Visualização normal

Antes de ontemFirewall Daily – The Cyber Express

The Cyber Express Weekly Roundup: Claude Session Hijacking, PaperCut Exploits, and Enterprise Cyberattacks

4 de Setembro de 2026, 08:48

Weekly Roundup September 2026

This weekly roundup highlights a range of cybersecurity developments affecting artificial intelligence platforms, enterprise software, healthcare organizations, social media accounts, and internet-facing infrastructure.  From stolen Claude sessions and bypassed PaperCut security fixes to an attempted attack targeting hundreds of thousands of X users, recent incidents demonstrate how attackers continue to exploit both software vulnerabilities and active user sessions.  The latest developments also show that organizations face growing risks across AI services, on-premises systems, enterprise edge devices, and account recovery infrastructure. Security teams are being urged to respond quickly as attackers increasingly target exposed systems and authentication mechanisms. 

The Cyber Express Weekly Roundup 

Anthropic Warns of Claude Session Hijacking 

Anthropic has warned that common infostealer malware is being used to steal active Claude sessions, potentially allowing attackers to bypass passwords and two-factor authentication. The campaign involves malware such as Vidar, LummaC2, RedLine, and Atomic Stealer, which is often distributed through pirated software and illicit downloads. Attackers may also consume victims’ paid AI usage. Read more… 

PaperCut Releases Second Emergency Patch After First Fix Is Bypassed 

PaperCut has released a second emergency patch for two actively exploited vulnerabilities affecting its NG and MF print management servers. Researchers discovered ways to bypass the initial security fix, potentially allowing attackers to chain the flaws and achieve pre-authentication remote code execution on exposed systems. Read more… 

Boston Scientific Cyberattack Limited to Certain On-Premises Systems 

Boston Scientific says its ongoing cybersecurity incident is limited to certain on-premises systems, with no impact identified on its cloud-based applications. The company has also reported no confirmed data breach or evidence of unauthorized activity since August 25, as its investigation into the incident continues. Read more… 

DOJ Investigates Attempted Cyberattack on Hundreds of Thousands of X Users 

The U.S. Department of Justice is investigating a large-scale cyberattack targeting hundreds of thousands of X accounts through the platform’s password-recovery system. Attorney General Todd Blanche said X detected and disrupted the campaign before the targeted accounts could be captured, preventing the attempted account takeover operation from succeeding. Read more… 

Two Citrix NetScaler Flaws Put Enterprise Edge Devices at Risk 

Two vulnerabilities in Citrix NetScaler ADC and Gateway have prompted an urgent patching warning from Australia’s cybersecurity agency. CVE-2026-19489, a memory overflow flaw, and CVE-2026-19490, an authentication bypass, can affect systems with specific configurations involving SIP ALG, SAML, or VPN gateway functionality. Read more… 

Weekly Cybersecurity Takeaway 

This week’s developments demonstrate that cybersecurity threats are increasingly targeting authentication systems, active user sessions, exposed enterprise infrastructure, and critical business applications. AI platforms, print management servers, healthcare environments, social media accounts, and network edge devices all remain potential targets for attackers.  Organizations should prioritize rapid security patching, protection of active sessions, strong authentication controls, careful monitoring of exposed infrastructure, and timely investigation of suspicious activity. Security teams should also review systems that rely on password-recovery mechanisms and identify enterprise devices operating with vulnerable configurations.  As businesses continue to rely on cloud services, AI platforms, remote access technologies, and internet-facing enterprise systems, attackers are finding new opportunities to exploit trusted sessions and security weaknesses. Organizations must maintain continuous monitoring and rapid response capabilities to reduce the impact of increasingly targeted cyberattacks. 

The Cyber Express Weekly Roundup: Exploited Entra ID Flaw, AI Agent Risks, and Global Cybercrime Crackdown

28 de Agosto de 2026, 08:17

The Cyber Express weekly roundup, podcast

This weekly roundup highlights a broad range of cybersecurity and technology developments affecting cloud identity infrastructure, social media platforms, businesses, digital assets, and international law enforcement.   From a critical Microsoft Entra ID vulnerability exploited before remediation to a global crackdown on West African cybercrime networks, recent developments demonstrate how attackers continue to target both technical systems and human trust.  The latest developments also show that cybersecurity risks are expanding alongside the rapid adoption of cloud services and artificial intelligence. Organizations are facing threats involving identity infrastructure, autonomous AI agents, software vulnerabilities, digital transactions, online fraud, and the misuse of emerging technologies. 

The Cyber Express Weekly Roundup 

Microsoft Confirms Exploited Entra ID Flaw 

Microsoft confirmed that a critical vulnerability in Entra ID, CVE-2026-69836, was exploited before the flaw was fixed server-side. The vulnerability carries a CVSS score of 10.0 and could allow unauthenticated attackers to achieve remote code execution, potentially affecting Microsoft’s cloud-based identity infrastructure. Read more... 

New Zealand Proposes Social Media Ban for Under-16s 

New Zealand has introduced legislation that would require high-risk social media platforms to prevent users under the age of 16 from accessing their services. Proposed age-verification methods could include digital identification, facial age estimation, or official identification documents. Read more... 

Cyble and DRONA Launch AI Cyber Defense Initiative in India 

Cyble and DRONA Cyber Solutions have launched an AI-powered cybersecurity initiative in Ahmedabad aimed at helping mid-sized businesses detect, investigate, and contain cyber threats. The initiative combines threat intelligence, AI-driven investigations, and endpoint enforcement to provide organizations with faster and more coordinated responses to security incidents. Read more... 

AI Agents Could Create New Cybersecurity Risks 

Adarsh Kant Sinha, CEO of ANVE.AI, warned that autonomous AI agents could introduce significant new cybersecurity risks as organizations increasingly allow them to interact with business-critical systems. AI agents may gain access to email, customer relationship management platforms, cloud infrastructure, and financial systems, potentially creating new avenues for misuse or compromise. Read more... 

Ledger Fixes Ethereum App Flaw Amid Disclosure Dispute 

Ledger said it fixed a clear-signing vulnerability in its Ethereum application approximately two weeks before security firm TestMachine publicly disclosed the issue. The vulnerability could potentially allow a malicious application to display one transaction to a user while preparing a different transaction for signing. Read more... 

Global Crackdown Nets 58 Arrests in West African Crime Networks 

An eight-month international law enforcement operation led by INTERPOL has resulted in 58 arrests and the identification of 263 suspects across 22 countries. Operation Jackal IV targeted West African criminal networks involved in cyber-enabled fraud, money laundering, romance scams, and investment scams. Read more... 

Weekly Cybersecurity Takeaway 

This week’s developments demonstrate that cybersecurity threats are crossing organizational, technological, and geographical boundaries, affecting cloud identity systems, artificial intelligence, digital platforms, cryptocurrency applications, and international financial crime.  Organizations should prioritize strong identity and access controls, rapid vulnerability remediation, careful management of AI-agent permissions, secure integrations, human oversight, and continuous threat monitoring.   As autonomous technologies become more deeply integrated into business operations and cybercriminal networks continue to operate across borders, security teams must adapt to a threat landscape that is becoming broader, more interconnected, and increasingly difficult to contain. 

The Cyber Express Weekly Roundup: Tax Data Breach, AI Security Risks, and Critical GitLab Flaw

21 de Agosto de 2026, 10:28

The Cyber Express August 21 Weekly Roundup

This weekly roundup highlights a broad range of cybersecurity threats affecting government agencies, businesses, enterprise AI systems, and software platforms. From a major French tax authority breach to a critical GitLab vulnerability, recent incidents demonstrate how attackers continue to exploit sensitive data, digital systems, and emerging technologies. The latest developments also show that cybersecurity risks are expanding beyond traditional attacks. Organizations are increasingly facing threats involving sensitive customer information, AI-powered systems, supply-chain risks, software vulnerabilities, and potential interference with critical operations.

The Cyber Express Weekly Roundup

French Tax Authority Data Breach Hits 678,000 People 

France’s tax authority, DGFiP, confirmed a cyberattack that exposed tax and cadastral information belonging to 678,000 individuals and professionals. The accessed information includes tax income, withholding rates, business details, addresses, and property information. DGFiP said online accounts and passwords were not compromised and is continuing to investigate the incident. Read more... 

Cyberattack Targets Ukraine Agency Ahead of Major Asset Tender 

Ukraine’s Asset Recovery and Management Agency (ARMA) suffered a suspected cyberattack shortly before a major deadline to select a manager for assets linked to sanctioned Russian oligarch Mikhail Fridman. ARMA said the incident, combined with earlier cyber activity and increased information pressure, could indicate a coordinated attempt to disrupt its operations or influence the tender. Read more... 

Oz Hair and Beauty Data Breach Exposes Customer Information 

Oz Hair and Beauty confirmed that an unauthorized party accessed customer information, including names, email addresses, phone numbers, and purchase history. The company said credit card, banking, and home-address information were not compromised. The number of affected customers remains undisclosed, while an investigation into the breach continues. Read more... 

Enterprise AI Is Expanding the Cybersecurity Risk 

Guild Group’s Mohammad Arif warned that the rapid adoption of enterprise AI is creating new cybersecurity challenges as AI systems gain access to sensitive data, applications, and business workflows. Key concerns include shadow AI, data leakage, insecure integrations, AI supply-chain attacks, prompt injection, and AI-powered phishingRead more... 

Critical GitLab Flaw Could Let Attackers Delete Public Projects 

GitLab patched a critical vulnerability, CVE-2026-19478, that could allow unauthenticated attackers to remotely modify or delete public projects and user data. The flaw carries a CVSS score of 9.4. GitLab also addressed a high-severity GraphQL CSRF vulnerability, CVE-2026-19650. Read more... 

