Visualização normal

Antes de ontemFirewall Daily – The Cyber Express

The Cyber Express Weekly Roundup: Claude Session Hijacking, PaperCut Exploits, and Enterprise Cyberattacks

4 de Setembro de 2026, 08:48

Weekly Roundup September 2026

This weekly roundup highlights a range of cybersecurity developments affecting artificial intelligence platforms, enterprise software, healthcare organizations, social media accounts, and internet-facing infrastructure.  From stolen Claude sessions and bypassed PaperCut security fixes to an attempted attack targeting hundreds of thousands of X users, recent incidents demonstrate how attackers continue to exploit both software vulnerabilities and active user sessions.  The latest developments also show that organizations face growing risks across AI services, on-premises systems, enterprise edge devices, and account recovery infrastructure. Security teams are being urged to respond quickly as attackers increasingly target exposed systems and authentication mechanisms. 

The Cyber Express Weekly Roundup 

Anthropic Warns of Claude Session Hijacking 

Anthropic has warned that common infostealer malware is being used to steal active Claude sessions, potentially allowing attackers to bypass passwords and two-factor authentication. The campaign involves malware such as Vidar, LummaC2, RedLine, and Atomic Stealer, which is often distributed through pirated software and illicit downloads. Attackers may also consume victims’ paid AI usage. Read more… 

PaperCut Releases Second Emergency Patch After First Fix Is Bypassed 

PaperCut has released a second emergency patch for two actively exploited vulnerabilities affecting its NG and MF print management servers. Researchers discovered ways to bypass the initial security fix, potentially allowing attackers to chain the flaws and achieve pre-authentication remote code execution on exposed systems. Read more… 

Boston Scientific Cyberattack Limited to Certain On-Premises Systems 

Boston Scientific says its ongoing cybersecurity incident is limited to certain on-premises systems, with no impact identified on its cloud-based applications. The company has also reported no confirmed data breach or evidence of unauthorized activity since August 25, as its investigation into the incident continues. Read more… 

DOJ Investigates Attempted Cyberattack on Hundreds of Thousands of X Users 

The U.S. Department of Justice is investigating a large-scale cyberattack targeting hundreds of thousands of X accounts through the platform’s password-recovery system. Attorney General Todd Blanche said X detected and disrupted the campaign before the targeted accounts could be captured, preventing the attempted account takeover operation from succeeding. Read more… 

Two Citrix NetScaler Flaws Put Enterprise Edge Devices at Risk 

Two vulnerabilities in Citrix NetScaler ADC and Gateway have prompted an urgent patching warning from Australia’s cybersecurity agency. CVE-2026-19489, a memory overflow flaw, and CVE-2026-19490, an authentication bypass, can affect systems with specific configurations involving SIP ALG, SAML, or VPN gateway functionality. Read more… 

Weekly Cybersecurity Takeaway 

This week’s developments demonstrate that cybersecurity threats are increasingly targeting authentication systems, active user sessions, exposed enterprise infrastructure, and critical business applications. AI platforms, print management servers, healthcare environments, social media accounts, and network edge devices all remain potential targets for attackers.  Organizations should prioritize rapid security patching, protection of active sessions, strong authentication controls, careful monitoring of exposed infrastructure, and timely investigation of suspicious activity. Security teams should also review systems that rely on password-recovery mechanisms and identify enterprise devices operating with vulnerable configurations.  As businesses continue to rely on cloud services, AI platforms, remote access technologies, and internet-facing enterprise systems, attackers are finding new opportunities to exploit trusted sessions and security weaknesses. Organizations must maintain continuous monitoring and rapid response capabilities to reduce the impact of increasingly targeted cyberattacks. 

The Cyber Express Weekly Roundup: Exploited Entra ID Flaw, AI Agent Risks, and Global Cybercrime Crackdown

28 de Agosto de 2026, 08:17

The Cyber Express weekly roundup, podcast

This weekly roundup highlights a broad range of cybersecurity and technology developments affecting cloud identity infrastructure, social media platforms, businesses, digital assets, and international law enforcement.   From a critical Microsoft Entra ID vulnerability exploited before remediation to a global crackdown on West African cybercrime networks, recent developments demonstrate how attackers continue to target both technical systems and human trust.  The latest developments also show that cybersecurity risks are expanding alongside the rapid adoption of cloud services and artificial intelligence. Organizations are facing threats involving identity infrastructure, autonomous AI agents, software vulnerabilities, digital transactions, online fraud, and the misuse of emerging technologies. 

The Cyber Express Weekly Roundup 

Microsoft Confirms Exploited Entra ID Flaw 

Microsoft confirmed that a critical vulnerability in Entra ID, CVE-2026-69836, was exploited before the flaw was fixed server-side. The vulnerability carries a CVSS score of 10.0 and could allow unauthenticated attackers to achieve remote code execution, potentially affecting Microsoft’s cloud-based identity infrastructure. Read more... 

New Zealand Proposes Social Media Ban for Under-16s 

New Zealand has introduced legislation that would require high-risk social media platforms to prevent users under the age of 16 from accessing their services. Proposed age-verification methods could include digital identification, facial age estimation, or official identification documents. Read more... 

Cyble and DRONA Launch AI Cyber Defense Initiative in India 

Cyble and DRONA Cyber Solutions have launched an AI-powered cybersecurity initiative in Ahmedabad aimed at helping mid-sized businesses detect, investigate, and contain cyber threats. The initiative combines threat intelligence, AI-driven investigations, and endpoint enforcement to provide organizations with faster and more coordinated responses to security incidents. Read more... 

AI Agents Could Create New Cybersecurity Risks 

Adarsh Kant Sinha, CEO of ANVE.AI, warned that autonomous AI agents could introduce significant new cybersecurity risks as organizations increasingly allow them to interact with business-critical systems. AI agents may gain access to email, customer relationship management platforms, cloud infrastructure, and financial systems, potentially creating new avenues for misuse or compromise. Read more... 

Ledger Fixes Ethereum App Flaw Amid Disclosure Dispute 

Ledger said it fixed a clear-signing vulnerability in its Ethereum application approximately two weeks before security firm TestMachine publicly disclosed the issue. The vulnerability could potentially allow a malicious application to display one transaction to a user while preparing a different transaction for signing. Read more... 

Global Crackdown Nets 58 Arrests in West African Crime Networks 

An eight-month international law enforcement operation led by INTERPOL has resulted in 58 arrests and the identification of 263 suspects across 22 countries. Operation Jackal IV targeted West African criminal networks involved in cyber-enabled fraud, money laundering, romance scams, and investment scams. Read more... 

Weekly Cybersecurity Takeaway 

This week’s developments demonstrate that cybersecurity threats are crossing organizational, technological, and geographical boundaries, affecting cloud identity systems, artificial intelligence, digital platforms, cryptocurrency applications, and international financial crime.  Organizations should prioritize strong identity and access controls, rapid vulnerability remediation, careful management of AI-agent permissions, secure integrations, human oversight, and continuous threat monitoring.   As autonomous technologies become more deeply integrated into business operations and cybercriminal networks continue to operate across borders, security teams must adapt to a threat landscape that is becoming broader, more interconnected, and increasingly difficult to contain. 

The Cyber Express Weekly Roundup: Tax Data Breach, AI Security Risks, and Critical GitLab Flaw

21 de Agosto de 2026, 10:28

The Cyber Express August 21 Weekly Roundup

This weekly roundup highlights a broad range of cybersecurity threats affecting government agencies, businesses, enterprise AI systems, and software platforms. From a major French tax authority breach to a critical GitLab vulnerability, recent incidents demonstrate how attackers continue to exploit sensitive data, digital systems, and emerging technologies. The latest developments also show that cybersecurity risks are expanding beyond traditional attacks. Organizations are increasingly facing threats involving sensitive customer information, AI-powered systems, supply-chain risks, software vulnerabilities, and potential interference with critical operations.

The Cyber Express Weekly Roundup

French Tax Authority Data Breach Hits 678,000 People 

France’s tax authority, DGFiP, confirmed a cyberattack that exposed tax and cadastral information belonging to 678,000 individuals and professionals. The accessed information includes tax income, withholding rates, business details, addresses, and property information. DGFiP said online accounts and passwords were not compromised and is continuing to investigate the incident. Read more... 

Cyberattack Targets Ukraine Agency Ahead of Major Asset Tender 

Ukraine’s Asset Recovery and Management Agency (ARMA) suffered a suspected cyberattack shortly before a major deadline to select a manager for assets linked to sanctioned Russian oligarch Mikhail Fridman. ARMA said the incident, combined with earlier cyber activity and increased information pressure, could indicate a coordinated attempt to disrupt its operations or influence the tender. Read more... 

Oz Hair and Beauty Data Breach Exposes Customer Information 

Oz Hair and Beauty confirmed that an unauthorized party accessed customer information, including names, email addresses, phone numbers, and purchase history. The company said credit card, banking, and home-address information were not compromised. The number of affected customers remains undisclosed, while an investigation into the breach continues. Read more... 

Enterprise AI Is Expanding the Cybersecurity Risk 

Guild Group’s Mohammad Arif warned that the rapid adoption of enterprise AI is creating new cybersecurity challenges as AI systems gain access to sensitive data, applications, and business workflows. Key concerns include shadow AI, data leakage, insecure integrations, AI supply-chain attacks, prompt injection, and AI-powered phishingRead more... 

