News · 158 articles

News

Latest cybersecurity news — hacks, breaches, vulnerabilities, regulatory moves

Compliance

RBI Tightens IT Outsourcing Norms: Cloud Audit, Exit Plans Mandatory from October 2026

RBI's anticipated update to the IT Governance Master Direction adds cloud DR tests, concentration risk registers and board-attested exit plans for NBFCs.

May 12, 2026 · 3 min read
Compliance

DPDP Rules Phase 2 Notified: Consent Manager, SDF Criteria, Cross-Border Negative List

India notifies the second tranche of DPDP Rules: Consent Manager registration, SDF thresholds, children's age-gating and cross-border negative list.

May 12, 2026 · 3 min read
Compliance

CERT-In Flags Microsoft May 2026 Patch Tuesday: 73 Flaws, Zero-Days Active

CERT-In advisory flags Microsoft May 2026 Patch Tuesday: 73 CVEs including exploited zero-days in Windows TCP/IP and Win32k. Patch within 72 hours.

May 12, 2026 · 3 min read
News

AiTM Phishing in 2026 — How EvilProxy, Mamba, Tycoon, and Astaroth Defeat Microsoft 365 MFA

Adversary-in-the-Middle phishing kits proxy your real login page and capture both credentials and post-MFA session cookies in real time. Why Microsoft Authenticator…

May 8, 2026 · 6 min read
News

Cl0p MFT Mass-Exploit Pattern — From Accellion to Cleo, Why Indian Enterprises Keep Ending Up Downstream

Cl0p ransomware perfected the managed-file-transfer (MFT) mass-exploit playbook across Accellion, GoAnywhere, MOVEit, and Cleo — 2,700+ victims in MOVEit alone. Why MFT…

May 8, 2026 · 6 min read
News

Indian Android Banking Trojans 2026 — SoumniBot, Brokewell, Gigabud and the Accessibility-Service Endgame

Indian Android banking trojans (SoumniBot, Brokewell, Gigabud, GoldDigger) converge on a single playbook: side-loaded APK → Accessibility Service grant → SMS interception…

May 8, 2026 · 6 min read
News

Snowflake Mega-Breach Anatomy — How UNC5537 Hit 165 Customers Without a Single Vulnerability

UNC5537 (ShinyHunters) compromised 165+ Snowflake customer tenants in 2024 — Ticketmaster, AT&T, Santander — using infostealer credentials replayed against MFA-disabled accounts. Technical…

May 8, 2026 · 7 min read
News

Salt Typhoon — How a PRC APT Mapped the US Telecom Backbone (and What Indian Carriers Should Steal From It)

Salt Typhoon (UNC2286 / GhostEmperor) sat inside US telecom carriers for 18+ months exploiting Cisco IOS XE CVE-2023-20198. Technical breakdown of Demodex…

May 8, 2026 · 7 min read
News

Top 10 Latest Vulnerabilities — Theory, Technical Analysis & Remediation (April–May 2026)

In-depth ~10-page technical breakdown of the 10 most consequential vulnerabilities CISA added to its Known Exploited Vulnerabilities catalog in April–May 2026. For…

May 4, 2026 · 27 min read
News

Star Health Data Breach 2024 — 31M Customer Records Exposed via Telegram Bots: Full Technical Analysis & DPDP Implications

India's largest standalone health insurer leaked 31 million customer records — names, PANs, phone numbers, claim documents, medical reports — via attacker-operated…

Apr 30, 2026 · 17 min read