News

Short summaries of the cyber-crime stories moving in India and globally. We link back to the original source — always.

7-Eleven Data Breach Affects 185,000 Customers
Data Breaches

7-Eleven Data Breach Affects 185,000 Customers

A data breach at 7-Eleven has compromised personal information of approximately 185,000 individuals. The hacking group ShinyHunters claims responsibility for the incident and has leaked stolen data including email addresses, full names, residential addresses, and dates of birth. This type of breach exposes victims to identity theft and targeted fraud schemes. Customers affected should monitor their accounts for suspicious activity and consider placing fraud alerts with credit bureaus. Data breaches involving such personal information remain a significant cybersecurity concern for retail chains globally. Source: SecurityWeek.

via RSS: SecurityWeekRead source
AI-Powered DDoS Attacks: Rising Threat to Indian Websites
Malware

AI-Powered DDoS Attacks: Rising Threat to Indian Websites

Cybercriminals are increasingly leveraging artificial intelligence to conduct more sophisticated and damaging distributed denial-of-service (DDoS) attacks. Unlike traditional methods, AI-enhanced attacks are faster, more powerful, and difficult to counter. Hackers use these intelligent tools to identify system vulnerabilities automatically, making defenses less effective. Security experts warn that organizations must adopt advanced detection mechanisms and stronger safeguards to protect against these evolving threats. Understanding these new attack patterns is crucial for Indian businesses and website operators to implement adequate preventive measures and stay ahead of cybercriminals. Source: The Hacker News.

via RSS: The Hacker NewsRead source
Microsoft Fixes Critical SharePoint Vulnerability CVE-2026-45659
Malware

Microsoft Fixes Critical SharePoint Vulnerability CVE-2026-45659

Microsoft has released security patches for CVE-2026-45659, a remote code execution flaw affecting SharePoint across multiple server versions. The vulnerability, rated 8.8 on the CVSS scale, stems from improper handling of untrusted data during deserialization processes. Attackers could exploit this weakness without meeting any special conditions, potentially gaining unauthorized code execution on affected systems. The patch has been classified as important and is now available across SharePoint versions. Organizations using SharePoint should prioritize applying these updates to protect their systems from potential exploitation. Source: Cybersecurity News.

via The Hacker NewsRead source
Anthropic's Claude AI Integrates With 28 Enterprise Security Tools
Cyber Law (India)

Anthropic's Claude AI Integrates With 28 Enterprise Security Tools

Anthropic has expanded Claude, its AI assistant, with 28 new security integrations to strengthen enterprise governance and protection. The integrations include partnerships with leading cybersecurity firms like CrowdStrike, Palo Alto Networks, Microsoft, Okta, Zscaler, Netskope, Cloudflare, Fortinet, and Wiz. These integrations aim to enhance organizational security posture by enabling Claude to work seamlessly with existing enterprise security infrastructure and tools. This development allows businesses to leverage AI capabilities while maintaining robust security controls and governance frameworks across their operations. Source: SecurityWeek.

via RSS: SecurityWeekRead source
TrapDoor malware targets developer workstations across code platforms
Malware

TrapDoor malware targets developer workstations across code platforms

Security researchers have identified TrapDoor, a malicious package campaign spanning over 34 packages across npm, PyPI, and Crates.io repositories. The malware targets developer workstations to steal sensitive credentials including AWS keys, GitHub tokens, SSH keys, and cryptocurrency wallet data. The campaign exploits common development workflows like npm postinstall scripts and Rust build scripts, making detection difficult. Notably, TrapDoor also attempts to compromise AI coding assistants by modifying configuration files with hidden instructions to trick them into exposing secrets. The campaign highlights growing risks to developer environments, which contain access to source code, cloud infrastructure, and CI/CD pipelines. Compromising a single workstation could give attackers broader access to organizational systems. Source: The Register.

via RSS: CSO OnlineRead source
RemotePilot: Desktop App for Remote Job Tracking
Cyber Law (India)

RemotePilot: Desktop App for Remote Job Tracking

RemotePilot is a new desktop application designed to help job seekers find and manage remote work opportunities. The tool allows users to track companies offering remote positions, organize job applications, and customize resumes and cover letters for each opportunity. It also includes interview preparation features with personalized guides. Created by an indie developer, RemotePilot aims to simplify the remote job search process for professionals struggling to navigate the distributed workforce market. The application emphasizes personalization to help users tailor their job applications more effectively. Source: Hacker News.

