News

Short summaries of the cyber-crime stories moving in India and globally. We link back to the original source — always.

Microsoft's Auto Device Isolation Feature: Benefits and Security Risks
Malware

Microsoft's Auto Device Isolation Feature: Benefits and Security Risks

Microsoft is testing automatic device isolation in Defender for Endpoint to help security teams rapidly contain ongoing cyberattacks. The feature acts as a quick network disconnection to prevent attackers from maintaining control and stealing data. However, SANS Institute research warns that misconfigured settings could allow attackers to disable user accounts. Security experts emphasize that such automated defense tools are essential since modern ransomware and malware operate at machine speed, faster than human response. The feature is particularly valuable for under-resourced security teams and helps limit damage spread. Still, these automation capabilities require careful tuning and testing to prevent misuse. No production release date has been announced yet. Source: SecurityWeek.

via RSS: CSO OnlineRead source
Cryptojacking Campaign Uses Search Poisoning and Remote Tools
Malware

Cryptojacking Campaign Uses Search Poisoning and Remote Tools

Microsoft has identified a cryptojacking campaign exploiting SEO poisoning techniques to direct users to malicious websites that hijack GPU resources for cryptocurrency mining. The attackers abuse ScreenConnect remote access software and Microsoft .NET utilities to establish control over high-performance computers. The campaign also leverages AI chatbots to distribute malicious links, expanding its reach. Victims unknowingly allow their systems' processing power to be used for unauthorized mining operations, degrading performance and increasing electricity consumption. Source: Microsoft Security Blog.

via RSS: Microsoft SecurityRead source
KnowledgeDeliver LMS Zero-Day Exploited for Web Shell Installation
Malware

KnowledgeDeliver LMS Zero-Day Exploited for Web Shell Installation

Attackers have exploited a critical zero-day vulnerability in KnowledgeDeliver, a learning management system, to deploy Godzilla web shells on compromised servers. This vulnerability allows unauthorized access and control over affected systems. Organizations using KnowledgeDeliver should immediately patch their systems and monitor for suspicious activity. Web shells enable attackers to execute commands remotely, potentially leading to data theft or further system compromise. Educational institutions and enterprises relying on this LMS platform are advised to check their infrastructure for signs of exploitation and implement security updates as soon as they become available. Source: Original Report.

via BleepingComputerRead source
Critical flaw in open-source package threatens millions of AI agents
Malware

Critical flaw in open-source package threatens millions of AI agents

A critical vulnerability has been discovered in a widely-used open-source software package that poses significant risks to millions of artificial intelligence agents deployed globally. The flaw could potentially be exploited by threat actors to compromise AI systems and the applications they support. Security experts have warned organizations using this package to apply patches immediately. The vulnerability highlights the importance of maintaining updated software dependencies and conducting regular security audits of open-source components used in critical infrastructure. Developers are urged to review their systems and implement necessary security measures to protect their AI deployments from potential exploitation. Source: Ars Technica.

via GoogleNews: vulnerability CVERead source
Megalodon Malware Targets 5,500+ GitHub Repositories
Malware

Megalodon Malware Targets 5,500+ GitHub Repositories

A malware campaign called 'Megalodon' has infected thousands of GitHub repositories in a rapid six-hour attack. The attackers injected malicious code commits into over 5,500 repositories, targeting developers and organizations. The malware was designed to steal sensitive credentials, developer secrets, and other valuable data from compromised accounts. This mass-scale attack demonstrates the vulnerability of popular code-sharing platforms to sophisticated threats. GitHub users are advised to review their repository activity, check for unauthorized commits, and secure their authentication tokens immediately. Source: Cybersecurity news outlet.

via RSS: Dark ReadingRead source
Charter Communications confirms data breach after extortion threat
Data Breaches

Charter Communications confirms data breach after extortion threat

US telecom company Charter Communications has acknowledged a data breach following threats from the ShinyHunters cybercriminal group. The threat actors demanded ransom in exchange for not releasing the stolen data publicly. This incident highlights the growing risk of extortion-based cyberattacks targeting major infrastructure providers. Organizations are increasingly targeted by criminal groups who steal sensitive information and threaten disclosure to coerce payment. Charter is investigating the scope of the breach and notifying affected individuals. Source: Cyber News.

via BleepingComputerRead source
Shai-Hulud Worm: Skill or Luck Behind TeamPCP Attacks?
Malware

Shai-Hulud Worm: Skill or Luck Behind TeamPCP Attacks?

