Visualização normal

Antes de ontemFirewall Daily – The Cyber Express
  • ✇Firewall Daily – The Cyber Express
  • AI Cyber Attacks Emerge as Biggest Threat to Indian Banking: RBI Samiksha Jain
    The Reserve Bank of India (RBI) has identified AI Cyber Attacks as the biggest near-term cybersecurity threat facing the Indian banking system, according to the June 2026 edition of its Financial Stability Report (FSR). The central bank's latest assessment highlights that while banks and financial institutions have strengthened cyber risk management practices, rapid advances in artificial intelligence are making cyber threats more difficult to counter. The findings are based on a survey condu
     

AI Cyber Attacks Emerge as Biggest Threat to Indian Banking: RBI

AI Cyber Attacks

The Reserve Bank of India (RBI) has identified AI Cyber Attacks as the biggest near-term cybersecurity threat facing the Indian banking system, according to the June 2026 edition of its Financial Stability Report (FSR). The central bank's latest assessment highlights that while banks and financial institutions have strengthened cyber risk management practices, rapid advances in artificial intelligence are making cyber threats more difficult to counter. The findings are based on a survey conducted by the RBI to assess the preparedness of major banks and non-banking financial companies (NBFCs) against evolving cyber risks. The survey found that institutions have established robust cybersecurity practices, particularly in vulnerability assessment and penetration testing of critical systems. However, AI Cyber Attacks emerged as the most significant challenge expected over the next 12 months.

AI Cyber Attacks Lead RBI's Cyber Risk Assessment

According to the RBI Financial Stability Report, AI-enabled cyber threats can increase the speed, scale and sophistication of attacks targeting financial infrastructure. Survey responses showed that most financial institutions are still in the developing or intermediate stages of integrating AI-specific threat preparedness into their existing cybersecurity frameworks, while only a smaller number reported mature capabilities. The report states that continued improvements in threat monitoring, detection, response mechanisms, employee awareness and cyber resilience will remain critical as AI-powered attacks continue to evolve.

Cybersecurity Practices Improve, But Gaps Remain

The RBI noted that financial institutions have made significant progress in cyber risk management. Regulatory reporting processes and board-level reporting of major cyber incidents have also matured. However, the report identified employee cybersecurity awareness and training as areas requiring further improvement, noting that human behaviour remains one of the most exploited entry points for cyberattacks. It also highlighted the need to strengthen forensic preparedness to improve incident response, preserve digital evidence and support regulatory and law enforcement investigations following sophisticated cyber incidents. The survey further revealed that around 67 percent of respondents increased IT and cybersecurity staffing between March 2025 and March 2026. Additionally, 71 percent reported higher cybersecurity spending as a share of overall IT expenditure during the last three financial years.

Third-Party Risk Emerges as Second Biggest Concern

Beyond AI Cyber Attacks, the RBI ranked third-party risk and supply chain dependencies as the second most important cybersecurity challenge for the financial sector. The survey found that 93 percent of respondents rely partially or substantially on external vendors for cybersecurity functions such as security operations centre monitoring, cloud security, incident response, threat intelligence and vulnerability assessments. Three-fourths of respondents also reported moderate to very high dependence on third-party technology providers for critical applications. According to the RBI, a major cyber incident affecting a common service provider could rapidly disrupt multiple regulated entities and create broader financial stability risks.

Growing Digital Transactions Increase Cyber Risk

The report noted that cyber risk has become a major financial stability concern as India's financial ecosystem becomes increasingly digital and interconnected. About 79 percent of surveyed institutions said more than three-fourths of their customer transactions are now conducted through digital financial services. Although 98 percent of respondents rated their current cyber risk exposure as very low to moderate and reported minimal disruption to customer services during 2025-26, nearly one-third indicated that cyber risk had increased compared with the previous year. The RBI also observed that geopolitical uncertainty is contributing to the evolving threat landscape, with 42 percent of surveyed institutions believing it has increased the likelihood of cyberattacks.

