Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Cyber Security. Show all posts

Indian Banks Increase Cybersecurity Investments to Counter AI-Powered Cyber Threats

 

Indian banks are ramping up cybersecurity spending as artificial intelligence-fueled cyber threats grow more sophisticated. As per the Digital Threat Report 2025-26 for the Banking, Financial Services and Insurance (BFSI) sector, six out of seven cyber threats identified by the report in the previous year have become operational, forcing banks to shore up their cyber defenses. 

“The threat landscape is evolving with bad actors using AI, impersonation, and payment process orchestration to mimic legitimate customer behavior. BFSI players are adopting advanced security technologies and countermeasures such as AI-driven fraud detection and prevention, zero-trust architecture, micro segmentation, and enhanced cyber defenses,” said the report. 

With security being increasingly prioritized as an operating imperative over technology spending, banks are also investing more in secure digital lending platforms, Unified Payment Interface (UPI) services, cloud, and AI applications. 

PNB, for instance, has set aside about 20% of its FY27 technology budget or ₹7-8 billion for cybersecurity. This is more than double the spending made in the previous fiscal. “We can always increase our cybersecurity budget if the need arises,” said the bank. The Reserve Bank of India (RBI) has also been focusing on cybersecurity and AI governance. 

In the recent past, the central bank has been interacting with banks on AI, geopolitical issues, and ECL (expected credit loss) implementation. Additionally, RBI has also shared a draft framework on AI governance for regulated entities. “The BFSI cybersecurity market size is estimated to grow at a double-digit CAGR through 2030 as banks and financial institutions continue to focus on operational resilience, address technology-related third-party risks, respond to tightening regulatory compliance needs, and mitigate the talent shortage in specialized cybersecurity roles,” said the report. 

While BFSI players are witnessing a dip in capital expenditures (capex) on physical infrastructure, technology budgets are being allocated to cyber monitoring, identity management, fraud management systems, cloud security, and regular vulnerability assessments. “The Financial Stability Report (FSR) 2025 has identified AI-enabled cyber threats as one of the critical emerging risks to the financial stability of the Indian economy. 

Even as India’s banking system remains resilient with stress tests showing that gross NPAs will remain below 2% through 2028 in the baseline scenario, the focus on cybersecurity, particularly AI-driven financial crime prevention, is gaining momentum,” said the report. “With AI-driven financial crime prevention becoming a strategic imperative, cybersecurity is set to be one of the largest technology expenditures for banks. 

The question now is not whether banks will increase cybersecurity spending but how quickly they can build resilient and AI-ready digital ecosystems to secure their digital banking ecosystems,” added the report.

Fitness Trackers Can Expose Your Health Data, EFF Warns

 

Fitness trackers have become part of everyday life, helping people monitor steps, sleep, heart rate, stress, and workouts with impressive convenience. But a recent investigation highlighted a serious privacy issue: much of the health data collected by popular wearables is not protected under federal health privacy law, which means it can be exposed through legal requests far more easily than many users realize. 

Among the major brands reviewed, Apple stands out because its health data can be protected with end-to-end encryption, giving users a stronger layer of control over sensitive information. The core concern is that most wearable devices rely on cloud storage, where the company that makes the device often holds the keys to the data. That setup may feel secure because the information is encrypted while being transferred and stored, but it is not the same as true end-to-end encryption. If the company can access the data, then law enforcement may also be able to obtain it through a subpoena. 

For users, that means intimate details such as sleep patterns, location history, menstrual cycles, and heart-rate trends may be accessible outside the privacy protections many people assume apply.  This issue matters because wearable health data is highly revealing. A fitness tracker can create a detailed picture of daily routines, physical condition, and even emotional stress patterns. In legal disputes, such records have already been used to challenge alibis, verify movements, and support claims in civil cases. 

As wearable adoption continues to grow, the volume of personal information collected will only increase, making privacy protections more important than ever. Many consumers buy these products for wellness, but they may not realize they are also generating a persistent data trail. Apple’s approach is different because its Health ecosystem supports end-to-end encryption when properly configured. 