TeamPCP, the hacking group behind the Shai-Hulud worm, has inflicted substantial damage on the open source software ecosystem. Security experts debate whether their success stems primarily from technical expertise or fortunate circumstances. The worm's impact highlights vulnerabilities in widely-used open source projects that developers rely on globally. Analysts suggest that while the attackers demonstrated capability in deploying the malware, their effectiveness may also reflect gaps in security practices within the open source community. This incident underscores the importance of robust security measures and rapid patching protocols for critical software infrastructure. Source: Cybersecurity News.

via Dark ReadingRead source
CBSE Denies Portal Security Breach Claims
Cyber Law (India)

CBSE Denies Portal Security Breach Claims

The Central Board of Secondary Education (CBSE) has dismissed claims made by a social media user alleging unauthorized access to its portal. The board issued an official clarification stating that no security breach occurred on their systems. CBSE conducted an investigation into the allegations and found them to be unfounded. The incident highlights the importance of verifying cybersecurity claims before spreading them on social media, which can cause unnecessary panic among students and parents. CBSE continues to maintain security protocols for its online platforms. Source: India.Com.

via GoogleNews: data breach IndiaRead source
MyPillow faces ransomware extortion demand
Ransomware

MyPillow faces ransomware extortion demand

Bedding manufacturer MyPillow has reportedly been targeted by ransomware criminals demanding payment following an alleged network intrusion. The attackers claim to have accessed the company's systems and are pressuring the organization to pay a ransom to prevent data theft or system damage. MyPillow has not yet publicly confirmed details of the breach or responded to the extortion demands. This incident highlights the ongoing threat ransomware poses to businesses across various sectors in the United States. Companies affected by such attacks typically face difficult decisions regarding ransom payments, data recovery, and notification obligations.

via RSS: The Register SecurityRead source
MyPillow hit by ransomware attack
Ransomware

MyPillow hit by ransomware attack

MyPillow, the bedding company owned by Mike Lindell, has become the latest target of a ransomware attack. Ransomware attacks involve criminals encrypting a company's data and demanding payment for its release. Such incidents have become increasingly common against businesses of all sizes. Companies typically face operational disruptions and potential data theft during these attacks. MyPillow joins numerous organizations that have suffered similar cyber incidents in recent times. The attack highlights the ongoing threat ransomware poses to commercial enterprises. Source: Straight Arrow News.

via GoogleNews: ransomware globalRead source
Iranian Hackers Use DLL Technique in Global Espionage Push
Malware

Iranian Hackers Use DLL Technique in Global Espionage Push

MuddyWater, an Iranian-linked hacking group, has conducted a coordinated espionage campaign affecting at least nine organizations across multiple continents during early 2026. The campaign targeted diverse sectors including manufacturing, electronics, education, government agencies, finance, and professional services firms. Security researchers from Symantec and Carbon Black identified the group's use of DLL side-loading techniques—a method that exploits legitimate system processes to execute malicious code. This approach allows attackers to evade detection while maintaining access to sensitive systems. Organizations across multiple countries remain at risk from this sophisticated threat. Source: Symantec Threat Hunter Team.

via The Hacker NewsRead source
CBSE denies security breach in OSM portal amid exam sheet controversy
Data Breaches

CBSE denies security breach in OSM portal amid exam sheet controversy

The Central Board of Secondary Education (CBSE) has dismissed claims of a security breach in its Online System for Monitoring (OSM) portal following recent issues with answer sheet distribution. The board stated there were no security vulnerabilities or unauthorized access to the system. The denial comes amid ongoing concerns about answer sheet mix-ups affecting students. CBSE officials emphasized that the portal's security measures remain intact and functional. The incident highlights the importance of reliable digital systems in educational administration during examination processes. Source: The Times of India.

via GoogleNews: data breach IndiaRead source