Showing posts with label cyber security. Show all posts
Showing posts with label cyber security. Show all posts

Sophos Unveils Exploit Path Verification to Prioritize Real‑World Vulnerabilities with OpenAI Cyber Models

Sophos, a global cybersecurity leader, today announced Exploit Path Verification (EPV), a new capability that will be built into Sophos Managed Risk to help security teams better prioritize and manage exploitable vulnerabilities in their environment. The capability will be built with OpenAI's GPT cyber models through the Daybreak Defense Network, to return verified, evidence-backed verdicts that give defenders the clarity they need to fix the exposures that matter first. Availability will be announced at a later date.

Security teams face a widening gap between the vulnerabilities they can find and the ones they can fix. Scanners surface thousands of exposures and severity scores and rank them, but a severity score cannot tell whether a critical flaw sits behind a control that blocks it, or whether two low-severity findings chain into the path that leads to a breach. As a result, security teams often patch by generic score, rather than by whether an attacker could reach and use a flaw in their specific environment.

Sophos is designing EPV to close that gap. It is being built to reason over asset and patch state, endpoint protection policy, network reachability, identity and privilege facts, and known exploit availability, and returns a clear evidence-backed exploitability verdict:
  • Confirmed Exploitable
  • Blocked by a Control
  • Not Reachable
  • Insufficient Evidence
EPV will also be designed to identify chained paths where multiple lower-severity findings combine into one exploitable route, assess whether a control blocks a technique class or only a common public proof of concept, and draft remediation text ready for a ticket.

The capability will be advisory and additive by design. Every verdict is labeled as AI-generated with its evidence visible, and Sophos analysts review the results.

One of the most common challenges we hear from security teams today is the volume of findings they need to sift through, and the lack of clarity of which findings matter most, or in other words, put them at greatest risk,” said John Peterson, chief technology officer, Sophos. “Exploit Path Verification is being built to make it clear what in their environment is reachable by an attacker, with the evidence to prove it, so they fix what counts first.”

EPV extends Sophos' work with OpenAI. Through the OpenAI Daybreak Defense Network (formerly OpenAI Daybreak Cyber Partner Program), which Sophos joined in June 2026, the company brought frontier cyber models into MDR investigation, advisory assessments, and workflows that help customers discover, validate, and remediate exposure. EPV will build on that work inside a product customers already run. OpenAI's GPT cyber models provide frontier reasoning to help assess exploitability. Sophos supplies the environment-specific evidence and product controls, and its analysts review the results delivered to customers.

Our goal through the OpenAI Daybreak Defense Network is to give defenders the advantage of frontier AI, safely,” said McCall McIntyre, Head of Global Cyber Partnerships, OpenAI. Sophos has been a thoughtful partner since joining the program, and Exploit Path Verification is a clear example of frontier reasoning applied to a real defensive problem, with the guardrails that responsible deployment demands.”

Sophos defends more than 625,000 organizations worldwide, including 40,000 managed detection and response (MDR) customers across enterprise, mid-market, and commercial segments, delivered through one of the industry's largest partner ecosystems. That reach is central to EPV's purpose. Verified exploitability should not be a capability reserved for the largest security teams with the deepest budgets.

EPV is in development for enterprise and mid-market business customers of Sophos Managed Risk. Sophos will announce availability, including early access and general availability timing, at a later date.

For more on Sophos Managed Risk, please visit sophos.com/services/managed-risk.

Education Sector Hit Hard: 85% of Ransomware Driven by Identity Attacks, Sophos Report Warns

Education Sector Hit Hard: 85% of Ransomware Driven by Identity Attacks, Sophos Report Warns

Malicious email is the leading attack method, and recovery costs now average $2.26 million

Sophos, a global cybersecurity leader, today released its annual State of Ransomware in Education 2026 report, which found that identity-based attack techniques were used in 85% of ransomware attacks against education institutions. Those techniques include malicious email, phishing, compromised credentials and brute force attacks. The 85% rate exceeded the cross-sector average of 79%, underscoring the role identity compromise continues to play in ransomware incidents targeting lower and higher education institutions.

Malicious email was the leading technical root cause of ransomware attacks in both lower education (31%) and higher education (29%). The report also found that 77% of higher education organizations and 71% of lower education organizations said their ransomware incident was also their most significant identity attack.

Education institutions also recover more slowly from attacks. Lower and higher education institutions are roughly twice as likely as the cross-sector average to need one to three months to fully recover. Lower education fared worst of all: 31% took a month or more to get back on their feet, the highest share of any sector.

"Education institutions remain attractive targets because they hold vast amounts of personal data while operating under significant resource constraints," said Ross McKerchar, chief information security officer, Sophos. "Today's attackers don't need a crowbar when they can steal the keys. Identity compromise has become one of the most effective paths into an organization, and AI is only increasing the speed, scale and sophistication of these attacks. The most resilient institutions are the ones that treat identity as a core security control and combine it with integrated detection and response capabilities that can stop threats before they become full-scale incidents.”

Additional findings from the report include:

  • Operational challenges: More than half (53%) of higher education institutions said they lacked the skills or expertise to detect and stop attacks in time compared with 35% across all sectors, while lower education institutions most commonly cited human error (52%), lack of protection (47%), unknown security gaps (42%) and limited capacity (41%).
  • Data encryption rates: The percentage of lower education organizations whose data was encrypted during a ransomware attack more than doubled year over year, rising from 29% in 2025 to 61% in 2026. Across the education sector, 58% of ransomware attacks resulted in encrypted data.
  • Data restoration: Over three quarters (77%) of lower education institutions and 69% of higher education institutions restored encrypted data using backups, both above the 66% cross-sector average.
  • Ransom demands: The median ransom demand for education institutions was $775,200, above the cross-sector median of $698,000. Education median ransom demands have gone down two years in a row, while payments increased by $15,000 from the 2025 report to 2026.
  • Recovery costs: Average ransomware recovery costs reached $2.26 million across the education sector, exceeding the cross-sector average of $1.7 million. More than a quarter (26%) of education institutions required one to three months to fully recover from an attack, nearly double the cross-sector average (14%).
  • Human toll: Over half (53%) of higher education teams reported increased pressure from senior leaders, versus 40% across all sectors. Around 39% of education organizations reported staff absences due to stress or mental health issues following a ransomware attack, compared to 29% across all sectors. Education also reported elevated leadership turnover, with 29% of higher education and 27% of lower education teams seeing their leadership replaced after the attack, compared with a cross-sector average of 21%.
The findings are based on an independent survey of 226 IT and cybersecurity leaders in the education sector across 17 countries whose organizations were impacted by ransomware in the past year. Research was conducted between January and March 2026. For the purposes of this report, age cohorts are defined as lower education (typically students up to age 18) and higher education (typically students over 18). This is the sixth year Sophos has tracked this data.

To download the full State of Ransomware in Education 2026 report, visit https://www.sophos.com/en-us/resources/white-papers/state-of-ransomware-in-education

About Sophos

Sophos, a global cybersecurity leader, defends more than 625,000 organizations worldwide with Sophos Fusion, the industry's first and most complete AI-native cybersecurity defense system: a single, connected architecture where every control point operates as one. Powered by agentic AI and elite human expertise, Sophos detects, investigates, and neutralizes threats before they become business-disrupting events. Working alongside a global ecosystem of managed service providers, resellers, and technology partners, Sophos compounds intelligence from every threat encountered and every environment defended to make every customer's defense stronger than the last. Sophos is headquartered in Oxford, U.K. More information is available at www.sophos.com.

Wipro and Rubrik Launch Enterprise Resilience as a Service to Deliver Continuous Cyber Resilience

Wipro and Rubrik Launch Enterprise Resilience as a Service to Deliver Continuous Cyber Resilience

Wipro Limited (NYSE: WIT, BSE: 507685, NSE: WIPRO), a leading AI-powered technology services and consulting company, and Rubrik, the Security and AI Operations company, today announced the launch of Enterprise Resilience as a Service (ERaaS). The consulting-led, outcome-driven ERaaS is designed to help enterprises prevent, withstand, and rapidly recover from cyber and operational disruptions.