Critical GitLab Flaw Could Let Attackers Delete Public Projects 

GitLab patched a critical vulnerability, CVE-2026-19478, that could allow unauthenticated attackers to remotely modify or delete public projects and user data. The flaw carries a CVSS score of 9.4. GitLab also addressed a high-severity GraphQL CSRF vulnerability, CVE-2026-19650. Read more... 

Weekly Cybersecurity Takeaway 

This week’s incidents demonstrate that cybersecurity threats are increasingly crossing organizational and technological boundaries, affecting government systems, customer data, enterprise AI, and software development platforms. Organizations should prioritize strong access controls, rapid vulnerability patching, data protection, AI governance, employee awareness, and continuous monitoring. As attackers continue exploiting both human trust and technical weaknesses, security teams must adapt to a threat landscape that is becoming broader, faster, and increasingly interconnected.

The Cyber Express Weekly Roundup: Corporate Cyberattacks, AI Security Risks, Zero-Days, and Data Theft

14 de Agosto de 2026, 08:20

weekly roundup The Cyber Express cybersecurity 2026

This weekly roundup highlights the expanding range of threats facing businesses, technology platforms, and individuals. From social engineering attacks against corporate systems and vulnerabilities uncovered by AI agents to large-scale software patches and cyberattacks disrupting logistics operations, recent incidents demonstrate how quickly the threat landscape is evolving.  The latest developments also show that cybersecurity risks are no longer limited to traditional malware or ransomware. Attackers are increasingly exploiting human behavior, software weaknesses, interconnected supply chains, and personal online accounts. At the same time, artificial intelligence is emerging as both a defensive tool and a new way to identify security weaknesses. 

The Cyber Express Weekly Roundup 

Levi Strauss Targeted in Cyberattack, Corporate Files Accessed 

Levi Strauss & Co. disclosed a cybersecurity incident after attackers used social engineering techniques to gain access to three company-issued computers. The company believes certain corporate files were accessed and some information may have been exfiltrated. Levi Strauss said it moved quickly to contain the incident and terminate the unauthorized access, limiting the potential impact of the attack. Read more...

AI Agent Exploits Gym Booking Vulnerability 

An AI-powered agent reportedly identified an authentication weakness in an Australian gym’s online booking system. The agent, powered by Anthropic’s Claude and operated through OpenClaw, was originally instructed to help a user book a popular class. During the process, it was able to reserve classes months ahead and cancel another customer's booking. Read more...

AI Will Automate Cybersecurity Toil, Not Replace Security Professionals 

Harsha Reddy, Head of Information Security at Veterinary Emergency Group, argues that artificial intelligence is more likely to transform cybersecurity work than eliminate cybersecurity jobs. AI can assist with repetitive activities such as reviewing logs, triaging alerts, and collecting evidence, allowing security professionals to concentrate on investigation, strategy, and higher-value defensive operations. Read more...

Microsoft Fixes More Than 400 Security Flaws 

Microsoft’s August 2026 Patch Tuesday addresses roughly 400 vulnerabilities across its products, including three zero-days. One of the vulnerabilities was reportedly being actively exploited, while two others had been publicly disclosed before patches became available. The update includes 42 critical vulnerabilities, with 37 associated with remote code execution, reinforcing the importance of timely patching across enterprise environments. Read more...

CEVA Logistics Cyberattack Disrupts European Operations 

A cyberattack against CEVA Logistics disrupted activity at eight European warehouses on July 29, affecting shipments and exposing customer data connected to several major clients. The logistics company, part of the CMA CGM Group, has not publicly identified the attackers or provided detailed information about the technical nature of the incident. Read more...

FBI Warns of Theft of Explicit Content From Social Media 

The FBI has warned that cybercriminals are targeting social media and personal accounts to steal explicit images and videos, including non-consensual intimate images. Stolen material may subsequently be distributed or sold online, while associated personal information can expose victims to harassment, stalking, and sextortion. Read more...

Weekly Cybersecurity Takeaway 

This week’s incidents demonstrate that cybersecurity risks are expanding across corporate networks, software ecosystems, supply chains, AI-powered systems, and personal accounts.  Organizations should prioritize strong authentication, rapid vulnerability patching, employee awareness, third-party risk management, and continuous monitoring. At the same time, responsible use of AI could help security teams reduce repetitive workloads and respond more effectively to emerging threats.  As attackers continue finding new ways to exploit technology and human trust, organizations and individuals must strengthen security controls while remaining prepared for threats that increasingly cross traditional digital boundaries. 

💾

Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.

The Cyber Express Weekly Roundup: Ransomware Surge, Government Data Breaches, Logistics Disruptions, and Third-Party Security Risks

The Cyber Express weekly roundup H1

This weekly roundup highlights the growing cybersecurity risks affecting businesses, government agencies, and critical service providers. From the continued dominance of ransomware operations to government database breaches and third-party supply chain incidents, recent events demonstrate how attackers are increasingly targeting trusted systems and external service providers to maximize disruption and data exposure.  The latest developments reinforce that cyber threats are no longer limited to direct attacks on organizations. Threat actors are exploiting ransomware-as-a-service ecosystems, compromising government registries, targeting law enforcement databases, and abusing third-party platforms that support retail and healthcare operations.   Organizations must strengthen third-party risk management, improve data protection measures, and enhance incident response capabilities to reduce the impact of evolving cyber threats. 

The Cyber Express Weekly Roundup 

Qilin Dominated Ransomware Attacks in H1 2026 

Qilin emerged as the most active ransomware group during the first half of 2026, targeting organizations worldwide through its ransomware-as-a-service (RaaS) operation. Manufacturing, healthcare, construction, and professional services were among the sectors most affected as the group continued expanding its global reach. Read more… 

Hackers Breach Beneficial Owners Registry, Expose Data of 31,000 Firms 

Hackers breached the Register of Beneficial Owners (VwbP), gaining unauthorized access to data associated with approximately 31,000 legal entities. Authorities temporarily took the registry offline, launched an investigation, and established a crisis response team, stating there is currently no evidence that records were altered or deleted. Read more… 

PNLD Data Breach Leaks Police and Government Contact Details 

A data breach involving the Police National Legal Database (PNLD) exposed names, organizations, and work email addresses belonging to police officers, government partners, criminal justice professionals, and some Ask the Police users after the information appeared on the dark web. Authorities are investigating the incident and assessing its potential impact. Read more… 

De Bijenkorf Logistics Cyberattack Delays Orders and Raises Data Exposure Concerns 

A cyberattack targeting a third-party logistics provider disrupted deliveries, returns, and refunds for Dutch retailer De Bijenkorf. While the retailer confirmed its internal systems were not compromised, investigators are assessing whether customer contact details and order information were exposed. Payment information, passwords, and financial data were not affected, and customers have been advised to remain vigilant against phishing attempts. Read more… 

Updoc Data Breach Exposes Customer Contact Information 

Australian telehealth provider Updoc disclosed a data breach after unauthorized access to a third-party operational platform exposed some customers' names, email addresses, and postal addresses. The company confirmed that its internal systems remained secure and that no medical records, payment information, or financial data were compromised. Read more… 

Weekly Cybersecurity Takeaway 

This week's incidents highlight the continued evolution of cyber threats across ransomware operations, government data breaches, and third-party supply chain compromises.  A common theme across these events is the growing risk posed by trusted third-party platforms and shared digital ecosystems. Attackers are targeting external service providers, government databases, and ransomware affiliate networks to expand their reach and maximize operational disruption.  Organizations should prioritize stronger third-party risk management, continuous monitoring, robust access controls, and timely incident response to reduce the impact of supply chain attacks and data breaches. As businesses become more interconnected, strengthening the security of partner ecosystems is becoming just as important as protecting internal infrastructure. 

Updoc Data Breach Exposes Patient Contact Information Following Third-Party Security Incident

Updoc data breach

The Updoc data breach has raised fresh concerns about cybersecurity in Australia's healthcare sector after the telehealth provider confirmed that an unauthorized third party may have accessed customer contact information through an external system.   The data breach at Updoc, disclosed on August 7, stemmed from a brief security incident involving a third-party platform that supports the company's operations. While the Updoc cyberattack did not expose medical or financial records, it is the latest cyber incident affecting Australia's healthcare sector. 

Updoc Data Breach Traced to Third-Party Platform 

Updoc, an Australian telehealth provider offering round-the-clock online healthcare services, including medical certificates, prescriptions, and specialist referrals, detected unauthorized access to a third-party operational system on Friday, July 31.  In a statement shared with The Cyber Express, the company said the incident was limited to an external system used to support its operations. The exposure was confined to customer contact information, which may have included account holders' names, email addresses, and postal addresses.  Updoc said its internal systems were not accessed during the incident and confirmed that no health records, financial information, or payment details were involved. The company added that it acted immediately to block the unauthorized access and found no evidence of any further activity after the initial event.  According to the company, customers are not required to take any immediate action because account logins and security remain unaffected. Updoc also apologized for any concern or inconvenience caused by the incident. 

