorized access to financial accounts. Job seekers in India should verify company credentials through official websites, avoid sharing biometric data with unverified sources, and be cautious of interview requests from unknown numbers or email addresses. Report suspicious recruiting activity to relevant authorities immediately. Source: The News Mill.

via GoogleNews: job scam IndiaRead source
Cyber Crime Threats Growing Across India
Cyber Law (India)

Cyber Crime Threats Growing Across India

India faces an escalating cyber crime problem affecting individuals and organizations nationwide. Criminal activities span multiple domains including financial fraud, data theft, and identity compromise. The rise reflects both increasing internet penetration and criminals' evolving tactics. Legal frameworks exist to combat these threats, but awareness and preventive measures remain crucial for citizens. Understanding cyber crime types and protective steps is essential as digital transactions become more prevalent in Indian society. Source: Legal Service India.

via GoogleNews: cyber attack IndiaRead source