News

Short summaries of the cyber-crime stories moving in India and globally. We link back to the original source — always.

Vercel Security Breach Linked to Third-Party AI Tool Compromise
Data Breaches

Vercel Security Breach Linked to Third-Party AI Tool Compromise

Web infrastructure provider Vercel has reported a security breach affecting its internal systems. The incident originated from a hack involving Context.ai, a third-party artificial intelligence tool used by a Vercel employee. As a result of this breach, the attacker was able to gain unauthorized access to the employee's Google Workspace account. This incident raises concerns about the security of third-party applications and the potential risk they pose to a company's sensitive information. Vercel is currently assessing the scope of the breach and its implications for customer data. While it is indicated that customer credentials may have been limitedly exposed, Vercel has not provided detailed information on the extent of the data compromised. Source: [publication name].

via The Hacker NewsRead source
NSA Uses Anthropic's AI Tool Despite Security Concerns
Cyber Law (India)

NSA Uses Anthropic's AI Tool Despite Security Concerns

The US National Security Agency (NSA) is reportedly utilizing Anthropic's AI tool, Mythos Preview, despite warnings from the Pentagon about potential supply-chain risks associated with the company. Mythos is recognized for its advanced capabilities in programming and automation, which experts believe could bolster the NSA's capabilities in cyber operations. The use of this AI by a major national security agency raises questions about the balance between technological advancement and cybersecurity risks. Furthermore, there have been discussions between Anthropic and US authorities regarding these issues. This situation highlights the ongoing tension between innovation and security in the field of cybersecurity. Source: Axios.

via Economic Times TechRead source
Vercel Reports Security Breach Involving Stolen Data Claims
Data Breaches

Vercel Reports Security Breach Involving Stolen Data Claims

Vercel, a cloud development platform, has confirmed a security breach after hackers claimed to have accessed its systems. The attackers are reportedly trying to sell the stolen data. Vercel has not released specific details about the number of users affected or the type of data involved. The company is actively investigating the incident and has assured its users of their commitment to data security. As cyber threats continue to evolve, users are advised to be vigilant about their personal information and implement security measures to protect themselves against potential misuse. Source: [publication name].

via BleepingComputerRead source
Phishing Scams Exploit Apple Account Change Notifications
Phishing

Phishing Scams Exploit Apple Account Change Notifications

A new phishing scam is leveraging Apple account change notifications to trick users into believing they are receiving legitimate communications from Apple. Scammers are sending fake emails that mimic genuine notifications but promote fraudulent iPhone purchase schemes. These emails are sent from Apple's servers, enhancing their credibility and making it difficult for spam filters to detect them. Users are advised to verify the authenticity of such emails before taking any action and to avoid clicking on suspicious links or providing personal information. Staying vigilant can help prevent falling victim to these scams. Source: [publication name].

via BleepingComputerRead source
AI Startup Cursor Plans $2 Billion Fundraising at $50 Billion Valuation
Investment Fraud

AI Startup Cursor Plans $2 Billion Fundraising at $50 Billion Valuation

AI coding startup Cursor is reportedly in negotiations to raise over $2 billion in its latest funding round, which could set its valuation at approximately $50 billion. Major investors expected to participate include well-known firms such as Thrive Capital and Andreessen Horowitz, with possible involvement from Nvidia. This potential influx of capital underscores the growing interest and confidence in AI technologies and their applications. As firms continue to invest heavily, Cursor aims to enhance its product offerings and expand its market presence. Source: [publication name].

via Economic Times TechRead source
Y Combinator Launches Startup School in India Amid Initial Challenges
Investment Fraud

Y Combinator Launches Startup School in India Amid Initial Challenges

The first edition of Y Combinator's Startup School in India attracted over 2,000 aspiring entrepreneurs, showcasing the country's growing AI-driven startup ecosystem. The event featured established figures like Aadit Palicha from Zepto and Mukund Jha from Emergent, who shared valuable insights with participants. Y Combinator emphasized the importance of innovative ideas that can have a global impact. However, the event experienced some initial challenges as organizers worked to accommodate the large turnout. This initiative is part of YC’s efforts to inspire and support the next generation of startups in India. Source: [publication name].