That means the company cannot read the protected health data, and a subpoena would not produce the same level of information that cloud-based systems can reveal. Apple also allows users to limit syncing and keep more data local, which adds another privacy advantage. For users who want the strongest protection, this makes Apple Watch and Apple Health a standout option compared with most other wearable brands. 

Before buying a fitness tracker, consumers should look beyond features like battery life, workout tracking, and smartwatch functions. Privacy policies, transparency reports, local storage options, and encryption standards should matter just as much as design and price. In an era where health data is constantly collected, the best wearable is not only the one that tracks well, but the one that protects personal information responsibly.

Location Sharing: Convenience at the Cost of Safety

 

Location sharing has become a routine feature in messaging, navigation, and social apps, yet it carries security and privacy risks that many users underestimate. While convenient for coordinating meetups or ensuring family safety, careless configuration can expose sensitive patterns about your daily life to strangers, advertisers, and even attackers who compromise the platforms you trust. 

The most immediate danger is physical safety. Continuous location sharing reveals where you live, work, study, and spend leisure time, effectively mapping your routine for anyone with access. Stalkers, harassers, or opportunistic criminals can exploit this data to time thefts, orchestrate impersonation scams, or physically follow you. Real-time updates on platforms like Snapchat’s Snap Maps make it trivial to see when you are home or away, turning a social feature into a surveillance tool if permissions are too broad. 

Beyond individual bad actors, the apps themselves and their data ecosystems present another layer of risk. Many services collect and retain location histories, which can be sold to data brokers, advertisers, or accessed by third parties through data breaches. Incidents like the Gravy Analytics hack show how aggregated location data can leak at scale, exposing users who never intended their movements to be public. Even when companies claim strong security, breaches and insider misuse remain persistent threats in today’s threat landscape. 

Location data also fuels more sophisticated cyberattacks through social engineering and targeted fraud. Attackers can correlate your whereabouts with spending habits, social posts, and device usage to craft convincing phishing messages, fake support calls, or credential-reset scams. For example, seeing that you just visited a shopping mall or a specific campus building can help criminals personalize spam about credit-card fraud or IT alerts, increasing the chance you click a malicious link. Geotagged photos and live stories further amplify this risk by publicly broadcasting your precise coordinates. 

Mitigating these risks requires deliberate permission management and a mindset Of location sharing has become a routine feature in messaging, navigation, and social apps, yet it carries security and privacy risks that many users underestimate. While convenient for coordinating meetups or ensuring family safety, careless configuration can expose sensitive patterns about your daily life to strangers, advertisers, and even attackers who compromise the platforms you trust.

Vatican ‘Click to Pray’ App Security Flaw Exposed Data of 700,000 Users


Approximately 700,000 personal data of Vatican users were reportedly exposed due to a critical security vulnerability in Click to Pray, causing concerns about data privacy and phishing. An independent security researcher BobDaHacker discovered in January 2026 that the backend API lacked basic authentication and access controls, leading to the discovery of the flaw. 

Researchers indicate that anyone could retrieve user information by simply altering sequential user ID numbers in API requests, thereby making sensitive data publicly accessible without authorization. It has been identified as an Insecure Direct Object Reference (IDOR) flaw, a type of access control weakness that can allow unauthorized users to manipulate object identifiers in order to gain access to restricted data. 

Using the exposed API endpoint, the researcher reported that no authentication was required, thus anybody with knowledge of the endpoint could access user records directly through a web browser, without requiring advanced technical knowledge. The information exposed was reported to include first and last names, email addresses, dates of birth, preferred language, and account information. However, cybersecurity experts caution that, even though financial information was not disclosed, email addresses combined with personal information can significantly increase the risk of targeted phishing scams and social engineering attacks. 

Additionally, the exposed records revealed the country of origin of each user, his account status, and the level of privileges he or she possessed, including whether the account belongs to an administrator or a regular user. Research findings identified that the platform's staff accounts were among the lowest-numbered user IDs, which made internal accounts accessible via the same vulnerable API. Other security flaws were also identified by the researcher. 