As enterprises accelerate AI adoption and operate in increasingly complex digital environments, ensuring continuous resilience against cyber and operational disruptions has become a critical business priority. ERaaS enables organizations to move beyond the traditional backup and disaster recovery model by operating as a continuously managed, enterprise-wide capability across technology, operations, and business processes.

ERaaS will enable continuous assessment of resilience posture, support recovery decisions, and automate recovery workflows. The new service will transform resilience from a periodic, incident-triggered function to a predictive, self-optimizing capability that evolves continuously. The AI capabilities will be operationalized through Wipro’s AI-powered delivery platform WINGS, part of Wipro Intelligence™, the suite of AI-powered platforms, solutions, and transformative offerings.

Where most resilience engagements start with technology, Wipro's starts with the business use cases, and that distinction is what makes ERaaS stand out,” said Satish Yadavalli, Global Business Head – Cloud, Infrastructure, and Security Services, Wipro Limited. “Together with Rubrik's Zero Trust recovery capabilities, ERaaS will identify critical systems, map impact tolerances, and quickly establish recovery priorities. Leveraging our consulting capabilities, we will work closely with clients to translate these insights into resilience-by-design architectures, governance frameworks, and recovery playbooks."

Together with Wipro, we are helping customers operationalize cyber recovery as a core part of a broader enterprise resilience strategy,” said Alok Agrawal, Chief Solutions Officer, Rubrik.Moments of disruption are inevitable, which is why this joint offering is critical for safe, confident, agile recovery.”

ERaaS is built on Rubrik’s unified cyber and data resilience platform, offering capabilities such as immutable protection, rollback of AI-driven changes, rapid identification of clean recovery points and threat-aware recovery. The platform also supports the protection of critical identity systems, enabling organisations to recover data, infrastructure and identities with greater confidence while minimising downtime and business risk.

To find out more about Wipro and Rubrik ERaaS, visit here.

About Wipro Limited

Wipro Limited (NYSE: WIT, BSE: 507685, NSE: WIPRO) is a leading AI-powered technology services and consulting company focused on building innovative solutions that address clients’ most complex digital transformation needs. Leveraging our consulting-led approach and the Wipro Intelligence™ unified suite of AI-powered platforms, solutions and transformative offerings, we help clients realize their boldest ambitions to build intelligent and sustainable businesses. The Wipro Innovation Network–part of the Wipro Intelligence™ suite–underpins our commitment to client-centric co-innovation and co-creation by bringing together capabilities from the innovation labs and partner labs, academia, and global tech communities. With over 240,000 employees and business partners across 65 countries, we deliver on the promise of helping our customers, colleagues, and communities thrive in an ever-changing world. For additional information, visit us at www.wipro.com.

About Rubrik

Rubrik (NYSE: RBRK), the Security and AI Operations Company, leads at the intersection of data protection, cyber resilience, and enterprise AI acceleration. Rubrik Security Cloud delivers complete cyber resilience by securing, monitoring, and recovering data, identities, and workloads across clouds. Rubrik Agent Cloud accelerates trusted AI agent deployments at scale by monitoring and auditing agentic actions, enforcing real-time guardrails, fine-tuning for accuracy and undoing agentic mistakes. For more information, please visit www.rubrik.com and follow @rubrikInc on X (formerly Twitter) and Rubrik on LinkedIn.

IBM & Red Hat Invest $5B to Secure Open Source Software in AI Era

IBM & Red Hat Invest $5B to Secure Open Source Software in AI Era

IBM and Red Hat’s Project Lightwell is being positioned as a landmark effort to secure open-source software in the age of AI-driven cyber threats. Rather than treating vulnerabilities as isolated incidents, Lightwell embeds remediation directly into enterprise workflows, ensuring that fixes are not only discovered but also deployed seamlessly across production environments.

At its core, Lightwell operates as an enterprise clearinghouse. This means it coordinates vulnerability disclosures, validates patches, and manages lifecycle fixes across the open-source ecosystem. Enterprises can integrate Lightwell into their existing build tools—such as Maven, Nexus, or Artifactory—by redirecting them to Red Hat’s secure registry. With a single configuration change, organizations gain access to a catalog of more than 6,500 digitally signed, remediated dependencies. These are backported to the exact versions running in production, eliminating the need for disruptive upgrades that often stall patch adoption.

The initiative is powered by a combination of frontier AI models and 20,000 engineers. AI accelerates vulnerability discovery and triage, while human experts validate and remediate issues with enterprise-grade rigor. This dual approach is critical because AI alone can generate false positives or incomplete fixes, but when paired with human oversight, it becomes a force multiplier for security.

Lightwell is structured around two major offerings. The Lightwell Network, already live, provides enterprises with immediate access to remediated dependencies. The Clearinghouse Premier, currently in limited rollout, acts as a trusted intermediary for patch embargoes and vertical threat coordination. Financial services firms are the first adopters, with expansion planned into healthcare, government, and telecom.

The program’s importance lies in its response to AI-accelerated threats. Advanced models can discover thousands of vulnerabilities in minutes, compressing the time between discovery and exploit. For industries like finance and healthcare, where downtime or breaches can have systemic consequences, Lightwell offers a way to maintain operational continuity while staying ahead of attackers.

Partnerships are central to its rollout. Major banks including Goldman Sachs, JPMorgan Chase, Visa, Citi, and Wells Fargo are early adopters. Deloitte has joined as a collaborator, providing orchestration services, compliance reporting, and Forward Deployed Engineers to ensure validated fixes are deployed at machine speed. This adds a layer of trust and auditability that regulators demand in highly scrutinized sectors.

In essence, Lightwell is not just a patching service—it is a new industry model for securing open source software. By embedding AI-driven remediation into enterprise workflows and coordinating disclosures through a trusted clearinghouse, IBM and Red Hat are attempting to redefine how global industries defend against systemic cyber risks.

IBM, Red Hat, and Palo Alto Networks Expand Project Lightwell to Help Organizations Respond to Software Vulnerabilities

  • Collaboration combines vulnerability discovery, virtual patching and software remediation to help organizations reduce the time between vulnerability discovery and protection.
Palo Alto Networks (NASDAQ: PANW), IBM (NYSE: IBM) and Red Hat today announced a collaboration to help organizations identify vulnerabilities early and deploy protections fast across open source software, commercial applications, operational technology (OT) and healthcare technologies. By integrating Palo Alto Networks Virtual Patching capability with Project Lightwell from IBM and Red Hat, the collaboration combines rapid network-level protection with software remediation to help organizations reduce exposure to emerging threats.

AI has supercharged vulnerability discovery, enabling flaws to be identified at unprecedented speed and scale. AI-driven threats can uncover security gaps across codebases far faster than defenders can patch them, exposing organizations to systemic supply-chain risks.

Nikesh Arora, CEO and Chairman of Palo Alto Networks
AI has compressed the window between vulnerability discovery and exploit from weeks to minutes. Traditional patching cannot keep pace. By collaborating with IBM and Red Hat, we are shifting the advantage back to defenders. This powerful combination allows us to neutralize threats in the network while providing uninterrupted business continuity for our global clients.

Arvind Krishna, Chairman and CEO of IBM
IBM established Project Lightwell to secure the open-source software foundation that enterprises rely on every day. By collaborating with Palo Alto Networks, we are extending that security from the source code directly to the network front lines. This joint solution gives our clients exactly what they need to thrive in the AI era: immediate, automated resilience against emerging threats, combined with the rigorous validation required to safely update their core systems.

A Seamless "Shield-and-Fix" Workflow

The collaboration connects IBM and Red Hat’s $5 billion commitment to open-source security via Project Lightwell with Palo Alto Networks’ security platform. This creates a dual-action defense: Palo Alto Networks rapidly deploys a virtual patch at the network layer to block exploit attempts, while IBM and Red Hat’s Project Lightwell offer remediation software for open-source software that customers can test and deploy in their environment.