Updoc Cyberattack Adds to Healthcare Sector Threats 

Founded in 2021, Updoc generates approximately $10 million in annual revenue. According to its founders, the platform has served more than one million patients since launch, while its website states that it has over 500,000 users.  The Updoc cyberattack follows a series of cybersecurity incidents targeting Australian healthcare and consumer-facing organizations. In June, clinic network Partnered Health disclosed a cyberattack in which hackers stole personal information and health records from patients across at least 21 clinics in five Australian states.  That breach exposed sensitive information, including medical records, Medicare numbers, consultation notes, referral letters, and pathology results. The attack affected clinics in Melbourne, Sydney, Canberra, the Gold Coast, Sunshine Coast, and Coffs Harbour. At the time, another five clinics, including several in Western Australia, remained under investigation.  Although the Updoc data breach was limited to contact information and did not compromise medical or payment data, the data breach at Updoc highlights the risks associated with third-party service providers. As healthcare organizations continue to depend on external platforms, the incident underscores how vulnerabilities outside a company's own infrastructure can still result in customer information being exposed. 
  • ✇Firewall Daily – The Cyber Express
  • Estée Lauder Confirms Cyberattack Affecting Personal Information Ashish Khaitan
    The Estée Lauder data breach has prompted the global cosmetics company to notify affected individuals after hackers exploited a vulnerability in Oracle E-Business Suite, a platform used for human resources (HR) operations.   The Estée Lauder cyberattack stemmed from unauthorized access that occurred on or around August 9, 2025, though the company said it identified the incident last month and confirmed the scope of the breach on June 19, 2026.  Estée Lauder Data Breach Exposed Sensitive Pers
     

Estée Lauder Confirms Cyberattack Affecting Personal Information

Estée Lauder data breach

The Estée Lauder data breach has prompted the global cosmetics company to notify affected individuals after hackers exploited a vulnerability in Oracle E-Business Suite, a platform used for human resources (HR) operations.   The Estée Lauder cyberattack stemmed from unauthorized access that occurred on or around August 9, 2025, though the company said it identified the incident last month and confirmed the scope of the breach on June 19, 2026. 

Estée Lauder Data Breach Exposed Sensitive Personal Information 

According to the company's notification letter, the attackers gained access to the Oracle E-Business Suite system and obtained personal information belonging to certain individuals.  We became aware of a cybersecurity issue involving a vulnerability in the Oracle E-Business Suite system which is used by the Estee Lauder Companies for HR management purposes," the notice states.  It further adds: "On June 19, 2026, we determined through our investigation that, on or around August 9, 2025, an unauthorized third party gained access to the Oracle E-Business Suite system and obtained personal information of certain individuals."  The exposed data in the incident includes full names, postal addresses, email addresses, dates of birth, Social Security numbers (SSNs), passport numbers, financial account information, including bank account numbers, health information, and employment records such as payroll and performance reports. 

Oracle Vulnerability Tied to Estée Lauder Cyberattack 

Although Estée Lauder did not identify the specific vulnerability used in the attack, the timeline aligns with the widespread exploitation of the Oracle E-Business Suite flaw CVE-2025-61882.  In October 2025, researchers from Google warned that the Clop ransomware group had exploited the vulnerability as a zero-day to steal data. The flaw affected Oracle EBS versions 12.2.3 through 12.2.14, allowing attackers to bypass authentication and remotely execute code through the BI Publisher Integration component. Successful exploitation could provide access to sensitive HR and business information.  Oracle released security patches for CVE-2025-61882 on October 4, 2025. Soon after, cybersecurity company CrowdStrike confirmed that Clop had been exploiting the vulnerability since early August 2025. 

Company Offers Identity Monitoring 

Estée Lauder, headquartered in New York, generates annual revenue of $14.3 billion, employs around 57,000 people, and operates retail stores and online businesses worldwide, making it the world's second-largest cosmetics company.  Following the Estée Lauder data breach, the company is urging recipients of its notification letter to monitor for signs of identity theft and fraud. It is also providing 24 months of complimentary identity monitoring services through Kroll.  The Estée Lauder cyberattack is part of a broader campaign that affected several high-profile organizations, including Harvard, the University of Pennsylvania, Dartmouth, the University of Phoenix, The Washington Post, Logitech, GlobalLogic, Cox Enterprises, and American Airlines subsidiary Envoy Air.  This is not the first time the company has been impacted by Clop. In 2023, Estée Lauder was also compromised after the ransomware group exploited a separate zero-day vulnerability in the MOVEit Transfer platform, one of the company's internal software tools. 
  • ✇Firewall Daily – The Cyber Express
  • Partnered Health Cyberattack Exposes Patient Data Across Australia Ashish Khaitan
    The Partnered Health cyberattack has exposed sensitive patient information across multiple Australian clinics, raising fresh concerns about healthcare cybersecurity. The Partnered Health data breach, involving clinics owned by healthcare provider Partnered Health, a company backed by Quadrant, affected facilities in New South Wales, Victoria, Queensland, Western Australia, and the ACT. The incident has also renewed scrutiny of the growing number of cyberattacks targeting Australia's health
     

Partnered Health Cyberattack Exposes Patient Data Across Australia

Partnered Health cyberattack

The Partnered Health cyberattack has exposed sensitive patient information across multiple Australian clinics, raising fresh concerns about healthcare cybersecurity. The Partnered Health data breach, involving clinics owned by healthcare provider Partnered Health, a company backed by Quadrant, affected facilities in New South Wales, Victoria, Queensland, Western Australia, and the ACT. The incident has also renewed scrutiny of the growing number of cyberattacks targeting Australia's healthcare sector.

Partnered Health Data Breach Impacted Medical and Personal Information 

Partnered Health confirmed that a malicious actor accessed its systems on 23 June, compromising data from 21 clinics across cities, including Sydney, Melbourne, and Canberra. The healthcare provider disclosed the breach more than three weeks later, informing patients that investigations had confirmed personal and health information had been taken from some clinics within its network. "Our investigations to date have confirmed that personal information (including health information) was taken from some of the clinics in our network," the company said. It added, "As a health services provider, we know our patients and our people trust us with personal and medical information, and we sincerely apologise for any concern and inconvenience this may cause them." The stolen information includes names, dates of birth, addresses, contact details, Medicare information, private health insurance details, concession card information, consultation notes, referral letters, pathology reports, diagnostic results, and other treatment records maintained by general practitioners.

Investigation into the Partnered Health Cyberattack Continues 

Partnered Health said the cyberattack has been reported to the Australian Cyber Security Centre, the Office of the Australian Information Commissioner, and law enforcement authorities. The company has also secured an interim injunction from the NSW Supreme Court preventing the stolen information from being used or published. While investigations remain ongoing, the provider said the extent of the breach is still being determined at five clinics, including three in Western Australia and two in Victoria. "While there is no direct evidence that patient records have been viewed, as a precaution we have written to patients from these clinics to make them aware of this and provide details of steps that can be taken to protect their information," a Partnered Health spokesperson said. The spokesperson added, "We understand that this sort of news can cause concern. We sincerely apologize for any distress this may have caused our patients."

Quadrant-backed Healthcare Provider Faces Growing Scrutiny 

Established in 2013, Partnered Health operates more than 60 medical centres, along with skin cancer, allied health, and mental health clinics, providing services to more than 5 million people nationwide. The company is owned by Quadrant, while Bupa announced in June that it would acquire the healthcare provider. The Partnered Health data breach comes amid a record year for cybersecurity incidents in Australia. According to the Office of the Australian Information Commissioner, 1,205 data breach notifications were recorded in 2025, marking an 8% increase compared with 2024. Among the year's largest incidents was the cyberattack on Qantas, which compromised the information of 5.7 million customers and was reportedly leaked on the dark web. A spokesperson for the Department of Home Affairs said the federal government is aware of the Partnered Health cyberattack and confirmed that relevant agencies are engaged as investigations continue. Authorities have not yet disclosed how many patients were affected or the full scope of the stolen data.
  • ✇Firewall Daily – The Cyber Express
  • Australia-India PACTS to Deepen Cybersecurity and Tech Collaboration Samiksha Jain
    Australia and India have unveiled the Australia-India PACTS, a new framework designed to deepen bilateral cooperation on cybersecurity, critical technologies, supply chain resilience, digital resilience, and defence research. The new partnership replaces the 2020 Framework Arrangement on Cyber and Cyber Enabled Critical Technology Cooperation and aims to strengthen national security, economic growth, and regional stability across the Indo-Pacific. The two countries said the Aus
     

Australia-India PACTS to Deepen Cybersecurity and Tech Collaboration

Australia-India PACTS

Australia and India have unveiled the Australia-India PACTS, a new framework designed to deepen bilateral cooperation on cybersecurity, critical technologies, supply chain resilience, digital resilience, and defence research.

The new partnership replaces the 2020 Framework Arrangement on Cyber and Cyber Enabled Critical Technology Cooperation and aims to strengthen national security, economic growth, and regional stability across the Indo-Pacific.

The two countries said the Australia-India Partnership on Cyber, Critical Technologies and Supply Chains (PACTS) builds on two decades of research collaboration, operational coordination, and policy engagement. It also reflects their shared commitment to creating secure digital ecosystems while promoting trusted technology partnerships.

Australia-India PACTS Built on Five Pillars

The Australia-India PACTS is structured around five pillars that will drive collaboration between governments, research institutions, universities, and the private sector. The framework is intended to increase two-way investment in emerging technologies while supporting innovation and the commercialisation of research.