Weekly Cybersecurity Takeaway 

This week’s incidents demonstrate that cybersecurity threats are increasingly crossing organizational and technological boundaries, affecting government systems, customer data, enterprise AI, and software development platforms. Organizations should prioritize strong access controls, rapid vulnerability patching, data protection, AI governance, employee awareness, and continuous monitoring. As attackers continue exploiting both human trust and technical weaknesses, security teams must adapt to a threat landscape that is becoming broader, faster, and increasingly interconnected.
  • ✇Firewall Daily – The Cyber Express
  • Guild Group’s Mohammad Arif on the Security Risks of Enterprise AI Samiksha Jain
    Every enterprise wants the upside of AI — faster workflows, sharper decisions, leaner teams. Far fewer have asked the harder question: what happens when the same systems delivering that upside are also quietly rewriting who, or what, has access to the crown jewels? Autonomous agents are now reading contracts, touching customer data, writing production code, and triggering workflows once reserved for trusted employees. The attack surface hasn't just grown — it's changed shape entirely. Mohamma
     

Guild Group’s Mohammad Arif on the Security Risks of Enterprise AI

20 de Agosto de 2026, 07:53

The Cyber Express Mohammad Arif

Every enterprise wants the upside of AI — faster workflows, sharper decisions, leaner teams. Far fewer have asked the harder question: what happens when the same systems delivering that upside are also quietly rewriting who, or what, has access to the crown jewels? Autonomous agents are now reading contracts, touching customer data, writing production code, and triggering workflows once reserved for trusted employees. The attack surface hasn't just grown — it's changed shape entirely. Mohammad Arif, Head of Information Security at Guild Group, has been on the front line of that shift, helping enterprise leaders separate genuine AI-driven cyber risk from the noise around it. In this interview with The Cyber Express, he makes the case that AI security isn't a niche technical concern to be handed off to a working group — it's a boardroom issue, sitting at the intersection of data protection, vendor risk, identity, and human accountability. His warning is blunt: organisations still treating AI security as tomorrow's problem are already behind, and the cost of catching up only rises from here.

The Cyber Expres: Everyone is talking about AI productivity. From a security leadership perspective, what is the biggest shift AI is creating for enterprises?

From a security leadership perspective, the biggest shift is that AI is changing the enterprise trust model. It is no longer only about protecting systems, networks, and users. Organisations now need to consider what AI can access, what data it can process, what decisions it may influence, and what actions it may trigger. AI can significantly improve productivity, cyber defence, and business decision-making. But the risk increases when adoption moves faster than governance. If AI tools are connected to sensitive data, enterprise workflows, identity systems, APIs, or business processes without clear controls, the risk is no longer just a technology issue. It becomes a data, privacy, operational resilience, and trust issue. So the real shift is this: AI is not just another productivity tool. It is becoming part of the enterprise operating model, and therefore it needs to be governed and secured like any other critical capability.

The Cyber Express: What worries you most about the current pace of AI adoption across organisations?

What worries me most is the gap between the speed of AI adoption and the maturity of AI governance. Many organisations are moving quickly to unlock productivity benefits, but they may not yet have clear rules around approved use cases, sensitive data handling, vendor assurance, retention of information, model outputs, and human accountability. The immediate risk is uncontrolled or "shadow" AI adoption, where employees or teams use public or unapproved AI tools without understanding what data is being entered, how that data may be retained, or whether it could be used to improve external models. This can create confidentiality, privacy, intellectual property, and regulatory risks. The challenge for enterprises is not to slow down innovation unnecessarily. The challenge is to enable AI safely — giving employees approved pathways to use AI, while putting the right controls around data protection, access, monitoring, and risk-based governance.

The Cyber Express: At what point does AI stop being just a productivity tool and become a real enterprise security challenge?

AI becomes a real enterprise security challenge when it moves from simply generating content to being connected to enterprise data, identity, applications, APIs, tools, and workflows. A standalone AI assistant used for drafting general content has a different risk profile from an AI agent that can access customer information, analyse internal documents, write code, trigger workflows, or make recommendations that people rely on. The risk increases further when AI has autonomy, can call external tools, or can operate across multiple systems. This is where agentic AI becomes important. The question is no longer only "what can the model say?" It becomes "what can the AI access, what can it do, and who is accountable for the outcome?" That is the point where traditional security controls need to extend into AI governance, identity, permissions, logging, monitoring, and human oversight.

The Cyber Express: Do you think most organisations are prepared for AI-driven cyber threats, or are many still treating AI security as a future problem?

Preparedness varies significantly. Some organisations are taking AI security seriously and are building governance, security review, data protection, and monitoring into their AI adoption programs. But many are still treating AI security as a future problem, even though AI is already inside the enterprise through productivity tools, SaaS platforms, coding assistants, analytics tools, third-party services, and employee-led experimentation. The issue is that AI adoption is often decentralised. It may start in business teams, technology teams, vendors, or individual users before the organisation has a complete view of the risks. That means security leaders need to shift from reactive control to proactive enablement. AI security readiness should include clear acceptable-use guidance, approved tools, data classification, vendor due diligence, secure development practices, incident response scenarios, awareness training, and monitoring. Without those foundations, organisations may not know where AI is being used, what data is exposed, or where the risk is accumulating.

The Cyber Express: What AI-related security incidents do you realistically expect enterprises to face over the next 12 months?

Over the next 12 months, I expect most enterprises to see AI-related incidents in a few practical areas. The first is AI-assisted social engineering. Phishing, impersonation, business email compromise, and executive fraud will become more convincing because AI allows attackers to generate personalised and credible content at scale. The second is sensitive data leakage into AI tools, which may happen when employees enter confidential business information, customer data, source code, contracts, security information, or internal documents into tools that have not been approved or assessed. The third is insecure AI integration. As teams connect AI to internal knowledge bases, applications, plugins, and workflows, weaknesses such as prompt injection, excessive permissions, poor output validation, or weak monitoring may create new attack paths. The fourth is AI supply-chain risk. Organisations increasingly rely on third-party models, APIs, datasets, plugins, open-source components, and AI-enabled SaaS platforms — each introducing dependencies that need to be assessed and monitored. So the threat is not one single scenario. It is an expanded attack surface across people, data, applications, vendors, and business processes.

The Cyber Express: AI-generated phishing and deepfakes are receiving significant attention. Have these threats become genuinely dangerous, or are they still more hype than reality?

They are genuinely dangerous, but the risk needs to be understood properly. The concern is not only that AI can create fake emails, voices, images, or videos. The bigger issue is that AI reduces the effort required to create believable, personalised, and scalable deception. Traditional phishing often had indicators such as poor grammar, generic wording, or obvious formatting issues. AI reduces those indicators. Attackers can tailor messages to specific roles, business processes, recent events, or organisational language. Deepfakes also create risk where organisations rely heavily on voice, video, or informal executive instructions for approvals or sensitive actions. This does not mean every organisation will face sophisticated deepfake attacks immediately. But it does mean that trust-based processes need to be strengthened. Payment approvals, changes to bank details, privileged access requests, sensitive data transfers, and executive instructions should have strong verification controls that do not rely on one communication channel alone.

The Cyber Express: Do enterprises fully understand the risks of feeding sensitive data, business context, or internal information into frontier AI systems?

Not always. Many organisations understand the general concern, but they may not fully understand the practical ways sensitive information can be exposed through AI usage. The risk is broader than simply entering customer data into a public tool. Employees may enter internal strategies, contracts, security designs, source code, incident information, board papers, commercial terms, or confidential business context. Even if the data is not used for model training, there may still be risks around retention, access, logging, jurisdiction, vendor terms, and downstream use. Enterprises need to apply the same discipline to AI that they apply to other sensitive platforms — understanding what data is allowed, which tools are approved, whether enterprise-grade privacy and security settings are enabled, how data is retained, and whether the vendor's contractual terms align with the organisation's obligations. The practical starting point is data classification. If organisations do not know what data is sensitive, they cannot consistently govern how that data should or should not be used with AI.

The Cyber Express: We have seen supply-chain attacks target software and open-source ecosystems. Could AI models, tools, plugins, agents, datasets, and integrations become the next major supply-chain risk?

Yes, AI supply-chain risk is likely to become a major area of focus. In traditional technology environments, organisations already assess software vendors, cloud providers, managed service providers, open-source libraries, and third-party integrations. AI expands that supply chain. The AI supply chain can include foundation models, fine-tuned models, datasets, model providers, APIs, plugins, orchestration platforms, vector databases, prompt libraries, AI coding tools, agent frameworks, and embedded AI features in SaaS products. A weakness or compromise in any of these areas can affect the confidentiality, integrity, or reliability of AI-enabled systems. A poorly governed dataset could introduce bias or inaccurate outputs. A vulnerable plugin could expose data. A compromised package could affect an AI-enabled application. An over-permissioned AI agent could access more information than it needs. These are not only technical risks; they are third-party, operational, and governance risks. Enterprises should therefore treat AI supply-chain assurance as part of broader cyber risk and vendor risk management, including due diligence, contractual controls, security testing, data protection review, monitoring, and clear accountability between the organisation and its providers.

The Cyber Express: How should security leaders rethink traditional cybersecurity strategies in a world where AI can write code, analyse vulnerabilities, automate tasks, and support attackers as well as defenders?

Security leaders should not abandon traditional cybersecurity principles. Instead, they need to extend them into AI-enabled environments. Identity and access management remains critical, but now we need to consider identities and permissions associated with AI agents, service accounts, APIs, and automated workflows. Data protection remains critical, but now we need to monitor prompts, outputs, embeddings, and knowledge retrieval systems. Secure development remains critical, but now we need to assess AI-generated code, model behaviour, prompt injection risks, and third-party AI components. The same applies to monitoring and incident response. Security teams need visibility into AI usage, unusual activity, sensitive data exposure, misuse of AI tools, and unexpected agent behaviour. Incident response plans also need to consider AI-specific scenarios such as data leakage through AI platforms, compromise of AI integrations, prompt injection, poisoned data, or misuse of AI-generated code. The key point is that AI security should not sit outside the cybersecurity operating model. It should be integrated into governance, architecture, procurement, engineering, monitoring, awareness, and incident response.

The Cyber Express: Are existing cybersecurity teams equipped to handle AI-era threats, or does the industry need new skills and operating models?

Existing cybersecurity skills remain highly relevant, but they need to be expanded. The fundamentals still matter: identity, data protection, secure architecture, vulnerability management, incident response, third-party risk, and governance. However, AI introduces new concepts that security teams need to understand. Security professionals now need AI literacy — how large language models work at a practical level, how AI applications are integrated, how prompts and outputs can be manipulated, how retrieval-augmented generation works, how AI agents interact with tools, and how AI supply chains are structured. The operating model also needs to evolve. AI security cannot be owned by security alone. It requires collaboration between cybersecurity, technology, data, privacy, legal, risk, procurement, HR, and business teams. In many organisations, the most effective model will be a cross-functional AI governance group supported by security-by-design processes. So yes, the industry needs new skills, but not at the expense of existing cybersecurity disciplines. The future is a combination of traditional cyber expertise, AI literacy, risk management, and business enablement.

