News

Short summaries of the cyber-crime stories moving in India and globally. We link back to the original source — always.

Ransomware Gang Uses Social Engineering to Target Law Firms
Social Engineering

Ransomware Gang Uses Social Engineering to Target Law Firms

The FBI has issued a warning about the Silent Ransom Group, a cybercriminal organization targeting law firms across the United States. The gang employs social engineering tactics to gain unauthorized access to servers and databases containing sensitive client information. Rather than relying solely on malware, the actors are using deceptive techniques to manipulate employees into granting access to critical systems. Law firms are particularly attractive targets due to the confidential nature of their data, including client communications and financial records. The FBI's alert highlights the importance of employee security awareness training and strict access controls. Indian legal professionals should implement similar protective measures, including multi-factor authentication, regular security audits, and staff training on recognizing social engineering attempts. Source: FBI Advisory.

via RSS: Dark ReadingRead source
Delivery Worker Arrested in Nursing Job Scam Ring
Social Engineering

Delivery Worker Arrested in Nursing Job Scam Ring

Police have arrested a delivery worker as the third suspect in an ongoing nursing job scam investigation. The suspect allegedly posed as a recruitment official to defraud job seekers aspiring for nursing positions. Victims reportedly paid fees for placement promises that never materialized. Authorities are continuing their investigation to identify additional accomplices and recover fraudulently obtained funds. Job seekers are advised to verify recruitment agencies through official channels and avoid paying upfront fees for employment opportunities. Source: The Times of India.

via GoogleNews: job scam IndiaRead source
Cybercriminals Leak Uruguayan Citizens' Data
Data Breaches

Cybercriminals Leak Uruguayan Citizens' Data

A significant data breach has exposed approximately 5.8 million records belonging to Uruguayan citizens, marking another instance of cybercriminals targeting government institutions across Latin America. The stolen information is being leveraged for financial gain by threat actors. This incident highlights growing vulnerabilities in government cybersecurity infrastructure in the region, where personal data of millions remains at risk of exploitation. Authorities are investigating the breach to determine how attackers accessed such large volumes of sensitive citizen information and what protective measures are needed. Source: Cybersecurity publication.

via RSS: Dark ReadingRead source
Cyberabad Police Arrest 10 in Multi-State Cybercrime Crackdown
Cyber Law (India)

Cyberabad Police Arrest 10 in Multi-State Cybercrime Crackdown

Telangana's Cyberabad Cybercrime Police concluded a week-long operation targeting online criminals across multiple states. The coordinated effort resulted in the detection of six distinct criminal cases and the arrest of ten accused individuals. The crackdown reflects ongoing efforts by law enforcement to combat organized cybercriminal networks operating across state boundaries. Authorities coordinated with law enforcement agencies in other states to apprehend suspects and gather evidence. The operation highlights the growing coordination between state police forces to address interstate cybercrime. Further details about the specific nature of offences and accused profiles are expected as the investigation progresses. Source: The Hindu.

via GoogleNews: job scam IndiaRead source
AI-powered cyber threats escalating globally, warns UK spy chief
Cyber Law (India)

AI-powered cyber threats escalating globally, warns UK spy chief

Britain's chief cyber intelligence officer, Anne Keast-Butler, has raised alarm over artificial intelligence being weaponized for cyber attacks threatening national security worldwide. She emphasizes that nations exist in an undefined space between peace and war due to escalating digital threats. Russia is actively targeting critical infrastructure and democratic institutions, necessitating urgent coordination among allied nations to strengthen cybersecurity defenses and counter evolving AI-driven threats effectively. Source: Reuters.

via Economic Times TechRead source
CISA Lists Three New Security Flaws Under Active Exploitation
Malware

CISA Lists Three New Security Flaws Under Active Exploitation

The US Cybersecurity and Infrastructure Security Agency (CISA) has identified three vulnerabilities being actively exploited by cyber attackers: CVE-2026-8398 in Daemon Tools Lite, CVE-2026-45321 in TanStack, and CVE-2026-48027 in Nx Console. All three contain embedded malicious code or unspecified security issues. CISA maintains a Known Exploited Vulnerabilities catalog to track threats affecting government systems. While federal agencies must patch these flaws urgently, CISA recommends all organizations prioritize fixing these vulnerabilities as part of their security practices. Regular monitoring and timely updates remain critical for protecting networks from active cyber threats. Source: CISA.

via RSS: CISA AlertsRead source
WhatsApp launches five security features to combat scams
Social Engineering

