General High 1 May

Google Adjusts Bug Bounties: Android Exploit Rewards Rise, Chrome Payouts Drop

Google has revised its bug bounty program, increasing rewards for critical Android exploits while reducing payouts for Chrome vulnerabilities. The maximum reward for a zero-click Pixel Titan M exploit with persistence has surged to $1.5 million, reflecting the high value of such severe vulnerabilities. This adjustment signals Google's strategic focus on securing its Android ecosystem […]

Why it matters: Indian organizations using Android devices, particularly Pixel phones, must remain vigilant about potential zero-day exploits and ensure timely security updates to mitigate high-impact threats.
General High 1 May

New Android Spyware Platform Enables Easy Resale and Rebranding

A new Android spyware platform is being openly sold online, offering buyers the ability to rebrand and resell surveillance malware. This tool allows anyone to customize the spyware with their own name and logo for distribution. The platform significantly lowers the barrier for creating and deploying sophisticated mobile surveillance threats. Source: Cybersecurity News

Why it matters: Indian organizations must enhance mobile device security, implement robust MDM policies, and educate employees on the risks of sophisticated, easily customizable Android spyware to protect sensitive data.
General High 1 May

Attackers Evolve Phishing with CAPTCHA, ClickFix for Credential Theft

Cybercriminals are enhancing credential theft campaigns by integrating CAPTCHA pages and ClickFix techniques, moving beyond simple email tricks. Microsoft Threat Intelligence observed 8.3 billion email-based phishing threats in Q1 2026, highlighting the scale of these sophisticated operations. This evolution in tactics aims to bypass traditional security measures and increase the success rate of credential compromise. […]

Why it matters: Indian organizations must update their cybersecurity training and email security defenses to counter these advanced phishing and credential theft methods.
General High 1 May

New DDoS Malware Exploits Jenkins Servers to Target Game Infrastructure

A newly discovered DDoS botnet is leveraging exposed Jenkins servers to launch powerful attacks. This malware specifically targets Valve Source Engine game infrastructure, as identified by security researchers. Its unique targeting of video game servers combined with a smart infection method makes it a notable threat. Source: Cybersecurity News

Why it matters: Indian organizations using Jenkins must ensure their servers are not exposed and are properly secured to prevent exploitation by this or similar botnets.
General High 1 May

India’s Cybersecurity Talent Gap Widens Amid AI, Cloud Demand

India is experiencing a significant shortage of skilled cybersecurity professionals. This talent gap is exacerbated by the rapid adoption of AI and cloud technologies, increasing demand for specialized expertise. New research highlights a growing disparity between industry needs and the current workforce's preparedness in the Indian cybersecurity landscape. Source: Indian Express

Why it matters: Indian organizations must prioritize talent development, retention, and strategic hiring to mitigate risks posed by the expanding cybersecurity skills deficit.
General High 1 May

Microsoft Patches Remote Desktop Security Warning Display Flaw

Microsoft has released a fix addressing an issue where newly introduced Windows security warnings for Remote Desktop (.rdp) files were not displaying correctly. This problem could lead to users potentially overlooking critical security advisories when opening RDP connections. The update ensures that all security prompts related to RDP files are now presented accurately to users. […]

Why it matters: Indian organizations must ensure their Windows systems are updated to correctly display Remote Desktop security warnings, preventing potential user oversight of critical security prompts.
General High 1 May

Deep#Door Backdoor: Stealthy Python Implant for Espionage, Disruption

A new sophisticated Python-based backdoor framework, dubbed Deep#Door, has been identified. This stealthy threat deploys a persistent Windows implant designed for covert operations. Its primary purpose is likely espionage and potential system disruption. Source: Security Week

Why it matters: Indian organizations must enhance detection capabilities for Python-based threats and monitor Windows systems for signs of this persistent espionage backdoor.
General High 1 May

Cisco Releases Open Source Tool for AI Model Security

Cisco has released a new open-source tool designed to enhance the security and integrity of Artificial Intelligence models. This kit aims to mitigate risks associated with poisoned models, improve supply chain integrity, and bolster incident response capabilities for AI systems. The tool helps organizations verify the provenance of AI models, addressing critical cybersecurity challenges in […]

Why it matters: Indian organizations leveraging AI in critical infrastructure must consider such tools to ensure the trustworthiness and security of their AI models against emerging threats like data poisoning and supply chain attacks.
General High 1 May

Bombay HC: WhatsApp Must Proactively Remove Scam Groups

The Bombay High Court ruled that WhatsApp cannot delay removing scam groups, rejecting its argument to await court orders under Section 79 of the IT Act. The court emphasized that intermediaries must act on complaints received via their grievance systems, as mandated by the IT Rules 2021. This decision underscores the proactive responsibility of online […]

Why it matters: This ruling mandates proactive action from online platforms against scams, influencing how Indian organisations manage digital communication risks and report malicious activities targeting their personnel.
General Critical 1 May

Critical Wireshark Flaws Allow Code Execution, Immediate Update Urged

Wireshark has released a critical security update addressing over 40 vulnerabilities. Several flaws allow arbitrary code execution via malformed packet injection or malicious capture files. Organizations using Wireshark for network monitoring and forensics must update to version 4.6.5 immediately. Source: Cybersecurity News

Why it matters: Indian critical infrastructure operators and security teams must promptly update Wireshark to mitigate severe arbitrary code execution risks in their network analysis tools.
General High 1 May