The first pillar focuses on supply chain resilience by strengthening trusted technology supply chains and promoting secure trade. Both countries will establish a bilateral mechanism for trusted vendor frameworks and work together to improve undersea cable security through the Quad Partnership for Cable Connectivity and Resilience. The partnership also includes collaboration on semiconductor research, critical minerals, and trade diversification.

Australia-India PACTS Expands Critical Technology Collaboration

The second pillar focuses on critical technologies, with Australia and India planning to strengthen cooperation in artificial intelligence, telecommunications, biotechnology, advanced materials, and space technologies.

The framework also supports the development of international standards for trustworthy AI and encourages collaboration between academic institutions and industry to promote responsible AI deployment. The two countries will also explore joint research, investment initiatives, and commercial partnerships in emerging technologies to strengthen long-term economic security across the Indo-Pacific.

Australia-India Prioritises Cybersecurity

A major component of the partnership is Australia India cybersecurity cooperation. Under the third pillar, both governments will work together to counter cybercrime, deter malicious cyber activity, strengthen cyber policy coordination, and protect critical infrastructure.

The framework proposes a consolidated bilateral mechanism for cyber and ICT cooperation, expanded engagement in United Nations cyber processes, increased trade opportunities for cybersecurity businesses, and practical workshops involving government agencies and industry stakeholders.

The partnership will also establish a cyber technology skills incubator to promote knowledge exchange and workforce development.

Australia-India PACTS Advances Digital Resilience

The fourth pillar focuses on digital resilience across the Indo-Pacific. Australia and India will collaborate on trusted Digital Public Infrastructure initiatives and promote scalable digital solutions that support connectivity, healthcare, education, renewable energy, critical infrastructure, and digital transformation.

The partnership also seeks to expand pilot projects that help countries across the region build adaptable digital ecosystems while strengthening regional capabilities.

Defence Research and Governance Framework

The fifth pillar strengthens defence science collaboration through joint research, innovation partnerships, and greater engagement between Australia's Defence Science and Technology Group and India's Defence Research and Development Organisation.

Areas of cooperation include maritime surveillance, advanced materials, defence innovation, and stronger links between defence start-up ecosystems.

The Australia-India PACTS will be jointly overseen by the Australian Deputy Secretary of the International and Security Group within the Department of the Prime Minister and Cabinet and the Indian Deputy National Security Advisor. Annual Senior Officials Meetings will review progress, assess emerging cyber and technology risks, and identify future collaborative projects under each pillar.

With the launch of Australia-India Partnership on Cyber, Critical Technologies and Supply Chains (PACTS), both countries have outlined a long-term roadmap that brings together cybersecurity, critical technologies, supply chain resilience, digital resilience, and defence cooperation under a single strategic framework aimed at strengthening security and technology collaboration across the Indo-Pacific.

The Cyber Express Weekly Roundup: Five Eyes AI Warning, KDDI Data Breach, Garfield AI Legal Milestone, and Iranian Hacker Arrest

The Cyber Express weekly roundup June 2026

This week’s weekly roundup of cybersecurity developments highlights a rapid shift in global cyber risk conditions driven by artificial intelligence acceleration, large-scale data breaches, and expanding international enforcement actions. Across infrastructure, enterprise systems, public services, and regulated AI applications, organizations are increasingly exposed to faster-moving threats where traditional security assumptions are being challenged by automation and long-term intrusion campaigns.  The overarching theme in this weekly roundup is the erosion of response time in modern cybersecurity environments. Intelligence agencies, law enforcement bodies, and private-sector disclosures collectively point to a landscape where attackers are leveraging AI-enabled capabilities, third-party system weaknesses, and identity compromise to gain persistence across networks. At the same time, regulators and courts are beginning to define new boundaries for both cybercrime accountability and the operational use of AI in sensitive domains. 

The Cyber Express Weekly Roundup 

Five Eyes Warn AI Is Rapidly Outdating Cyber Risk Models 

The Five Eyes cybersecurity agencies warn that artificial intelligence is accelerating cyber threats and making traditional cyber risk assumptions obsolete. Attackers are exploiting vulnerabilities faster, shrinking response windows, and increasing the speed and sophistication of attacks. In guidance issued on June 23, 2026, they urged organizations to treat cyber resilience as a leadership priority, strengthen identity and access controls, accelerate patching cycles, and reduce dependence on legacy systems. Read more… 

TfL Hackers Plead Guilty After £29M Cyberattack 

Two members of the Scattered Spider cybercrime group have pleaded guilty to roles in the Transport for London cyberattack that caused £29 million in losses, disrupted services, and exposed customer data. The 2024 breach affected Oyster systems and forced mass password resets across TfL’s workforce. Investigators also linked the suspects to other attempted intrusions targeting U.S. healthcare networks. Read more… 

KDDI Data Breach May Expose 14.22 Million Email Accounts 

KDDI has disclosed a cybersecurity incident that may have exposed up to 14.22 million email addresses and passwords through systems used by multiple Japanese internet service providers. The breach, detected on June 17, 2026, stemmed from unauthorized access to a third-party email system. KDDI said it has secured the affected environment, notified partners, and is working with regulators while urging users to reset passwords as a precaution. Read more… 

Garfield AI Wins Landmark UK Case as AI-Powered Law Firm 

Garfield AI, a UK-regulated AI-powered law firm, has secured a landmark legal victory after successfully managing a small claims case in England with minimal human intervention. The AI system handled pre-trial work, including drafting court documents and preparing evidence, in a dispute over an unpaid £7,000 invoice. The case was ultimately won at Wandsworth County Court, marking a notable milestone for the use of AI in regulated legal services, though human counsel still represented the claimant at trial. Read more… 

Iranian Hacker Arrested in Montenegro Over Alleged $3.4B Cyberattack Campaign 

An alleged Iranian hacker has been arrested in Montenegro following a joint operation with the FBI over a long-running cyber campaign targeting U.S. infrastructure. Authorities say the 39-year-old suspect is linked to attacks dating back to 2013, allegedly targeting more than 150 U.S. universities and causing over $3.4 billion in damages. He now faces extradition to the United States on charges including computer fraud, hacking, conspiracy, and identity theft, while investigations into Iran-linked cyber activity continue. Read more… 

Weekly Cybersecurity Takeaway 

This week’s weekly roundup reflects a cybersecurity environment increasingly defined by the speed of AI-driven threat evolution, the scale of third-party exposure, and the persistence of long-running cybercrime operations. From the Five Eyes warning that artificial intelligence is rapidly reshaping cyber risk assumptions to the KDDI breach that may have exposed 14.22 million email accounts, organizations are facing mounting pressure to modernize defenses while reducing dependence on outdated security models. 

The Cyber Express Weekly Roundup: Cybersecurity Weekly Round on Emerging Threats, Data Breaches, and Global Policy Shifts

weekly roundup TCE

This week’s weekly roundup of cybersecurity developments highlights an expanding intersection of cyber risk, regulatory action, and enterprise vulnerability. Across healthcare, technology platforms, gaming companies, and government policy, organizations continue to confront a rapidly evolving cybersecurity landscape where data exposure, advanced intrusion tactics, and platform security failures are interconnected.  The overarching theme in this weekly roundup is the growing strain on digital ecosystems as attackers refine stealth techniques while institutions attempt to secure distributed systems. From cloud-based email exploitation to AI-related enterprise vulnerabilities, this week’s cybersecurity incidents underscore the difficulty of maintaining visibility and control across modern infrastructure. 

The Cyber Express Weekly Roundup 

Novo Nordisk Security Incident Exposes Limited Patient and HCP Data 

Novo Nordisk reported an unauthorized intrusion into internal systems that resulted in the external copying of limited clinical trial data along with healthcare professional contact details. According to the disclosure, core operational systems were not disrupted during the incident, and the breach did not affect ongoing business continuity. Read more... 

UNC6508 Used Google Workspace Trick to Spy on U.S. Medical Research 

A threat group identified as UNC6508, linked to China, reportedly conducted a long-term espionage campaign targeting North American medical and research institutions. Over a period described as exceeding two years, attackers infiltrated research environments and accessed sensitive systems related to medical and defense-linked projects. Read more... 

Critical SearchLeak Flaw in Microsoft 365 Copilot Exposed Enterprise Data 

A newly addressed vulnerability, identified as CVE-2026-42824, affected Microsoft 365 Copilot and carried the potential for significant enterprise data exposure. Researchers found that a chain of weaknesses—including prompt injection, HTML rendering issues, and server-side request forgery—could be exploited to extract sensitive data. Read more... 

UK Plans Social Media Ban for Under-16s by 2027 

The United Kingdom has proposed a policy restricting social media access for users under the age of 16, with implementation potentially targeted for spring 2027. If enacted, the ban would apply to major platforms including TikTok, Instagram, Snapchat, Facebook, YouTube, and X. Read more... 

Operation Endgame Disrupts SocGholish Malware Network 

International law enforcement agencies, operating under “Operation Endgame,” dismantled significant parts of the SocGholish malware infrastructure. The operation resulted in the cleanup of nearly 15,000 compromised websites and the takedown of multiple servers associated with cybercriminal activity. Read more... 

Nintendo Confirms Limited Employee Data Exposed in TinyPulse Attack 

Nintendo confirmed that employee survey data was exposed following a cyberattack involving the third-party platform TinyPulse. The company clarified that its internal systems and customer-facing data were not impacted by the incident. Read more... 