The collaboration combines vulnerability intelligence, software remediation and network-based protection to help organizations respond quickly to newly discovered vulnerabilities. Key capabilities include:
  • Broader Vulnerability Coverage: Protection across open-source software, commercial applications, operational technology (OT) environments and connected devices.
  • Preemptive Coverage: Organizations can receive virtual patch protection before official software patches become available, helping reduce exposure while remediation is underway.
  • Rapid Protection: When a new vulnerability is discovered, network-level protections can be deployed the same day, with a long-term goal of reducing the time from validated discovery to protection.
The companies also plan to establish secure processes for sharing vulnerability information across participating software vendors, technology providers and security teams. This collaboration is expected to support coordinated vulnerability disclosure, accelerate protection development and provide anonymized telemetry on real-world exploitation attempts.

Expert Deployment via IBM Consulting

To help organizations respond more effectively to newly discovered vulnerabilities, IBM Security Services can also provide advisory and deployment services that help customers identify which vulnerabilities pose the greatest risk to their business and determine the best path to remediation. Working alongside Palo Alto Networks' virtual patching capabilities and Project Lightwell's software remediation capabilities, IBM Security Services can help customers prioritize, deploy and validate protections and fixes across complex environments.

About Palo Alto Networks

Palo Alto Networks (NASDAQ: PANW), the global AI cybersecurity leader, protects our digital way of life with a comprehensive portfolio of cybersecurity solutions and platforms across Network, Cloud, Security Operations, AI and Identity. Trusted by 70,000+ customers and powered by Unit 42 threat intelligence, our AI-driven platforms eliminate complexity, empowering enterprises to modernize with confidence and securing the speed of innovation. Explore the future of security at www.paloaltonetworks.com.

Palo Alto Networks, Prisma, Prisma AIRS, Idira and the Palo Alto Networks logo are trademarks of Palo Alto Networks, Inc. in the United States and in jurisdictions throughout the world. All other trademarks, trade names, or service marks used or mentioned herein belong to their respective owners. Any unreleased services or features (and any services or features not generally available to customers) referenced in this or other press releases or public statements are not currently available (or are not yet generally available to customers) and may not be delivered when expected or at all. Customers who purchase Palo Alto Networks applications should make their purchase decisions based on services and features currently generally available.

About IBM

IBM is a leading provider of global hybrid cloud and AI, and consulting expertise. We help clients in more than 175 countries capitalize on insights from their data, streamline business processes, reduce costs and gain the competitive edge in their industries. Thousands of governments and corporate entities in critical infrastructure areas such as financial services, telecommunications and healthcare rely on IBM's hybrid cloud platform and Red Hat OpenShift to affect their digital transformations quickly, efficiently and securely. IBM's breakthrough innovations in AI, quantum computing, industry-specific cloud solutions and consulting deliver open and flexible options to our clients. All of this is backed by IBM's long-standing commitment to trust, transparency, responsibility, inclusivity and service.

Visit www.ibm.com for more information.

About Red Hat

Red Hat is the open hybrid cloud technology leader, delivering a trusted, consistent, and comprehensive foundation for transformative IT innovation and AI applications. Its portfolio of cloud, developer, AI, Linux, automation and application platform technologies enables any application, anywhere—from the datacenter to the edge. As the world's leading provider of enterprise open-source software solutions, Red Hat invests in open ecosystems and communities to solve tomorrow's IT challenges. Collaborating with partners and customers, Red Hat helps them build, connect, automate, secure, and manage their IT environments, supported by consulting services and award-winning training and certification offerings.

Wipro Expands Palo Alto Networks Partnership With Cortex XSIAM and CybershieldSM to Deliver AI‑powered Cyber Defense

Wipro Expands Palo Alto Networks Partnership With Cortex XSIAM and CybershieldSM to Deliver AI‑powered Cyber Defense

Wipro Limited (NYSE: WIT, BSE: 507685, NSE: WIPRO), a leading AI-powered technology services and consulting company, announced the expansion of its partnership with Palo Alto Networks, the global AI cybersecurity leader, to offer AI-driven Managed Detection and Response (MDR) services.

The partnership brings together Palo Alto Networks’ Cortex XSIAM with CyberShieldSM, Wipro’s managed security services capabilities in a more focused offering for modern security operations. The new offering will deliver proactive cyber defense with simplified workflows using machine learning, AI, and automation to predict and protect against future attacks. It will enable faster detection and response across complex environments, while filtering signals from noise, improving analyst efficiency, and increasing focus on critical, high-impact threats.

This offering is supported by Wipro’s WEGA and WINGS, AI delivery platforms that are a part of Wipro Intelligence™, suite of AI-powered platforms, solutions, and transformative offerings for workflow orchestration, service transition, and automation at scale across security operations.

“As organizations navigate a rapidly evolving landscape marked by accelerated AI adoption, the need for robust governance and strategic cost management has never been greater,” said Satish Yadavalli, Global Business Head - Cloud, Infrastructure, and Security Services, Wipro Limited. “Together with Palo Alto Networks, we are able to transform security operations through AI, automation, and platform consolidation, strengthening organizations’ security environments while optimizing costs and improving outputs.”

The expanded relationship builds on an existing foundation with Palo Alto Networks across cloud, network and security transformation, and reflects growing demand from clients for more integrated, AI-led security operations.

“AI-manufactured attacks require an AI-powered defense, and our partnership with Wipro helps deliver just that,” said Simone Gammeri, Senior Vice President and Chief Partnership Officer at Palo Alto Networks. “Our combined capabilities empower mutual customers to consolidate tools, eliminate data silos, and leverage AI and automation to reduce noise, accelerate response from days to minutes, and ultimately stop even the most sophisticated threats.”

The MDR services are delivered through Wipro’s eight Cyber Defense Centers (CDCs), anchored by the proprietary SOC GURU (Grand Unified Runbook Unleashed) framework—a unique IP that drives SOC transformation through attack- and alert-agnostic analysis. This unified, adaptive approach is designed to strengthen threat detection and response while supporting more resilient security operations.

This approach is already reflected in a recent engagement with a European gaming and entertainment leader, where Wipro and Palo Alto Networks helped transform security operations in a complex enterprise environment to deliver improved productivity, accelerated response, and reduced costs.





About Wipro Limited

Wipro Limited (NYSE: WIT, BSE: 507685, NSE: WIPRO) is a leading AI-powered technology services and consulting company focused on building innovative solutions that address clients’ most complex digital transformation needs. Leveraging our consulting-led approach and the Wipro Intelligence™ unified suite of AI-powered platforms, solutions and transformative offerings, we help clients realize their boldest ambitions to build intelligent and sustainable businesses. The Wipro Innovation Network–part of the Wipro Intelligence™ suite–underpins our commitment to client-centric co-innovation and co-creation by bringing together capabilities from the innovation labs and partner labs, academia, and global tech communities. With over 240,000 employees and business partners across 65 countries, we deliver on the promise of helping our customers, colleagues, and communities thrive in an ever-changing world. For additional information, visit us at www.wipro.com.

NetApp and Cisco Collaboration Strengthens Defense-in-Depth for Enterprise Cyber Resilience

NetApp and Cisco Collaboration Strengthens Defense-in-Depth for Enterprise Cyber Resilience
  • New NetApp Splunk SOAR playbook helps contain ransomware attacks and limit data loss
NetApp® (NASDAQ: NTAP), the Intelligent Data Infrastructure company, and Cisco, (NASDAQ: CSCO) today announced an expansion of their collaboration to help customers strengthen defense-in-depth strategies for customers. Combining Intelligent Data Infrastructure with advanced analytics and observability capabilities, NetApp and Splunk have delivered deep, real-time visibility into storage and infrastructure health. Together, they are helping customers turn operational data into actionable insights that improve reliability, security, and business outcomes. By expanding their collaboration with the new NetApp Splunk Security Orchestration, Automation, and Response (SOAR) playbook, NetApp and Splunk are helping joint customers contain ransomware attacks and limit data loss at the storage layer, enhancing the containment of the blast radius of cyberattacks while increasing the speed and reducing the cost of recovery.