The Cyber Express: AI vendors promise speed, scale, and automation. Where should organisations avoid over-relying on AI in cybersecurity and business decision-making?

Organisations should avoid over-relying on AI in areas where decisions are high-impact, sensitive, difficult to reverse, or require strong judgement. AI can assist, but accountability should remain human. In cybersecurity, this includes incident severity decisions, containment actions, identity and privileged access approvals, regulatory interpretation, legal assessments, and decisions that could materially affect customers, employees, or critical operations. AI can help summarise information, detect patterns, prioritise alerts, and recommend actions, but those recommendations should be validated by qualified people. There is also a risk of automation bias, where people trust AI outputs because they appear confident or well-structured. That can be dangerous if the output is incomplete, inaccurate, or based on weak context. Organisations need clear rules for where AI can automate, where it can recommend, and where human approval is mandatory. A practical principle is this: the greater the potential impact, the stronger the need for human oversight, auditability, and accountability.

The Cyber Express: If you were advising enterprise leaders today, what are the first three things they should do to prepare for the security impact of frontier AI models?

The first priority is to establish AI governance. Organisations need clear policies on approved use cases, acceptable tools, data handling, human oversight, and accountability. Governance should not be theoretical — it needs to be embedded into procurement, technology delivery, data management, security review, and business processes. The second priority is to protect sensitive data before scaling AI adoption. This means strengthening data classification, access controls, data-loss prevention, retention rules, and monitoring. Enterprises should know what data can be used with AI, under what conditions, and through which approved platforms. The third priority is to integrate AI into the cyber risk management operating model — including third-party risk assessments, threat modelling, secure development, incident response, employee awareness, logging, monitoring, and assurance activities. Security teams should also start preparing for AI-specific risks such as prompt injection, insecure integrations, sensitive data exposure, excessive agency, and AI supply-chain compromise. AI can create significant value, but only if organisations adopt it with discipline. The organisations that treat AI security as a future issue may already be behind.
"AI adoption without governance is not innovation — it is unmanaged risk. The next phase of enterprise security is about controlling what AI can access, what it can do, and who remains accountable." — Mohammad Arif, Head of Information Security, Guild Group

The Cyber Express Weekly Roundup: Corporate Cyberattacks, AI Security Risks, Zero-Days, and Data Theft

14 de Agosto de 2026, 08:20

weekly roundup The Cyber Express cybersecurity 2026

This weekly roundup highlights the expanding range of threats facing businesses, technology platforms, and individuals. From social engineering attacks against corporate systems and vulnerabilities uncovered by AI agents to large-scale software patches and cyberattacks disrupting logistics operations, recent incidents demonstrate how quickly the threat landscape is evolving.  The latest developments also show that cybersecurity risks are no longer limited to traditional malware or ransomware. Attackers are increasingly exploiting human behavior, software weaknesses, interconnected supply chains, and personal online accounts. At the same time, artificial intelligence is emerging as both a defensive tool and a new way to identify security weaknesses. 

The Cyber Express Weekly Roundup 

Levi Strauss Targeted in Cyberattack, Corporate Files Accessed 

Levi Strauss & Co. disclosed a cybersecurity incident after attackers used social engineering techniques to gain access to three company-issued computers. The company believes certain corporate files were accessed and some information may have been exfiltrated. Levi Strauss said it moved quickly to contain the incident and terminate the unauthorized access, limiting the potential impact of the attack. Read more...

AI Agent Exploits Gym Booking Vulnerability 

An AI-powered agent reportedly identified an authentication weakness in an Australian gym’s online booking system. The agent, powered by Anthropic’s Claude and operated through OpenClaw, was originally instructed to help a user book a popular class. During the process, it was able to reserve classes months ahead and cancel another customer's booking. Read more...

AI Will Automate Cybersecurity Toil, Not Replace Security Professionals 

Harsha Reddy, Head of Information Security at Veterinary Emergency Group, argues that artificial intelligence is more likely to transform cybersecurity work than eliminate cybersecurity jobs. AI can assist with repetitive activities such as reviewing logs, triaging alerts, and collecting evidence, allowing security professionals to concentrate on investigation, strategy, and higher-value defensive operations. Read more...

Microsoft Fixes More Than 400 Security Flaws 

Microsoft’s August 2026 Patch Tuesday addresses roughly 400 vulnerabilities across its products, including three zero-days. One of the vulnerabilities was reportedly being actively exploited, while two others had been publicly disclosed before patches became available. The update includes 42 critical vulnerabilities, with 37 associated with remote code execution, reinforcing the importance of timely patching across enterprise environments. Read more...

CEVA Logistics Cyberattack Disrupts European Operations 

A cyberattack against CEVA Logistics disrupted activity at eight European warehouses on July 29, affecting shipments and exposing customer data connected to several major clients. The logistics company, part of the CMA CGM Group, has not publicly identified the attackers or provided detailed information about the technical nature of the incident. Read more...

FBI Warns of Theft of Explicit Content From Social Media 

The FBI has warned that cybercriminals are targeting social media and personal accounts to steal explicit images and videos, including non-consensual intimate images. Stolen material may subsequently be distributed or sold online, while associated personal information can expose victims to harassment, stalking, and sextortion. Read more...

Weekly Cybersecurity Takeaway 

This week’s incidents demonstrate that cybersecurity risks are expanding across corporate networks, software ecosystems, supply chains, AI-powered systems, and personal accounts.  Organizations should prioritize strong authentication, rapid vulnerability patching, employee awareness, third-party risk management, and continuous monitoring. At the same time, responsible use of AI could help security teams reduce repetitive workloads and respond more effectively to emerging threats.  As attackers continue finding new ways to exploit technology and human trust, organizations and individuals must strengthen security controls while remaining prepared for threats that increasingly cross traditional digital boundaries. 

💾

Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.

The Cyber Express Weekly Roundup: Ransomware Surge, Government Data Breaches, Logistics Disruptions, and Third-Party Security Risks

The Cyber Express weekly roundup H1

This weekly roundup highlights the growing cybersecurity risks affecting businesses, government agencies, and critical service providers. From the continued dominance of ransomware operations to government database breaches and third-party supply chain incidents, recent events demonstrate how attackers are increasingly targeting trusted systems and external service providers to maximize disruption and data exposure.  The latest developments reinforce that cyber threats are no longer limited to direct attacks on organizations. Threat actors are exploiting ransomware-as-a-service ecosystems, compromising government registries, targeting law enforcement databases, and abusing third-party platforms that support retail and healthcare operations.   Organizations must strengthen third-party risk management, improve data protection measures, and enhance incident response capabilities to reduce the impact of evolving cyber threats. 

The Cyber Express Weekly Roundup 

Qilin Dominated Ransomware Attacks in H1 2026 

Qilin emerged as the most active ransomware group during the first half of 2026, targeting organizations worldwide through its ransomware-as-a-service (RaaS) operation. Manufacturing, healthcare, construction, and professional services were among the sectors most affected as the group continued expanding its global reach. Read more… 

Hackers Breach Beneficial Owners Registry, Expose Data of 31,000 Firms 

Hackers breached the Register of Beneficial Owners (VwbP), gaining unauthorized access to data associated with approximately 31,000 legal entities. Authorities temporarily took the registry offline, launched an investigation, and established a crisis response team, stating there is currently no evidence that records were altered or deleted. Read more… 

PNLD Data Breach Leaks Police and Government Contact Details 

A data breach involving the Police National Legal Database (PNLD) exposed names, organizations, and work email addresses belonging to police officers, government partners, criminal justice professionals, and some Ask the Police users after the information appeared on the dark web. Authorities are investigating the incident and assessing its potential impact. Read more… 

De Bijenkorf Logistics Cyberattack Delays Orders and Raises Data Exposure Concerns 

A cyberattack targeting a third-party logistics provider disrupted deliveries, returns, and refunds for Dutch retailer De Bijenkorf. While the retailer confirmed its internal systems were not compromised, investigators are assessing whether customer contact details and order information were exposed. Payment information, passwords, and financial data were not affected, and customers have been advised to remain vigilant against phishing attempts. Read more… 

Updoc Data Breach Exposes Customer Contact Information 

Australian telehealth provider Updoc disclosed a data breach after unauthorized access to a third-party operational platform exposed some customers' names, email addresses, and postal addresses. The company confirmed that its internal systems remained secure and that no medical records, payment information, or financial data were compromised. Read more… 

Weekly Cybersecurity Takeaway 

This week's incidents highlight the continued evolution of cyber threats across ransomware operations, government data breaches, and third-party supply chain compromises.  A common theme across these events is the growing risk posed by trusted third-party platforms and shared digital ecosystems. Attackers are targeting external service providers, government databases, and ransomware affiliate networks to expand their reach and maximize operational disruption.  Organizations should prioritize stronger third-party risk management, continuous monitoring, robust access controls, and timely incident response to reduce the impact of supply chain attacks and data breaches. As businesses become more interconnected, strengthening the security of partner ecosystems is becoming just as important as protecting internal infrastructure. 

Updoc Data Breach Exposes Patient Contact Information Following Third-Party Security Incident

Updoc data breach

The Updoc data breach has raised fresh concerns about cybersecurity in Australia's healthcare sector after the telehealth provider confirmed that an unauthorized third party may have accessed customer contact information through an external system.   The data breach at Updoc, disclosed on August 7, stemmed from a brief security incident involving a third-party platform that supports the company's operations. While the Updoc cyberattack did not expose medical or financial records, it is the latest cyber incident affecting Australia's healthcare sector. 

Updoc Data Breach Traced to Third-Party Platform 

Updoc, an Australian telehealth provider offering round-the-clock online healthcare services, including medical certificates, prescriptions, and specialist referrals, detected unauthorized access to a third-party operational system on Friday, July 31.  In a statement shared with The Cyber Express, the company said the incident was limited to an external system used to support its operations. The exposure was confined to customer contact information, which may have included account holders' names, email addresses, and postal addresses.  Updoc said its internal systems were not accessed during the incident and confirmed that no health records, financial information, or payment details were involved. The company added that it acted immediately to block the unauthorized access and found no evidence of any further activity after the initial event.  According to the company, customers are not required to take any immediate action because account logins and security remain unaffected. Updoc also apologized for any concern or inconvenience caused by the incident. 