Weekly Cybersecurity Takeaway 

This week’s weekly roundup reflects a cybersecurity environment increasingly shaped by cloud exploitation, AI-driven vulnerabilities, and cross-border espionage campaigns. From healthcare breaches like Novo Nordisk’s limited data exposure to long-running intrusions such as UNC6508’s email-forwarding operations, attackers continue to prioritize stealth and persistence over direct system disruption.  At the same time, critical vulnerabilities like the Microsoft 365 Copilot SearchLeak flaw demonstrate how AI integration is expanding enterprise risk surfaces. Meanwhile, enforcement actions under Operation Endgame and policy shifts such as the UK’s proposed under-16 social media restrictions show that both technical and regulatory responses are evolving in parallel. 
  • ✇Firewall Daily – The Cyber Express
  • What Ukraine’s Entry Into the EU Cybersecurity Reserve Means Samiksha Jain
    Ukraine Joins EU Cybersecurity Reserve after receiving approval from the Council of the European Union, enabling the country to access emergency cybersecurity assistance during large-scale cyber incidents that exceed national response capabilities. The decision allows Ukraine to activate support from the EU Cybersecurity Reserve, a mechanism managed by the European Union Agency for Cybersecurity (ENISA) that provides incident response services through trusted private-sector cybersecurity prov
     

What Ukraine’s Entry Into the EU Cybersecurity Reserve Means

Ukraine Joins EU Cybersecurity Reserve

Ukraine Joins EU Cybersecurity Reserve after receiving approval from the Council of the European Union, enabling the country to access emergency cybersecurity assistance during large-scale cyber incidents that exceed national response capabilities. The decision allows Ukraine to activate support from the EU Cybersecurity Reserve, a mechanism managed by the European Union Agency for Cybersecurity (ENISA) that provides incident response services through trusted private-sector cybersecurity providers. The move reflects ongoing EU-Ukraine cooperation on digital security and resilience amid evolving cyber threats.

Ukraine Joins EU Cybersecurity Reserve Under EU Cyber Solidarity Framework

The EU Cybersecurity Reserve was established under the Cyber Solidarity Act to help participating countries respond to significant cybersecurity incidents. Through the reserve, nations can request specialized assistance when their own incident response resources are overwhelmed. According to the European Commission, Ukraine will now be able to officially seek emergency European support if a cyberattack surpasses the capacity of its domestic response teams. This would allow cybersecurity experts from across the European Union to assist in incident containment and recovery efforts. The Commission described the decision as part of broader efforts to strengthen preparedness, improve rapid response capabilities, and encourage cooperation against growing cyber threats.

EU Highlights Digital Security Cooperation

Commenting on the development, Henna Virkkunen, Executive Vice-President for Tech Sovereignty, Security and Democracy, said Ukraine's inclusion strengthens collective cyber defenses and reflects the principle of solidarity at the core of Europe's digital future. The Commission noted that cyberattacks continue to present a persistent challenge and emphasized the importance of coordinated responses and shared expertise among partner nations. Ukraine's inclusion also aligns with the EU's strategic digital partnership agenda, which focuses on strengthening cybersecurity cooperation with neighboring countries.

Moldova Previously Granted Access

Ukraine becomes the second non-EU country to gain access to the reserve. Moldova was granted access in 2024 following an increase in Moscow-linked Cyber Threats and influence operations targeting the country. The Council's authorization for Moldova to use the reserve was described as a major step forward in regional cybersecurity cooperation. The arrangement was implemented under the Cyber Solidarity Act and formed part of broader EU-Moldova efforts to improve digital resilience. The European Commission stated that enhancing cybersecurity cooperation remains a key component of its partnership with Moldova.

Broader EU-Moldova Digital Cooperation Expands

Alongside cybersecurity initiatives, the European Union has expanded digital cooperation with Moldova in several strategic areas. The Commission welcomed a political agreement that will allow Moldova to join the EU Roaming Area under the "Roam Like at Home" framework following formal adoption. Once implemented, Moldovan citizens and EU travelers will be able to call, text, and use mobile data without additional roaming charges. Moldova has also joined the EU Third Countries' Trusted List, enabling easier validation of electronic signatures and seals between EU and Moldovan organizations, businesses, and citizens. To strengthen resilience against Disinformation and foreign interference, a new hub of the European Digital Media Observatory (EDMO) known as FACT has also been established with support from the European Commission.

Cyber Cooperation Advances as EU Membership Talks Progress

The cybersecurity announcement comes shortly after EU member states agreed to launch formal accession negotiations with both Ukraine and Moldova. European Commission President Ursula von der Leyen described the decision as a major milestone, stating that all member states had agreed to open the first accession negotiations cluster with the two countries. She said the move recognizes the reforms undertaken by Ukraine and Moldova despite significant challenges and reinforces the EU's commitment to peace, security, and stability across the region. With access to the EU Cybersecurity Reserve, Ukraine now gains an additional layer of support to strengthen its cyber resilience and coordinate responses to major cybersecurity incidents alongside European partners.

The Cyber Express Weekly Roundup: AI Security Controls, Major Patch Releases, Public Sector Audits, and Emerging Online Scams

TCE The Cyber Express Weekly Roundup

This week's cybersecurity developments highlight a growing emphasis on proactive security measures, governance oversight, and risk management across both public and private sectors. From large-scale vulnerability remediation efforts and AI security enhancements to government-led technology reviews and event-driven cybercrime campaigns, organizations continue to face a complex threat landscape.  A common theme across this week's stories is the balance between innovation and security. As institutions adopt AI-powered systems, expand digital services, and move critical operations online, security teams are being challenged to strengthen protections without slowing modernization efforts. At the same time, threat actors continue to capitalize on public-interest events and trusted digital platforms to conduct fraud and data-theft campaigns. 

The Cyber Express Weekly Roundup 

CBSE Re-Evaluation Portal Receives Final Security Clearance 

The Central Board of Secondary Education (CBSE) has completed the final cybersecurity review of its examiner-facing re-evaluation platform, clearing the way for the reassessment of Class 12 answer scripts. Following an IIT-led audit and security testing process, examiners can now access the system to process applications submitted by more than 70,000 students. Read more... 

OpenAI Expands Lockdown Mode Across ChatGPT Accounts 

OpenAI has extended its Lockdown Mode security feature to all personal ChatGPT users, including Free, Go, Plus, Pro, and self-service Business accounts. The feature is designed to reduce the risk of prompt injection-related data exposure by limiting access to high-risk capabilities such as live web browsing, Deep Research, Agent Mode, and external file interactions. Read more... 

UK Courts Explore AI-Powered Legal Assistance 

The UK government has announced plans to test AI legal assistants within Crown Courts as part of broader judicial modernization efforts. The tools are expected to assist with legal research, case review, scheduling, and administrative processes while remaining under human supervision. Read more... 

Microsoft Issues Largest Patch Tuesday Update on Record 

Microsoft's June 2026 Patch Tuesday addressed a record-breaking 200 security vulnerabilities across its product ecosystem, including Windows, Office, Azure, and Exchange. The release included fixes for three publicly disclosed zero-day vulnerabilities and dozens of critical flaws. Read more... 

ServiceNow Clarifies Nature of Recent Security Incident 

ServiceNow has provided additional details regarding a recently disclosed security vulnerability, stating that observed activity originated from security researchers and customer investigations rather than malicious attackers. The company released a security update to address the issue and emphasized that there is no evidence of customer data misuse. Read more... 

World Cup-Themed Scams Target Fans Ahead of FIFA 2026 

Cybercriminals are already leveraging interest in the FIFA World Cup 2026 to launch phishing campaigns, fake ticket sales, and fraudulent recruitment schemes. Security researchers and law enforcement agencies have identified numerous lookalike domains impersonating official FIFA services in an effort to steal personal and financial information. Read more... 

Weekly Cybersecurity Takeaway 

This week's developments demonstrate that cybersecurity is becoming a foundational requirement for digital transformation rather than a separate consideration. Whether securing AI platforms, protecting educational systems, modernizing public services, or managing enterprise vulnerabilities, organizations are being forced to address security challenges alongside innovation initiatives.  Meanwhile, threat actors continue to exploit trust, familiarity, and public interest to achieve their objectives. From phishing campaigns targeting global sporting events to attacks focused on cloud services and enterprise platforms, the most effective defenses remain strong security governance, timely patching, user awareness, and continuous monitoring of emerging risks. 

The Cyber Express Weekly Roundup: Cloud Extortion, Long-Term Espionage, Android Zero-Days, and Public Sector Security Reviews

weekly roundup TCE cybersecurity news

The cybersecurity landscape in this weekly roundup continues to show a clear shift toward identity-driven attacks, long-term persistence operations, and exploitation of trusted cloud environments. Threat actors are increasingly focusing on stealing credentials, abusing administrative access, and leveraging legitimate platforms to scale impact across organizations.  Rather than relying on one-off intrusions, attackers are now building sustained access paths into enterprise systems, enabling repeated exploitation, data theft, and extortion from within trusted environments. 

