General High 4 May

India Warns: AI Accelerates Software Flaw Exploitation

India's cybersecurity agency has issued a warning about emerging AI capabilities. Anthropic's Mythos AI is reportedly compressing the timeline between identifying software flaws and developing functional exploits. This acceleration poses a significant new challenge for cybersecurity defenses, potentially increasing the speed and impact of cyber attacks. Source: Techinasia

Why it matters: Indian organizations must prioritize rapid vulnerability patching and robust threat intelligence to mitigate risks from AI-accelerated exploit development.
General High 4 May

CERT-In Issues High-Severity Advisory on ‘Mythos’ Threat

India's CERT-In has issued a high-severity advisory concerning the 'Mythos' threat, which officials deem unprecedented. The directive urges all organizations to treat this threat with extreme caution and implement robust security measures. This development occurs as Anthropic introduces its Claude Security offering, highlighting growing concerns around advanced threats. Source: MediaNama

Why it matters: Indian organizations must heed CERT-In's high-severity advisory on the unprecedented Mythos threat and implement necessary security measures promptly to protect critical infrastructure.
General High 4 May

ESET Establishes Dedicated India Entity Amidst Rising Cyber Threats

ESET has announced the establishment of a dedicated entity in India, aiming to bolster its long-term growth strategy across the APAC region. This move comes as India's cybersecurity landscape experiences a significant increase in complexity and threats, including ransomware. The new entity will enable ESET to better serve the growing demand for robust cybersecurity solutions […]

Why it matters: Indian organisations can expect enhanced local support and access to ESET's cybersecurity solutions as the company deepens its commitment to the region.
General Critical 4 May

Critical MOVEit Flaws Allow Authentication Bypass, Full System Control

Progress Software has issued a critical security bulletin for its MOVEit Automation platform, detailing two highly severe vulnerabilities. These flaws could enable attackers to bypass security checkpoints and gain full system control over affected systems. The vulnerabilities pose a significant risk given MOVEit Automation's widespread use for secure enterprise file transfers. Source: Cybersecurity News

Why it matters: Indian critical infrastructure organizations utilizing MOVEit Automation must promptly review this alert and apply all necessary patches to mitigate the risk of authentication bypass and system compromise.
General Critical 4 May

CISA Warns of Active Exploitation of ‘Copy Fail’ Linux Root Vulnerability

CISA has issued a warning regarding the active exploitation of the 'Copy Fail' Linux security vulnerability. Threat actors are leveraging a recently disclosed proof-of-concept exploit to gain root access to affected systems. This critical flaw allows attackers to take full control of vulnerable Linux machines. Source: BleepingComputer

Why it matters: Indian organizations using Linux systems must immediately identify and patch vulnerable machines to prevent root compromise and potential data breaches.
General High 4 May

Microsoft April Windows Updates Cause Third-Party Backup Failures

Microsoft has confirmed that its April 2026 security updates are causing significant failures in third-party backup applications. The issue specifically affects software utilizing the psmounterex.sys driver, leading to operational disruptions. Organizations relying on these backup solutions should be aware of the problem and monitor for official resolutions from Microsoft. Source: BleepingComputer

Why it matters: Indian critical infrastructure operators must assess their backup systems for compatibility with recent Windows updates and prepare for potential recovery challenges.
General Critical 4 May

40,000 Servers Compromised via cPanel Zero-Day Exploitation

Over 40,000 servers have been compromised due to ongoing exploitation of a cPanel vulnerability. The attacks are targeting CVE-2026-41940, a recently patched zero-day flaw. This vulnerability grants administrative access to affected systems, posing a significant risk. Source: Security Week

Why it matters: Indian organizations utilizing cPanel must immediately verify patch status for CVE-2026-41940 to prevent administrative compromise of their servers.
General Critical 4 May

Apache MINA Critical Vulnerabilities Allow Remote Code Execution, Urgent Updates Issued

The Apache MINA project has released urgent security updates to address two critical vulnerabilities. These flaws could enable attackers to execute arbitrary code on affected systems. Developers are strongly advised to update their software immediately to prevent potential exploitation. Source: Cybersecurity News

Why it matters: Indian organizations utilizing Apache MINA in their network applications must apply these critical updates to mitigate severe remote code execution risks.
General High 4 May

CISA Warns: Critical cPanel & WHM Vulnerability Actively Exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical security flaw in cPanel & WHM web hosting platforms. This vulnerability, tracked as CVE-2026-41940, has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation by threat actors. The flaw affects WebPros products and poses a significant […]

Why it matters: Indian organizations utilizing cPanel & WHM for their web hosting or relying on service providers using these platforms must prioritize immediate patching or mitigation to prevent active exploitation.
General High 4 May

New Microsoft Teams Phishing Attacks Use Email Bombing, Fake IT Support

A new wave of cyberattacks is leveraging email bombing and fake IT support calls on Microsoft Teams to trick employees. These sophisticated phishing campaigns aim to gain remote access to user devices. Security researchers warn these attacks are increasing and pose a significant threat. Source: Cybersecurity News

Why it matters: Indian critical infrastructure organizations must enhance employee training on phishing awareness and implement robust email and collaboration platform security measures to counter these evolving threats.
General Critical 4 May

