News

Short summaries of the cyber-crime stories moving in India and globally. We link back to the original source — always.

FBI Warns of Rising Cyber-Enabled Cargo Theft in North America
Dark Web

FBI Warns of Rising Cyber-Enabled Cargo Theft in North America

The FBI has alerted the transportation and logistics sectors about an increase in cyber-enabled cargo thefts. It is projected that losses from these crimes could reach nearly $725 million in the U.S. and Canada by 2025. As cybercriminals utilize advanced techniques to exploit vulnerabilities in supply chains, the risk to cargo during transit has significantly intensified. Companies are urged to bolster their cybersecurity measures to protect against these threats, which could have wider implications for the industry. This situation serves as a cautionary reminder for Indian businesses in logistics to remain vigilant against similar attacks. Source: [publication name].

via BleepingComputerRead source
PyTorch Lightning Compromised in Recent Supply Chain Attack
Malware

PyTorch Lightning Compromised in Recent Supply Chain Attack

Cyber attackers have targeted the widely used Python package, PyTorch Lightning, managing to release two malicious updates aimed at stealing user credentials. The malicious versions, labeled 2.6.2 and 2.6.3, were made available on April 30, 2026. Reports from cybersecurity firms, including Aikido Security and OX Security, indicate that this is a part of ongoing supply chain attacks, which have become a significant concern for software integrity. Users of PyTorch Lightning are advised to check their installed versions and update their software to mitigate potential threats.

via The Hacker NewsRead source
India and UK Strengthen Tech Partnership for Supply Chain Security
Cyber Law (India)

India and UK Strengthen Tech Partnership for Supply Chain Security

India and the United Kingdom are enhancing their collaboration through the Technology Security Initiative, which aims to safeguard critical and emerging technologies. This partnership will focus on securing supply chains, while also expanding economic growth opportunities. Areas of cooperation include artificial intelligence, quantum technology, biotechnology, and health technology. Current joint innovation projects are already underway, which are expected to bolster the technological capabilities of both countries and enhance their positions in the global market. This initiative reflects the increasing importance of international cooperation in technology and security. Source: [publication name].

via Economic Times TechRead source
Brazilian Firm Linked to DDoS Attacks on Local ISPs
Malware

Brazilian Firm Linked to DDoS Attacks on Local ISPs

A Brazilian cybersecurity firm, which specializes in protecting against DDoS (Distributed Denial-of-Service) attacks, has been implicated in enabling a botnet that launched large-scale attacks on other internet service providers in Brazil. The company's CEO claimed that these cyberattacks stemmed from a security breach and suggested that a competitor may be behind the incident, aiming to damage the firm’s reputation. The situation highlights the complexities of cybersecurity, where attackers can exploit vulnerabilities even within protective organizations. Such incidents serve as a reminder of the need for continuous vigilance in network security to safeguard against potential threats. Source: KrebsOnSecurity.

via Krebs on SecurityRead source
Cyber Threats Update: Scam Texts, Software Vulnerabilities, and Hacks
Social Engineering

Cyber Threats Update: Scam Texts, Software Vulnerabilities, and Hacks

This week, cybersecurity issues have surged, including the use of fake cell towers to send fraudulent SMS messages. Additionally, developers are facing risks due to tools that unintentionally access private files during installations. Alarmingly, millions of servers are currently exposed online without password protection. Other reported incidents include hacking attempts targeting the popular game Roblox, affecting around 600,000 accounts. The internet landscape remains precarious with a variety of security threats emerging, keeping both users and developers on high alert. It’s crucial for everyone to stay informed and practice safe online habits. Source: [publication name].

via The Hacker NewsRead source
Concerns Rise Over New AI Model in Japan's Financial Sector
Malware

Concerns Rise Over New AI Model in Japan's Financial Sector

The recent introduction of a new AI model by Anthropic, referred to as a potential superhacker, has raised concerns among global financial institutions in Japan. While this has sparked panic regarding possible cyber threats, many cybersecurity experts believe that the fears may be overstated. They point out that advanced AI tools can also be used to enhance security measures, suggesting that a balanced view should be adopted. Ongoing dialogues in the cybersecurity community emphasize the importance of not overreacting to technological advancements while remaining vigilant against actual threats. Source: [publication name].