The Cyber Express Weekly Roundup

Pink Extortion Group Targets Microsoft 365 Users via Voice Phishing 

A newly identified cyber extortion group known as “Pink” is using voice phishing (vishing) campaigns to steal credentials for Microsoft 365 accounts. Once access is gained, the group rapidly exfiltrates data from cloud platforms such as SharePoint and OneDrive and sends extortion messages directly from compromised internal accounts to pressure victims. Read more… 

China-Linked VerdantBamboo Maintains 18-Month Network Access 

Researchers have uncovered an 18-month intrusion attributed to the China-linked threat group VerdantBamboo. The attackers maintained long-term access using compromised MSP credentials, multiple malware families, and repeated re-entry techniques after remediation attempts. Read more… 

DPDP and Cybersecurity: Why Less Data Means Better Security

India’s DPDP framework promotes data minimization as a key cybersecurity strategy. Organizations are urged to collect only necessary data, store it briefly, and delete unused information to reduce breach risk. Excess data increases attack surface and impact, making deletion as important as protection in modern security practices. Read more...

Google Patches Actively Exploited Android Zero-Day (CVE-2025-48595) 

Google’s June 2026 security update addresses 124 vulnerabilities in Android, including CVE-2025-48595, a high-severity zero-day that was actively exploited in targeted attacks. The flaw enables local privilege escalation without user interaction, underscoring the growing focus of sophisticated threat actors on mobile devices as high-value entry points. Read more… 

CBSE Launches Security Review of OSM Platform After Vulnerability Reports 

The Central Board of Secondary Education (CBSE) has engaged experts from the Indian Institute of Technology Madras and the Indian Institute of Technology Kanpur to review security concerns in its On-Screen Marking (OSM) system used for Class 12 board examinations. The audit follows reports of weak authentication controls and potential cloud storage exposure, prompting a full-scale security assessment and hardening exercise.  Read more… 

Weekly Cybersecurity Takeaway 

This week’s incidents reinforce a consistent pattern: attackers are prioritizing identity compromise and trusted cloud platforms over traditional perimeter breaches. From phishing-as-a-service extortion campaigns targeting Microsoft 365 to long-term espionage operations and mobile zero-days, the common thread is the abuse of legitimate access rather than forced intrusion.  As organizations continue to expand cloud and mobile reliance, the attack surface is increasingly defined not by infrastructure boundaries, but by identity trust and administrative privilege. 
  • ✇Firewall Daily – The Cyber Express
  • DPDP and Cybersecurity: Why the Safest Data May Be the Data You Delete Editorial
    By Malcolm Gomes, COO, IDfy Seventy percent of all sensitive data sitting in enterprise systems right now has not been accessed, used, or reviewed in years, according to a Data Risk report from 2021. It was never deleted when it should have been and, in a breach, it is just as exposed as everything else. For years, enterprises treated personal data as an asset to be collected first and governed later. More data meant better personalization, sharper analytics, stronger fraud models, and business
     

DPDP and Cybersecurity: Why the Safest Data May Be the Data You Delete

5 de Junho de 2026, 04:40

DPDP and Cybersecurity

By Malcolm Gomes, COO, IDfy

Seventy percent of all sensitive data sitting in enterprise systems right now has not been accessed, used, or reviewed in years, according to a Data Risk report from 2021. It was never deleted when it should have been and, in a breach, it is just as exposed as everything else. For years, enterprises treated personal data as an asset to be collected first and governed later. More data meant better personalization, sharper analytics, stronger fraud models, and business intelligence. But in DPDP and cybersecurity, that equation is changing. Data without a clear purpose is no longer an asset. It is an attack surface.

India’s cyber risk environment makes this urgent. In 2025, CERT-In handled over 29.44 lakh cyber incidents. IBM’s 2025 breach research pegged the average cost of a data breach in India at ₹220 million, while the global average stood at USD 4.44 million. Verizon’s 2026 Data Breach Investigations Report found that 31% of breaches now start with software vulnerability exploitation, overtaking stolen credentials as the leading entry point.

What that figure means in practice is that attackers are no longer just looking for weak passwords. They are looking for unguarded data stores, and enterprises that hold more data than they need are giving attackers more to find.

Why DPDP and Cybersecurity Are Now Closely Connected

This is why the Digital Personal Data Protection (DPDP) framework should not be viewed only as privacy compliance. It is also a cybersecurity reset. It forces enterprises to ask a fundamental security question: why are we holding this data in the first place?

Data minimization is not about doing less business. It is about reducing unnecessary exposure. Every extra field collected, every duplicated customer record, every old document retained beyond its purpose, and every vendor copy sitting outside the organization’s control expands the blast radius of a breach.

Security teams can encrypt systems and monitor networks, but they cannot fully protect data that the business does not know exists, no longer needs, or cannot justify.

How DPDP Is Reshaping Data Governance

DPDP and cybersecurity changes that conversation. Organizations must be able to explain what they collect, why they collect it, how long they keep it, whom they share it with, and when it must be deleted.

These are not just legal requirements. They are security design principles.

The law also carries serious consequences. Failure to maintain reasonable security safeguards can attract penalties of up to ₹250 crore, while failure to notify the Board or affected individuals of a personal data breach can attract penalties of up to ₹200 crore.

The most secure piece of personal data is the one you never collected unnecessarily. The second most secure is the one you deleted when its purpose was fulfilled.

Data Minimization as a Cybersecurity Strategy

For Indian enterprises, digital journeys have become data-heavy by default. Onboarding, lending, insurance, healthcare, ecommerce, and fraud prevention journeys may all have legitimate reasons to process personal data. The challenge is to distinguish necessary data from convenient data.

Cyber risk is no longer limited to firewalls and endpoint protection. It includes data hoarding, excessive access, old records, test data, unused integrations, shadow databases, and third-party copies.

When a breach happens, regulators, customers, and partners will not only ask how the attacker got in. They will ask why so much data was there to be exposed.

Data minimization reduces three risks.

  • First, it reduces data breach risk. If expired data has already been deleted, it cannot be stolen. If a system contains ten required fields instead of fifty collected by habit, the harm is lower.
  • Second, it improves visibility. Many organizations struggle not because they lack security tools, but because they lack a reliable map of personal data across applications, databases, documents, cloud environments, and third parties. You cannot secure what you cannot see.
  • Third, it strengthens accountability. Product, operations, legal, vendor, and security teams must now work from the same understanding of purpose, consent, retention, and safeguards.

Together, these three elements create a mature enterprise cybersecurity posture.

Balancing Fraud Prevention and Personal Data Protection

The hardest balancing act will be fraud prevention.

Banks, insurers, fintechs, marketplaces, and digital platforms need strong controls to detect synthetic identities, account takeover, mule activity, payment fraud, and suspicious behavior. But fraud prevention cannot become a blanket justification for collecting everything.

The way forward is not to weaken fraud controls. It is to make them sharper.

Purpose-bound fraud prevention means collecting only the data required for a specific risk decision, using it with clear controls, retaining it for a justified period, and restricting access to systems that genuinely need it.

Good security does not require unlimited data. It requires the right data, governed well.

Why Trust Is Becoming a Competitive Advantage

This is where trust becomes a competitive advantage. Enterprises that can demonstrate why they collect data, how they protect it, and when they delete it will earn customer and partner confidence.

In a market where cyber threats are rising and regulatory scrutiny is increasing, trust will influence both customer choice and institutional credibility.

For boards and leadership teams, the question is no longer, “Are we DPDP compliant?”

The sharper question is, “Can we prove that our data practices reduce risk?”

Answering that question requires more than a compliance audit. It requires a live view of personal data across the enterprise: what exists, where it goes, who can access it, and whether it still needs to.

Privacy and security used to be treated as separate disciplines with separate teams, budgets, and agendas. That separation is no longer viable. A security team that does not know what personal data the business holds cannot protect it. A privacy team that does not have technical visibility into data flows cannot govern them.

The Future of DPDP and Cybersecurity

DPDP is not asking enterprises to choose between innovation and protection. It is asking them to build digital systems where innovation does not depend on uncontrolled data accumulation.

For too long, “collect more” was seen as the safer business strategy. In the DPDP era, the safer cybersecurity strategy may be the opposite: collect with purpose, protect with discipline, and delete with confidence.

Data minimization is no longer a privacy checkbox. It is becoming one of the most practical security controls an enterprise can deploy.

(Disclaimer: The views and opinions expressed in this article are those of the author and do not necessarily reflect the official position of The Cyber Express. This article is published as part of our contributed content program and is intended for informational purposes only.)

The Cyber Express Weekly Roundup: Supply Chain Attacks, Mobile Banking Malware, and Expanding Cloud Phishing Campaigns

The Cyber Express weekly roundup TCE

The cybersecurity landscape in this weekly roundup shows how attackers are shifting away from isolated systems and focusing instead on the trusted ecosystems that underpin modern digital infrastructure. Developer platforms, software supply chains, mobile app environments, and enterprise cloud services are now prime targets because they offer far greater reach; one compromise can quickly ripple across thousands of downstream users and services.  This shift matters because these systems sit at the core of how software is built, delivered, and accessed. CI/CD pipelines, package registries, mobile applications, and identity systems are no longer supporting components; they are high-value entry points. Once compromised, they allow attackers to scale rapidly, turning a single breach into a widespread impact event. 

The Cyber Express Weekly Roundup 

Iranian-linked Group Blamed for LA Transit Cyberattack 

A cyberattack targeting Los Angeles’ public transit infrastructure in March has now been attributed by researchers to a group known as “Ababil of Minab,” which is believed to have links to Iranian intelligence operations. Read more... 

