News

Short summaries of the cyber-crime stories moving in India and globally. We link back to the original source — always.

Building Bridges: Community Groups Find Cybersecurity Support
Cyber Law (India)

Building Bridges: Community Groups Find Cybersecurity Support

Community organizations across India are increasingly partnering with volunteer cybersecurity experts to strengthen their digital defenses. These collaborations connect non-profits, local groups, and social organizations with professionals who provide free guidance on security practices, awareness training, and incident response. Such initiatives help smaller organizations access expert knowledge they might otherwise struggle to afford, building a stronger collective defense against cyber threats. Volunteers contribute their skills to educate communities about phishing, malware, and data protection measures. This grassroots approach complements institutional cybersecurity efforts by ensuring that organizations of all sizes can better protect their members' information and maintain digital safety standards.

via HN: cybersecurityRead source
The Unsolved Mystery of Shadow Hackers Behind NSA Tool Theft
Data Breaches

The Unsolved Mystery of Shadow Hackers Behind NSA Tool Theft

A mysterious hacking group remains unidentified despite stealing and publicly releasing classified NSA hacking tools. This incident continues to influence how organisations worldwide assess cybersecurity risks today. The theft of these powerful tools has had lasting consequences for digital security strategies across industries. Experts highlight that the identity of the group responsible for this breach remains one of the most significant unsolved cybersecurity mysteries, with implications that extend to modern threat assessment and defensive measures adopted by companies globally. Source: Original Publication.

via RSS: TechCrunch SecurityRead source
Iranian Hackers Targeted Los Angeles Transit System
Data Breaches

Iranian Hackers Targeted Los Angeles Transit System

Cybersecurity researchers have attributed a significant data breach affecting Los Angeles's transit infrastructure to Iranian state-sponsored hackers. The attack was linked to 'Ababil of Minab,' a persona claiming responsibility for multiple data breaches since the outbreak of conflict in Iran. According to an Israeli cybersecurity firm's investigation, the breach caused weeks of operational disruption to the transit system. The incident highlights growing concerns about state-sponsored cyber attacks targeting critical infrastructure. Indian organizations should strengthen their defenses against similar threats targeting transportation and essential services. Source: Reuters.

via RSS: TechCrunch SecurityRead source
NSA Guidelines on Securing AI Automation Systems
Cyber Law (India)

NSA Guidelines on Securing AI Automation Systems

The US National Security Agency has released security design considerations for AI-driven automation systems. The document outlines best practices for organizations implementing artificial intelligence in automated processes, focusing on potential vulnerabilities and mitigation strategies. Key recommendations include threat modeling, access controls, and security testing protocols. This guidance is relevant for Indian enterprises adopting AI automation, as it addresses risks like unauthorized access, data manipulation, and system compromise. Organizations should review these principles when deploying AI-powered automation to ensure robust security frameworks and protect sensitive operations from cyber threats. Source: NSA.

via HN: cybersecurityRead source
Minicor Simplifies Windows Desktop Automation for AI Integration
Cyber Law (India)

Minicor Simplifies Windows Desktop Automation for AI Integration

Minicor, a YC-backed startup, has developed a solution for automating Windows desktop systems at scale without requiring APIs. Founded by Faiz and Saheed, the platform addresses critical challenges in robotic process automation (RPA) including scripting complexity, orchestration issues, and debugging difficulties. The tool uses an MCP (Model Context Protocol) enabling AI models to navigate virtual machines and create RPA workflows as Python scripts. Features include API triggering, video replay logging, version control, VM cloning for parallel processing, and two-factor authentication handling. The platform aims to reduce failure rates that commonly exceed 30% in traditional RPA implementations, which can generate thousands of support tickets monthly when deployments fail at scale.

via HN: zero dayRead source
Claude Teams Vulnerability Exploited for Remote Code Execution
Social Engineering

Claude Teams Vulnerability Exploited for Remote Code Execution

Security researchers discovered a critical vulnerability in Claude Teams that allows attackers to execute remote code through deceptive team onboarding processes. The attack chain begins with phishing tactics targeting users during team setup, leading to unauthorized access and potential remote code execution (RCE) capabilities. This vulnerability highlights risks in collaborative AI platforms where social engineering can be combined with technical exploits. Users are advised to exercise caution during team invitations and verify authenticity of onboarding requests. Organizations using Claude Teams should review access controls and implement additional security measures to prevent unauthorized access attempts. Source: Security Research Publication.