via Economic Times TechRead source
NIST to Cease Rating Lower-Priority Vulnerabilities
Cyber Law (India)

NIST to Cease Rating Lower-Priority Vulnerabilities

The National Institute of Standards and Technology (NIST) announced it will no longer assign severity scores to lower-priority vulnerabilities. This decision comes in response to an overwhelming increase in the number of submissions, which has made it challenging for the agency to assess and manage all reported flaws effectively. By focusing on higher-priority issues, NIST aims to streamline its processes and better allocate resources. This change may impact how organizations prioritize their cybersecurity measures, as they will need to independently assess these lower-priority vulnerabilities. Source: cybersecurity publication.

via BleepingComputerRead source
Security Risks Emerge from Powerful AI Tools
Data Breaches

Security Risks Emerge from Powerful AI Tools

Recent advancements in AI agents, such as those developed with OpenClaw, have raised significant cybersecurity concerns. These AI tools are capable of performing risky actions, including deleting emails and exposing users' personal information. As they increasingly access sensitive accounts, they present attractive targets for cybercriminals who aim to exploit weaknesses and steal valuable data. The growing use of such powerful AI in daily tasks underlines the need for caution, as the potential security threats continue to evolve. Users are advised to remain vigilant and take necessary precautions to protect their information. Source: [publication name].

via Economic Times TechRead source
Critical Vulnerability Found in Protobuf.js Library for JavaScript
Malware

Critical Vulnerability Found in Protobuf.js Library for JavaScript

A serious vulnerability has been identified in protobuf.js, a popular JavaScript library used for Google's Protocol Buffers. This flaw allows remote code execution, meaning that attackers can potentially run harmful code on users' systems without permission. A proof-of-concept exploit has already been shared publicly, raising concerns about its impact on software relying on this library. Developers and users are urged to update their implementations to the latest secure versions to safeguard against possible attacks. This situation highlights the importance of regularly updating software to protect against emerging vulnerabilities. Source: [publication name].

via BleepingComputerRead source
Regulations Shape Growth of Razorpay, Says CEO Harshil Mathur
Cyber Law (India)

Regulations Shape Growth of Razorpay, Says CEO Harshil Mathur

Harshil Mathur, CEO of Razorpay, discussed the positive impact of regulations on business growth during his talk at YC Startup School. He pointed out that despite initial hurdles, such as losing bank support, the company has thrived in India's payments sector, which has surpassed $180 billion in transaction volume. Mathur credited the startup's adaptability, particularly its adoption of the Unified Payments Interface (UPI), for its success, especially during the rise of direct-to-consumer businesses amid the pandemic. These insights emphasize the balance between regulatory challenges and the potential for significant growth in a structured market environment. Source: [publication name].

via Economic Times TechRead source
NAKIVO Releases v11.2 with Enhanced Ransomware Defense Features
Ransomware

NAKIVO Releases v11.2 with Enhanced Ransomware Defense Features

NAKIVO Inc. has launched its Backup & Replication v11.2, which aims to provide fast and reliable data protection solutions. This version introduces improved defenses against ransomware attacks, alongside quicker data replication capabilities. It also supports the latest versions of vSphere 9 and Proxmox VE 9.0, making it compatible with newer virtual environments. These advancements are designed for proactive data management, crucial for businesses concerned about data security. With the increasing threat of cyber attacks, this new release may assist organizations in safeguarding their critical information. Source: [publication name].

via BleepingComputerRead source
Addressing Risks from Unmanaged Cloud Identities
Data Breaches

Addressing Risks from Unmanaged Cloud Identities

In 2024, a significant 68% of cloud breaches were due to compromised service accounts and overlooked API keys, rather than typical threats like phishing or weak passwords. Organizations often have 40 to 50 automated credentials for each employee, including service accounts and API tokens. When projects conclude or employees depart, these unmanaged identities can remain unmonitored, increasing security vulnerabilities. To mitigate these risks, companies should assess and eliminate 'ghost identities' that could potentially expose sensitive enterprise data. Effective management of such credentials is vital for maintaining cloud security. Source: [publication name].

via The Hacker NewsRead source