Critical WordPress Plugin Flaw Enabled Full Site Takeover 

A severe vulnerability in the WP Maps Pro plugin has placed more than 15,000 WordPress websites at risk of complete compromise. The flaw, present in versions up to 6.1.0, stemmed from missing access control checks in an AJAX function. This allowed unauthenticated attackers to create administrator accounts, effectively granting full control over affected sites. Read more... 

OverlayPhantom Android Trojan Spreads Across Banking Apps 

A newly identified Android malware strain, dubbed “OverlayPhantom,” is actively targeting users of more than 180 banking and cryptocurrency applications across at least 10 countries. The malware spreads through deceptive update prompts, tricking users into installing malicious packages. Read more... 

“Megalodon” Supply Chain Attack Hits Thousands of GitHub Projects 

Security researchers have uncovered a large-scale supply chain compromise affecting more than 5,500 repositories hosted on GitHub within a six-hour window. The campaign, dubbed “Megalodon,” used malicious GitHub Actions workflows to inject code into development pipelines. Read more... 

FBI Flags Kali365 Phishing-as-a-service Targeting Microsoft 365 

The U.S. Federal Bureau of Investigation has issued a warning about a phishing toolkit known as “Kali365,” which is being used to compromise Microsoft 365 accounts at scale. Unlike traditional phishing campaigns that rely on stolen passwords, Kali365 is designed to intercept authentication tokens, allowing attackers to bypass multi-factor authentication protections. Read more... 

Weekly Cybersecurity Takeaway 

This week’s incidents highlight a cybersecurity environment defined by scale and automation rather than isolated breaches. From state-linked intrusions into public infrastructure to supply chain attacks affecting thousands of repositories in hours, attackers are clearly prioritizing systems that can multiply impact through trust relationships.  At the same time, mobile malware and phishing-as-a-service platforms continue to lower the barrier for entry, enabling both sophisticated actors and low-skill operators to conduct high-impact campaigns. The consistent theme across all cases is simple: once trust in a platform is compromised, whether a plugin, a CI/CD pipeline, or a login system, the downstream consequences can spread far beyond the initial target. 
  • ✇Firewall Daily – The Cyber Express
  • Why AI-Native Cybersecurity Matters in the Age of Machine-Speed Threats Editorial
    By Sharat Sinha, CEO, Airtel Business The world has entered an era where more than 20 billion connected devices generate continuous digital exhaust. In this hyperconnected environment, AI-native cybersecurity is emerging as a critical foundation for protecting digital ecosystems. Every transaction, sensor read, API call and remote login now feeds a vast digital nervous system supporting economies, governments and critical infrastructure. As adversaries weaponize automation and AI to scale
     

Why AI-Native Cybersecurity Matters in the Age of Machine-Speed Threats

26 de Maio de 2026, 07:11

AI-Native Cybersecurity

By Sharat Sinha, CEO, Airtel Business The world has entered an era where more than 20 billion connected devices generate continuous digital exhaust. In this hyperconnected environment, AI-native cybersecurity is emerging as a critical foundation for protecting digital ecosystems. Every transaction, sensor read, API call and remote login now feeds a vast digital nervous system supporting economies, governments and critical infrastructure. As adversaries weaponize automation and AI to scale reconnaissance and exploitation, the cyberattack surface has expanded faster than traditional defenses can adapt. To safeguard national and enterprise resilience, security must evolve from fragmented, reactive controls to an AI-powered, human-led, always-on model delivered through a unified security platform.

Why Traditional Security Models Are Failing

Traditional architectures were designed for static networks and stable perimeters. They were never built for cloud-native workloads, edge computing, distributed workforces or API-centric digital ecosystems. Threat actors, however, now operate at machine speed—using AI to craft hyper-targeted phishing, escalate privileges autonomously and exploit misconfigurations in minutes. Meanwhile, breach discovery in many organizations still spans months. This widening gap between attacker speed and defender response highlights the need for continuous, intelligence-driven protection across network, identity, cloud and data layers.

AI-Native Cybersecurity Is Transforming Threat Detection

Within this shift, AI is emerging as a force multiplier—not a replacement—for human expertise. AI-driven analytics reduce false positives by up to 60%, correlate billions of signals across hybrid environments and detect weak anomalies invisible to manual analysis. Predictive models identify the vulnerabilities most likely to be weaponized, shrinking patch backlogs and strengthening overall resilience. Behavioral algorithms reinforce identity security by spotting subtle deviations that precede credential compromise. Even configuration hygiene improves as AI continuously validates cloud and network settings, eliminating exposures before they become incidents.

Unified Security Platforms Are Becoming the New Standard

AI is also enabling entirely new security capabilities. AI assistants for security leaders can summarize incidents, explain posture drift and produce board-ready insights in seconds. Autonomous SOC workflows now triage, enrich and contain threats across identity, endpoint and cloud layers. DevOps and cloud engineering teams use AI copilots to enforce guardrails and detect compliance drift—addressing misconfiguration risks that consistently rank among the top causes of breaches worldwide. These advancements reflect a broader global shift toward unified, AI-first cybersecurity platforms, where intelligence becomes the connective fabric linking telemetry from identity, network, cloud and data. Rather than operating dozens of siloed tools, organizations gain a single operating layer where detection, decision-making and response flow seamlessly. This consolidation accelerates containment, eliminates blind spots and frees security teams to focus on high-impact decisions. AI also strengthens data protection and regulatory alignment, including emerging requirements under India’s DPDP Act. Automated data classification, policy violation monitoring, retention enforcement and real-time breach alerts shift privacy oversight from periodic checks to continuous assurance. As India’s digital economy scales—driven by cloud adoption, fintech innovation and public digital infrastructure—AI-driven governance ensures both compliance and protection without increasing operational burden.

The Future of Cyber Resilience Will Be AI-Driven

The global direction is clear: AI-first, human-centered unified platforms are becoming the foundation of modern cyber resilience. With cyber incidents costing organizations millions of dollars and often causing systemic ripple effects, intelligent consolidation is no longer an efficiency strategy—it is a national and enterprise resilience strategy. Looking ahead, cybersecurity will be defined by how effectively organizations integrate AI across the entire lifecycle—posture management, threat prediction, protection, governance and automated response—while empowering human judgment at every critical decision point. In a world where threats operate at machine speed, always-on, AI-powered end-to-end protection is becoming the new standard. Organizations that embrace unified, AI-driven architectures will be best positioned to safeguard their people, data and services with confidence in an increasingly unpredictable digital landscape.

The Cyber Express Weekly Roundup: Supply Chain Breaches, AI Content Enforcement, And Event Disruption Attacks

weekly roundup TCE The Cyber Express

The global cybersecurity landscape continues to evolve rapidly as attackers expand their focus on developer ecosystems, public-facing institutions, and anonymization infrastructure. At the same time, regulators and law enforcement agencies are stepping up enforcement efforts around AI misuse and cybercrime-enabling services. This week’s weekly roundup developments highlight how cyber threats are becoming increasingly distributed across platforms and industries, with supply chain compromises, operational disruptions, and policy enforcement actions shaping the broader risk environment.

The Cyber Express Weekly Roundup 

Austria Blocks Hundreds of Cyberattacks During Eurovision Week in Vienna 

Austria successfully prevented nearly 500 cyberattack attempts targeting systems connected to Eurovision operations during the contest week in Vienna. Officials stated that the attacks were intended to disrupt event infrastructure and associated services, but no major operational failures were recorded. Read more... 

Massive npm Supply Chain Attack Hits AntV Ecosystem 

A large-scale software supply chain compromise has impacted more than 300 npm packages within the AntV ecosystem following the hijacking of a trusted maintainer account. The compromised packages were reportedly modified as part of the “Mini Shai-Hulud” malware campaign, which targeted developer environments and widely used JavaScript libraries. Read more... 

Chanhassen Dinner Theatres Cyberattack Disrupts Operations and Ticketing Systems 

A cyberattack targeting Chanhassen Dinner Theatres disrupted key operational systems, including ticketing, payment processing, and customer communications, forcing additional cancellations of scheduled performances of “Guys and Dolls.” The disruption comes amid concurrent operational challenges, including an illness outbreak affecting performers and attendees, further complicating recovery efforts. Read more... 

FTC Targets AI “Nudify” Platforms Over TAKE IT DOWN Act Violations 

The U.S. Federal Trade Commission has issued formal warnings to multiple AI-powered “nudify” platforms over alleged violations of the TAKE IT DOWN Act, which requires rapid removal of nonconsensual intimate content upon valid request. According to regulators, several platforms failed to implement compliant removal workflows, including the mandated 48-hour takedown requirement. Read more... 

GitHub Confirms Internal Repository Breach via Malicious VS Code Extension 

GitHub has confirmed a security incident in which attackers accessed thousands of internal repositories after compromising an employee's device through a malicious Visual Studio Code extension. The company stated that there is no evidence of customer repository compromise or enterprise data exposure, and that the incident was contained following detection. Read more... 

European Authorities Shut Down VPN Service Used in Ransomware Operations 

European law enforcement agencies have seized the infrastructure of a VPN service known as First VPN during “Operation Saffron,” targeting its alleged use in supporting ransomware and cybercriminal operations. Authorities dismantled 33 servers and detained the suspected administrator in Ukraine. Read more... 