“With AI accelerating both the speed and sophistication of cyberattacks, the window to respond has never been smaller,” said Sandeep Singh, Senior Vice President and General Manager, Platform at NetApp. “To limit the cost and impact of ransomware, organizations must act the moment a threat is detected, which means extending security automation into the storage layer where data lives. As the company delivering the most secure storage on the planet, NetApp is uniquely positioned to make storage an active part of a defense-in-depth strategy. By working with Cisco to enable Splunk SOAR workflows to take direct action on data stored in NetApp ONTAP®, we’re helping make a defense-in-depth security strategy simpler and more effective.”

To give customers the resiliency and flexibility they need to protect their data, Cisco and NetApp are releasing the NetApp Splunk SOAR playbook. Splunk Enterprise Security is already integrated with NetApp Ransomware Resilience to collect analytics from the data layer, enhancing incident triage and prioritization. With the new playbook, Splunk SOAR users can now use those signals as well as signals from other solutions to automatically take incident response actions directly on NetApp ONTAP storage as an integral part of their incident response. These actions include blocking a suspicious user, taking snapshots of the data and taking data volumes offline to protect against further infection. As a result, customers will be better able to contain ransomware attacks and limit data loss at the storage layer. Utilized as part of the organization’s defense in depth security strategy, the NetApp Splunk SOAR playbooks help to strengthen collaboration between security and storage teams.

Automating the response and recovery actions against cyber threats with the NetApp Splunk SOAR playbook improves security team metrics like mean time to contain (MTTC) and reduces the manual effort and skills required to protect data. As a result, NetApp and Cisco are making it faster and more efficient for enterprises to achieve cyber resilience.

Effective security strategies require visibility and action across the entire technology stack, including the data layer,” said David Dalling, GVP, Splunk Security at Cisco. “With the new NetApp Splunk SOAR playbook, ONTAP storage becomes an active participant in the security ecosystem, enabling organizations to contain threats directly targeting enterprise data. By connecting NetApp storage into Splunk SOAR workflows, we’re helping security and storage teams collaborate more seamlessly and respond to incidents with greater speed and confidence.”

The partnership between Splunk and NetApp helps customers run their businesses more securely and effectively, connecting operations across storage and security teams,” said Dallas Olson, Chief Commercial Officer at NetApp.By giving customers real-time visibility into what’s happening across their environments, NetApp and Splunk enable enterprises to reduce disruption and optimize performance so they can use their data to drive measurable business outcomes.”

The NetApp Splunk SOAR playbook is now available to download from SplunkBase.

Additional Resources Cyber Resilience: The Most Secure Storage on the Planet
Ransomware Resilience: Ransomware Protection Using AI-Based Detection

About NetApp

For more than three decades, NetApp has helped the world’s leading organizations navigate change – from the rise of enterprise storage to the intelligent era defined by data and AI. Today, NetApp is the Intelligent Data Infrastructure company, helping customers turn data into a catalyst for innovation, resilience, and growth.

At the heart of that infrastructure is the NetApp data platform – the unified, enterprise-grade, intelligent foundation that connects, protects, and activates data across every cloud, workload, and environment. Built on the proven power of NetApp ONTAP, our leading data management software and OS, and enhanced by automation through the AI Data Engine and AFX, it delivers observability, resilience, and intelligence at scale

Disaggregated by design, the NetApp data platform separates storage, services, and control so enterprises can modernize faster, scale efficiently, and innovate without lock-in. As the only enterprise storage platform natively embedded in the world’s largest clouds, it gives organizations the freedom to run any workload anywhere with consistent performance, governance, and protection.

With NetApp, data is always ready – ready to defend against threats, ready to power AI, and ready to drive the next breakthrough. That’s why the world’s most forward-thinking enterprises trust NetApp to turn intelligence into advantage.

About Cisco

Cisco (NASDAQ: CSCO) is the worldwide technology leader that is revolutionizing the way organizations connect and protect in the AI era. For more than 40 years, Cisco has securely connected the world. With its industry leading AI-powered solutions and services, Cisco enables its customers, partners and communities to unlock innovation, enhance productivity and strengthen digital resilience. With purpose at its core, Cisco remains committed to creating a more connected and inclusive future for all. Discover more on The Newsroom and follow us on X at @Cisco.

Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. A listing of Cisco’s trademarks can be found at http://www.cisco.com/go/trademarks. Third-party trademarks mentioned are the property of their respective owners. The use of the word ‘partner’ does not imply a partnership relationship between Cisco and any other company.

Massive Browser-Based RTO Scam Targets Indian Vehicle Owners; Over 36 Fake e-Challan Domains Discovered

Massive Browser-Based RTO Scam Targets Indian Vehicle Owners; Over 36 Fake e-Challan Domains Discovered

  • Sophisticated Phishing Campaign Uses Localized Infrastructure Including Reliance Jio Numbers and State Bank Account Links; Shared Infrastructure Also Targets BFSI and Logistics Sectors
Cyble Research and Intelligence Labs (CRIL) has uncovered a large-scale browser-based phishing campaign targeting Indian vehicle owners through fake e-Challan portals. The sophisticated operation, which represents an evolution from previous malware-driven attacks, leverages over 36 fraudulent domains and exploits trust in Regional Transport Office (RTO) services to harvest banking credentials.

The investigation, which aligns with recent warnings from mainstream media including Hindustan Times, reveals an active and ongoing campaign using localized infrastructure to enhance credibility and maximize victim impact.

"This campaign demonstrates a pivot from the previously observed Android malware use to browser-based fraud, which significantly lowers the technical barriers and expands the pool of potential victims," said Daksh Nakra, Senior Manager of Research and Intelligence at Cyble. "The use of Indian mobile numbers registered with popular telecom operators and linked to State Bank of India accounts shows how attackers deliberately exploit trust in familiar institutions to increase success rates."

Campaign Overview and Attack Flow

Multi-Stage Phishing Operation

  • Victims receive SMS messages claiming overdue traffic fines.
  • Urgency created through threats of license suspension, court summons, and legal proceedings.
  • Messages contain shortened URLs mimicking legitimate e-Challan domains.
  • Victims are led to cloned government portals.

Key Technical Findings:

Dynamic Challan Fabrication

  • Portal generates realistic-looking violation records regardless of input.
  • Displays modest fine amounts (typically INR 590) with near-term expiration dates.
  • No backend verification occurs—purely psychological manipulation.
  • Replicates official MoRTH branding and NIC insignia.

Card Data Harvesting

  • Payment pages restrict options to credit/debit cards only.
  • Avoids traceable UPI and net banking transactions.
  • Collects full card details including CVV and expiry dates.
  • Claims processing through Indian banks.
  • Accepts repeated submissions, transmitting all data to attacker backend.

Localized Infrastructure for Enhanced Credibility

  • SMS sent from Indian mobile number registered with Reliance Jio Infocomm Limited.
  • Phone number linked to State Bank of India account.
  • Combination of local telecom carrier and public-sector bank association increases perceived legitimacy.

Shared Fraud Infrastructure Uncovered

  • Over 36 phishing domains impersonating e-Challan services.
  • Additional targets: HSBC-themed payment lures (BFSI sector).
  • Logistics company impersonation: DTDC, Delhivery.
  • Consistent UI patterns and payment-harvesting logic across campaigns.

Secondary Infrastructure

  • Multiple domains mimicking Parivahan services.
  • Automatically generated phishing domains suggesting rotation techniques.
  • Designed to evade takedowns and blocklists.
  • Same operational flow as primary campaign.

Anti-Detection Measures:

  • Content originally authored in Spanish, translated via browser prompts.
  • Indicates reuse of phishing templates across regions.
  • Browser-based warnings (Microsoft Defender) ignored due to urgency cues.
  • Domain generation techniques for infrastructure resilience.