Financial Sector Cybersecurity Strategy Advances

The report said the proposed Financial Sector Cybersecurity Strategy is at an advanced stage of formulation. Developed by an Inter-Ministerial Group under the Financial Stability and Development Council, the strategy aims to establish governance frameworks, regulatory harmonisation and implementation timelines across the financial sector. The RBI said the strategy will address cybersecurity risks associated with artificial intelligence, cloud computing, quantum technologies, third-party dependencies, consumer protection and cross-sector critical infrastructure, strengthening the resilience of India's financial system against emerging cyber threats.
  • ✇Firewall Daily – The Cyber Express
  • FBI Warns of a Hidden Web Tactic Fueling Phishing and Ransomware Samiksha Jain
    The FBI Warns of Malicious Traffic Distribution Systems being increasingly used by cybercriminals to redirect internet users to phishing pages, malware downloads, ransomware attacks, and online financial scams. In a newly released Public Service Announcement (PSA), the Federal Bureau of Investigation cautioned that cybercriminals are leveraging Traffic Distribution Systems (TDS) to gain access to victim networks while evading traditional security controls. According to the FBI, TDS technology
     

FBI Warns of a Hidden Web Tactic Fueling Phishing and Ransomware

FBI Warns of Malicious Traffic

The FBI Warns of Malicious Traffic Distribution Systems being increasingly used by cybercriminals to redirect internet users to phishing pages, malware downloads, ransomware attacks, and online financial scams. In a newly released Public Service Announcement (PSA), the Federal Bureau of Investigation cautioned that cybercriminals are leveraging Traffic Distribution Systems (TDS) to gain access to victim networks while evading traditional security controls. According to the FBI, TDS technology is designed to route internet traffic to different destinations after users visit websites, click advertisements, download applications, or engage with online promotions. While the technology itself has legitimate uses, cybercriminals are exploiting it to selectively redirect users to compromised websites and fraudulent login pages.

FBI Warns of Malicious Traffic Distribution Systems Used in Cyber Attacks

As the FBI Warns of Malicious Traffic Distribution Systems, the agency explained that cybercriminals often drive victims to a malicious TDS through various methods, including Social Engineering, phishing emails, malicious advertisements, and compromised websites. One common technique involves Search Engine Optimization (SEO) Poisoning, where fraudulent advertisements are designed to imitate legitimate websites. Users who click these links may unknowingly enter a redirection chain controlled by threat actors. Cybercriminals also compromise legitimate websites by exploiting weak passwords, outdated plugins, and vulnerable website themes. Once administrative access is obtained, attackers can modify website code to automatically redirect visitors to a malicious TDS infrastructure.

How Traffic Distribution Systems Help Evade Detection

According to the FBI, Traffic Distribution Systems (TDS) can bypass traditional firewall protections that would normally block access to malicious websites. The system uses multiple intermediate nodes before directing users to the final destination, making it more difficult for defenders to identify and block malicious activity. In addition to hiding malicious infrastructure, attackers use TDS platforms to gather information about visitors. Data collected may include:
  • IP address
  • Operating system
  • Geographic location
  • Device information
  • Browser details
The FBI noted that this information allows attackers to determine whether a victim is a suitable target. It also enables cybercriminals to avoid detection by presenting harmless content to users they are not interested in targeting, including security researchers and analysts.

Phishing, Malware, and Ransomware Risks

The FBI warned that users reaching the end of a malicious redirection chain may encounter Phishing Pages, financial fraud schemes, or malware downloads. In some cases, attackers use malware delivered through a TDS to gain access to victim networks. The agency stated that compromised accounts and network access obtained through these methods may later be sold to other criminal groups, including Ransomware operators. The PSA highlights how a single visit to a compromised website or malicious advertisement can ultimately lead to broader cybersecurity incidents.

FBI Shares Protection Measures

To reduce the risk of compromise, the FBI advised individuals to verify website URLs before clicking advertisements or promotional links. The agency also recommended keeping software, website plugins, and themes updated to address known vulnerabilities. Additional recommendations include:
  • Using strong passwords
  • Enabling Two-Factor Authentication (2FA)
  • Installing reputable security plugins and web application firewalls
  • Downloading software only from trusted developers
For businesses, the FBI recommended monitoring endpoints for suspicious activity involving JavaScript, PowerShell, and script execution tools. Organizations are also encouraged to strengthen phishing awareness training, regularly audit website administration accounts, and patch content management systems and third-party components.

FBI Urges Victims to Report Incidents

The FBI encouraged individuals and organizations that believe they have been affected by activity linked to malicious TDS infrastructure to report the incident through the Internet Crime Complaint Center (IC3) and contact their local FBI field office. The agency emphasized that cybercriminals continue to evolve their techniques for delivering malware and conducting online fraud, making vigilance and proactive cybersecurity measures essential for both individuals and businesses.
❌
❌