Weekly Cybersecurity Takeaway 

This week’s weekly roundup reflects a cybersecurity landscape defined by ecosystem-level compromise rather than isolated incidents. Supply chain attacks continue to target developer tooling and open-source ecosystems, while AI-related enforcement actions signal growing regulatory pressure around synthetic content abuse.  At the same time, law enforcement actions against anonymization infrastructure demonstrate a stronger focus on disrupting the operational backbone of cybercriminal networks. Taken together, these events highlight a shifting threat environment where compromise of platforms, dependencies, and infrastructure can cascade across multiple industries simultaneously. 
  • ✇Firewall Daily – The Cyber Express
  • EMEA Emerges as Global Hotspot for Financial Services DDoS Attacks Samiksha Jain
    The global financial sector is facing a sharp rise in Financial Services DDoS Attacks, with cybercriminals increasingly targeting banks, payment systems, and online financial platforms through larger, longer, and more attacks, according to new research from Akamai. In its latest State of the Internet (SOTI) Security report titled AI-Empowered Botnets and API Visibility Gaps: Attack Trends in Financial Services, research warned that AI-powered botnets and politically motivated hacktivist group
     

EMEA Emerges as Global Hotspot for Financial Services DDoS Attacks

Financial Services DDoS Attacks

The global financial sector is facing a sharp rise in Financial Services DDoS Attacks, with cybercriminals increasingly targeting banks, payment systems, and online financial platforms through larger, longer, and more attacks, according to new research from Akamai. In its latest State of the Internet (SOTI) Security report titled AI-Empowered Botnets and API Visibility Gaps: Attack Trends in Financial Services, research warned that AI-powered botnets and politically motivated hacktivist groups are intensifying the cyber threat landscape for the banking and financial services industry. Researchers found that Financial Services DDoS Attacks have become more persistent and operationally disruptive, particularly across Layers 3 and 4 web and API infrastructure.

Financial Services DDoS Attacks Top the Chart

According to the report, financial services organizations are now the most targeted industry for web and API distributed denial-of-service attacks. Akamai revealed that the median duration of global Layers 3 and 4 Financial Services DDoS Attacks has increased by 738% since 2024. The company attributed the surge to AI-powered attack infrastructure and growing hacktivist activity, including campaigns linked to pro-Iran cyber groups. Security researchers said attackers are increasingly focusing on:
  • Online banking systems
  • Real-time payment platforms
  • API infrastructure
  • Customer-facing financial applications
The report noted that while financial institutions continue expanding digital banking and payment services, the growing reliance on APIs and cloud-connected infrastructure has also expanded the attack surface available to threat actors.

API-Related Cyber Risks Emerging as Major Security Weakness

One of the strongest findings in the report involved API-related cyber risks. According to reserach’s 2026 API Security Impact Study, 96% of financial service leaders surveyed reported at least one API security incident within the past year. That figure was the highest recorded among all industries included in the research. The report also found that:
  • 60% of all web attacks in 2025 targeted banking institutions
  • 83% of attacks against API endpoints focused on financial organizations
Researchers warned that APIs are increasingly becoming high-value targets because they support critical services such as digital payments, account management, authentication systems, and mobile banking applications. Steve Winterfeld, Advisory Chief Information Security Officer at Akamai, said APIs are now central to modern cyberattacks against financial institutions. “Cybercriminals and hacktivists continue to escalate DDoS from nuisance attacks to a sustained siege encompassing both hacktivism and cybercrime, and financial services are in the crosshairs,” Winterfeld said. He added that artificial intelligence is accelerating existing cybersecurity threats rather than replacing them.

AI Botnets Driving DDoS Campaigns

The report highlighted how AI-driven infrastructure is helping attackers automate and scale malicious operations more effectively. Researchers observed a 147% surge in advanced bot activity during late 2025. In one case study referenced by Akamai, nearly 96% of all traffic reaching a targeted website was identified as malicious scraping bot activity. The company warned that AI-powered botnets are making Financial Services DDoS Attacks more difficult to detect and mitigate because attackers can dynamically adapt attack patterns and traffic behavior. These botnets are also being used to:
  • Overwhelm infrastructure
  • Disrupt payment systems
  • Target APIs
  • Scrape sensitive data
  • Launch credential abuse campaigns
Cybersecurity experts have increasingly warned that AI-enabled automation allows threat actors to launch large-scale attacks with fewer technical resources.

Attack Patterns Differ Across Global Regions

Research also identified major regional differences in cyberattack patterns targeting financial institutions. The report found:
  • Europe, the Middle East, and Africa accounted for 62% of Layers 3 and 4 DDoS attacks
  • Asia-Pacific experienced 52% of Layer 7 DDoS attacks
  • North America recorded the highest volume of web attacks at 44%
Researchers said these differences reflect varying attacker strategies, infrastructure deployment patterns, and regional cybersecurity maturity levels. The report also revealed that nearly 80% of financial institutions experienced ransomware attacks during the past two years. However, fewer than half of surveyed organizations reported adopting advanced cybersecurity technologies capable of handling modern attack methods.

Growing Pressure on Financial Sector Cybersecurity

The latest findings add to growing concerns around operational resilience within the global financial industry. As banks and financial institutions continue accelerating digital transformation initiatives, cybersecurity teams are being forced to defend increasingly complex environments that rely heavily on APIs, cloud platforms, automated infrastructure, and third-party integrations. Research said organizations must improve visibility into APIs, strengthen DDoS mitigation strategies, and modernize threat detection capabilities to address the evolving threat landscape. The SOTI report also includes guidance on DNS security, DDoS mitigation practices, AI architecture security considerations, and insights from financial sector cybersecurity experts, including contributions from the FS-ISAC.

The Cyber Express Weekly Roundup: AI Threat Escalation, Ransomware Disruption, Supply Chain Attacks, and Expanding Cybersecurity Risks

TCE weekly roundup TCE

In this weekly roundup from The Cyber Express, the global cybersecurity landscape in 2026 continues to shift rapidly as emerging technologies and evolving cyber threats reshape the digital environment. Governments are increasing oversight of artificial intelligence and data practices, while ransomware groups, nation-state actors, and cybercriminal networks are refining their tactics to target enterprises, critical infrastructure, and software supply chains.

This week’s developments highlight how modern cyber risks are becoming more interconnected across industries, with AI-driven attacks, ransomware operations, privacy concerns, and software supply chain compromises continuing to place pressure on organizations worldwide.

The Cyber Express Weekly Roundup 

AI Cyberattacks Surge Across the Americas in Early 2026 

Americas cyber threat landscape Cyber activity linked to artificial intelligence has intensified across the Americas during Q1 2026, with attackers increasingly leveraging AI-driven tools to scale ransomware campaigns, automate reconnaissance, and enhance social engineering operations. A scheduled webinar on May 28 by Cyble will bring together security specialists to examine emerging cyber trends, including ransomware evolution, nation-state activity, and defensive strategies to improve cyber resilience. Read more... 

Foxconn Confirms Cyberattack Amid Ransomware Claims of Massive Data Theft 

Manufacturing giant Foxconn confirmed a cyberattack that disrupted operations at several North American facilities following claims from the Nitrogen ransomware group. The attackers alleged they had stolen more than 8TB of corporate data, including over 11 million files. Foxconn activated incident response procedures and stated that operations were gradually returning to normal. Read more... 

Microsoft Patches 120 Vulnerabilities in May 2026 Security Update 

In its May 2026 Patch Tuesday release, Microsoft addressed approximately 120 security vulnerabilities across a wide range of products, including Windows, Office, SharePoint, DNS services, and enterprise platforms. Among these were 17 classified as critical severity issues. Although no actively exploited zero-day vulnerabilities were reported in this cycle, multiple high-risk remote code execution flaws prompted security researchers to recommend immediate patch deployment across enterprise environments. Read more... 

California Issues Record $12.75 Million Privacy Settlement Against GM 

California regulators reached a $12.75 million settlement with General Motors over allegations tied to violations of the California Consumer Privacy Act (CCPA). Authorities claimed the company collected, retained, and sold driver data without proper consent. The investigation alleged that General Motors shared sensitive geolocation and driving behavior data from its OnStar platform with data brokers LexisNexis and Verisk between 2020 and 2024. Read more... 

Malicious npm Packages Fuel JavaScript Supply Chain Attack 

Security researchers have identified a supply chain compromise targeting the widely used node-ipc npm package ecosystem. Several versions—including 9.1.6, 9.2.3, and 12.0.1—were found to contain malicious code designed to act as a credential-stealing backdoor. The compromised packages reportedly collected sensitive system information, developer credentials, and CI/CD pipeline secrets from affected environments. Read more... 

Weekly cybersecurity takeaway 

This week’s The Cyber Express weekly roundup highlights how modern cybersecurity threats are increasingly interconnected across technology, regulation, and supply chains. AI-driven attacks are expanding operational scale; ransomware groups continue to rely on data theft and disruption, and software supply chain compromises are increasingly targeting developer ecosystems. At the same time, regulatory and legal responses, from privacy settlements to vulnerability patch cycles, continue to evolve in parallel. The overall landscape suggests that cyber risk in 2026 is no longer confined to individual incidents but is instead shaped by continuous pressure across infrastructure, software, and data governance layers.
❌
❌