Updoc Cyberattack Adds to Healthcare Sector Threats 

Founded in 2021, Updoc generates approximately $10 million in annual revenue. According to its founders, the platform has served more than one million patients since launch, while its website states that it has over 500,000 users.  The Updoc cyberattack follows a series of cybersecurity incidents targeting Australian healthcare and consumer-facing organizations. In June, clinic network Partnered Health disclosed a cyberattack in which hackers stole personal information and health records from patients across at least 21 clinics in five Australian states.  That breach exposed sensitive information, including medical records, Medicare numbers, consultation notes, referral letters, and pathology results. The attack affected clinics in Melbourne, Sydney, Canberra, the Gold Coast, Sunshine Coast, and Coffs Harbour. At the time, another five clinics, including several in Western Australia, remained under investigation.  Although the Updoc data breach was limited to contact information and did not compromise medical or payment data, the data breach at Updoc highlights the risks associated with third-party service providers. As healthcare organizations continue to depend on external platforms, the incident underscores how vulnerabilities outside a company's own infrastructure can still result in customer information being exposed. 

The Cyber Express Weekly Roundup: AI Fraud, Data Leaks, Malware Campaigns, and Critical Infrastructure Threats

The Cyber Express weekly Roundup July 2026 new

This weekly roundup highlights the growing complexity of digital threats affecting governments, businesses, developers, and consumers. From artificial intelligence being misused for financial fraud to large-scale customer data exposures, malicious software targeting developer ecosystems, and cyberattacks against critical infrastructure, recent incidents demonstrate how attackers are exploiting both emerging technologies and existing security weaknesses.  The latest developments show that cyber risks are expanding beyond traditional network attacks. Threat actors are targeting identities, trusted platforms, software supply chains, and operational technology environments. Organizations must strengthen security controls, improve monitoring capabilities, and adopt proactive measures to protect sensitive data and critical services. 

The Cyber Express Weekly Roundup 

Four Men Admit to $2.2 Million Medicaid Fraud Scheme Using AI 

Four Minnesota men have pleaded guilty in connection with a Medicaid fraud scheme that allegedly generated approximately $2.2 million through fraudulent claims for housing-related services. Prosecutors stated that artificial intelligence tools, including ChatGPT, were used to create false documentation supporting fraudulent billing activity. Read more... 

Tribeca Data Leak Exposes Celebrity-Linked Information 

A reported data leak connected to the Tribeca Film Festival exposed nearly 666,000 records containing personal information associated with attendees, contacts, and individuals linked to the entertainment industry. The exposed data reportedly included names, email addresses, phone numbers, and limited device-related information. Read more... 

Origin Energy Data Breach Impacts Around 900,000 Customers 

Australian energy company Origin Energy confirmed a data breach affecting approximately 900,000 current and former customers. The exposed information may include customer names, contact details, dates of birth, and partial account information. The company is investigating the incident and has advised customers to remain alert for possible scams or suspicious communications. Read more... 

Joyfill npm Packages Found Distributing DEV#POPPER Malware 

Security researchers discovered that two beta versions of Joyfill npm packages were distributing DEV#POPPER, a remote access trojan (RAT) capable of stealing information, executing commands, and compromising developer environments. Read more... 

Student Accused of IIT Website Breaches Offered Technical Assessment 

A student accused of breaching parts of the IIT Kanpur and IIT Madras websites after being rejected from IIT Kanpur’s cybersecurity program will undergo a technical skills assessment rather than facing immediate legal action. The institute stated that admissions for the current session are closed but indicated that future opportunities may be considered if the student demonstrates strong cybersecurity abilities. Read more... 

FBI Warns of PLC Cyberattacks Targeting U.S. Water Utilities 

The FBI and the U.S. Environmental Protection Agency warned that cyberattacks targeting internet-connected programmable logic controllers (PLCs) have disrupted water utilities across multiple U.S. states. Attackers reportedly manipulated PLC settings, affecting monitoring and operational processes. Read more... 

Weekly Cybersecurity Takeaway

This week’s incidents demonstrate how cyber threats continue to evolve across multiple domains, including artificial intelligence abuse, personal data exposure, software supply chain attacks, and critical infrastructure targeting.  A common theme across these events is the exploitation of trust. Attackers are abusing trusted technologies, legitimate software ecosystems, customer databases, and connected infrastructure to achieve their objectives.  Organizations must focus on building cyber resilience through stronger identity protection, secure development practices, continuous monitoring, and effective incident response planning.  As emerging technologies such as artificial intelligence and connected industrial systems become more widespread, cybersecurity strategies must evolve alongside them. Protecting digital assets requires not only stronger technical defenses but also responsible for technology use, awareness, and proactive risk management. 
  • ✇Firewall Daily – The Cyber Express
  • Estée Lauder Confirms Cyberattack Affecting Personal Information Ashish Khaitan
    The Estée Lauder data breach has prompted the global cosmetics company to notify affected individuals after hackers exploited a vulnerability in Oracle E-Business Suite, a platform used for human resources (HR) operations.   The Estée Lauder cyberattack stemmed from unauthorized access that occurred on or around August 9, 2025, though the company said it identified the incident last month and confirmed the scope of the breach on June 19, 2026.  Estée Lauder Data Breach Exposed Sensitive Pers
     

Estée Lauder Confirms Cyberattack Affecting Personal Information

Estée Lauder data breach

The Estée Lauder data breach has prompted the global cosmetics company to notify affected individuals after hackers exploited a vulnerability in Oracle E-Business Suite, a platform used for human resources (HR) operations.   The Estée Lauder cyberattack stemmed from unauthorized access that occurred on or around August 9, 2025, though the company said it identified the incident last month and confirmed the scope of the breach on June 19, 2026. 

Estée Lauder Data Breach Exposed Sensitive Personal Information 

According to the company's notification letter, the attackers gained access to the Oracle E-Business Suite system and obtained personal information belonging to certain individuals.  We became aware of a cybersecurity issue involving a vulnerability in the Oracle E-Business Suite system which is used by the Estee Lauder Companies for HR management purposes," the notice states.  It further adds: "On June 19, 2026, we determined through our investigation that, on or around August 9, 2025, an unauthorized third party gained access to the Oracle E-Business Suite system and obtained personal information of certain individuals."  The exposed data in the incident includes full names, postal addresses, email addresses, dates of birth, Social Security numbers (SSNs), passport numbers, financial account information, including bank account numbers, health information, and employment records such as payroll and performance reports. 

Oracle Vulnerability Tied to Estée Lauder Cyberattack 

Although Estée Lauder did not identify the specific vulnerability used in the attack, the timeline aligns with the widespread exploitation of the Oracle E-Business Suite flaw CVE-2025-61882.  In October 2025, researchers from Google warned that the Clop ransomware group had exploited the vulnerability as a zero-day to steal data. The flaw affected Oracle EBS versions 12.2.3 through 12.2.14, allowing attackers to bypass authentication and remotely execute code through the BI Publisher Integration component. Successful exploitation could provide access to sensitive HR and business information.  Oracle released security patches for CVE-2025-61882 on October 4, 2025. Soon after, cybersecurity company CrowdStrike confirmed that Clop had been exploiting the vulnerability since early August 2025. 

Company Offers Identity Monitoring 

Estée Lauder, headquartered in New York, generates annual revenue of $14.3 billion, employs around 57,000 people, and operates retail stores and online businesses worldwide, making it the world's second-largest cosmetics company.  Following the Estée Lauder data breach, the company is urging recipients of its notification letter to monitor for signs of identity theft and fraud. It is also providing 24 months of complimentary identity monitoring services through Kroll.  The Estée Lauder cyberattack is part of a broader campaign that affected several high-profile organizations, including Harvard, the University of Pennsylvania, Dartmouth, the University of Phoenix, The Washington Post, Logitech, GlobalLogic, Cox Enterprises, and American Airlines subsidiary Envoy Air.  This is not the first time the company has been impacted by Clop. In 2023, Estée Lauder was also compromised after the ransomware group exploited a separate zero-day vulnerability in the MOVEit Transfer platform, one of the company's internal software tools. 
  • ✇Firewall Daily – The Cyber Express
  • Partnered Health Cyberattack Exposes Patient Data Across Australia Ashish Khaitan
    The Partnered Health cyberattack has exposed sensitive patient information across multiple Australian clinics, raising fresh concerns about healthcare cybersecurity. The Partnered Health data breach, involving clinics owned by healthcare provider Partnered Health, a company backed by Quadrant, affected facilities in New South Wales, Victoria, Queensland, Western Australia, and the ACT. The incident has also renewed scrutiny of the growing number of cyberattacks targeting Australia's health
     

Partnered Health Cyberattack Exposes Patient Data Across Australia

Partnered Health cyberattack

The Partnered Health cyberattack has exposed sensitive patient information across multiple Australian clinics, raising fresh concerns about healthcare cybersecurity. The Partnered Health data breach, involving clinics owned by healthcare provider Partnered Health, a company backed by Quadrant, affected facilities in New South Wales, Victoria, Queensland, Western Australia, and the ACT. The incident has also renewed scrutiny of the growing number of cyberattacks targeting Australia's healthcare sector.

Partnered Health Data Breach Impacted Medical and Personal Information 

Partnered Health confirmed that a malicious actor accessed its systems on 23 June, compromising data from 21 clinics across cities, including Sydney, Melbourne, and Canberra. The healthcare provider disclosed the breach more than three weeks later, informing patients that investigations had confirmed personal and health information had been taken from some clinics within its network. "Our investigations to date have confirmed that personal information (including health information) was taken from some of the clinics in our network," the company said. It added, "As a health services provider, we know our patients and our people trust us with personal and medical information, and we sincerely apologise for any concern and inconvenience this may cause them." The stolen information includes names, dates of birth, addresses, contact details, Medicare information, private health insurance details, concession card information, consultation notes, referral letters, pathology reports, diagnostic results, and other treatment records maintained by general practitioners.

