News

Short summaries of the cyber-crime stories moving in India and globally. We link back to the original source — always.

Google Blocks Over 8.3 Billion Fraudulent Ads, Updates Android Privacy Policies
Data Breaches

Google Blocks Over 8.3 Billion Fraudulent Ads, Updates Android Privacy Policies

In a significant move to enhance user privacy and combat fraud, Google reported blocking 8.3 billion ads and suspending 24.9 million accounts in 2025. The company unveiled policy updates aimed at reinforcing user protection related to contact and location permissions on Android devices. These changes will impact how third-party applications access sensitive user information, such as contact lists and geographical locations. Google's latest efforts reflect a growing commitment to safeguard users' data and security on its platforms. This initiative highlights the importance of user privacy in an increasingly digital world. Source: [publication name].

via The Hacker NewsRead source
NIST Updates CVE Processing Due to Surge in Submissions
Cyber Law (India)

NIST Updates CVE Processing Due to Surge in Submissions

The National Institute of Standards and Technology (NIST) has revised its approach to handling cybersecurity vulnerabilities. Due to a significant increase of 263% in submissions for Common Vulnerabilities and Exposures (CVEs), NIST will now only enhance those entries that meet specific criteria. While all CVEs will still be recorded in the National Vulnerability Database (NVD), only some will receive detailed enrichment. This decision comes as part of an effort to manage the growing volume of submissions and ensure that critical vulnerabilities are effectively prioritized. Such changes aim to improve overall cybersecurity measures and awareness. Source: [publication name].

via The Hacker NewsRead source
International Operation Dismantles DDoS Crime Network
Dark Web

International Operation Dismantles DDoS Crime Network

A global law enforcement operation, named Operation PowerOFF, has led to the seizure of 53 domains involved in distributed denial-of-service (DDoS) attacks and the arrest of four individuals. These operations provided DDoS-for-hire services that were utilized by over 75,000 cybercriminals. The action effectively disrupted their infrastructure and revealed approximately 3 million criminal accounts, highlighting the scale of cybercrime involved. This operation underscores the increasing international collaboration required to combat cyber threats and protect online services from such attacks.

via The Hacker NewsRead source
NIST Updates CVE Framework to Target Critical Software Vulnerabilities
Malware

NIST Updates CVE Framework to Target Critical Software Vulnerabilities

The National Institute of Standards and Technology (NIST) has revised its Common Vulnerabilities and Exposures (CVE) framework to better prioritize high-impact software vulnerabilities. This new approach aims to enhance the process of identifying and addressing critical security flaws in software. By focusing on the most significant vulnerabilities, NIST intends to streamline vulnerability remediation efforts, ensuring that resources are allocated effectively to mitigate risks. This update reflects a commitment to improving cybersecurity practices and protecting users from potential threats. The changes are expected to support software developers and organizations in enhancing their security measures. Source: [publication name].

via Dark ReadingRead source
North Korea Targets macOS Users with ClickFix Malware Attacks
Malware

North Korea Targets macOS Users with ClickFix Malware Attacks

A North Korean hacking group, known as Sapphire Sleet, is reportedly using a strategy called ClickFix to target macOS users. They issue fraudulent job offers and fake Zoom software updates as a way to deliver malware that harvests personal information and login credentials from affected devices. This campaign illustrates the ongoing threat posed by cyber attackers to steal sensitive data, highlighting the importance for users to remain vigilant against suspicious links and offers. Individuals are advised to verify the authenticity of job proposals and software updates before engaging with them. Maintaining up-to-date security practices is crucial to protect personal information from such malicious attacks. Source: CyberSathi.in.

via Dark ReadingRead source
Two-Factor Authentication Expands Beyond Desktop Use
Data Breaches

Two-Factor Authentication Expands Beyond Desktop Use

Cybercriminals are increasingly adept at bypassing security measures, particularly in environments outside traditional IT settings. To enhance security, the adoption of Two-Factor Authentication (2FA) is recommended. This method adds an additional layer of protection, making it harder for unauthorized users to gain access, even in physical locations. As threats evolve, implementing 2FA can be a critical step for individuals and businesses looking to safeguard sensitive information and mitigate risks associated with cyberattacks. This shift towards broader usage of 2FA underscores the importance of proactive security measures in combating cyber crime. Source: [publication name].