via HN: India hackRead source
Critical SQL Injection Flaw Found in Drupal PostgreSQL Systems
Data Breaches

Critical SQL Injection Flaw Found in Drupal PostgreSQL Systems

A critical SQL injection vulnerability, tracked as CVE-2026-9082, has been identified in Drupal installations running PostgreSQL databases. This flaw allows attackers to execute arbitrary SQL commands, potentially compromising sensitive data stored in affected systems. Organizations using Drupal with PostgreSQL backends are urged to apply security patches immediately. The vulnerability poses significant risks to websites and applications relying on this content management system. Security experts recommend administrators prioritize updates and implement additional access controls to prevent exploitation. Source: Security Boulevard.

via GoogleNews: vulnerability CVERead source
Crypto Wallet Security Gaps Widen After Major Bybit Theft
Crypto Scams

Crypto Wallet Security Gaps Widen After Major Bybit Theft

A $1.4 billion cryptocurrency theft from Bybit has exposed serious vulnerabilities in self-custody wallet solutions, emphasizing the importance of robust underlying software architecture. The incident is prompting a shift towards more secure wallet designs that prioritize offline-first functionality and key protection over user convenience. Industry experts now stress the need for architecturally isolated systems and post-quantum cryptography integration. This highlights that cryptocurrency wallets vary significantly in their security measures, and users must carefully evaluate their chosen platform's technical safeguards. Source: Original news report.

via Economic Times TechRead source
MFA Prompt Bombing: When Second Factor Authentication Fails
Social Engineering

MFA Prompt Bombing: When Second Factor Authentication Fails

Multi-factor authentication (MFA) was designed to prevent unauthorized access even when passwords are compromised. However, attackers have discovered a simpler approach: instead of stealing the second authentication factor, they manipulate users into voluntarily providing it. This technique, known as MFA prompt bombing, exploits human psychology by overwhelming users with repeated authentication requests until they approve access out of frustration or confusion. The attack bypasses traditional security measures by targeting the user rather than the technology. Organizations relying solely on MFA should implement additional safeguards like notification monitoring and user education to recognize such social engineering tactics. Source: Security Industry Publication.

via The Hacker NewsRead source
CERT-In Issues 12-Hour Patching Directive Against AI-Driven Attacks
Cyber Law (India)

CERT-In Issues 12-Hour Patching Directive Against AI-Driven Attacks

India's CERT-In has released updated guidelines mandating organizations to patch critical vulnerabilities in internet-facing systems within 12 hours when feasible. This directive addresses growing concerns about threat actors leveraging artificial intelligence tools and large language models to automate vulnerability discovery and exploitation. The accelerated patching timeline aims to reduce the window of opportunity for attackers using AI-assisted techniques to compromise systems. Organizations are advised to prioritize remediation of internet-exposed flaws to strengthen their security posture against evolving AI-powered cyber threats. Source: CERT-In Advisory.

via The Hacker NewsRead source
AI Governance Must Be Built Into Release Process, Not Added Later
Cyber Law (India)

AI Governance Must Be Built Into Release Process, Not Added Later

Traditional compliance approaches treat governance as a final review step after product development. This model fails for AI systems that continuously evolve—retrieval indices update, new tools are added, and evaluations become outdated between review cycles. Most organizations still govern AI like traditional software: build, ship, then seek legal approval. This leaves critical changes unmonitored. Chinese AI companies demonstrate an alternative: embedding governance directly into deployment pipelines as release infrastructure. Compliance checkpoints become mandatory gates before launch, not post-release reviews. This approach requires tracking live retrieval indices, setting output-monitoring thresholds, and tying model evaluations to enforceable release gates. Making governance part of the product development process rather than an external audit layer better addresses AI's dynamic nature and ensures safety throughout the system's lifecycle. Source: Original tech publication.

via RSS: CSO OnlineRead source
US agencies ordered to patch Drupal SQL vulnerability
Malware

US agencies ordered to patch Drupal SQL vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated all federal agencies to patch a critical SQL injection vulnerability in Drupal, a widely-used content management system. The vulnerability is currently being actively exploited by threat actors in the wild. Agencies have been given a strict deadline of Wednesday evening to secure their systems. SQL injection flaws allow attackers to manipulate database queries, potentially leading to unauthorized data access, modification, or deletion. This vulnerability poses significant risk to government infrastructure and sensitive data. Organizations worldwide using Drupal should also prioritize applying security patches immediately. Source: CISA.

via RSS: BleepingComputerRead source