Capillary Technologies’ recent deepfake-enabled cyber fraud incident highlights how rapidly evolving AI tools are transforming from business enablers into serious security threats for global enterprises. The Bengaluru-based SaaS company disclosed that an overseas step-down subsidiary lost around €3 million,…
Category: CySecurity News – Latest Information Security and Hacking Incidents
UK Court Sentences Two Hackers to 5.5 Years for Transport for London Cyberattack That Caused £29 Million in Damages
Two hackers have been sentenced to five and a half years in prison each for carrying out the 2024 cyberattack on Transport for London (TfL), in what the UK’s National Crime Agency (NCA) has described as the country’s largest…
TRAI Seeks IT Act Powers to Act Against Spam-Tagging Apps Like Truecaller
The Telecom Regulatory Authority of India (TRAI) seeks new powers in the Information Technology (IT) Act to take action against call management apps, including Truecaller, Hiya, and Whoscall, for marking or blocking legitimate commercial calls as spam. The regulator…
Coca-Cola says ransomware attack disrupts Fairlife operations, temporarily suspends U.S. dairy production
The Coca-Cola Company has revealed that a ransomware attack targeting its Fairlife dairy business has temporarily disrupted production across the United States after threat actors gained unauthorized access to company systems, including those supporting manufacturing operations. The incident was…
Dutch Authorities Arrest Multiple Suspects in Global Investment Fraud Investigation
Dutch authorities have arrested multiple suspects as part of an international investigation into an alleged investment fraud network that investigators believe defrauded victims worldwide through fake online investment schemes, with the operation at one point generating more than €100…
Govt: Kudankulam Data Breach Did Not Impact Nuclear Security, No Immediate Review Planned
The Centre has attempted to reassure the public that the data breach incident involving electronic files of the Kudankulam Nuclear Power Plant (KKNPP) has no implication on the nation’s nuclear security or reactor operations. Union Minister of State for…
Bengaluru Housewife’s WhatsApp Hacked; Morphed Obscene Videos Shared Online
A 42-year-old housewife in Bengaluru has fallen victim to a disturbing cybercrime after her WhatsApp account was hacked and morphed obscene videos were shared online, triggering widespread outrage and highlighting the growing threat of digital harassment against women. The…
Windows 11 KB5101650 and KB5099414 Updates Released With Security Fixes and New Features
A cumulative update for Windows 11 based on Patch Tuesday July 2026 is now available, with KB5101650 for versions 25H2 and 24H2 and KB5099414 for version 23H2. As well as addressing 571 security vulnerabilities, the mandatory updates also improve…
Pentagon Pauses CMMC Phase Two Rollout for 60-Day Review of Cybersecurity Program
The US Department of Defense (DoD) has decided to suspend the implementation of the cybersecurity maturity model certification (CMMC) second phase on a temporary basis. The DoD will conduct a 60-day review before continuing with the implementation of the…
Researchers Find Claude for Chrome Flaws That Could Let Malicious Extensions Trigger Sensitive Google Tasks
Researchers at Manifold Security have disclosed two security weaknesses in Anthropic’s Claude for Chrome extension that could allow another browser extension with access to the Claude website to trigger predefined AI-powered actions involving a user’s Gmail, Google Docs and Google…
RabbitMQ Flaw Exposes OAuth Secrets, Risks Full Broker Takeover
A serious vulnerability in RabbitMQ is threatening enterprise messaging systems by allowing attackers to steal OAuth secrets and take full control of brokers. Tracked as CVE-2026-57219, the flaw has a CVSS score of 8.7 and affects popular RabbitMQ versions…
Japan’s Largest Taxi Service Goes Offline After Cyberattack
Nihon Kotsu, Japan’s largest taxi operator, said that its systems were impacted in a cyberattack, causing the company to close down some of its infrastructure. The incident happened last week and impacted business operations such as the company’s taxi dispatch…
CrashStealer macOS Malware Uses Apple-Notarized App to Evade Security Checks
CrashStealer, a new macOS information-stealing malware named for Apple’s Mac operating system, bypasses built-in security protections by using an Apple notarized application, demonstrating a growing trend of malicious actors utilizing legitimate software verification mechanisms in order to target Apple users. …
How the Apple Copy-Paste Scam Can Give Attackers Remote Access to Your Mac
Apple users are being urged to exercise caution when following troubleshooting instructions found online after cybersecurity experts underlined a growing social engineering tactic that tricks victims into pasting malicious commands into the macOS Terminal application. Rather than exploiting a…
GoDaddy Challenges Indian Court Order Over Domain Privacy and Internet Governance Rules
A legal battle in India over online fraud could have major implications for privacy and regulation of the internet around the globe, as domain name registrar Go Daddy takes exception to a Delhi High Court ruling that would impose…
UK Warns Parents: Limit Online Sharing of Kids’ Photos Amid AI Abuse Risks
UK authorities have issued urgent warnings to parents about sharing children’s photos online, as AI tools increasingly enable digital abuse and exploitation. The National Crime Agency (NCA) and the Internet Watch Foundation (IWF) say that ordinary images of kids…
Anthropic Delays Claude Fable 5 Usage Credit Requirement Until July 19
A number of Anthropic’s flagship AI model, Claude Fable 5, has been extended to eligible paid subscribers until July 19, 2026 for free access. This extension provides customers with another week of access while the company continues to expand…
Microsoft and Google Remove ModHeader After Finding Dormant Collector
ModHeader is a famous header-editing extension with over 1.6 million installs across Microsoft’s Edge and Google’ Chrome browser. Google and Microsoft remove the collector Experts discovered a secret browsing-history collector built into its official store variant, and have withdrawn the…
Compromised Jscrambler npm Releases Target Developer Environments with Cross-Platform Rust Infostealer
Developers and organizations using the Jscrambler npm package are being urged to audit their systems after multiple malicious releases were uploaded to the npm registry through a compromised publishing credential. The incident transformed a trusted development dependency into a…
Counterfeit USB Drives Spread China-Linked Virus in Japan’s Military
Counterfeit USB flash drives supplied to Japan’s Ground Self-Defense Force (JGSDF) in March 2024 spread a China-linked computer virus across secure military networks for nearly a year before the breach was finally detected. The incident, first reported by Japan’s…