via Dark ReadingRead source
Microsoft's Windows Secure Boot Certificate Set to Expire Soon
Malware

Microsoft's Windows Secure Boot Certificate Set to Expire Soon

Microsoft has announced that the original Secure Boot certificate for Windows is nearing its expiration date. This certificate is crucial for maintaining the security of devices running Windows operating systems. As a part of a significant security maintenance initiative, users are urged to update their PCs promptly to ensure continued protection. The updates will help in sustaining the integrity of system boot processes and mitigating potential vulnerabilities. Keeping devices up to date is essential for safeguarding against cyber threats. Users should check for available updates to avoid issues arising from the expiration of the certificate.

via Dark ReadingRead source
AI-Powered Vulnerability Discovery: Enterprise Defense Strategies
Malware

AI-Powered Vulnerability Discovery: Enterprise Defense Strategies

Artificial intelligence models are now capable of discovering software vulnerabilities and generating exploits faster than traditional methods, creating significant security risks for enterprises. While AI integration into development will eventually strengthen code, the transition period presents a critical vulnerability window that attackers will exploit. Organizations face dual challenges: rapidly hardening existing software and defending systems still containing unpatched vulnerabilities. Security experts recommend enterprises strengthen incident response plans, reduce system exposure, and integrate AI-driven security tools into their defensive strategies. As threat actors leverage AI capabilities to identify zero-day vulnerabilities, companies must act urgently to modernize their cybersecurity approaches before malicious actors weaponize these powerful tools at scale. Source: Wiz Security Blog.

via RSS: Mandiant BlogRead source
Long-Running Ransomware Campaign Affects Turkish Homes and Small Businesses
Ransomware

Long-Running Ransomware Campaign Affects Turkish Homes and Small Businesses

A ransomware campaign spanning six years has been targeting private homes and small to medium-sized businesses (SMBs) in Turkey. While larger enterprise breaches typically receive more media attention, these smaller incidents go largely unreported. This lack of visibility allows such campaigns to persist with minimal disruption, making them a significant concern for local security. The ongoing threat demonstrates the importance of cybersecurity awareness and protective measures for all types of organizations, regardless of their size. Individuals and SMBs should remain vigilant and implement robust security protocols to safeguard against ransomware attacks. Source: [publication name].

via Dark ReadingRead source
Security Challenges in Asia's Digital Supply Chain
Data Breaches

Security Challenges in Asia's Digital Supply Chain

Asian organizations face unique security risks due to varied regulations, interconnected digital systems, and the increasing use of artificial intelligence. These factors have made the digital supply chain complex, requiring organizations to adapt and implement robust security measures. The diverse regulatory landscape across countries adds another layer of difficulty in standardizing security protocols. As businesses continue to rely on digital solutions, understanding these risks and developing strategies to mitigate them is crucial. Awareness and preparedness can help combat potential cyber threats in this evolving environment. Source: [publication name].

via Dark ReadingRead source
Microsoft and Salesforce Fix Data Leak Vulnerabilities
Data Breaches

Microsoft and Salesforce Fix Data Leak Vulnerabilities

Microsoft and Salesforce have recently addressed critical vulnerabilities in their AI products, Salesforce Agentforce and Microsoft Copilot. These flaws, known as prompt injections, could have allowed unauthorized attackers to access and leak sensitive information from the systems. By implementing these patches, both companies aim to enhance the security of their applications and protect user data from potential breaches. Users are advised to ensure their software is updated to benefit from these security improvements. Keeping software up to date is essential for safeguarding against cyber threats. Source: [publication name].

via Dark ReadingRead source
Microsoft and Google Release Critical Security Updates
Malware

Microsoft and Google Release Critical Security Updates

Microsoft has released updates that address 167 security vulnerabilities in its Windows operating systems and related software. Among these issues is a zero-day vulnerability in SharePoint Server and a weakness in Windows Defender known as 'BlueHammer.' Additionally, Google Chrome has fixed its fourth zero-day vulnerability of 2026, while Adobe Reader has issued an emergency update to resolve a flaw that could allow remote code execution. These updates highlight the importance of keeping software updated to protect against potential exploits. Users are advised to apply these updates promptly to enhance their cybersecurity. Source: CyberSathi.in.

via Krebs on SecurityRead source