News

Short summaries of the cyber-crime stories moving in India and globally. We link back to the original source — always.

CERT-In Sets 12-Hour Patch Window for Critical AI Security Flaws
Cyber Law (India)

CERT-In Sets 12-Hour Patch Window for Critical AI Security Flaws

India's CERT-In has released updated cybersecurity guidelines specifically addressing artificial intelligence systems. The new directive mandates that organizations patch critical vulnerabilities within 12 hours of discovery. These guidelines aim to strengthen the security posture of AI-based systems deployed across Indian organizations. The move reflects growing concerns about AI vulnerabilities and the rapid exploitation timeline attackers employ. Organizations handling sensitive data or critical infrastructure must comply with these stricter timelines. CERT-In emphasizes that AI systems require enhanced monitoring and faster incident response protocols. The guidelines provide a framework for vulnerability assessment, reporting, and remediation specific to AI environments. Source: The Indian Express.

via GoogleNews: cyber attack IndiaRead source
Hackers Exploit Palo Alto VPN Security Flaw in Network Attacks
Malware

Hackers Exploit Palo Alto VPN Security Flaw in Network Attacks

Palo Alto Networks has alerted organizations about active exploitation of a critical authentication bypass vulnerability in its PAN-OS GlobalProtect VPN service, identified as CVE-2026-0257. Threat actors are leveraging this flaw to bypass login protections and gain unauthorized access to corporate networks. The vulnerability allows attackers to circumvent standard authentication mechanisms, potentially enabling them to infiltrate sensitive systems and data. Organizations using Palo Alto's GlobalProtect VPN are advised to apply security patches immediately and monitor their networks for suspicious access attempts. This active exploitation underscores the importance of timely security updates for enterprise infrastructure. Source: Palo Alto Networks.

via RSS: BleepingComputerRead source
Linux Kernel Flaw Allows Attackers to Gain Root Access
Malware

Linux Kernel Flaw Allows Attackers to Gain Root Access

A newly identified vulnerability called 'CIFSwitch' in the Linux kernel poses a significant security risk across multiple Linux distributions. The flaw enables local privilege escalation by allowing attackers to manipulate CIFS authentication key descriptions and misuse the kernel's key request mechanism. This exploitation could grant attackers root-level access to affected systems. The vulnerability affects various Linux distributions and requires immediate attention from system administrators and users. Patching and updating systems is recommended to mitigate potential threats. Source: Cybersecurity News.

via RSS: BleepingComputerRead source
Bombay HC Blocks Hackers from Releasing HDFC AMC Investor Data
Data Breaches

Bombay HC Blocks Hackers from Releasing HDFC AMC Investor Data

The Bombay High Court has issued a restraining order against cybercriminals threatening to publish allegedly stolen investor information from HDFC Asset Management Company. The order prevents the hackers from disclosing the confidential data obtained during a cyberattack on the financial firm. This legal intervention aims to protect the privacy and financial interests of affected investors. The court's action demonstrates India's judicial response to cyber incidents targeting major financial institutions and the sensitive data they hold. Source: Free Press Journal.

via GoogleNews: ransomware IndiaRead source
SentinelOne to lay off 8% workforce
Cyber Law (India)

SentinelOne to lay off 8% workforce

Cybersecurity firm SentinelOne announced job cuts affecting 8% of its workforce. The company, known for providing endpoint protection and threat intelligence solutions, is implementing this restructuring as part of operational optimization efforts. Such industry adjustments reflect broader trends in the global cybersecurity sector. While the specific reasons weren't detailed, tech companies often cite market conditions and efficiency improvements. The move impacts employees across various departments. SentinelOne continues to operate its security services despite the workforce reduction, maintaining its platform for enterprise clients seeking protection against cyber threats.

via GoogleNews: ransomware IndiaRead source
Weekly Security News Roundup
Cyber Law (India)

Weekly Security News Roundup

This weekly digest covers various cybersecurity stories and developments in the news. The post serves as an open forum for discussing security incidents and cyber threats that may not have received dedicated coverage. Readers are encouraged to share relevant cybersecurity news, data breach updates, and threat intelligence in the comments section. The platform maintains a moderation policy to ensure discussions remain focused on legitimate security awareness and protection of users. Regular updates help Indian internet users stay informed about emerging threats and best practices for online safety.

via RSS: Schneier on SecurityRead source
Rohtak Man Arrested for WhatsApp Scam Targeting Ellenabad Resident
Social Engineering