via HN: phishingRead source
CBSE denies security breach in evaluation portal
Data Breaches

CBSE denies security breach in evaluation portal

The Central Board of Secondary Education (CBSE) has refuted claims of a security breach in its evaluation portal. According to the board's statement, the targeted website contains only test data and no actual student records or sensitive information were compromised. CBSE emphasized that their main evaluation systems remain secure and unaffected. The clarification comes after reports suggested unauthorized access to the portal. Officials stated that routine security protocols are in place to protect educational data. Students and parents are advised not to panic, as no personal or examination-related information has been exposed from the official systems. Source: India Today.

via GoogleNews: data breach IndiaRead source
CBSE rejects OSM breach claims amid hacker URL dispute
Data Breaches

CBSE rejects OSM breach claims amid hacker URL dispute

The Central Board of Secondary Education (CBSE) has denied allegations of a breach affecting its Open Source Management (OSM) system. A hacker claiming responsibility sparked controversy by registering similar URLs, creating confusion about which website was legitimate. CBSE clarified that no sensitive data was compromised and that the incident involved only a URL registration dispute rather than an actual security breach. The board advised users to verify official websites before accessing educational portals. This incident highlights the risks of domain spoofing and the importance of verifying authentic government websites. Source: India Today.

via GoogleNews: data breach IndiaRead source
CERT-In Alerts on AI-Powered Cyber Attacks
Malware

CERT-In Alerts on AI-Powered Cyber Attacks

India's CERT-In has issued a warning about the increasing threat of artificial intelligence-driven cyberattacks, as hackers leverage advanced automated tools to breach systems. The advisory highlights how attackers are utilizing AI technologies to enhance their attack capabilities, enabling more sophisticated and targeted campaigns against organizations and individuals. CERT-In recommends strengthening security measures and maintaining vigilant monitoring of network activities. Users are advised to keep systems updated with latest patches and implement robust security protocols to defend against these evolving threats. Source: sarkaritel.com

via GoogleNews: cyber attack IndiaRead source
Megalodon Attack Injects Malicious Code Into 5,500 GitHub Repos
Malware

Megalodon Attack Injects Malicious Code Into 5,500 GitHub Repos

A coordinated cyber attack called Megalodon compromised over 5,500 public GitHub repositories by injecting malicious commits into GitHub Actions workflows. Researchers at SafeDep detected the campaign on May 18, which pushed 5,718 harmful commits within six hours using stolen credentials. The attack modified workflow files to include base64-encoded scripts designed to steal sensitive data like cloud credentials, SSH keys, and OIDC tokens during code execution. Major targets included repositories from Wiznet, Tiledesk, and persian-tools projects. Security researchers recommend monitoring unexpected workflow runs and reviewing cloud audit logs for suspicious token requests. The operation bore similarities to previous TeamPCP attacks, using backdated commits to conceal malicious activity timing. Source: SafeDep and OX Security Research.

via RSS: CSO OnlineRead source
AppOmni's Marlin AI Automates SaaS Security Investigations
Data Breaches

AppOmni's Marlin AI Automates SaaS Security Investigations

AppOmni has launched Marlin AI, a tool designed to automatically detect and investigate misconfigurations in Software-as-a-Service (SaaS) applications used by enterprises. The AI system analyzes security vulnerabilities across cloud environments and traces related suspicious activities within organizational networks. It provides detailed remediation recommendations to address identified issues. However, the system stops short of implementing fixes automatically, requiring human approval before taking corrective actions. This approach balances efficiency with safety, allowing security teams to review recommendations before deployment. The development highlights growing reliance on AI for managing complex cloud security challenges in modern enterprises. Source: SecurityWeek.

via RSS: SecurityWeekRead source
Iranian Hacker Group Targets Aviation, Software Firms
Malware

Iranian Hacker Group Targets Aviation, Software Firms

Nimbus Manticore, an Iranian advanced persistent threat (APT) group, continues targeting aviation and software companies with newly upgraded hacking tools. The group has maintained its cyber operations during and after recent US military activities against Iran. This represents an ongoing threat to critical infrastructure and technology sectors globally. Indian organizations in aviation and software development should enhance their security measures, including employee awareness training, network monitoring, and incident response protocols. Organizations are advised to patch vulnerabilities promptly and implement multi-factor authentication to mitigate risks from such state-sponsored cyber threats. Source: SecurityWeek.

via RSS: SecurityWeekRead source