By assigning sequential user IDs to newly created accounts, automated requests were able to access the entire user database. Additionally, the API did not contain rate limits, which allowed attackers to collect a large number of user records without restrictions. Additionally, the validation hash used to verify emails was stored in plain text, thus providing another potential attack vector. 

Further, the researchers indicated that the vulnerable endpoint could be exploited without specialized tools, since user IDs were assigned sequentially. This allowed attackers to automate requests to enumerate the database and gather user information at a large scale. Due to the absence of authorization checks, the vulnerability represents a fundamental failure in access control rather than a sophisticated attack. 

In accordance with the disclosure, the researcher attempted to inform multiple contacts related to the application of the vulnerabilities immediately after discovery. However, despite several requests for responses, the issues were not resolved for nearly six months. Security journalist Nate Nelson of Dark Reading also contacted the developers, but did not receive a response. 

The vulnerability was independently tested prior to publication by cybersecurity publication Dark Reading. As stated in the publication, the Pope's Worldwide Prayer Network, which operates the platform, as well as La Machi Communication for Good Causes, the agency responsible for developing the application, were also contacted, but no response was received before the issue became public. 

According to the researcher, the vulnerabilities were addressed only after they were made public through media coverage. Although the researcher followed responsible disclosure practices, no formal acknowledgement was provided for the vulnerabilities. There are reportedly nearly 720,000 registered accounts on Click to Pray by July 2026, making the exposure significant despite the app's niche target audience. 

According to researchers, many faith-based application users might not be aware of cybersecurity threats, thus making them attractive targets for online scams and phishing attacks. As a result of this incident, fundamental API security measures such as authentication, authorization, rate limiting, and safe handling of sensitive information need to be implemented. Furthermore, the incident emphasizes the importance of maintaining effective vulnerability disclosure programs and responding promptly when security researchers uncover security flaws. 

Security experts point out that the incident highlights one of the most common vulnerabilities in application security. There is no doubt that broken access control is one of the most critical risks in OWASP's Top 10. Issues with IDOR vulnerabilities persist across organizations of all sizes when developers implement authentication procedures without properly enforcing authorization procedures. 

Organizations collecting personal information, including commercial businesses, nonprofit organizations, and religious institutions, should implement robust security controls and maintain effective vulnerability disclosure processes as a result of this incident. Keeping user information secure is an integral part of every organization that has been given personal information.

Click to Pray illustrates that no organization is exempt from cybersecurity risks. Using strong access controls, secure API practices, and responding to vulnerabilities promptly remain essential for protecting user data and maintaining public trust in digital platforms.

Phishing and Compromised Identities Replace Software Exploits as Leading Ransomware Entry Ooint, Sophos Reports





Phishing campaigns, malicious emails and compromised credentials have overtaken software vulnerability exploitation as the leading entry points for ransomware attacks, according to Sophos' State of Ransomware 2026 report, signalling that threat actors are placing greater focus on stealing identities than breaking into unpatched systems.

The report is based on responses from 2,158 IT and cybersecurity leaders across 17 countries whose organisations experienced ransomware attacks during the previous year. While ransomware groups continue to encrypt data in a large share of incidents, the findings point to a clear change in how attackers gain their initial foothold inside enterprise networks.

Malicious email accounted for 26% of ransomware attacks, making it the most common root cause identified by respondents. Phishing followed closely at 24%, while compromised credentials were responsible for another 23% of incidents. In comparison, exploited vulnerabilities accounted for 18% of attacks, a sharp decline from 32% reported in the previous edition of the survey.

Taken together, email-based attacks and stolen credentials were responsible for nearly three-quarters of reported ransomware intrusions, showing that attackers are increasingly relying on social engineering and identity compromise instead of searching for vulnerable internet-facing systems.

Sophos also found that 67% of organisations described the ransomware incident as the most serious identity-related attack they encountered during the past 12 months. Across the surveyed organisations, almost four out of five ransomware attacks originated through compromised identities, placing user accounts and authentication systems at the centre of modern ransomware operations.

The findings also challenge a common assumption about multifactor authentication. Sophos reported that MFA had already been deployed in 97% of attacks where compromised credentials were identified as the root cause, yet attackers still succeeded in gaining access.