Investigation into the Partnered Health Cyberattack Continues 

Partnered Health said the cyberattack has been reported to the Australian Cyber Security Centre, the Office of the Australian Information Commissioner, and law enforcement authorities. The company has also secured an interim injunction from the NSW Supreme Court preventing the stolen information from being used or published. While investigations remain ongoing, the provider said the extent of the breach is still being determined at five clinics, including three in Western Australia and two in Victoria. "While there is no direct evidence that patient records have been viewed, as a precaution we have written to patients from these clinics to make them aware of this and provide details of steps that can be taken to protect their information," a Partnered Health spokesperson said. The spokesperson added, "We understand that this sort of news can cause concern. We sincerely apologize for any distress this may have caused our patients."

Quadrant-backed Healthcare Provider Faces Growing Scrutiny 

Established in 2013, Partnered Health operates more than 60 medical centres, along with skin cancer, allied health, and mental health clinics, providing services to more than 5 million people nationwide. The company is owned by Quadrant, while Bupa announced in June that it would acquire the healthcare provider. The Partnered Health data breach comes amid a record year for cybersecurity incidents in Australia. According to the Office of the Australian Information Commissioner, 1,205 data breach notifications were recorded in 2025, marking an 8% increase compared with 2024. Among the year's largest incidents was the cyberattack on Qantas, which compromised the information of 5.7 million customers and was reportedly leaked on the dark web. A spokesperson for the Department of Home Affairs said the federal government is aware of the Partnered Health cyberattack and confirmed that relevant agencies are engaged as investigations continue. Authorities have not yet disclosed how many patients were affected or the full scope of the stolen data.
  • ✇Firewall Daily – The Cyber Express
  • Australia-India PACTS to Deepen Cybersecurity and Tech Collaboration Samiksha Jain
    Australia and India have unveiled the Australia-India PACTS, a new framework designed to deepen bilateral cooperation on cybersecurity, critical technologies, supply chain resilience, digital resilience, and defence research. The new partnership replaces the 2020 Framework Arrangement on Cyber and Cyber Enabled Critical Technology Cooperation and aims to strengthen national security, economic growth, and regional stability across the Indo-Pacific. The two countries said the Aus
     

Australia-India PACTS to Deepen Cybersecurity and Tech Collaboration

Australia-India PACTS

Australia and India have unveiled the Australia-India PACTS, a new framework designed to deepen bilateral cooperation on cybersecurity, critical technologies, supply chain resilience, digital resilience, and defence research.

The new partnership replaces the 2020 Framework Arrangement on Cyber and Cyber Enabled Critical Technology Cooperation and aims to strengthen national security, economic growth, and regional stability across the Indo-Pacific.

The two countries said the Australia-India Partnership on Cyber, Critical Technologies and Supply Chains (PACTS) builds on two decades of research collaboration, operational coordination, and policy engagement. It also reflects their shared commitment to creating secure digital ecosystems while promoting trusted technology partnerships.

Australia-India PACTS Built on Five Pillars

The Australia-India PACTS is structured around five pillars that will drive collaboration between governments, research institutions, universities, and the private sector. The framework is intended to increase two-way investment in emerging technologies while supporting innovation and the commercialisation of research.

The first pillar focuses on supply chain resilience by strengthening trusted technology supply chains and promoting secure trade. Both countries will establish a bilateral mechanism for trusted vendor frameworks and work together to improve undersea cable security through the Quad Partnership for Cable Connectivity and Resilience. The partnership also includes collaboration on semiconductor research, critical minerals, and trade diversification.

Australia-India PACTS Expands Critical Technology Collaboration

The second pillar focuses on critical technologies, with Australia and India planning to strengthen cooperation in artificial intelligence, telecommunications, biotechnology, advanced materials, and space technologies.

The framework also supports the development of international standards for trustworthy AI and encourages collaboration between academic institutions and industry to promote responsible AI deployment. The two countries will also explore joint research, investment initiatives, and commercial partnerships in emerging technologies to strengthen long-term economic security across the Indo-Pacific.

Australia-India Prioritises Cybersecurity

A major component of the partnership is Australia India cybersecurity cooperation. Under the third pillar, both governments will work together to counter cybercrime, deter malicious cyber activity, strengthen cyber policy coordination, and protect critical infrastructure.

The framework proposes a consolidated bilateral mechanism for cyber and ICT cooperation, expanded engagement in United Nations cyber processes, increased trade opportunities for cybersecurity businesses, and practical workshops involving government agencies and industry stakeholders.

The partnership will also establish a cyber technology skills incubator to promote knowledge exchange and workforce development.

Australia-India PACTS Advances Digital Resilience

The fourth pillar focuses on digital resilience across the Indo-Pacific. Australia and India will collaborate on trusted Digital Public Infrastructure initiatives and promote scalable digital solutions that support connectivity, healthcare, education, renewable energy, critical infrastructure, and digital transformation.

The partnership also seeks to expand pilot projects that help countries across the region build adaptable digital ecosystems while strengthening regional capabilities.

Defence Research and Governance Framework

The fifth pillar strengthens defence science collaboration through joint research, innovation partnerships, and greater engagement between Australia's Defence Science and Technology Group and India's Defence Research and Development Organisation.

Areas of cooperation include maritime surveillance, advanced materials, defence innovation, and stronger links between defence start-up ecosystems.

The Australia-India PACTS will be jointly overseen by the Australian Deputy Secretary of the International and Security Group within the Department of the Prime Minister and Cabinet and the Indian Deputy National Security Advisor. Annual Senior Officials Meetings will review progress, assess emerging cyber and technology risks, and identify future collaborative projects under each pillar.

With the launch of Australia-India Partnership on Cyber, Critical Technologies and Supply Chains (PACTS), both countries have outlined a long-term roadmap that brings together cybersecurity, critical technologies, supply chain resilience, digital resilience, and defence cooperation under a single strategic framework aimed at strengthening security and technology collaboration across the Indo-Pacific.

The Cyber Express Weekly Roundup: Five Eyes AI Warning, KDDI Data Breach, Garfield AI Legal Milestone, and Iranian Hacker Arrest

The Cyber Express weekly roundup June 2026

This week’s weekly roundup of cybersecurity developments highlights a rapid shift in global cyber risk conditions driven by artificial intelligence acceleration, large-scale data breaches, and expanding international enforcement actions. Across infrastructure, enterprise systems, public services, and regulated AI applications, organizations are increasingly exposed to faster-moving threats where traditional security assumptions are being challenged by automation and long-term intrusion campaigns.  The overarching theme in this weekly roundup is the erosion of response time in modern cybersecurity environments. Intelligence agencies, law enforcement bodies, and private-sector disclosures collectively point to a landscape where attackers are leveraging AI-enabled capabilities, third-party system weaknesses, and identity compromise to gain persistence across networks. At the same time, regulators and courts are beginning to define new boundaries for both cybercrime accountability and the operational use of AI in sensitive domains. 

The Cyber Express Weekly Roundup 

Five Eyes Warn AI Is Rapidly Outdating Cyber Risk Models 

The Five Eyes cybersecurity agencies warn that artificial intelligence is accelerating cyber threats and making traditional cyber risk assumptions obsolete. Attackers are exploiting vulnerabilities faster, shrinking response windows, and increasing the speed and sophistication of attacks. In guidance issued on June 23, 2026, they urged organizations to treat cyber resilience as a leadership priority, strengthen identity and access controls, accelerate patching cycles, and reduce dependence on legacy systems. Read more… 

TfL Hackers Plead Guilty After £29M Cyberattack 

Two members of the Scattered Spider cybercrime group have pleaded guilty to roles in the Transport for London cyberattack that caused £29 million in losses, disrupted services, and exposed customer data. The 2024 breach affected Oyster systems and forced mass password resets across TfL’s workforce. Investigators also linked the suspects to other attempted intrusions targeting U.S. healthcare networks. Read more… 

KDDI Data Breach May Expose 14.22 Million Email Accounts 

KDDI has disclosed a cybersecurity incident that may have exposed up to 14.22 million email addresses and passwords through systems used by multiple Japanese internet service providers. The breach, detected on June 17, 2026, stemmed from unauthorized access to a third-party email system. KDDI said it has secured the affected environment, notified partners, and is working with regulators while urging users to reset passwords as a precaution. Read more… 

Garfield AI Wins Landmark UK Case as AI-Powered Law Firm 

Garfield AI, a UK-regulated AI-powered law firm, has secured a landmark legal victory after successfully managing a small claims case in England with minimal human intervention. The AI system handled pre-trial work, including drafting court documents and preparing evidence, in a dispute over an unpaid £7,000 invoice. The case was ultimately won at Wandsworth County Court, marking a notable milestone for the use of AI in regulated legal services, though human counsel still represented the claimant at trial. Read more… 

Iranian Hacker Arrested in Montenegro Over Alleged $3.4B Cyberattack Campaign 

An alleged Iranian hacker has been arrested in Montenegro following a joint operation with the FBI over a long-running cyber campaign targeting U.S. infrastructure. Authorities say the 39-year-old suspect is linked to attacks dating back to 2013, allegedly targeting more than 150 U.S. universities and causing over $3.4 billion in damages. He now faces extradition to the United States on charges including computer fraud, hacking, conspiracy, and identity theft, while investigations into Iran-linked cyber activity continue. Read more… 

Weekly Cybersecurity Takeaway 

This week’s weekly roundup reflects a cybersecurity environment increasingly defined by the speed of AI-driven threat evolution, the scale of third-party exposure, and the persistence of long-running cybercrime operations. From the Five Eyes warning that artificial intelligence is rapidly reshaping cyber risk assumptions to the KDDI breach that may have exposed 14.22 million email accounts, organizations are facing mounting pressure to modernize defenses while reducing dependence on outdated security models. 

The Cyber Express Weekly Roundup: Cybersecurity Weekly Round on Emerging Threats, Data Breaches, and Global Policy Shifts

weekly roundup TCE

This week’s weekly roundup of cybersecurity developments highlights an expanding intersection of cyber risk, regulatory action, and enterprise vulnerability. Across healthcare, technology platforms, gaming companies, and government policy, organizations continue to confront a rapidly evolving cybersecurity landscape where data exposure, advanced intrusion tactics, and platform security failures are interconnected.  The overarching theme in this weekly roundup is the growing strain on digital ecosystems as attackers refine stealth techniques while institutions attempt to secure distributed systems. From cloud-based email exploitation to AI-related enterprise vulnerabilities, this week’s cybersecurity incidents underscore the difficulty of maintaining visibility and control across modern infrastructure. 