Multi-Sector Risk:

  • Government service users (e-Challan, Parivahan).
  • Banking customers (HSBC-themed lures).
  • E-commerce users (DTDC, Delhivery impersonation).

Critical Recommendations

  • Never click links in unsolicited SMS claiming traffic violations.
  • Always verify fines directly through official government portals (parivahan.gov.in).
  • Scrutinize domains carefully—look for spelling variations and unusual TLDs.
  • Be suspicious of payment pages accepting only credit/debit cards.
  • Report suspicious messages to cybercrime authorities immediately.
Complete technical analysis, indicators of compromise (IoCs), MITRE ATT&CK mappings, and detection guidance are available in the full blog post here.

IoCs have been published to Cyble's GitHub repository for immediate integration into security platforms and threat intelligence feeds.

About Cyble

Cyble is a global AI-powered threat intelligence company providing organizations with real-time visibility into cyber threats through advanced research, dark web monitoring, attack surface management, and comprehensive security solutions. Cyble's platform delivers actionable intelligence enabling security teams to detect, respond to, and prevent cyberattacks before they cause significant damage.

For more information, visit www.cyble.com.

120,000 Home Cameras Breached: Privacy at Risk in the Digital Age

120,000 Home Cameras Breached: Privacy at Risk in the Digital Age

South Korean police revealed that over 120,000 internet-connected home cameras were hacked, with footage exploited to create and sell sexually explicit videos. Four suspects have been arrested in connection with the scheme.

National Police Agency (NPA) of South Korea has issued an official statement confirming the arrests of four suspects who hacked approximately 120,000 home and business IP cameras to produce and sell sexually exploitative material.

About 120,000 IP cameras (often called “home cams”) installed in private homes, karaoke rooms, Pilates studios, and clinics were compromised.

Four individuals were arrested. Importantly, police clarified that they acted independently and were not accomplices. The suspects created and sold hundreds of sexual abuse videos on overseas websites. Police noted they are working with overseas agencies to track website operators and buyers involved in distributing the material.

The NPA highlighted that weak passwords and poor security settings on IP cameras were the main vulnerabilities exploited. The case is being treated under South Korea’s strict digital sex crime laws, which have been strengthened in recent years after similar scandals. Authorities urged citizens to immediately change default passwords and update firmware to prevent further breaches.  

Key details of the case

  • Scale of the breach: More than 120,000 surveillance cameras in homes and businesses across South Korea were compromised.
  • Targets: Cameras were placed in private homes, karaoke rooms, Pilates studios, and clinics, making the intrusion deeply invasive.
  • Suspects: Police charged four individuals. One suspect alone hacked 63,000 cameras and produced 545 exploitative videos, earning about 35 million won (~₹21 lakh) from sales.
  • Method: Hackers exploited weak security in IP cameras, such as default or easy-to-guess passwords.
  • Content: The stolen footage was turned into sexually exploitative material and distributed online.

Broader implications

  • Privacy crisis: This case highlights how vulnerable consumer-grade surveillance devices can be when users fail to change default settings or manufacturers neglect strong security protocols.
  • Legal crackdown: South Korea has strict laws against digital sex crimes, and this incident is expected to intensify calls for tougher regulation of surveillance technology.
  • Global warning: Similar risks exist worldwide. Any internet-connected device with a camera or microphone can be hijacked if not properly secured.

How to protect yourself

  • Change default passwords immediately on all smart devices.
  • Enable two-factor authentication where possible.
  • Update firmware regularly to patch vulnerabilities.
  • Avoid cheap, unverified brands that may lack proper security safeguards.
  • Use encrypted networks and avoid exposing devices directly to the internet.


This incident is a stark reminder that digital safety is inseparable from physical privacy. The exploitation of everyday devices for sexual crimes shows how technology can be weaponized when security is neglected.

India Makes Cyber Safety App Mandatory on All Smartphones

India Makes Cyber Safety App Mandatory on All Smartphones

India’s government has ordered smartphone makers to preload its state-owned cyber safety app, Sanchar Saathi, on all new devices within 90 days, and users will not be able to delete it.


What’s Happening

  • The Telecom Ministry issued an order on November 28, 2025 requiring smartphone makers (Apple, Samsung, Vivo, Oppo, Xiaomi, etc.) to pre-install the Sanchar Saathi app on all new phones.
  • Users cannot disable or delete the app, making it a permanent fixture on devices.
  • For phones already in the supply chain, manufacturers must push the app via software updates.

 Purpose of the App

  • Sanchar Saathi, launched in January 2025, is designed to combat cyber fraud and phone theft.
  • Government data shows it has already helped recover more than 700,000 lost phones, including 50,000 in October alone.
  • It also addresses telecom cyber security risks, such as duplicate or spoofed IMEI numbers.

Why It’s Controversial

  • Privacy concerns: Since the app cannot be deleted, critics argue this undermines user choice and raises surveillance fears.
  • Apple’s resistance: Apple has previously clashed with Indian regulators over mandatory government apps (like the anti-spam app). This new directive is expected to spark another tussle.
  • Global implications: India is the world’s second-largest smartphone market with over 1.2 billion subscribers, so this mandate affects nearly every major phone manufacturer.

 Broader Context

  • India’s move reflects a global trend of governments tightening control over digital infrastructure to combat fraud and enhance cyber safety.
  • However, balancing security with privacy remains a major challenge. Similar debates have occurred in the EU and US around mandatory apps or backdoors in devices.

Key Takeaways

  • Deadline: Smartphone makers have 90 days to comply.
  • Non-removable: The app will be permanent on devices.
  • Impact: Likely to trigger pushback from Apple and privacy advocates, but welcomed by those concerned about rising cyber fraud.
Sanchar Saathi works by giving users direct tools to report fraud and recover stolen phones, while the legal mandate forces smartphone makers to preload it permanently, raising privacy and compliance challenges.

🔧 How Sanchar Saathi Works Under the Hood

  • Fraud Detection Features
    • The app lets users report suspicious calls and SMS directly from their call/SMS logs in just a few taps.
    • It integrates with the Department of Telecommunications (DoT) database to flag numbers linked to scams, spoofing, or misuse of telecom resources.
    • Supports English, Hindi, and 21 regional languages, ensuring accessibility across India’s diverse user base.
  • Phone Recovery Process
    • Users can register their device’s IMEI number on the Sanchar Saathi portal.
    • If a phone is lost or stolen, the app helps block the IMEI, making the device unusable on Indian networks.
    • Once recovered, the IMEI can be unblocked, restoring normal use.
    • Government data shows the app has already helped recover over 700,000 lost phones, including 50,000 in October 2025 alone.
  • Citizen Empowerment
    • The app is designed as a Jan Bhagidari (citizen participation) tool, encouraging users to actively report fraud and contribute to telecom security.
    • It acts as a bridge between users and telecom authorities, reducing delays in fraud reporting and recovery.

⚖️ Legal & Regulatory Implications for Smartphone Makers

  • Mandatory Preloading
    • The Telecom Ministry’s order (Nov 28, 2025) requires all smartphone makers (Apple, Samsung, Vivo, Oppo, Xiaomi, etc.) to pre-install Sanchar Saathi within 90 days.
    • For devices already in the supply chain, manufacturers must push the app via software updates.
  • Non-Removable Requirement
    • The app cannot be deleted or disabled, which raises privacy and user choice concerns.
    • This is expected to trigger pushback from Apple, which has previously resisted similar government mandates (like India’s anti-spam app).
  • Compliance Burden
    • Smartphone makers must adapt their software build processes to include the app permanently.
    • This could complicate global compliance strategies, as India’s rules diverge from norms in other major markets.
  • Market Impact
    • India is the world’s second-largest smartphone market with 1.2 billion subscribers, so compliance is unavoidable for global brands.
    • The move reflects India’s broader push to tighten control over digital infrastructure, balancing cyber safety with potential surveillance risks.