Rohtak Man Arrested for WhatsApp Scam Targeting Ellenabad Resident

A Rohtak youth has been arrested for defrauding an Ellenabad resident of Rs 42,580 through a WhatsApp-based scam. The suspect used social engineering tactics to gain the victim's trust on the messaging platform before manipulating them into transferring money. Police recovered evidence from the accused's devices during investigation. This case highlights the growing threat of messaging app frauds targeting unsuspecting users across Haryana. Authorities urge residents to verify identities before sharing sensitive information or making financial transfers through WhatsApp. Source: The Tribune.

via GoogleNews: WhatsApp scamRead source
Cybersecurity's Human Challenge: Fostering Respectful Communities
Cyber Law (India)

Cybersecurity's Human Challenge: Fostering Respectful Communities

The cybersecurity industry faces a persistent challenge in promoting respectful interactions among professionals and communities. Despite technical expertise, maintaining civility in online spaces remains difficult. Industry experts emphasize that collaborative security practices require mutual respect and constructive communication. Building a culture of professionalism helps improve threat intelligence sharing and collective defense strategies. Indian cybersecurity professionals are encouraged to foster positive workplace environments while addressing technical vulnerabilities. Creating supportive communities strengthens overall security posture and enables better incident response coordination across organizations. Source: Cybersecurity Publication.

via HN: cybersecurityRead source
RBI's Kill Switch: New Defence Against Digital Scams
UPI Fraud

RBI's Kill Switch: New Defence Against Digital Scams

The Reserve Bank of India has introduced a 'kill switch' facility designed to rapidly block fraudulent digital transactions and prevent financial losses. This emergency mechanism allows authorities to immediately halt suspicious payment activities across banking channels. The facility targets various digital scams including UPI fraud, unauthorized fund transfers, and compromise of banking credentials. By enabling swift intervention, RBI aims to protect consumers from escalating cyber threats in India's growing digital payment ecosystem. The kill switch represents a proactive regulatory approach to combating real-time fraud threats and strengthening the security infrastructure of the country's digital financial system. Source: The Indian Express.

via GoogleNews: digital arrest scamRead source
Former Food Officer Arrested in Rs 77 Lakh LPG Fraud Case
Investment Fraud

Former Food Officer Arrested in Rs 77 Lakh LPG Fraud Case

Chhattisgarh police have arrested two individuals in connection with a Rs 77 lakh LPG subsidy scam. A former food department officer has been identified as the mastermind behind the scheme. The fraud involved illegal diversion of subsidized cooking gas meant for beneficiaries. Police investigations revealed systematic misappropriation of public funds through forged documents and unauthorized transactions. Two suspects have been apprehended, and further investigation is underway to identify additional accomplices. Source: India Today.

via GoogleNews: WhatsApp scamRead source
Self-Censorship Rising as Threats Chill Free Speech
Cyber Law (India)

Self-Censorship Rising as Threats Chill Free Speech

A concerning trend of self-censorship is emerging across American institutions as people fear punitive measures for speaking out. Students are avoiding campus activism, professors are revising lectures, researchers are removing sensitive terms from grant applications, and media outlets are modifying coverage—all driven by fear of legal action and government retaliation. Experts describe this as a 'chilling effect,' where threats cause people to restrict their activities for self-protection. The phenomenon extends beyond academia to law firms, publishers, and regulatory agencies, suggesting widespread suppression of free expression and discourse across multiple sectors of society. Source: The Guardian.

via RSS: Schneier on SecurityRead source
Multiple Industries Face Rising Cyber Attacks
Malware

Multiple Industries Face Rising Cyber Attacks

Various industrial sectors across India are experiencing increased cyber threats and attacks. Organizations are confronting sophisticated security challenges that compromise their digital infrastructure and operational continuity. Cybercriminals are targeting businesses through multiple vectors, exploiting vulnerabilities in systems and networks. The attacks impact productivity, data security, and financial stability. Industries need to strengthen their cybersecurity posture through robust defense mechanisms, employee training, and incident response planning. Experts recommend implementing multi-layered security approaches and staying updated on emerging threats. Organizations should conduct regular security audits and maintain backup systems to mitigate risks. The rising threat landscape underscores the importance of proactive cyber defense strategies for business resilience. Source: varindia.com.

via GoogleNews: cyber attack IndiaRead source