The Cyber Express Weekly Roundup 

Novo Nordisk Security Incident Exposes Limited Patient and HCP Data 

Novo Nordisk reported an unauthorized intrusion into internal systems that resulted in the external copying of limited clinical trial data along with healthcare professional contact details. According to the disclosure, core operational systems were not disrupted during the incident, and the breach did not affect ongoing business continuity. Read more... 

UNC6508 Used Google Workspace Trick to Spy on U.S. Medical Research 

A threat group identified as UNC6508, linked to China, reportedly conducted a long-term espionage campaign targeting North American medical and research institutions. Over a period described as exceeding two years, attackers infiltrated research environments and accessed sensitive systems related to medical and defense-linked projects. Read more... 

Critical SearchLeak Flaw in Microsoft 365 Copilot Exposed Enterprise Data 

A newly addressed vulnerability, identified as CVE-2026-42824, affected Microsoft 365 Copilot and carried the potential for significant enterprise data exposure. Researchers found that a chain of weaknesses—including prompt injection, HTML rendering issues, and server-side request forgery—could be exploited to extract sensitive data. Read more... 

UK Plans Social Media Ban for Under-16s by 2027 

The United Kingdom has proposed a policy restricting social media access for users under the age of 16, with implementation potentially targeted for spring 2027. If enacted, the ban would apply to major platforms including TikTok, Instagram, Snapchat, Facebook, YouTube, and X. Read more... 

Operation Endgame Disrupts SocGholish Malware Network 

International law enforcement agencies, operating under “Operation Endgame,” dismantled significant parts of the SocGholish malware infrastructure. The operation resulted in the cleanup of nearly 15,000 compromised websites and the takedown of multiple servers associated with cybercriminal activity. Read more... 

Nintendo Confirms Limited Employee Data Exposed in TinyPulse Attack 

Nintendo confirmed that employee survey data was exposed following a cyberattack involving the third-party platform TinyPulse. The company clarified that its internal systems and customer-facing data were not impacted by the incident. Read more... 

Weekly Cybersecurity Takeaway 

This week’s weekly roundup reflects a cybersecurity environment increasingly shaped by cloud exploitation, AI-driven vulnerabilities, and cross-border espionage campaigns. From healthcare breaches like Novo Nordisk’s limited data exposure to long-running intrusions such as UNC6508’s email-forwarding operations, attackers continue to prioritize stealth and persistence over direct system disruption.  At the same time, critical vulnerabilities like the Microsoft 365 Copilot SearchLeak flaw demonstrate how AI integration is expanding enterprise risk surfaces. Meanwhile, enforcement actions under Operation Endgame and policy shifts such as the UK’s proposed under-16 social media restrictions show that both technical and regulatory responses are evolving in parallel. 
  • ✇Firewall Daily – The Cyber Express
  • What Ukraine’s Entry Into the EU Cybersecurity Reserve Means Samiksha Jain
    Ukraine Joins EU Cybersecurity Reserve after receiving approval from the Council of the European Union, enabling the country to access emergency cybersecurity assistance during large-scale cyber incidents that exceed national response capabilities. The decision allows Ukraine to activate support from the EU Cybersecurity Reserve, a mechanism managed by the European Union Agency for Cybersecurity (ENISA) that provides incident response services through trusted private-sector cybersecurity prov
     

What Ukraine’s Entry Into the EU Cybersecurity Reserve Means

Ukraine Joins EU Cybersecurity Reserve

Ukraine Joins EU Cybersecurity Reserve after receiving approval from the Council of the European Union, enabling the country to access emergency cybersecurity assistance during large-scale cyber incidents that exceed national response capabilities. The decision allows Ukraine to activate support from the EU Cybersecurity Reserve, a mechanism managed by the European Union Agency for Cybersecurity (ENISA) that provides incident response services through trusted private-sector cybersecurity providers. The move reflects ongoing EU-Ukraine cooperation on digital security and resilience amid evolving cyber threats.

Ukraine Joins EU Cybersecurity Reserve Under EU Cyber Solidarity Framework

The EU Cybersecurity Reserve was established under the Cyber Solidarity Act to help participating countries respond to significant cybersecurity incidents. Through the reserve, nations can request specialized assistance when their own incident response resources are overwhelmed. According to the European Commission, Ukraine will now be able to officially seek emergency European support if a cyberattack surpasses the capacity of its domestic response teams. This would allow cybersecurity experts from across the European Union to assist in incident containment and recovery efforts. The Commission described the decision as part of broader efforts to strengthen preparedness, improve rapid response capabilities, and encourage cooperation against growing cyber threats.

EU Highlights Digital Security Cooperation

Commenting on the development, Henna Virkkunen, Executive Vice-President for Tech Sovereignty, Security and Democracy, said Ukraine's inclusion strengthens collective cyber defenses and reflects the principle of solidarity at the core of Europe's digital future. The Commission noted that cyberattacks continue to present a persistent challenge and emphasized the importance of coordinated responses and shared expertise among partner nations. Ukraine's inclusion also aligns with the EU's strategic digital partnership agenda, which focuses on strengthening cybersecurity cooperation with neighboring countries.

Moldova Previously Granted Access

Ukraine becomes the second non-EU country to gain access to the reserve. Moldova was granted access in 2024 following an increase in Moscow-linked Cyber Threats and influence operations targeting the country. The Council's authorization for Moldova to use the reserve was described as a major step forward in regional cybersecurity cooperation. The arrangement was implemented under the Cyber Solidarity Act and formed part of broader EU-Moldova efforts to improve digital resilience. The European Commission stated that enhancing cybersecurity cooperation remains a key component of its partnership with Moldova.

Broader EU-Moldova Digital Cooperation Expands

Alongside cybersecurity initiatives, the European Union has expanded digital cooperation with Moldova in several strategic areas. The Commission welcomed a political agreement that will allow Moldova to join the EU Roaming Area under the "Roam Like at Home" framework following formal adoption. Once implemented, Moldovan citizens and EU travelers will be able to call, text, and use mobile data without additional roaming charges. Moldova has also joined the EU Third Countries' Trusted List, enabling easier validation of electronic signatures and seals between EU and Moldovan organizations, businesses, and citizens. To strengthen resilience against Disinformation and foreign interference, a new hub of the European Digital Media Observatory (EDMO) known as FACT has also been established with support from the European Commission.

Cyber Cooperation Advances as EU Membership Talks Progress

The cybersecurity announcement comes shortly after EU member states agreed to launch formal accession negotiations with both Ukraine and Moldova. European Commission President Ursula von der Leyen described the decision as a major milestone, stating that all member states had agreed to open the first accession negotiations cluster with the two countries. She said the move recognizes the reforms undertaken by Ukraine and Moldova despite significant challenges and reinforces the EU's commitment to peace, security, and stability across the region. With access to the EU Cybersecurity Reserve, Ukraine now gains an additional layer of support to strengthen its cyber resilience and coordinate responses to major cybersecurity incidents alongside European partners.

The Cyber Express Weekly Roundup: AI Security Controls, Major Patch Releases, Public Sector Audits, and Emerging Online Scams

TCE The Cyber Express Weekly Roundup

This week's cybersecurity developments highlight a growing emphasis on proactive security measures, governance oversight, and risk management across both public and private sectors. From large-scale vulnerability remediation efforts and AI security enhancements to government-led technology reviews and event-driven cybercrime campaigns, organizations continue to face a complex threat landscape.  A common theme across this week's stories is the balance between innovation and security. As institutions adopt AI-powered systems, expand digital services, and move critical operations online, security teams are being challenged to strengthen protections without slowing modernization efforts. At the same time, threat actors continue to capitalize on public-interest events and trusted digital platforms to conduct fraud and data-theft campaigns. 

The Cyber Express Weekly Roundup 

CBSE Re-Evaluation Portal Receives Final Security Clearance 

The Central Board of Secondary Education (CBSE) has completed the final cybersecurity review of its examiner-facing re-evaluation platform, clearing the way for the reassessment of Class 12 answer scripts. Following an IIT-led audit and security testing process, examiners can now access the system to process applications submitted by more than 70,000 students. Read more... 

OpenAI Expands Lockdown Mode Across ChatGPT Accounts 

OpenAI has extended its Lockdown Mode security feature to all personal ChatGPT users, including Free, Go, Plus, Pro, and self-service Business accounts. The feature is designed to reduce the risk of prompt injection-related data exposure by limiting access to high-risk capabilities such as live web browsing, Deep Research, Agent Mode, and external file interactions. Read more... 

UK Courts Explore AI-Powered Legal Assistance 

The UK government has announced plans to test AI legal assistants within Crown Courts as part of broader judicial modernization efforts. The tools are expected to assist with legal research, case review, scheduling, and administrative processes while remaining under human supervision. Read more... 

Microsoft Issues Largest Patch Tuesday Update on Record 

Microsoft's June 2026 Patch Tuesday addressed a record-breaking 200 security vulnerabilities across its product ecosystem, including Windows, Office, Azure, and Exchange. The release included fixes for three publicly disclosed zero-day vulnerabilities and dozens of critical flaws. Read more... 

ServiceNow Clarifies Nature of Recent Security Incident 

ServiceNow has provided additional details regarding a recently disclosed security vulnerability, stating that observed activity originated from security researchers and customer investigations rather than malicious attackers. The company released a security update to address the issue and emphasized that there is no evidence of customer data misuse. Read more... 

World Cup-Themed Scams Target Fans Ahead of FIFA 2026 

Cybercriminals are already leveraging interest in the FIFA World Cup 2026 to launch phishing campaigns, fake ticket sales, and fraudulent recruitment schemes. Security researchers and law enforcement agencies have identified numerous lookalike domains impersonating official FIFA services in an effort to steal personal and financial information. Read more... 

