Visualização normal

Antes de ontemCybersecurity News

The Cyber Express Weekly Roundup: AI Security Controls, Major Patch Releases, Public Sector Audits, and Emerging Online Scams

TCE The Cyber Express Weekly Roundup

This week's cybersecurity developments highlight a growing emphasis on proactive security measures, governance oversight, and risk management across both public and private sectors. From large-scale vulnerability remediation efforts and AI security enhancements to government-led technology reviews and event-driven cybercrime campaigns, organizations continue to face a complex threat landscape.  A common theme across this week's stories is the balance between innovation and security. As institutions adopt AI-powered systems, expand digital services, and move critical operations online, security teams are being challenged to strengthen protections without slowing modernization efforts. At the same time, threat actors continue to capitalize on public-interest events and trusted digital platforms to conduct fraud and data-theft campaigns. 

The Cyber Express Weekly Roundup 

CBSE Re-Evaluation Portal Receives Final Security Clearance 

The Central Board of Secondary Education (CBSE) has completed the final cybersecurity review of its examiner-facing re-evaluation platform, clearing the way for the reassessment of Class 12 answer scripts. Following an IIT-led audit and security testing process, examiners can now access the system to process applications submitted by more than 70,000 students. Read more... 

OpenAI Expands Lockdown Mode Across ChatGPT Accounts 

OpenAI has extended its Lockdown Mode security feature to all personal ChatGPT users, including Free, Go, Plus, Pro, and self-service Business accounts. The feature is designed to reduce the risk of prompt injection-related data exposure by limiting access to high-risk capabilities such as live web browsing, Deep Research, Agent Mode, and external file interactions. Read more... 

UK Courts Explore AI-Powered Legal Assistance 

The UK government has announced plans to test AI legal assistants within Crown Courts as part of broader judicial modernization efforts. The tools are expected to assist with legal research, case review, scheduling, and administrative processes while remaining under human supervision. Read more... 

Microsoft Issues Largest Patch Tuesday Update on Record 

Microsoft's June 2026 Patch Tuesday addressed a record-breaking 200 security vulnerabilities across its product ecosystem, including Windows, Office, Azure, and Exchange. The release included fixes for three publicly disclosed zero-day vulnerabilities and dozens of critical flaws. Read more... 

ServiceNow Clarifies Nature of Recent Security Incident 

ServiceNow has provided additional details regarding a recently disclosed security vulnerability, stating that observed activity originated from security researchers and customer investigations rather than malicious attackers. The company released a security update to address the issue and emphasized that there is no evidence of customer data misuse. Read more... 

World Cup-Themed Scams Target Fans Ahead of FIFA 2026 

Cybercriminals are already leveraging interest in the FIFA World Cup 2026 to launch phishing campaigns, fake ticket sales, and fraudulent recruitment schemes. Security researchers and law enforcement agencies have identified numerous lookalike domains impersonating official FIFA services in an effort to steal personal and financial information. Read more... 

Weekly Cybersecurity Takeaway 

This week's developments demonstrate that cybersecurity is becoming a foundational requirement for digital transformation rather than a separate consideration. Whether securing AI platforms, protecting educational systems, modernizing public services, or managing enterprise vulnerabilities, organizations are being forced to address security challenges alongside innovation initiatives.  Meanwhile, threat actors continue to exploit trust, familiarity, and public interest to achieve their objectives. From phishing campaigns targeting global sporting events to attacks focused on cloud services and enterprise platforms, the most effective defenses remain strong security governance, timely patching, user awareness, and continuous monitoring of emerging risks. 
  • ✇Firewall Daily – The Cyber Express
  • CBSE Engages IIT Experts After Admitting OSM Security Vulnerabilities Ashish Khaitan
    The Central Board of Secondary Education (CBSE) has intensified its response to concerns about an OSM vulnerability by engaging cybersecurity specialists from IIT Madras, IIT Kanpur, and several government agencies to conduct a detailed security assessment of its On-Screen Marking (OSM) platform. The portal, introduced in 2026 for the evaluation of the Class 12 board exam, has come under scrutiny following allegations from security researchers and ethical hackers about multiple weaknesses in
     