According to the company, the figures do not mean MFA has become ineffective. Instead, they point to weaknesses in deployment and the growing sophistication of credential theft techniques. Some organisations may have protected only part of their infrastructure, leaving legacy systems, remote access services or administrative interfaces outside MFA coverage. Those gaps can provide attackers with alternative routes into corporate environments.

Attackers have also refined methods for bypassing authentication protections. Adversary-in-the-middle phishing kits can intercept authentication sessions, while stolen browser cookies and authenticated session tokens allow attackers to access accounts without repeatedly triggering MFA challenges. MFA fatigue attacks, where users are bombarded with repeated authentication requests until one is approved, continue to be used against organisations relying on push-based authentication.

Among organisations using MFA, one-time passwords, push notification applications and passkeys were the most widely deployed authentication methods. FIDO2 security keys ranked behind those options despite offering one of the strongest defences against phishing because authentication is tied to legitimate websites and cannot be replayed through fake login pages.

Although software vulnerabilities no longer ranked as the leading ransomware entry point, Sophos cautioned that organisations should not reduce their focus on patch management. Instead, the report recommends pairing vulnerability remediation with stronger identity security controls to reduce opportunities for attackers to obtain valid credentials.

To reduce the risk of email-driven intrusions, Sophos recommends deploying advanced email filtering alongside domain authentication technologies including DMARC, DKIM and SPF. These controls help organisations verify legitimate senders, detect spoofed domains and prevent fraudulent emails from reaching employees. The company also recommends regular phishing awareness training to help users identify increasingly convincing social engineering campaigns.

Beyond email security, Sophos advises organisations to strengthen identity protection through Identity Threat Detection and Response (ITDR), enforce MFA across every access point and routinely review both human and machine identities to remove unnecessary privileges, dormant accounts and outdated credentials that could be abused during an attack.

Chet Wisniewski, director and global field chief information security officer at Sophos, said organisations with stronger ransomware resilience typically rely on multiple defensive layers rather than a single security control. Network segmentation can slow lateral movement after an initial breach, Zero Trust Network Access (ZTNA) reduces dependence on traditional VPNs, and continuous threat detection gives security teams more opportunities to identify malicious activity before ransomware spreads across the network.

The report also found that ransomware operators successfully encrypted data in 56% of reported attacks. Although median ransom demands and payments have fallen compared with previous years, the findings show that attackers continue to achieve their primary objective once they obtain access. For defenders, protecting identities has become just as important as patching software, with user accounts, credentials and authentication systems now representing the most frequently targeted path into enterprise environments. 

Steam Forum Scam Uses ClickFix Technique to Infect Gamers With XMRig Cryptominer

 



Cybercriminals are targeting Steam users through fraudulent troubleshooting posts that exploit the increasingly common ClickFix social engineering technique, tricking gamers into manually executing malicious PowerShell commands that ultimately install cryptocurrency mining malware on Windows systems.

Rather than relying on software vulnerabilities, the campaign abuses trust within Steam's community discussion forums. Attackers reportedly create newly registered accounts and respond to users seeking help with problems such as game crashes, missing inventory items, or other technical issues. Their replies appear to offer legitimate troubleshooting steps, encouraging victims to launch Windows PowerShell with administrator privileges and paste a command that supposedly resolves the issue.

Instead of fixing the reported problem, the command downloads and installs XMRig, an open-source cryptocurrency mining application that has frequently been repurposed by cybercriminals to mine Monero using victims' computing resources without their knowledge or consent.

The campaign reflects the continued rise of ClickFix attacks, a social engineering method that persuades users to execute malicious commands themselves. These attacks typically imitate security checks, CAPTCHA verifications, software updates, or troubleshooting instructions that appear credible because they are presented as solutions to an existing problem. Since the victim willingly launches the command, the activity may evade security controls designed to block automatically executed malware.

The PowerShell script distributed in this campaign disguises itself as a Windows optimisation utility named "msf utility \ PC Opt." Once started, it displays what appear to be routine maintenance operations, including cleaning temporary files, flushing the DNS cache, updating drivers, checking disk health, disabling unnecessary startup applications, scanning for malware, repairing the Windows image, and running the System File Checker.