Weekly Cybersecurity Takeaway 

This week's developments demonstrate that cybersecurity is becoming a foundational requirement for digital transformation rather than a separate consideration. Whether securing AI platforms, protecting educational systems, modernizing public services, or managing enterprise vulnerabilities, organizations are being forced to address security challenges alongside innovation initiatives.  Meanwhile, threat actors continue to exploit trust, familiarity, and public interest to achieve their objectives. From phishing campaigns targeting global sporting events to attacks focused on cloud services and enterprise platforms, the most effective defenses remain strong security governance, timely patching, user awareness, and continuous monitoring of emerging risks. 
  • ✇Firewall Daily – The Cyber Express
  • Microsoft Patches Record 200 Vulnerabilities in June 2026 Patch Tuesday Ashish Khaitan
    Microsoft's June 2026 Patch Tuesday, released on June 10, 2026, addressed 200 security vulnerabilities across Windows, Office, Azure, and related products—the largest single Patch Tuesday release in the programme's history, surpassing the previous record of 167 CVEs. The update includes fixes for three publicly disclosed zero-day vulnerabilities and 33 critical-severity flaws. The June 2026 release patches vulnerabilities across all major Microsoft product families: Windows 11 and Windows
     

Microsoft Patches Record 200 Vulnerabilities in June 2026 Patch Tuesday

June 2026 Patch Tuesday

Microsoft's June 2026 Patch Tuesday, released on June 10, 2026, addressed 200 security vulnerabilities across Windows, Office, Azure, and related products—the largest single Patch Tuesday release in the programme's history, surpassing the previous record of 167 CVEs. The update includes fixes for three publicly disclosed zero-day vulnerabilities and 33 critical-severity flaws. The June 2026 release patches vulnerabilities across all major Microsoft product families: Windows 11 and Windows Server, Microsoft Office, Exchange Server, .NET Framework, Azure services, Hyper-V, Remote Desktop Services, and HTTP.sys. Of the 200 CVEs addressed, 33 are rated Critical, 166 are rated Important, and one is rated Moderate. Twenty-eight of the critical flaws are remote code execution vulnerabilities, four are elevation of privilege issues, and one is an information disclosure flaw.

June 2026 Patch Tuesday: Three Zero-Day Vulnerabilities

This month's release includes patches for three publicly disclosed zero-days. None are currently known to be under active exploitation, but security researchers note that patch reversal is underway. CVE-2026-50507 – Windows BitLocker Bypass (publicly disclosed): This vulnerability, nicknamed "YellowKey" by the researcher who discovered it, allows a local attacker with physical access to a device to bypass BitLocker's full-disk encryption and access data on an encrypted drive. The flaw requires local access and an elevated privilege context, reducing immediate remote risk—but it is significant for organisations that rely on BitLocker to protect data on lost or stolen hardware. The severity rating is Important. CVE-2026-49160 – HTTP/2 Denial of Service (publicly disclosed): Dubbed "HTTP/2 Bomb," this vulnerability was publicly disclosed by researchers at offensive security firm Calif before the patch was available. An unauthenticated remote attacker can exhaust server memory by sending crafted HTTP/2 frames, causing denial of service on Windows IIS and other HTTP.sys-dependent services. CVE-2026-45586 – Windows CTFMON Privilege Escalation (publicly disclosed): This elevation-of-privilege flaw in the Windows Collaborative Translation Framework Monitor (ctfmon.exe) grants a logged-in attacker SYSTEM-level privileges. While exploitation requires local access, it is a valuable component in multi-stage attack chains following initial compromise. Headline Critical Vulnerability: CVE-2026-45657
Beyond the three zero-days, security professionals should prioritise CVE-2026-45657, a Windows Kernel use-after-free vulnerability with a CVSS score of 9.8. The flaw stems from improper handling of TCP/IP operations within the Windows Kernel and allows a remote, unauthenticated attacker to execute arbitrary code at the SYSTEM level with no user interaction. Microsoft has classified it as "wormable" under certain network configurations. "CVE-2026-45657 is the kind of vulnerability that keeps defenders up at night," said a Zero Day Initiative researcher. The CVSS 9.8 score, combined with wormable potential, means we could see mass exploitation the moment a reliable exploit is developed.
The record-breaking scale of this month's release creates prioritisation challenges for already-stretched security teams. Microsoft and independent researchers recommend prioritising patches for BitLocker-protected devices, HTTP.sys and IIS infrastructure, Remote Desktop Services, Hyper-V hosts, and Windows Kernel components.

Mitigation Steps

  • Deploy June 2026 cumulative updates (KB5094126 for Windows 11, KB5094127 for Windows 10) without delay.
  • Prioritise CVE-2026-45657 patching on all internet-accessible Windows systems.
  • Apply the IIS/HTTP.sys patch for CVE-2026-49160 on all public-facing web servers.
  • Audit BitLocker-protected device inventory and apply CVE-2026-50507 patches before deploying new field hardware.
  • Review CTFMON and SYSTEM privilege escalation detections in endpoint security tooling.
  • Use the Microsoft Security Update Guide (msrc.microsoft.com) to filter by CVSS >= 9.0 for prioritisation.
  • Validate patch deployment through automated compliance reporting within 72 hours.
  • ✇Firewall Daily – The Cyber Express
  • Kuwait and Oman Sign Cybersecurity Pact to Counter Rising Digital Threats Ashish Khaitan
    As digital transformation accelerates across the Gulf region, Kuwait and Oman have taken a significant step toward strengthening their collective cybersecurity capabilities. The two countries recently signed a Memorandum of Understanding (MoU) designed to enhance bilateral cooperation in cybersecurity and improve their ability to address sophisticated digital threats.  The agreement reflects a growing recognition that cybersecurity has become a critical component of national security. With go
     

Kuwait and Oman Sign Cybersecurity Pact to Counter Rising Digital Threats

Kuwait and Oman

As digital transformation accelerates across the Gulf region, Kuwait and Oman have taken a significant step toward strengthening their collective cybersecurity capabilities. The two countries recently signed a Memorandum of Understanding (MoU) designed to enhance bilateral cooperation in cybersecurity and improve their ability to address sophisticated digital threats.  The agreement reflects a growing recognition that cybersecurity has become a critical component of national security. With government services, public institutions, and essential infrastructure becoming more dependent on digital technologies, Kuwait and Oman are seeking to strengthen their defenses against emerging cyber risks while ensuring the security of sensitive government data and digital systems. 

Key Areas Covered Under the Kuwait and Oman Cybersecurity MoU 

The cybersecurity MoU between Kuwait and Oman outlines several areas of cooperation aimed at boosting digital resilience and preparedness in both countries.  One of the primary focuses of the agreement is the exchange of technical expertise. Through dedicated communication channels, both nations will share information related to newly identified vulnerabilities, cyber threats, and emerging attack methods. This information-sharing framework is expected to improve situational awareness and enable faster responses to evolving cybersecurity challenges.  The MoU also emphasizes joint training initiatives. Kuwait and Oman plan to launch advanced training programs designed to develop highly skilled national professionals specializing in cybersecurity incident response. By strengthening local expertise, both countries aim to improve their readiness to manage and mitigate cyber incidents effectively. In addition, the agreement promotes greater field coordination between relevant authorities. Enhanced coordination will help improve the ability of both nations to respond to advanced cyberattacks, particularly those targeting critical sectors and essential infrastructure. 

A Shared Vision for a Secure Digital Future 

Officials from Kuwait and Oman have described the MoU as a reflection of their shared commitment to building what they referred to as a “digital fortress” capable of protecting national assets and strategic resources.  The agreement comes at a time when government institutions are expanding the use of electronic services and cloud computing technologies. In this environment, cybersecurity is no longer viewed as an optional technical consideration. Instead, it has become a foundational requirement for ensuring business continuity, safeguarding sensitive information, and protecting citizen privacy.  The cybersecurity partnership demonstrates how Kuwait and Oman are aligning their efforts to address common digital security concerns while preparing for future technological developments. By working together, both countries aim to establish stronger protective measures against cyber threats that transcend national borders. 

Expanding Cooperation Beyond Cyber Defense 

Beyond immediate security objectives, the MoU is expected to create opportunities for broader technological collaboration between Kuwait and Oman. Officials noted that the agreement represents an advancement in bilateral relations and could serve as a foundation for future initiatives in emerging areas of cybersecurity innovation.  Potential areas of cooperation include the development of advanced encryption technologies, the integration of artificial intelligence into cyber defense systems, and the creation of unified security standards. Such initiatives could contribute to stronger regional cybersecurity frameworks and support the shared interests of Gulf Cooperation Council (GCC) member states.  The agreement therefore extends beyond traditional cyber protection measures, positioning Kuwait and Oman to explore innovative solutions that address the evolving nature of digital threats while supporting long-term technological growth. 

Cisco Warns of Active Exploitation of Catalyst SD-WAN Flaw With No Patch Available

CVE-2026-20245

Cisco has issued an urgent warning that a high-severity vulnerability in its Catalyst SD-WAN Manager platform is being actively exploited in the wild—and no patch exists yet. CVE-2026-20245 allows authenticated attackers with netadmin privileges to execute arbitrary commands as root, placing wide-area network infrastructure at severe risk.
The disclosure is particularly alarming because Catalyst SD-WAN Manager controls and orchestrates SD-WAN deployments across enterprise and carrier networks. A successful exploit could allow attackers to push malicious configurations to thousands of edge devices simultaneously.

Understanding CVE-2026-20245

CVE-2026-20245 exists in the command-line interface (CLI) of Cisco Catalyst SD-WAN Manager, resulting from insufficient validation of user-supplied input when processing file arguments. The vulnerability carries a CVSS base score of 7.8 (High), with a vector of CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.
To exploit the flaw, an attacker must have netadmin-level credentials on the affected system. While this limits the immediate attack surface, Cisco noted in its advisory that attackers are chaining CVE-2026-20245 with two related vulnerabilities—CVE-2026-20182 and CVE-2026-20127—to achieve initial access before escalating to root execution. This chaining technique effectively reduces the privilege prerequisite in practice.
An attacker supplies a specially crafted file to the Catalyst SD-WAN Manager CLI. Insufficient input validation allows the crafted file to execute arbitrary OS-level commands with root privileges. Cisco confirmed "limited cases" in which exploitation resulted in configuration changes being pushed to downstream edge devices—a significant escalation of potential impact.

No Patch Available — Cisco Plans Future Release

Unlike most critical vulnerability advisories, Cisco has disclosed CVE-2026-20245 without an accompanying patch. The company stated it plans to address the vulnerability in a future software release but did not provide a specific timeline.
This leaves organisations with only partial mitigations at their disposal. Cisco advises restricting CLI access to only trusted users and applying strict controls on file upload functionality within SD-WAN Manager administrative interfaces.
A vulnerability without a patch and with confirmed in-the-wild exploitation is a worst-case scenario for network defenders," noted a network security practitioner familiar with SD-WAN infrastructure. Every day without a patch is another day of active risk.