WhatsApp launches five security features to combat scams

WhatsApp has introduced multiple anti-scam tools to protect users from fraudulent activities. The features include Silence Unknown Callers, which blocks calls from numbers not in your contact list, Context Cards that display caller information, and Device Linking alerts to notify users of unauthorized access attempts. These tools aim to reduce scam-related incidents by providing users with better visibility and control over incoming communications. The platform continues enhancing its security infrastructure to combat social engineering attacks and fraudulent schemes targeting Indian users. Source: MobiGyaan.

via GoogleNews: WhatsApp scamRead source
Does cybercrime insurance cover Mythos threats?
Malware

Does cybercrime insurance cover Mythos threats?

Cybercrime insurance policies are being examined for their effectiveness against Mythos-related threats. As cyber attacks evolve, businesses in India are questioning whether existing insurance coverage adequately protects against emerging malware variants and sophisticated cyber threats. Insurance providers are reassessing policy terms and coverage limits to address modern cybersecurity challenges. Understanding policy exclusions and claim procedures is crucial for Indian organizations seeking comprehensive protection. Experts recommend reviewing coverage details and working with insurers to ensure adequate protection against current threats. Source: Forbes India.

via GoogleNews: data breach IndiaRead source
India Tests Critical Systems Against Advanced AI Threats
Cyber Law (India)

India Tests Critical Systems Against Advanced AI Threats

India is conducting comprehensive security assessments of its government and financial infrastructure against Anthropic's Mythos AI system. Major technology companies including Infosys and TCS are participating in these evaluations, while CERT-In is examining national systems like Aadhaar for potential vulnerabilities. This proactive initiative addresses global concerns about Mythos' dual-use nature—its capacity to both strengthen cybersecurity defenses and potentially be exploited for cyberattacks. The testing aims to identify and mitigate risks before malicious actors could leverage the powerful AI model against India's critical digital infrastructure. Source: The Hindu.

via Economic Times TechRead source
CBSE Denies Hacking Claims Despite Teen's Video Evidence
Cyber Law (India)

CBSE Denies Hacking Claims Despite Teen's Video Evidence

The Central Board of Secondary Education (CBSE) has rejected allegations of a security breach after a teenager released video footage claiming to demonstrate unauthorized access to their systems. The student's video purportedly shows how vulnerabilities in CBSE's digital infrastructure could be exploited. CBSE officials have disputed the hacking claims, stating their systems remain secure. This incident raises concerns about educational institution cybersecurity and the importance of responsible disclosure practices. Cybersecurity experts suggest institutions should thoroughly investigate such claims to strengthen their defenses against potential threats. Source: MSN.

via GoogleNews: data breach IndiaRead source
RBI Lottery and Inheritance Emails Are Scams: PIB Alert
Phishing

RBI Lottery and Inheritance Emails Are Scams: PIB Alert

India's Press Information Bureau (PIB) has warned citizens against fraudulent emails claiming to be from the Reserve Bank of India offering lottery winnings or inheritance claims. These messages are scams designed to deceive recipients into revealing personal and financial information or making payments. Scammers impersonate RBI officials to appear legitimate. Citizens receiving such emails should immediately delete them without clicking any links or providing information. The PIB advises reporting suspicious communications to relevant authorities. The RBI does not conduct lotteries or send unsolicited inheritance notifications via email. Stay vigilant and verify any official communication directly through RBI's official website or helpline before responding. Source: Business Standard.

via GoogleNews: phishing IndiaRead source
AI Adoption Exposing Enterprise Cloud Security Vulnerabilities
Data Breaches

AI Adoption Exposing Enterprise Cloud Security Vulnerabilities

A new Check Point report reveals significant security weaknesses emerging as enterprises rapidly adopt artificial intelligence technologies in their cloud infrastructure. The study highlights that organizations implementing AI solutions often overlook critical security measures, creating vulnerabilities that cyber attackers can exploit. These gaps primarily stem from inadequate security protocols during AI deployment, insufficient monitoring of AI systems, and lack of proper access controls. The research emphasizes that while AI offers operational benefits, enterprises must balance innovation with robust security practices. Indian businesses scaling their cloud and AI infrastructure should prioritize comprehensive security audits and implement industry-standard protections to prevent unauthorized access and data compromise. Organizations are urged to evaluate their current cloud security frameworks before expanding AI implementations. Source: itwire.com.

via GDELT: ransomwareRead source