News

Short summaries of the cyber-crime stories moving in India and globally. We link back to the original source — always.

US Agencies Ordered to Patch Oracle WebLogic Critical Flaw
Malware

US Agencies Ordered to Patch Oracle WebLogic Critical Flaw

US Cyber Security and Infrastructure Security Agency (CISA) has directed all federal agencies to patch a critical vulnerability in Oracle WebLogic Server. The flaw poses significant security risks and could be exploited by threat actors to compromise government systems. WebLogic Server, widely used for business applications, requires immediate patching to prevent potential attacks. The directive mandates agencies complete patching within specified timeframes as part of critical infrastructure protection measures. Organizations running WebLogic Server deployments should prioritize applying available security updates to mitigate exploitation risks. Source: SC Media.

via GoogleNews: vulnerability CVERead source
Pan-India cyber fraud ring defrauding 196 victims dismantled
Investment Fraud

Pan-India cyber fraud ring defrauding 196 victims dismantled

Law enforcement agencies have successfully dismantled a widespread cyberfraud network operating across India that targeted and defrauded 196 victims. The criminal ring employed sophisticated tactics to steal money from unsuspecting individuals through various online schemes. Investigations revealed the network's organized structure and coordinated operations spanning multiple states. Authorities arrested key members involved in the fraudulent activities and recovered evidence of their operations. The case highlights the growing threat of organized cybercrime in India and the importance of coordinated law enforcement efforts. Victims lost substantial amounts through the scheme. This bust demonstrates authorities' commitment to combating digital fraud and protecting citizens from online financial crimes. Source: The Times of India.

via GoogleNews: job scam IndiaRead source
Security breach at film event highlights venue safety concerns
Children Safety

Security breach at film event highlights venue safety concerns

A security breach occurred during a promotional event for the film 'Peddi' where an unauthorized person managed to bypass security measures and approach actor Janhvi Kapoor, leaving her visibly shocked. Co-star Ram Charan remained composed during the incident, earning praise for his calm demeanor. The incident highlights vulnerabilities in event security protocols and the importance of robust access control measures at public celebrity appearances. Such breaches raise concerns about personal safety at organized events and demonstrate the need for improved security procedures to prevent unauthorized access.

via GoogleNews: data breach IndiaRead source
Password Stealer Attacks Surge 20%, Threatening Indian Business Data
Malware

Password Stealer Attacks Surge 20%, Threatening Indian Business Data

Kaspersky reports a concerning 20% increase in password stealer attacks targeting Indian businesses, putting corporate credentials at significant risk. These malicious tools are designed to extract login information from employees' systems, enabling unauthorized access to sensitive business accounts and data. The surge highlights growing threats to organizational cybersecurity infrastructure across India. Businesses are advised to implement robust security measures, including multi-factor authentication, regular password updates, and employee security awareness training. IT teams should monitor network activity for suspicious behavior and deploy advanced threat detection solutions. This trend underscores the importance of proactive credential protection strategies for enterprises operating in India's digital ecosystem. Source: Deccan Herald.

via GoogleNews: ransomware IndiaRead source
US Agencies Warn of Cyber Attacks on Tank Gauge Systems
Malware

US Agencies Warn of Cyber Attacks on Tank Gauge Systems

US cybersecurity authorities, including CISA, FBI, NSA, and other agencies, have identified malicious cyber activity targeting automatic tank gauge (ATG) systems used across energy, chemical, food, agriculture, and transportation sectors in America. These systems monitor fuel levels, temperature, and detect leaks in storage tanks. Attackers are exploiting vulnerabilities through authentication bypass, hardcoded credentials, and command execution to compromise internet-exposed ATG systems. The agencies recommend operators secure systems with strong passwords and disconnect them from the internet to minimize exposure. The attack source remains unattributed to any specific nation-state or threat group. Source: CISA.

via RSS: CISA AlertsRead source
CISA Lists Two Active Exploited Vulnerabilities
Malware

CISA Lists Two Active Exploited Vulnerabilities

The US Cybersecurity and Infrastructure Security Agency (CISA) has identified two vulnerabilities actively exploited by attackers: CVE-2022-0492 affecting Linux Kernel authentication and CVE-2025-48595 impacting Android Framework. These have been added to CISA's Known Exploited Vulnerabilities catalog, which tracks threats to critical infrastructure. While mandatory remediation applies to US federal agencies under Binding Operational Directive 22-01, CISA recommends all organizations prioritize patching these vulnerabilities to reduce cyberattack exposure. The catalog serves as a living resource for vulnerability management practices globally. Source: CISA.