However, these operations largely serve as a visual distraction. Instead of performing meaningful system maintenance, the script displays convincing progress messages and introduces short delays to create the impression that legitimate optimisation tasks are taking place while malicious actions occur in the background.

The script's primary malicious routine first disables Transport Layer Security (TLS) certificate validation before confirming that it has been launched with administrator privileges. If elevated permissions are unavailable, execution stops after displaying an error requesting administrative access.

Once running with the required privileges, the malware establishes persistence by creating a directory within the Windows installation path and modifying Microsoft Defender settings to exclude that location from antivirus scanning. Excluding a directory from security scans reduces the likelihood that the installed malware will be detected or quarantined.

The script also checks for traces of previous installations by attempting to stop an existing scheduled task associated with the miner, terminating related processes, and removing older configuration files. While the exact purpose of this cleanup remains uncertain, it may help replace an earlier installation or remove conflicting miner components before deploying a fresh payload.

To retrieve the malware, the script temporarily creates an outbound Windows Firewall rule permitting network communication with an attacker-controlled server over TCP port 443. After downloading the payload, it verifies that the retrieved file is both non-empty and a valid executable before moving it into its final installation directory.

To maintain long-term access, the malware creates a scheduled Windows task configured to launch the XMRig executable automatically whenever the operating system starts. The task executes with SYSTEM privileges, giving the miner elevated permissions while allowing it to continue operating after reboots.

XMRig itself is a legitimate open-source cryptocurrency miner designed for authorised mining operations. However, threat actors frequently misuse the software in cryptojacking campaigns because it efficiently mines the privacy-focused cryptocurrency Monero, allowing attackers to generate revenue by exploiting compromised computers' CPU resources. Victims often experience unusually high processor usage, increased power consumption, system slowdowns, excessive fan activity, and reduced hardware lifespan.

This indicates a new wave in cybercriminal tactics. Rather than exploiting software flaws, attackers increasingly rely on convincing users to compromise their own systems through social engineering. ClickFix campaigns have been observed across multiple platforms in recent months, targeting individuals through fake browser alerts, fraudulent technical support pages, counterfeit software updates, and deceptive verification prompts.

Users should exercise caution when following technical advice posted by unknown forum members, particularly when instructions require launching PowerShell, Command Prompt, or other administrative tools. Legitimate game support rarely requires manually executing complex commands obtained from public discussion forums.

Systems that may have been exposed should be examined for unexpected scheduled tasks related to XMRig, suspicious Microsoft Defender exclusions, and unfamiliar files or folders created within protected Windows directories. A full antivirus scan should be performed immediately, and any malicious scheduled tasks, Defender exclusions, or installed payloads should be removed. Where compromise cannot be confidently ruled out, performing a complete operating system reinstallation may provide the most reliable method of restoring system integrity, as additional malicious activity may have occurred after the initial infection.

US Sanctions on VPN Service Briefly Disrupt Telegram’s t.me Link Shortener Due to Compliance Action

 

iTelegram's t.me link-shortening domain briefly went offline earlier this week after a compliance action linked to US sanctions inadvertently affected the entire domain instead of a specific Telegram link.

Users began reporting on Monday that t.me short links were inaccessible after the domain was placed under a "serverHold" status, effectively making it unavailable across the internet. The registry status suggested that the action had been initiated by the domain's registry operator, causing widespread disruption to Telegram's link-sharing functionality.

Following the outage, Telegram CEO Pavel Durov reached out to DomainME, the registry responsible for managing the .me top-level domain, requesting an investigation into the issue.

On Tuesday, DomainME clarified the reason behind the disruption, stating, "t.me was on hold due to the OFAC compliance, but it is back online now."

The reference to OFAC points to the US Treasury Department's Office of Foreign Assets Control, which oversees and enforces US economic and trade sanctions. The same day the domain became unavailable, OFAC announced sanctions against First VPN Service, alleging that the platform had been used by multiple ransomware groups to conceal malicious activities targeting US businesses, hospitals, and government organizations.

