India/E/Secure India Cybersecurity Intelligence
News Policy Threats Podcast Submit a Tip About Contact
Banking Power Telecom Health Government Defence Transport Water General
General High 16 May
Ionut Ilascu / BleepingComputer:

TeamPCP hackers advertise Mistral AI code repos for sale

The TeamPCP hacker group is threatening to leak source code from the Mistral AI project unless a buyer is found for the data. [...]

General High 16 May
Bill Toulas / BleepingComputer:

Funnel Builder WordPress plugin bug exploited to steal credit cards

A critical vulnerability in the Funnel Builder plugin for WordPress is being actively exploited to inject malicious JavaScript snippets into WooCommerce checkout pages. [...]

General High 16 May
(The Hacker News) / The Hacker News:

CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits

The U.S.Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly disclosed vulnerability impacting Cisco Catalyst SD-WAN Controller to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to remediate the issue by May

General Critical 16 May
(The Hacker News) / The Hacker News:

On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email

Microsoft has disclosed a new security vulnerability impacting on-premise versions of Exchange Server that it said has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-42897 (CVSS score: 8.1), has been described as a spoofing bug stemming from a cross-site scripting

General Critical 16 May
(The Hacker News) / The Hacker News:

What 45 Days of Watching Your Own Tools Will Tell You About Your Real Attack Sur

In Your Biggest Security Risk Isn't Malware — It's What You Already Trust, we made a simple argument: the most dangerous activity inside most organizations no longer looks like an attack. It looks like administration. PowerShell, WMIC, netsh, Certutil, MSBuild — the same trusted utilities your IT te

Government High 16 May
Msn:

54 propaganda songs & videos glorifying slain Maoist commander Hidma removed fro

... (CERT-In).After Hidma was eliminated by security forces in November last ye...

Government High 16 May
Techcircle:

Is Mythos the real threat—or is our lack of preparedness? – Techcircle

Coordinated reviews by CERT-In, the Finance Ministry and MeitY reflect how seriously the system views this shift. Loading... However, what is ...

General High 15 May
Tushar Subhra Dutta / Cybersecurity News:

New Malware Framework Enables Screen Control, Browser Artifact Access, and UAC B

A newly uncovered malware framework is raising serious alarms across the cybersecurity community. Researchers have identified a previously unknown implant called TencShell, a sophisticated tool capable of giving attackers full remote control over a compromised system. The discovery highlights how th

General High 15 May
Tushar Subhra Dutta / Cybersecurity News:

Sandworm Hackers Pivot From Compromised IT Systems Toward Critical OT Assets

A Russian state-sponsored hacking group known as Sandworm has been caught making a calculated pivot from compromised IT networks into operational technology systems that control physical infrastructure. The campaign is alarming because it does not rely on cutting-edge exploits. Instead, Sandworm wal

General High 15 May
Eduard Kovacs / Security Week:

Akamai to Acquire AI and Browser Security Firm LayerX for $205 Million

The acquisition enables Akamai to expand its Zero Trust portfolio to add protection directly into the browser. The post Akamai to Acquire AI and Browser Security Firm LayerX for $205 Million appeared first on SecurityWeek.

General High 15 May
Kevin Townsend / Security Week:

Mythos Proves Potent in Vulnerability Discovery, Less Convincing Elsewhere

Independent benchmarking finds Mythos highly effective for source code audits, reverse engineering, and native-code analysis, though its exploit validation and reasoning capabilities remain inconsistent. The post Mythos Proves Potent in Vulnerability Discovery, Less Convincing Elsewhere appeared fir

General High 15 May
Sponsored by NMFTA / BleepingComputer:

Cyber-Enabled Cargo Crime: How Cybercrime Tradecraft is Used to Steal Freight

Cargo theft now starts with phishing emails and stolen credentials, not hijackings, to reroute and steal freight from supply chains. NMFTA outlines how cyber-enabled cargo crime is changing transportation security. [...]

General High 15 May
Sergiu Gatlan / BleepingComputer:

Windows 11 and Microsoft Edge hacked at Pwn2Own Berlin 2026

On the first day of Pwn2Own Berlin 2026, security researchers collected $523,000 in cash awards after exploiting 24 unique zero-days. [...]

General High 15 May
Lawrence Abrams / BleepingComputer:

OpenAI confirms security breach in TanStack supply chain attack

OpenAI says two employees' devices were breached in the recent TanStack supply chain attack that impacted hundreds of npm and PyPI packages, causing the company to rotate code-signing certificates for its applications as a precaution. [...]

General High 15 May
(The Hacker News) / The Hacker News:

PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of Disclosure

Threat actors have been observed attempting to exploit a recently disclosed security vulnerability in PraisonAI, an open-source multi-agent orchestration framework, within four hours of public disclosure. The vulnerability in question is CVE-2026-44338 (CVSS score: 7.3), a case of missing authentica

General High 15 May
(The Hacker News) / The Hacker News:

Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer Secrets

Cybersecurity researchers are sounding the alarm about what has been described as "malicious activity" in newly published versions of node-ipc. According to Socket and StepSecurity, three different versions of the npm package have been confirmed as malicious - node-ipc@9.1.6 node-ipc@9.2.3 node-ipc@

Government High 15 May
Military:

Army Defense Contractor Leaked 70,000 Files Containing Sensitive Information

"Roy reported to us that he notified the US-CERT in 2024," he said. "After that, Roy received confirmation that US-CERT is 'in contact with the ...

Government Critical 15 May
Ndtvprofit:

CERT-In Sounds ‘Critical’ Alert Over Multiple Vulnerabilities In SAP Products –

CERT-In stated that the vulnerabilities indicated a high risk of unauthorised access, data compromise, and potential remote code execution.

General High 14 May
Ionut Arghire / Security Week:

Government to Scrutinize Instructure Over Canvas Disruption, Data Breach

The Committee on Homeland Security has requested to be briefed on the incident and Instructure’s remediation steps. The post Government to Scrutinize Instructure Over Canvas Disruption, Data Breach appeared first on SecurityWeek.

General High 14 May
The Record:

Microsoft on pace to break annual vulnerability record as AI-driven patch wave t

Five months into 2026, Microsoft has already patched more than 500 vulnerabilities — although the exact monthly count varies depending on whether analysts include Edge, Chromium and fixes shipped earlier in the month.

« 1 … 12 13 14 15 16 … 28 »
Sector Heat Index (7d)
General
57
Government
9
Telecom
2
Recent Stories
Gemini Voice Assistant Hijacked via Messaging Notifications
High  5 Jun
Webinar Today: Third-Party Risk in Practice – Where Programs Break Down and How
High  5 Jun
CISA directive for AI executive order to be released this week, Andersen says
High  5 Jun
Hackers Are After the Gaps in Your Vulnerability Program: Here’s Their Playbook
High  5 Jun
New IronWorm malware hits 36 packages in npm supply-chain attack
High  5 Jun
UN food agency discloses breach affecting 600,000 Gaza households
High  5 Jun
ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS
High  5 Jun

© 2026 IndiaESecure — India Cybersecurity Intelligence  •  About  •  admin@indiaesecure.com