🚨 Key Takeaway

  • Sanchar Saathi empowers users to fight fraud and recover stolen phones, but the mandatory, non-removable installation raises significant privacy, compliance, and global trade concerns.
  • For smartphone makers, this is not just a technical requirement—it’s a regulatory test case that could reshape how governments worldwide enforce digital safety mandates.

Comparative mandates for government or safety apps across regions
Region Mandate type Removability Scope of requirement Notable tensions
India Preload state-owned cyber safety app (Sanchar Saathi) on all new smartphones within 90 days Non-removable for users Applies to all major OEMs; updates pushed to existing devices in supply chain Likely clash with Apple; strong privacy pushback; framed as anti-fraud and IMEI control
EU No EU-wide mandate to preload a government app; relies on telecom/data protection rules N/A Security standards via GDPR/ePrivacy; device-level mandates uncommon Tension around privacy-by-design and app store gatekeeping, but no forced preload norm
US No federal mandate to preload a government safety app on consumer devices N/A Sectoral laws; carriers/apps handle spam and fraud; device backdoors opposed Long-standing resistance to mandated backdoors or compulsory apps on privacy grounds
China Government-linked safety/control apps may be required in specific contexts (work, education, local policies) Often non-optional within those contexts Strong platform compliance with state directives; app store governance aligned Lower friction due to centralized policy; broader content and data control expectations
Global OEMs Compliance with local requirements per market build Varies by market Separate ROMs/policies per region; risk of fragmentation Balancing privacy, brand policies (e.g., Apple), and regulatory divergence

India’s directive in context

  • India’s telecom ministry ordered smartphone makers to preload the state-owned Sanchar Saathi app on all new devices within 90 days.
  • The app must be non-deletable and delivered via updates for devices already in the supply chain.
  • Government figures cite more than 700,000 devices recovered and 50,000 in October alone.
  • Major OEMs including Apple, Samsung, Vivo, Oppo, and Xiaomi are covered, with expected friction from Apple.

Key differences with the EU and US

  • EU and US rely on regulatory frameworks (GDPR/ePrivacy in the EU; sectoral laws in the US) rather than mandating a government app.
  • Both regions emphasize privacy safeguards and oppose device-level backdoors.
  • No precedent for non-removable state apps on consumer phones, unlike India’s compulsory preload.

China’s model and compliance dynamics

  • China features stronger alignment between platforms and state directives.
  • Government-linked apps are commonly required across specific sectors or contexts.
  • Tighter app store governance makes compliance smoother compared to India’s contested rollout.

Practical OEM implications

  • Build variants: Maintain India-specific ROMs or configuration profiles to include a non-removable system app.
  • Policy alignment: Anticipate Apple’s scrutiny on non-removable government apps; plan for negotiations or OS-level allowances.
  • User trust: Transparent disclosures and on-device privacy notices can reduce backlash while meeting the mandate.
  • Support ops: Train support channels for IMEI blocking/unblocking workflows and fraud reporting flows tied to Sanchar Saathi.

Hexaware Acquires CyberSolve to Strengthen Global Identity Security and AI-Driven Cyber Resilience

Hexaware Technologies [NSE: HEXT], a global provider of IT solutions and services, today announced it has acquired CyberSolve, a global specialist in identity and access management (IAM) solutions. Together, the companies will help enterprises modernize identity foundations, automate controls with artificial intelligence (AI), and run secure operations across complex, hybrid technology estates.

Across boardrooms, chief information officers cite cybersecurity as a top priority, as trusted digital identity—and the governance, risk, and compliance frameworks around it—now underpin every transformation, from cloud adoption and application modernization to data protection and workforce productivity.

CyberSolve brings nearly a decade of focused work in large identity programs, with 230+ specialists, 20+ IAM tech alliances, and 650+ implementations across sectors including retail, healthcare, pharma, automotive, financial services, logistics, government, and technology. Its teams are known for fast, reliable app onboarding, smooth platform migrations, and audit-ready operations. Hexaware adds consulting depth, engineering excellence, and 24x7 cybersecurity and resilience operations, spanning GRC, cloud security, and DevSecOps—helping clients move from isolated fixes to an integrated identity capability that reduces risk and accelerates growth at global scale.

Cybersecurity has moved from an IT concern to a business imperative, and chief information officers tell us that getting identity right is at the top of the agenda,” said Siddharth Dhar, President & Global Head – Digital IT Operations & AI, Hexaware. “By bringing CyberSolve into Hexaware, we combine their craftsmanship in identity programs with our platform-led delivery and global operations. Clients will see faster value, stronger controls, and a clearer path to secure digital growth.”

Our mission has always been to inspire trust in every digital interaction,” said Mohit Vaish, CEO, CyberSolve. “Joining Hexaware allows us to scale that mission—expanding our reach, applying AI more deeply, and creating measurable security outcomes for enterprises worldwide.”

Atul Agrawal, Managing Partner, CyberSolve, said, “We’re truly delighted to join Hexaware. The combined strengths of our IAM expertise and Hexaware’s AI-first operations create tremendous potential to redefine how global enterprises approach digital identity and security.”

Shubham Khandelia, Managing Partner, CyberSolve, added, “This is an exciting milestone for our people and clients alike. Together, we can deliver broader capabilities, faster innovation, and stronger assurance, building on our shared commitment to trust and excellence.

Client organizations also welcomed the announcement. Chris Lugo, VP – CISO, Blue Cross Blue Shield Association, said, “CyberSolve has consistently helped bring clarity and momentum to complex initiatives. With Hexaware, they’ll have the scale and structure to deliver even greater impact. I’m excited to see what the two teams achieve together.

The combined team will focus on what leaders need most today, delivering accurate and effective identity security, dependable operations, and easier adoption of change across large enterprises, resulting in faster onboarding, smoother migrations, continuous compliance, and secure work from anywhere.

UP Police Embraces AI and Cyber Training in Yogi Adityanath’s Hybrid Model for 60,244 Recruits

UP Police Embraces AI and Cyber Training in Yogi Adityanath’s Hybrid Model for 60,244 Recruits

In a landmark move to modernize law enforcement, Uttar Pradesh Chief Minister Yogi Adityanath has unveiled a tech-forward hybrid training model for 60,244 newly appointed police personnel. The initiative marks one of India’s largest digital transformations in police training, integrating artificial intelligence, cybercrime modules, and simulation-based learning into the traditional curriculum.

Tech Highlights of the Hybrid Training Model

  • AI-Powered Simulations: Recruits will engage with artificial intelligence-driven scenarios that mimic real-world policing challenges—ranging from crowd control to cyber fraud detection. These simulations aim to sharpen decision-making and situational awareness.
  • Cybercrime and Digital Forensics: The curriculum includes hands-on training in cybercrime investigation, digital evidence handling, and online threat mitigation. Officers will learn to trace IP addresses, decrypt digital trails, and respond to phishing and ransomware cases.
  • Smart Classrooms and E-Learning: Training centers are being equipped with smart boards, biometric attendance systems, and cloud-based learning platforms. Recruits can access legal modules, case studies, and forensic tutorials remotely.
  • Drone and Surveillance Tech: Select units will receive exposure to drone operations, facial recognition systems, and real-time surveillance tools—preparing them for tech-assisted field operations.
  • Data Ethics and Privacy: Officers will be sensitized to digital rights, data protection laws, and ethical boundaries in tech-enabled policing.

Strategic Vision

The hybrid model reflects CM Yogi Adityanath’s broader vision to align UP Police with global standards in digital law enforcement. By embedding technology into foundational training, the state aims to build a force that is not only physically agile but digitally literate and ethically grounded.

Accenture Announces Its Largest Ever Cybersecurity Acquisition of CyberCX

Accenture Announces Its Largest Ever Cybersecurity Acquisition of CyberCX

Global consulting giant Accenture has announced its largest-ever cybersecurity acquisition, acquiring Australian firm CyberCX in a landmark deal reportedly valued at $650 million. The move significantly expands Accenture’s cyber defense capabilities across the Asia-Pacific region and beyond.