CBSE Engages IIT Experts After Admitting OSM Security Vulnerabilities

OSM vulnerability

The Central Board of Secondary Education (CBSE) has intensified its response to concerns about an OSM vulnerability by engaging cybersecurity specialists from IIT Madras, IIT Kanpur, and several government agencies to conduct a detailed security assessment of its On-Screen Marking (OSM) platform. The portal, introduced in 2026 for the evaluation of the Class 12 board exam, has come under scrutiny following allegations from security researchers and ethical hackers about multiple weaknesses in the system.  In an official statement shared on X on May 31, 2026, CBSE acknowledged the issue and confirmed that remedial measures were already underway. The board stated, “The identified vulnerabilities have been contained, and other exploitable weaknesses are being ruled out.”  The announcement is a notable development in the controversy surrounding the OSM platform. While CBSE had previously maintained that the system was secure, the latest statement confirms that vulnerabilities did exist and required immediate attention from cybersecurity experts. 

Decoding the OSM Vulnerability 

The controversy emerged after security researchers and ethical hackers highlighted several alleged flaws in the OSM platform used for the Class 12 board exam evaluation process. According to the concerns raised, the vulnerabilities could have exposed sensitive examination-related data and administrative controls.  Among the issues reported were: 
  • A hardcoded master password allegedly embedded within publicly accessible source code, potentially enabling unauthorized access. 
  • One-time passwords (OTPs) are reportedly visible through web browsers without requiring authentication. 
  • The ability to reset evaluator passwords without proper authorization. 
  • Potential access to or modification of student marks stored within the system. 
  • An Amazon Web Services (AWS) cloud storage bucket allegedly contains scanned 2026 examination records that could be accessed publicly without login credentials. 
Ethical hacker Nisarga Adhikary further alleged that scanned answer sheets and question papers stored within the AWS repository could be viewed and downloaded without authentication. These allegations intensified concerns regarding the scale and potential impact of the reported OSM vulnerability. 

CBSE Deploys Expert Teams for Security Audit 

As part of its response, CBSE has assembled a specialized team comprising experts from IIT Madras, IIT Kanpur, and the Digital Infrastructure Corporation of India. The objective is to perform a comprehensive audit of the platform and identify any remaining vulnerabilities.  According to the board, the security teams have been working on the matter for several days. CBSE stated that all known vulnerabilities have been contained and that the platform is currently being migrated to a more secure environment as part of a broader strengthening exercise.  The board has also initiated direct communication with some of the security researchers who reported the issues. 

CBSE’s Security Measures at a Glance 

As part of its response to the reported OSM vulnerability, CBSE has deployed a specialized team comprising experts from IIT Madras, IIT Kanpur, and the Digital Infrastructure Corporation of India. The board said these cybersecurity teams have been working on the matter for several days to assess the system and strengthen its security framework.  According to CBSE, the known vulnerabilities identified in the OSM portal have been contained. The board also stated that the platform is currently being migrated to a more secure environment as part of its broader effort to enhance protection against potential cyber threats.  CBSE has engaged directly with some of the security researchers and ethical hackers who brought the issues to light. The board has also invited additional inputs from researchers and cybersecurity professionals, requesting that any relevant information or findings be shared with its security team via email at secy-cbse@nic.in. 

Board Invites Further Input from Researchers 

CBSE publicly acknowledged the role played by ethical hackers and security researchers in identifying weaknesses within the platform.  In its statement, the board said:  “We are grateful to all alert citizens and ethical hackers pointing out such weaknesses and have gotten in touch with some of them directly.”  The board further added:  We request any others to reach out to our security teams at secy-cbse@nic.in for any further inputs.”  CBSE reiterated that the identified OSM vulnerability issues have been contained while a wider security review remains ongoing. 

Post-Result Services Begin Despite Security Concerns 

Despite the ongoing scrutiny surrounding the OSM platform, CBSE proceeded with the launch of its Class 12 post-result services on June 1, 2026, as previously scheduled.  Students who appeared for the Class 12 board exam can now access post-result services through the official portal and apply for: 
  • Scanned copies of answer books 
  • Verification of marks 
  • Re-evaluation requests 
CBSE stated that the portal underwent security hardening measures before becoming operational on June 1. The controversy has also expanded beyond cybersecurity concerns. Student Sarthak Sidhant had earlier raised questions regarding the procurement and tendering process associated with the OSM system, adding another layer to the ongoing debate. 
❌
❌