Why It Matters

SD-WAN infrastructure occupies a privileged position in modern enterprise networks, providing policy control over traffic routing across branches, data centres, and cloud environments. Compromising the management plane—which CVE-2026-20245 enables—gives attackers visibility into traffic flows, the ability to redirect connectivity, and the power to inject backdoor configurations across all managed edges.
The impact extends beyond a single organisation. Managed service providers (MSPs) and telecommunications carriers that use Cisco Catalyst SD-WAN to manage multiple customer environments face the prospect of cross-tenant compromise if their management platform is breached.

Mitigation Steps

  • Immediately audit who holds netadmin credentials on Catalyst SD-WAN Manager deployments and revoke unnecessary access.
  • Enable multi-factor authentication (MFA) for all SD-WAN Manager administrative accounts to reduce credential-theft risk.
  • Restrict file upload functionality within the SD-WAN Manager interface to the absolute minimum required for operations.
  • Monitor SD-WAN Manager CLI logs for unusual file upload activity or unexpected root-level command executions.
  • Apply network segmentation to isolate the SD-WAN management plane from general enterprise networks.
  • Subscribe to Cisco Security Advisories (tools.cisco.com/security/center) and apply the patch immediately upon release.
  • Conduct a configuration audit of all managed edge devices to identify any unauthorized configuration pushes already applied.

The Cyber Express Weekly Roundup: Cloud Extortion, Long-Term Espionage, Android Zero-Days, and Public Sector Security Reviews

weekly roundup TCE cybersecurity news

The cybersecurity landscape in this weekly roundup continues to show a clear shift toward identity-driven attacks, long-term persistence operations, and exploitation of trusted cloud environments. Threat actors are increasingly focusing on stealing credentials, abusing administrative access, and leveraging legitimate platforms to scale impact across organizations.  Rather than relying on one-off intrusions, attackers are now building sustained access paths into enterprise systems, enabling repeated exploitation, data theft, and extortion from within trusted environments. 

The Cyber Express Weekly Roundup

Pink Extortion Group Targets Microsoft 365 Users via Voice Phishing 

A newly identified cyber extortion group known as “Pink” is using voice phishing (vishing) campaigns to steal credentials for Microsoft 365 accounts. Once access is gained, the group rapidly exfiltrates data from cloud platforms such as SharePoint and OneDrive and sends extortion messages directly from compromised internal accounts to pressure victims. Read more… 

China-Linked VerdantBamboo Maintains 18-Month Network Access 

Researchers have uncovered an 18-month intrusion attributed to the China-linked threat group VerdantBamboo. The attackers maintained long-term access using compromised MSP credentials, multiple malware families, and repeated re-entry techniques after remediation attempts. Read more… 

DPDP and Cybersecurity: Why Less Data Means Better Security

India’s DPDP framework promotes data minimization as a key cybersecurity strategy. Organizations are urged to collect only necessary data, store it briefly, and delete unused information to reduce breach risk. Excess data increases attack surface and impact, making deletion as important as protection in modern security practices. Read more...

Google Patches Actively Exploited Android Zero-Day (CVE-2025-48595) 

Google’s June 2026 security update addresses 124 vulnerabilities in Android, including CVE-2025-48595, a high-severity zero-day that was actively exploited in targeted attacks. The flaw enables local privilege escalation without user interaction, underscoring the growing focus of sophisticated threat actors on mobile devices as high-value entry points. Read more… 

CBSE Launches Security Review of OSM Platform After Vulnerability Reports 

The Central Board of Secondary Education (CBSE) has engaged experts from the Indian Institute of Technology Madras and the Indian Institute of Technology Kanpur to review security concerns in its On-Screen Marking (OSM) system used for Class 12 board examinations. The audit follows reports of weak authentication controls and potential cloud storage exposure, prompting a full-scale security assessment and hardening exercise.  Read more… 

Weekly Cybersecurity Takeaway 

This week’s incidents reinforce a consistent pattern: attackers are prioritizing identity compromise and trusted cloud platforms over traditional perimeter breaches. From phishing-as-a-service extortion campaigns targeting Microsoft 365 to long-term espionage operations and mobile zero-days, the common thread is the abuse of legitimate access rather than forced intrusion.  As organizations continue to expand cloud and mobile reliance, the attack surface is increasingly defined not by infrastructure boundaries, but by identity trust and administrative privilege. 
  • ✇Firewall Daily – The Cyber Express
  • DPDP and Cybersecurity: Why the Safest Data May Be the Data You Delete Editorial
    By Malcolm Gomes, COO, IDfy Seventy percent of all sensitive data sitting in enterprise systems right now has not been accessed, used, or reviewed in years, according to a Data Risk report from 2021. It was never deleted when it should have been and, in a breach, it is just as exposed as everything else. For years, enterprises treated personal data as an asset to be collected first and governed later. More data meant better personalization, sharper analytics, stronger fraud models, and business
     

DPDP and Cybersecurity: Why the Safest Data May Be the Data You Delete

5 de Junho de 2026, 04:40

DPDP and Cybersecurity

By Malcolm Gomes, COO, IDfy

Seventy percent of all sensitive data sitting in enterprise systems right now has not been accessed, used, or reviewed in years, according to a Data Risk report from 2021. It was never deleted when it should have been and, in a breach, it is just as exposed as everything else. For years, enterprises treated personal data as an asset to be collected first and governed later. More data meant better personalization, sharper analytics, stronger fraud models, and business intelligence. But in DPDP and cybersecurity, that equation is changing. Data without a clear purpose is no longer an asset. It is an attack surface.

India’s cyber risk environment makes this urgent. In 2025, CERT-In handled over 29.44 lakh cyber incidents. IBM’s 2025 breach research pegged the average cost of a data breach in India at ₹220 million, while the global average stood at USD 4.44 million. Verizon’s 2026 Data Breach Investigations Report found that 31% of breaches now start with software vulnerability exploitation, overtaking stolen credentials as the leading entry point.

What that figure means in practice is that attackers are no longer just looking for weak passwords. They are looking for unguarded data stores, and enterprises that hold more data than they need are giving attackers more to find.

Why DPDP and Cybersecurity Are Now Closely Connected

This is why the Digital Personal Data Protection (DPDP) framework should not be viewed only as privacy compliance. It is also a cybersecurity reset. It forces enterprises to ask a fundamental security question: why are we holding this data in the first place?

Data minimization is not about doing less business. It is about reducing unnecessary exposure. Every extra field collected, every duplicated customer record, every old document retained beyond its purpose, and every vendor copy sitting outside the organization’s control expands the blast radius of a breach.

Security teams can encrypt systems and monitor networks, but they cannot fully protect data that the business does not know exists, no longer needs, or cannot justify.

How DPDP Is Reshaping Data Governance

DPDP and cybersecurity changes that conversation. Organizations must be able to explain what they collect, why they collect it, how long they keep it, whom they share it with, and when it must be deleted.

These are not just legal requirements. They are security design principles.

The law also carries serious consequences. Failure to maintain reasonable security safeguards can attract penalties of up to ₹250 crore, while failure to notify the Board or affected individuals of a personal data breach can attract penalties of up to ₹200 crore.

The most secure piece of personal data is the one you never collected unnecessarily. The second most secure is the one you deleted when its purpose was fulfilled.

Data Minimization as a Cybersecurity Strategy

For Indian enterprises, digital journeys have become data-heavy by default. Onboarding, lending, insurance, healthcare, ecommerce, and fraud prevention journeys may all have legitimate reasons to process personal data. The challenge is to distinguish necessary data from convenient data.

Cyber risk is no longer limited to firewalls and endpoint protection. It includes data hoarding, excessive access, old records, test data, unused integrations, shadow databases, and third-party copies.

When a breach happens, regulators, customers, and partners will not only ask how the attacker got in. They will ask why so much data was there to be exposed.

Data minimization reduces three risks.

  • First, it reduces data breach risk. If expired data has already been deleted, it cannot be stolen. If a system contains ten required fields instead of fifty collected by habit, the harm is lower.
  • Second, it improves visibility. Many organizations struggle not because they lack security tools, but because they lack a reliable map of personal data across applications, databases, documents, cloud environments, and third parties. You cannot secure what you cannot see.
  • Third, it strengthens accountability. Product, operations, legal, vendor, and security teams must now work from the same understanding of purpose, consent, retention, and safeguards.

Together, these three elements create a mature enterprise cybersecurity posture.

Balancing Fraud Prevention and Personal Data Protection

The hardest balancing act will be fraud prevention.

Banks, insurers, fintechs, marketplaces, and digital platforms need strong controls to detect synthetic identities, account takeover, mule activity, payment fraud, and suspicious behavior. But fraud prevention cannot become a blanket justification for collecting everything.

The way forward is not to weaken fraud controls. It is to make them sharper.

Purpose-bound fraud prevention means collecting only the data required for a specific risk decision, using it with clear controls, retaining it for a justified period, and restricting access to systems that genuinely need it.

Good security does not require unlimited data. It requires the right data, governed well.

Why Trust Is Becoming a Competitive Advantage

This is where trust becomes a competitive advantage. Enterprises that can demonstrate why they collect data, how they protect it, and when they delete it will earn customer and partner confidence.

In a market where cyber threats are rising and regulatory scrutiny is increasing, trust will influence both customer choice and institutional credibility.

For boards and leadership teams, the question is no longer, “Are we DPDP compliant?”

The sharper question is, “Can we prove that our data practices reduce risk?”

Answering that question requires more than a compliance audit. It requires a live view of personal data across the enterprise: what exists, where it goes, who can access it, and whether it still needs to.

Privacy and security used to be treated as separate disciplines with separate teams, budgets, and agendas. That separation is no longer viable. A security team that does not know what personal data the business holds cannot protect it. A privacy team that does not have technical visibility into data flows cannot govern them.

The Future of DPDP and Cybersecurity

DPDP is not asking enterprises to choose between innovation and protection. It is asking them to build digital systems where innovation does not depend on uncontrolled data accumulation.

For too long, “collect more” was seen as the safer business strategy. In the DPDP era, the safer cybersecurity strategy may be the opposite: collect with purpose, protect with discipline, and delete with confidence.

Data minimization is no longer a privacy checkbox. It is becoming one of the most practical security controls an enterprise can deploy.

(Disclaimer: The views and opinions expressed in this article are those of the author and do not necessarily reflect the official position of The Cyber Express. This article is published as part of our contributed content program and is intended for informational purposes only.)

❌
❌