As part of the sanctions, OFAC designated the VPN service's alleged administrator, Ukrainian national Dmytro Rashevskyi, along with associated infrastructure, including the domains 1vpns.com and 1vpns.net, as well as cryptocurrency wallet addresses. The sanctions are intended to prevent US individuals and businesses from engaging with the VPN provider.

According to reports, the sanctions documentation specifically referenced the Telegram support link t.me/FirstVPNService. This appears to have led to an unintended compliance action in which the entire t.me domain was placed on hold instead of only the sanctioned Telegram link.

In a subsequent statement, DomainME said, "the .ME Registry works closely with law enforcement to monitor and mitigate issues across the .ME domain in accordance with applicable laws, including sanctions requirements." The company suggested that the suspension was part of its sanctions compliance process rather than a simple technical error.

The t.me domain has since been restored and now redirects users to Telegram's primary website.

Meanwhile, the FBI has warned that First VPN Service, operational since 2014, has been widely used by cybercriminals. Investigators say at least 25 ransomware groups have relied on the VPN platform. While the service promoted itself as a privacy-focused VPN, authorities allege it has also been connected to botnet operations, distributed denial-of-service (DDoS) attacks, online scams, and hacking campaigns.

The FBI further stated, “First VPN Service was almost exclusively advertised in known criminal dark web forums such as Exploit[.]in and XSS[.]is, two of the most prominent Russian-language online forums which provide marketplaces for cyber criminals to buy and sell unauthorized access to computer systems, stolen personal identifying information, hacking tools, and contraband,” the agency added.

US Indicts Three Russian Nationals Over Bulletproof Hosting Network Linked to Global Cybercrime

 

The EU sanctioned nine Russian citizens and four entities for engaging in cyber-espionage campaigns and attacks against the EU, member states, Ukraine, and other countries. The sanctions were imposed by the Council of the European Union and coordinated with the UK as the first joint action under the cyber sanctions of the EU and the UK. 

According to the EU, the sanctioned entities and individuals are integral parts of Russia’s cyber ecosystem that have supported ransomware perpetrators, phishing campaigns, DDoS services, and attacks on enterprises and government infrastructure. Among the sanctioned entities are Media Land LLC, its owner Alexander Volosovik, and affiliated company ML.Cloud that have allegedly facilitated ransomware and phishing campaigns that have resulted in billions of dollars in damages to enterprises around Europe. 

The pro-Russian hacker group Z-Pentest was also sanctioned for targeting critical infrastructure such as Denmark’s water supply in the December 2024 attack. Along with Z-Pentest’s leader Yuliya Pankratova and the group’s chief hacker Denis Degtyarenko, the EU sanctioned the pro-Russian hacker collective Cyber Army of Russia Reborn (CARR). Cyber Army of Russia Reborn is accused of launching DDoS attacks on government resources worldwide in support of Russia’s war effort against Ukraine since 2022. 

The sanctioned individuals include Evgeniy Bashev, the owner of Impuls LLC, a Russian cyber security firm, and Maksim Voronin, Maksim Gordienko, and Vitaly Kovalov, four Russian hackers. They have been accused of facilitating the development and proliferation of hacking software, including the LummaC2 botnet, Trickbot, and Conti ransomware, which have been used in numerous cybercrime activities in Europe. 

Additionally, the EU sanctioned Ivan Kasyanenko, the deputy commander of Russia’s Main Intelligence Directorate 29155 for allegedly facilitating military and paramilitary activities in Europe and Afghanistan. He has been identified as the person responsible for coordinating cyber operations in Russia against the EU and Ukraine and supporting Wagner Group mercenaries in Africa. Kasyanenko is also accused of being involved in the poisoning of Sergei and Yulia Skripal in the UK in 2018.  

The EU is currently finalizing its 21st sanctions package against Russia, which will involve further economic and trade restrictions. According to the spokesperson, the coordination of cyber sanctions measures by the EU and UK sends a strong signal to Russia that the EU is willing to take more steps to weaken its cyber capacities and disrupt its espionage and disinformation activities in the EU, UK, and critical infrastructure in Europe.