Weekly Roundup: Data Breaches, AI Risks, Phishing Dominate Cyber Landscape

The Cyber Express weekly roundup details significant cybersecurity developments across healthcare, public administration, and digital platforms. It highlights major data breaches, a high-impact AI operational failure, and large-scale phishing campaigns. These incidents reflect the increasing scale and sophistication of cyber threats, leveraging social engineering and systemic weaknesses. Source: The Cyber Express

Why it matters: Indian organizations must remain vigilant against evolving data breach tactics, AI-related risks, and sophisticated phishing campaigns to protect critical data and infrastructure.
General High 1 May

NDMA Urged to Test India’s Critical Infrastructure Cyber Defenses

The article recommends that India's National Disaster Management Authority (NDMA) test the cyber defense capabilities of the nation's critical infrastructure. This proactive measure is essential for ensuring preparedness against any potential cyber eventualities. Such drills would strengthen India's resilience in the face of evolving cyber threats. Source: Tatsatchronicle

Why it matters: Indian critical infrastructure operators should heed this call for enhanced cyber defense testing and integrate comprehensive drills into their security strategies to protect vital national assets.
General High 1 May

US Ransomware Negotiators Jailed 4 Years for BlackCat Attacks

Two former cybersecurity incident response employees received four-year prison sentences for their involvement in BlackCat (ALPHV) ransomware attacks targeting US companies. These individuals, previously with Sygnia and DigitalMint, were found to have facilitated the attacks. Their sentencing highlights the legal risks for those complicit in ransomware operations, even in negotiation roles. Source: BleepingComputer

Why it matters: This case underscores the severe legal repercussions for individuals involved in ransomware activities, serving as a critical reminder for Indian organizations to maintain robust defenses and scrutinize third-party incident response services.
General Critical 1 May

Critical Gemini CLI Flaw Allows Host Code Execution, Supply Chain Attacks

A critical vulnerability was discovered in the Gemini Command Line Interface. This flaw could enable attackers to execute arbitrary code on host systems by planting malicious configurations. The vulnerability also posed a significant risk for supply chain attacks, allowing commands to run outside the intended sandbox environment. Source: Security Week

Why it matters: Indian organizations using Gemini CLI must immediately assess their systems for this critical vulnerability and apply any available patches to prevent host code execution and supply chain attacks.
General Critical 1 May

Qilin Ransomware Maps Networks via RDP Authentication History

Qilin ransomware, a prominent cyber threat, has evolved its tactics since its 2022 emergence. The group now enumerates Remote Desktop Protocol (RDP) authentication history on compromised servers. This new technique allows Qilin to quickly and stealthily map target networks. Source: Cybersecurity News

Why it matters: Indian organizations must enhance RDP security, implement multi-factor authentication, and monitor for suspicious RDP activity to mitigate this advanced ransomware threat.
General Critical 1 May

AI Accelerates Industrial Cybercrime, Exploit Timeframes Shrink to Hours

Artificial intelligence is significantly enhancing the scale, speed, and success of cybercrime, leading to industrialized attacks. The time available for organizations to patch or respond to vulnerabilities before exploitation has drastically reduced to mere hours. Cybersecurity defenders must urgently leverage AI and automation to effectively counter these rapidly evolving and sophisticated threats. Source: Security Week

Why it matters: Indian critical infrastructure operators must urgently enhance their defensive capabilities with AI and automation to counter rapidly evolving, industrialized cyber threats and shrinking exploit windows.
General High 1 May

New Bluekit Phishing Service Leverages AI, Expands Templates

A new phishing kit named Bluekit has been identified, offering over 40 templates designed to target various popular online services. This service incorporates basic AI features to assist threat actors in generating campaign drafts, streamlining the creation of malicious phishing emails. The combination of AI and a broad template library significantly enhances the efficiency and […]

Why it matters: Indian organisations must enhance their phishing detection capabilities and employee training to counter the increased sophistication enabled by AI-powered phishing kits like Bluekit.
General High 30 Apr

India’s DPDP Act Addresses Foreign AI Data Privacy, Surveillance Risks

Governments globally are sounding alerts over data privacy and surveillance risks posed by foreign AI tools. India has enacted the Digital Personal Data Protection Act, 2023, to address these specific challenges. This law provides a framework for managing personal data and mitigating potential risks from AI tool usage. Source: Msn

Why it matters: Indian organizations must understand and comply with the DPDP Act when deploying foreign AI tools to safeguard sensitive data and avoid regulatory penalties.
General High 30 Apr

New Python Backdoor DEEP#DOOR Steals Browser, Cloud Credentials

Cybersecurity researchers have detailed DEEP#DOOR, a stealthy Python-based backdoor framework. This backdoor establishes persistent access and harvests sensitive browser and cloud credentials from compromised Windows hosts. The intrusion chain begins by disabling Windows security controls via a batch script. Source: The Hacker News

Why it matters: Indian organizations must update security controls, monitor for DEEP#DOOR indicators, and educate users to prevent credential theft and unauthorized access.
General High 30 Apr

Windows 11 Security Update KB5083769 Breaks Backup Software

The April 2026 KB5083769 security update for Windows 11 is causing significant issues. It is reported to break third-party backup applications on systems running Windows 11 24H2 and 25H2. This defect compromises data recovery capabilities and operational resilience for affected organizations. Source: BleepingComputer

Why it matters: Indian critical infrastructure operators must exercise caution with this Windows 11 update, as backup failures could severely impact incident recovery and business continuity.