via RSS: CISA AlertsRead source
HR Tech Security: Safeguarding Employee Data
Data Breaches

HR Tech Security: Safeguarding Employee Data

HR technology platforms handle sensitive employee information including personal details, financial records, and identification documents. Organizations must implement robust cybersecurity measures to protect this data from unauthorized access and breaches. Key protection strategies include strong access controls, regular security audits, employee training on phishing and social engineering threats, encryption of sensitive data, and incident response plans. HR departments should ensure vendors comply with data protection standards and maintain compliance with regulations governing employee information. With increasing cyber threats targeting HR systems, companies must prioritize security infrastructure to prevent data theft and maintain employee trust. Source: SHRM.

via GoogleNews: data breach IndiaRead source
Android Zero-Day Flaw Used in Active Device Takeover Campaign
Malware

Android Zero-Day Flaw Used in Active Device Takeover Campaign

Security researchers have identified an unpatched vulnerability in Android devices that is being actively exploited by attackers to gain complete control over affected smartphones. The zero-day flaw allows threat actors to bypass security protections and take over devices remotely. Users may experience unauthorized access to personal data, applications, and device functions without their knowledge. Google has been notified and is reportedly working on a patch. Meanwhile, Android users are advised to exercise caution with suspicious links and downloads, enable automatic security updates, and consider using mobile security applications for enhanced protection. Source: gbhackers.com.

via GoogleNews: vulnerability CVERead source
Delhi GST Fraud: Job Promise Leads to ₹128 Crore Company Entanglement
Identity Theft

Delhi GST Fraud: Job Promise Leads to ₹128 Crore Company Entanglement

A Delhi resident became unwittingly entangled in a GST fraud scheme after being promised a government job. Fraudsters used the victim's identity to register a ₹128 crore firm, implicating them in illegal business operations. The scam highlights how criminals exploit job-seekers through false employment promises while establishing fraudulent enterprises in their names. Victims of such schemes face serious legal consequences and financial liability. Authorities warn citizens to verify job offers independently and avoid sharing personal documents with unverified sources. This case demonstrates the intersection of identity theft and investment fraud targeting unsuspecting individuals seeking government positions.

via GoogleNews: job scam IndiaRead source
Anthropic Opens AI Safety Tool to EU Security Agency
Cyber Law (India)

Anthropic Opens AI Safety Tool to EU Security Agency

Anthropic, an AI safety company, has granted the European Union's cybersecurity agency ENISA access to Mythos, an advanced AI tool designed for security research. This collaboration is part of Project Glasswing, established through partnership between the European Commission and Anthropic. The initiative aims to enhance Europe's AI security capabilities and strengthen bilateral cooperation on emerging cyber threats. ENISA will leverage the tool to conduct independent security assessments and contribute to the development of safer AI systems across the EU. Source: Securityweek.

via Dark ReadingRead source
Microsoft's Legal Action Against Zero-Day Researcher Draws Criticism
Cyber Law (India)

Microsoft's Legal Action Against Zero-Day Researcher Draws Criticism

Microsoft faced backlash after threatening legal action against a security researcher who publicly disclosed multiple zero-day vulnerabilities. The researcher, reportedly frustrated, released details of several unpatched exploits affecting Microsoft systems. The company's response indicating potential criminal charges sparked controversy within the cybersecurity community, raising questions about vulnerability disclosure practices and researcher protections. This incident highlights the tension between companies seeking to protect their systems and security professionals aiming to improve overall cybersecurity through responsible disclosure. Source: Original Article.

via Dark ReadingRead source
WordPress Plugin Flaw Allows Admin Account Creation
Malware

WordPress Plugin Flaw Allows Admin Account Creation

A critical vulnerability (CVE-2026-8732) in the WP Maps Pro WordPress plugin enables unauthenticated attackers to create administrative accounts on vulnerable websites. This security defect could lead to complete site takeover, allowing malicious actors to modify content, steal data, or inject malicious code. WordPress site administrators using this plugin are advised to update immediately to patched versions. This vulnerability highlights the importance of keeping plugins updated and using security measures to protect WordPress installations from unauthorized access. Source: SecurityWeek.

via RSS: SecurityWeekRead source