CyberCX is one of the largest and most prominent cybersecurity firms in the Asia Pacific region. The company’s end-to-end services extend across consulting, transformation and managed security services and include advanced capabilities in offensive security and cyber physical security, crisis management, threat intelligence, managed detection and response, as well as strategic advisory, identity, cloud and network security.

Accenture’s acquisition of Australian cybersecurity firm CyberCX for a reported $650 million marks its largest-ever cybersecurity deal to date.

Why CyberCX?

  • CyberCX employs approximately 1,400 cybersecurity professionals.
  • Operates across Australia, New Zealand, London, and New York.
  • Specializes in sovereign cloud security, threat intelligence, and crisis response.
  • Offers advanced AI-powered cybersecurity platforms.
CyberCX was founded in October 2019 by John Paitaridis, who serves as CEO, and Alastair MacGibbon, the company’s Chief Strategy Officer. Paitaridis brought extensive experience from his leadership roles at Optus and Telstra, while MacGibbon contributed deep expertise from his tenure as Australia’s national cybersecurity advisor. Their vision was to create a sovereign cybersecurity powerhouse rooted in Australian and New Zealand capabilities.

CyberCX was financially backed by BGH Capital, a private equity firm that facilitated the rapid consolidation of 17 cybersecurity businesses to form CyberCX. This strategic roll-up enabled CyberCX to quickly establish itself as a dominant force in the region’s cybersecurity landscape.

    Strategic APAC Expansion

    Australia has faced a wave of high-profile cyberattacks in recent years, including breaches at Optus, Medibank, and Qantas. CyberCX’s strong local presence and government partnerships make it a strategic asset for Accenture’s push into the region. The acquisition positions Accenture as a dominant force in securing digital ecosystems across APAC.

    Accenture’s Cybersecurity Growth Trajectory

    Since 2015, Accenture has completed 20 security acquisitions, including most recently acquiring Morphus, MNEMO Mexico and Innotec Security.

    YearCompanyCountry
    2023MorphusBrazil
    2022MNEMOMexico
    2021Innotec SecuritySpain
    2025CyberCXAustralia

    What This Means for the Industry

    The acquisition signals a broader trend of consolidation in the cybersecurity sector, as global firms race to bolster defenses against increasingly sophisticated threats. For Accenture, it’s a bold step toward becoming the go-to provider for end-to-end cyber resilience, especially in geopolitically sensitive regions.

    Think Before You Click: SEBI’s #SEBIvsSCAM Campaign Targets Fake Apps, Deepfakes, and Dubious Tips

    Think Before You Click: SEBI’s #SEBIvsSCAM Campaign Targets Fake Apps, Deepfakes, and Dubious Tips

    Securities and Exchange Board of India (SEBI) has launched a nationwide investor awareness campaign titled #SEBIvsSCAM, aimed at educating investors about various types of financial scams and how to safeguard themselves. This initiative is part of SEBI’s ongoing commitment to protect the retail investors from such scams in the securities market. Under SEBI’s guidance and regulatory oversight, the National Stock Exchange of India Ltd. (NSE) has rolled out a comprehensive investor protection drive to support this campaign.

    The campaign comes at a critical time when digital financial frauds are on the rise, with fraudsters using increasingly sophisticated and deceptive methods to target investors. From fake trading apps and deepfake videos to unregistered investment advisors and misleading stock tips on social media, scammers are exploiting technology and denting investor’s trust. Many individuals fall prey to schemes promising guaranteed returns/unusually high returns, pump-and-dump tactics, dabba trading, fraudulent foreign portfolio investment offers, etc—often resulting in significant financial losses.

    #SEBIvsSCAM seeks to raise public awareness, promote safe investing habits and empower investors to make informed decisions. By spotlighting common scams and offering guidance, the campaign aims to help investors recognize warning signs, verify sources and report suspicious activities—ultimately contributing to a more secure and transparent financial ecosystem.

    To ensure maximum outreach, NSE, under the aegis of SEBI will leverage a mix of media platforms including television, radio, print, digital and social media. We will also spread the Investor Awareness messages through Investor Awareness Programs which are done through physical, digital and hybrid modes. This multi-channel approach is designed to reach investors across urban and rural areas, in multiple languages and through formats that are accessible and engaging to diverse audiences.

    Investor Advisory: Stay Alert, Stay Protected


    Issued in public interest by the National Stock Exchange of India Ltd under the aegis of Securities and Exchange Board of India.

    Deeptech QNu Labs Launches QNu Academy to Power India’s Quantum-Ready Workforce

    Deeptech QNu Labs Launches QNu Academy to Power India’s Quantum-Ready Workforce
    • This launch marks a strategic milestone in India's journey toward achieving quantum self-reliance & digital sovereignty
    • The academy is designed to serve a wide range of learners, including universities, faculties & students to build a skilled workforce capable of securing India’s digital future

    QNu Labs, India’s first and world’s no.1 integrated end-to-end quantum secured cybersecurity platform today announced the launch of QNu Academy, a global educational initiative aimed at building a future-ready talent pipeline in quantum technologies and cyber-security. As India advances its digital infrastructure and aligns with the National Quantum Mission, QNu Academy, backed by National Quantum Mission aims to bridge the existing talent gap. This launch marks a strategic milestone in India's journey toward achieving quantum self-reliance and digital sovereignty.

    QNu Academy offers in-depth education and practical training in advanced technologies such as Quantum Key Distribution (QKD), Quantum Random Number Generation (QRNG), and Post-Quantum Cryptography (PQC). The curriculum blends self-paced learning and instructor-led modules, curated in collaboration with experts from premier Indian institutions like the IITs and DRDO, as well as global quantum research bodies. Learners benefit from real-world use cases, hands-on lab assignments, continuous assessments, and mentorship from industry practitioners.
    • The academy is designed to serve a wide range of learners, including universities, faculties, and students, to build a skilled workforce capable of securing India’s digital future. In addition, QNu Academy actively supports educational institutions through Faculty Development Programs and the creation of Centres of Excellence (CoE) Labs to promote quantum innovation and applied research. Placement support, certifications and career readiness initiatives are also integrated into the learning journey.

    Speaking on the launch, Sunil Gupta, Co-Founder & CEO of QNu Labs, said, “QNu Academy is more than an educational platform. It is a national mission to democratize access to quantum education and build widespread awareness around quantum communications. Our goal is to create a sustainable ecosystem for quantum learning in India through faculty development programs, industry-relevant programs, CoE labs, certified programs, real-time projects, and assignments with placement opportunities to develop quantum experts, empowering you to become a future leader. The future of cybersecurity in India depends on how well we prepare today’s learners to tackle tomorrow’s threats.

    Through QNu Academy, we hope to foster a culture of innovation, encourage indigenous R&D in quantum tech and empower India’s workforce to lead on the global stage,” he added.

    QNu Academy represents a timely and important investment in human capital. The program aligns well with India’s broader goals of technological development, digital resilience, and global leadership in quantum innovation. It is envisioned as a long-term commitment to enabling India’s readiness for quantum disruption and equipping the country with the skilled manpower needed to thrive in the post-quantum era.

    Quick Heal's Seqrite Labs Identifies 650+ Cyber Incidents Linked to Geopolitical Tensions Surrounding ‘Operation Sindoor’

    Quick Heal's Seqrite Identifies 650+ Cyber Incidents Linked to Geopolitical Tensions Surrounding ‘Operation Sindoor’

    Quick Heal Technologies Limited, a global cybersecurity solutions provider, through its Seqrite Labs, India’s largest malware analysis facility, has revealed some critical details about coordinated cyberattacks exploiting geopolitical tensions during ‘Operation Sindoor’, India’s military counterterrorism response to the April 22, 2025 Pahalgam terror attack. While the Indian Armed Forces conducted precision strikes on terrorist infrastructure in Pakistan-administered Kashmir from May 7-10, 2025, the threat intelligence team at Seqrite Labs, identified parallel cyber campaigns by Pakistan-aligned threat actors targeting defense, healthcare, telecom, and government sectors across India.