via Dark ReadingRead source
SAP npm Packages Hacked to Steal Developer Credentials
Data Breaches

SAP npm Packages Hacked to Steal Developer Credentials

Several official npm packages from SAP were compromised in a reported supply-chain attack, attributed to a group named TeamPCP. This breach aimed to extract sensitive data, including credentials and authentication tokens from the systems of developers. Such incidents highlight the ongoing risks associated with software package management systems, where malicious actors can manipulate widely used software to target unsuspecting users. Developers are advised to remain vigilant and ensure they are using verified packages to mitigate such threats. It's crucial to stay informed about updates and security breaches in software repositories to protect sensitive information. Source: [publication name].

via BleepingComputerRead source
Hackers Use Vulnerabilities in Qinglong Tool for Cryptomining
Crypto Scams

Hackers Use Vulnerabilities in Qinglong Tool for Cryptomining

Cyber attackers are taking advantage of two vulnerabilities in the Qinglong task scheduler, an open-source tool, to install cryptominers on the servers of developers. These flaws allow hackers to bypass authentication, giving them unauthorized access to systems. This exploitation can lead to significant resource drain for organizations, as cryptominers consume considerable processing power and can disrupt normal operations. It highlights the ongoing need for software security and the importance of updating systems to safeguard against such attacks. Developers are advised to monitor their systems and apply necessary updates to prevent future intrusions. Source: [publication name].

via BleepingComputerRead source
AI Tool Identifies Serious Vulnerability in GitHub
Data Breaches

AI Tool Identifies Serious Vulnerability in GitHub

Wiz, a cybersecurity firm, has utilized an AI reverse-engineering tool to discover a critical vulnerability in GitHub. This discovery was made possible through advanced technology that significantly reduced the time and cost involved in traditional vulnerability detection methods. Such tools are proving to be instrumental in identifying security risks that may otherwise go unnoticed, highlighting the potential of AI in enhancing cybersecurity measures. With the rise of software development platforms like GitHub, securing these environments is crucial for protecting sensitive data and maintaining the integrity of development processes. The identification of this high-severity bug underscores the importance of continuous vigilance and updated security practices in the tech industry. Source: [publication name].

via Dark ReadingRead source
Credential-Stealing Malware Targets SAP-Related npm Packages
Malware

Credential-Stealing Malware Targets SAP-Related npm Packages

Cybersecurity experts have raised concerns over a new supply chain attack known as mini Shai-Hulud. This campaign has illicitly compromised various npm packages related to SAP's JavaScript and cloud applications, deploying malware designed to steal user credentials. Leading cybersecurity firms, including Aikido Security and Google-owned Wiz, have reported on the ongoing threats posed by this attack. The situation highlights the importance of safeguarding software supply chains and staying vigilant against potential security risks associated with third-party packages. Users and organizations using SAP-related technologies are urged to monitor their systems for any unusual activities and to employ robust cybersecurity measures. Source: CyberSathi.in.

via The Hacker NewsRead source
New Malware Discovered in npm Package Linked to DPRK Attacks
Malware

New Malware Discovered in npm Package Linked to DPRK Attacks

Cybersecurity experts found that a malicious code was embedded within the npm package named '@validate-sdk/v2'. This package is marketed as a software development kit (SDK) for various functions, including hashing and validation. The researchers linked this suspicious activity to North Korean cybercriminals, who are reportedly using artificial intelligence to enhance their attack methods. The package was used as a dependency in a project associated with Anthropic's Claude Opus language model. Users are advised to exercise caution when downloading and utilizing npm packages, as malicious software can pose serious risks. Source: [publication name].

via The Hacker NewsRead source
Small UPI Players Push for Fair Competition Against Major Brands
UPI Fraud

Small UPI Players Push for Fair Competition Against Major Brands

Smaller players in India’s Unified Payments Interface (UPI) sector are set to meet with the National Payments Corporation of India (NPCI) to address concerns about the dominance of industry leaders like PhonePe, Google Pay, and Paytm. These smaller companies aim to ensure a level playing field and fair competition within the UPI ecosystem, which has seen rapid growth primarily propelled by these larger platforms. The meeting represents a significant step towards fostering more equitable practices in digital payments in India. Meanwhile, WhatsApp is enhancing its defenses against scams to protect users from fraud attempts on its platform. Source: ETtech.

via Economic Times TechRead source