AI-Powered Threat Actors Automate Zero-Day Exploitation at Machine Speed

Threat actors are now leveraging artificial intelligence to rapidly discover and exploit zero-day vulnerabilities. This shift enables them to identify and weaponize software flaws in minutes, fundamentally changing the speed of cyberattacks. Organizations across all sectors face heightened and accelerated risks from these AI-driven, machine-speed attacks. Source: Cybersecurity News

Why it matters: Indian critical infrastructure operators must enhance their threat intelligence, vulnerability management, and rapid response capabilities to counter AI-accelerated zero-day exploitation.
General High 4 May

Microsoft Defender Flags Legitimate DigiCert Certificates as Trojan

Microsoft Defender is erroneously identifying legitimate DigiCert root certificates as Trojan:Win32/Cerdigent.A!dha. This widespread false-positive issue is causing alerts and, in some instances, the removal of critical certificates from Windows systems. Operators must be aware of this issue to prevent unnecessary remediation or operational disruption. Source: BleepingComputer

Why it matters: Indian organizations using Microsoft Defender on Windows systems must be vigilant for these false positives to avoid service disruptions caused by the removal of essential certificates.
General High 3 May

Telegram Mini Apps Exploited for Crypto Scams and Android Malware Delivery

Cybersecurity researchers have identified a widespread fraud operation leveraging Telegram's Mini App feature. This operation facilitates crypto scams, brand impersonation, and the distribution of Android malware. The abuse of this platform feature poses a significant risk to users. Source: BleepingComputer

Why it matters: Indian organisations must educate employees on the risks of Telegram Mini Apps to prevent crypto scams and Android malware infections.
General High 3 May

India Seeks AI Access for Critical Infra Security Amid CERT-In Warnings

India is actively pursuing access to advanced AI models like Anthropic's Mythos for enhancing critical infrastructure security. This initiative comes as CERT-In has issued warnings about the high-severity risks posed by AI-driven cyber threats. The government is urged to formally and urgently secure this access to mitigate emerging cyber risks. Source: Msn

Why it matters: Indian organizations must prepare for evolving AI-driven cyber threats and consider how AI tools can both pose risks and enhance their defensive capabilities.
General High 3 May

CERT-In Warns Indian Apple Users of iOS/iPadOS Vulnerabilities

India's CERT-In has issued a critical security alert for iPhone and iPad users in the country. The advisory highlights vulnerabilities found in older versions of iOS and iPadOS, posing risks to device security. Users are urged to update their devices immediately to mitigate potential cyber threats. Source: Thesouthindiatimes

Why it matters: Indian organizations must ensure employees using Apple devices for work update their operating systems to protect against potential data breaches and cyber attacks.
General Critical 2 May

CERT-In Flags Critical Windows Flaws, Urges Immediate Updates

CERT-In has issued an alert regarding critical security vulnerabilities affecting a wide range of Microsoft Windows products and services. These flaws could enable remote code execution, privilege escalation, or denial of service attacks. Indian users and organizations are strongly advised to apply the latest security updates immediately to mitigate potential risks. Source: Msn

Why it matters: Indian organizations must prioritize patching all affected Windows systems without delay to prevent exploitation of these critical vulnerabilities by malicious actors.
General High 2 May

CERT-In Warns India of AI Cyber Threats and Microsoft Vulnerabilities

CERT-In has issued a critical warning to Indian organizations regarding escalating cybersecurity risks. The alert specifically highlights the growing threat from AI-driven cyber attacks and unpatched Microsoft vulnerabilities. This emphasizes the urgent need for enhanced defensive measures across all sectors in India. Source: Dqindia

Why it matters: Indian critical infrastructure operators must prioritize patching Microsoft systems and implement robust strategies to counter emerging AI-powered cyber threats as advised by CERT-In.
General High 2 May

Khushhal Kaushik Named DG of India’s Cyber Security Association

Khushhal Kaushik has been appointed as the Director General of the Cyber Security Association of India. In this new role, he will contribute to strengthening India's cybersecurity framework amidst increasing digital threats. Kaushik, also the Founder and CEO of Lisianthus Tech, brings significant industry experience to the position. Source: Bignewsnetwork

Why it matters: This appointment signifies a key leadership change within an important Indian cybersecurity body, potentially influencing national cybersecurity strategies and initiatives relevant to all Indian organizations.
General High 2 May

Critical Exim Mail Server Vulnerabilities Require Immediate Patching

Exim has released version 4.99.2 to fix four new security vulnerabilities affecting its mail server software. These flaws could allow attackers to crash servers, corrupt memory, or leak sensitive data. As Exim is one of the most widely used message transfer agents, system administrators must apply the update promptly. Source: Cybersecurity News

Why it matters: Indian organizations using Exim mail servers must immediately patch to prevent service disruption, data breaches, and maintain email communication integrity.
General Critical 2 May

CISA Directs Federal Agencies to Patch Critical cPanel Vulnerability

CISA has issued a directive for US federal agencies to patch a critical cPanel vulnerability (CVE-2026-41940) by Sunday. Security researchers at Rapid7 confirm that successful exploitation of this bug allows attackers to gain full control over the cPanel host, its configurations, databases, and managed websites. This vulnerability poses a severe risk, enabling complete system compromise […]

Why it matters: Indian organizations using cPanel, particularly those in critical infrastructure, must prioritize patching this vulnerability immediately to prevent system compromise and data breaches.