    The cyber offensive began on April 17, 2025, with spear-phishing emails distributing weaponized files such as Final_List_of_OGWs.xlam and Preventive_Measures_Sindoor.ppam. These attachments exploited public concern about national security by masquerading as official Indian government advisories. Forensic analysis confirmed the use of Ares RAT, an evolved variant of APT36’s Crimson RAT malware, which established covert communication channels with command-and-control (C2) servers at IP 167.86.97[.]58:17854. Attackers spoofed legitimate Indian domains like nationaldefensecollege[.]com and zohidsindia[.]com to bypass security protocols.

    Between May 7-10, Seqrite’s telemetry recorded 650+ cyber incidents, including DDoS attacks on telecom providers (Jio, BSNL), defacements of state education portals, and credential harvesting campaigns against healthcare institutions like AIIMS and Apollo Hospitals. Hacktivist collectives such as #OpIndia and #OperationrSindoor coordinated via Telegram, claiming responsibility for leaking sensitive data from defense contractors and municipal databases.

    The attackers’ infrastructure leveraged virtual private servers (VPS) in Russia, Germany, and Indonesia to mask origins. Malicious .ppam and .Ink files triggered PowerShell scripts that disabled security tools, exfiltrated military communication logs, and deployed ransomware on healthcare systems. Seqrite’s countermeasures included 26 custom detection signatures deployed across Seqrite XDR, integration of YARA rules into national threat intelligence platforms, real-time alerts for spoofed domains, and threat advisory dissemination to Indian entities.

    The targeted cyberattacks on Indian institutions in wake of rising geopolitical tensions between India and Pakistan paint a clear picture of how nation-state actors now collaborate with non-state hacktivists, merging technical intrusion with psychological operations. The evolution of APT36 and the simultaneous hacktivist attacks signal a deliberate convergence of cyber espionage and ideological warfare. Instead of isolated malware campaigns, we now face digitally coordinated war games run with a common objective: that of destabilizing, disinforming, and disrupting.

    In light of these alarming findings, Seqrite urges organizations to exercise utmost caution with respect to their digital security. It is advised to adopt a zero-trust approach, deploy advanced, multi-layer security systems, create regular backups, and conduct awareness drives to impart essential cybersecurity training which can help reduce human error. Seqrite’s cutting-edge suite of cybersecurity solutions, including EPS, ZTNA, EDR, and XDR, along with Seqrite Malware Analysis Platform and Seqrite Threat Intel Platform, can help organizations of all sizes strengthen their cybersecurity stanc

    Hackers vs. AI: 86% of Firms Hit by Cyber Threats—Who’s Winning?

    Hackers vs. AI: 86% of Firms Hit by Cyber Threats—Who’s Winning?

    Cisco's 2025 Cybersecurity Readiness Index reveals that only 4% of organizations worldwide have reached a "Mature" level of cybersecurity readiness. This is a slight improvement from last year's 3%, but it still highlights significant gaps in global preparedness.

    The Index evaluates companies' readiness across five pillars—Identity Intelligence, Network Resilience, Machine Trustworthiness, Cloud Reinforcement, and AI Fortification— and encompassing 31 solutions and capabilities. Based on a double-blind survey of 8,000 private sector security and business leaders in 30 global markets, respondents detailed their deployment stages for each solution. Companies were then categorized into four readiness stages: Beginner, Formative, Progressive, and Mature.

    2025 Cybersecurity Readiness Index

    Key Findings:

    The lack of cybersecurity readiness globally is alarming as 71% of respondents anticipate business disruptions from cyber incidents within the next 12 to 24 months.
    • AI-related security incidents affected 86% of organizations in the past year.
    • 49% of respondents believe their employees fully understand AI-related threats, while 48% think their teams grasp how malicious actors use AI for attacks.
    • Nearly half of organizations suffered cyberattacks, struggling with complex security frameworks.
    • 71% of respondents anticipate business disruptions due to cyber incidents within the next 12 to 24 months.
    • Only 45% of organizations allocate more than 10% of their IT budget to cybersecurity, down from 53% last year.
    2025 Cybersecurity Readiness Index

    2025 Cybersecurity Readiness Index



    The report evaluates cybersecurity readiness across five pillars: Identity Intelligence, Network Resilience, Machine Trustworthiness, Cloud Reinforcement, and AI Fortification. AI is both a security tool and a threat, with 89% of organizations using AI for threat detection, response, and recovery

    The report said that — to tackle today’s cybersecurity challenges, organizations must invest in AI-driven solutions, simplify security infrastructures, and enhance AI threat awareness. Prioritizing AI for threat detection, response, and recovery is essential, as is addressing talent shortages and managing risks from unmanaged devices and shadow AI.

    India-US Researchers Creates Quantum-Safe Video Encryption Framework to Tackle Deepfake-like Threats

    India-US Researchers Creates Quantum-Safe Video Encryption Framework to Tackle Deepfake-like Threats

    Researchers from India and the USA have created a quantum-safe video encryption framework to tackle modern cyber threats like deepfakes and data manipulation. This innovative framework combines quantum computing's inherent randomness with advanced SSL-encrypted HTTP transmission, providing unmatched security and efficiency.

    The research, led by experts from Florida International University and the National Forensic Sciences University, has been featured in IEEE Transactions on Consumer Electronics.

    This framework integrates quantum encryption with classical video transmission methods to enhance security against evolving cyber threats.

    This breakthrough is expected to significantly enhance video communication security, especially for sensitive communications in defense, government, and military operations.
    India-US Researchers Creates Quantum-Safe Video Encryption Framework to Tackle Deepfake-like Threats

    Dr. Naveen Kumar Chaudhary from the National Forensic Sciences University in India collaborated with Dr. S.S. Iyengar and Dr. Yashas Hariprasad from Florida International University has led to the development of this quantum-safe encryption framework.

    A promising step towards a more secure digital future, the framework is based on hybrid quantum video encryption, which uniquely combines the power of quantum encryption with classical video transmission techniques, ensuring robust protection against potential quantum computing threats.

    The Quantum Encryption utilizes the principles of quantum mechanics to create encryption keys that are virtually impossible to crack using classical computing methods.

    The framework incorporates advanced SSL-encrypted HTTP transmission to maintain high-quality video communication. It Merges the strengths of both quantum and classical encryption, offering a dual layer of security.

    It has varied cybersecurity applications with an aims to protect sensitive video communications, particularly in sectors like defense, government, and military.

    Designed to withstand the advancements in quantum computing, making it a long-term solution for secure video transmission, the framework is a significant leap forward in cybersecurity, addressing the growing concerns over deepfakes and data manipulation.

    It's a promising development that could reshape the landscape of secure digital communication. The research has been funded by U.S. Army DEVCOM Army Research Laboratory and U.S. National Science Foundation (NSF), an independent agency of the United States federal government. 

    Tackling Deepfakes

    The quantum-safe encryption framework tackles deepfake threats by leveraging the inherent randomness of quantum computing and advanced SSL-encrypted HTTP transmission. Here's how it works:

    1. Pseudorandom Keys: The framework uses quantum-generated pseudorandom keys to encrypt video streams. These keys are extremely difficult to predict or replicate, making it challenging for deepfake creators to manipulate the video content.

    2. Quantum-Safe Protocols: Individual frames of the video are secured using quantum-safe protocols, ensuring that each frame is protected against tampering.

    3. Enhanced Security: By combining quantum encryption with classical methods, the framework provides a dual layer of security, significantly outperforming current methods.

    4. Authenticity and Integrity: The encryption ensures the authenticity and integrity of video communications, making it difficult for malicious actors to create convincing deepfakes.

    This approach is particularly effective in sensitive sectors like defense, government, and military operations, where the authenticity of video communications is crucial.

    Market Reports

    Market Report & Surveys
    IndianWeb2.com © all rights reserved