Visualização de leitura

Ransomware protection: how endpoint security and backup work together

According to Verizon’s 2023 Data Breach Investigations Report, ransomware was the primary method used in 24% of data breaches in 2023. To protect sensitive data, companies must implement proactive measures for ransomware protection. Understanding the nature of ransomware attacks is essential for developing effective prevention and recovery strategies.

Talos: Attackers Refine Phishing Playbook To Target Critical Infrastructure

Phishing played a part in more than half of all incident response engagements undertaken by Talos, Cisco's threat research organization, during the second quarter of 2026, with healthcare organizations and manufacturing firms among the top targets.

The post Talos: Attackers Refine Phishing Playbook To Target Critical Infrastructure appeared first on The Security Ledger with Paul F. Roberts.

Edge Devices Are Your Cyber Underbelly. Here’s Why.

In this episode of the podcast, host Paul Roberts interviews Nishawn Smagh of the firm GreyNoise Intelligence about the findings of their State of the Edge report, an analysis of GreyNoise data on risks stemming from compromised edge devices such as broadband routers, VPN gateways, smart home devices and more. Shawn and Paul talk about how attackers are turning edge devices into their favorite entry point, and strategies for organizations to counter the growing risk of compromised edge devices.

The post Edge Devices Are Your Cyber Underbelly. Here’s Why. appeared first on The Security Ledger with Paul F. Roberts.

💾

Australia-India PACTS to Deepen Cybersecurity and Tech Collaboration

Australia-India PACTS

Australia and India have unveiled the Australia-India PACTS, a new framework designed to deepen bilateral cooperation on cybersecurity, critical technologies, supply chain resilience, digital resilience, and defence research.

The new partnership replaces the 2020 Framework Arrangement on Cyber and Cyber Enabled Critical Technology Cooperation and aims to strengthen national security, economic growth, and regional stability across the Indo-Pacific.

The two countries said the Australia-India Partnership on Cyber, Critical Technologies and Supply Chains (PACTS) builds on two decades of research collaboration, operational coordination, and policy engagement. It also reflects their shared commitment to creating secure digital ecosystems while promoting trusted technology partnerships.

Australia-India PACTS Built on Five Pillars

The Australia-India PACTS is structured around five pillars that will drive collaboration between governments, research institutions, universities, and the private sector. The framework is intended to increase two-way investment in emerging technologies while supporting innovation and the commercialisation of research.

The first pillar focuses on supply chain resilience by strengthening trusted technology supply chains and promoting secure trade. Both countries will establish a bilateral mechanism for trusted vendor frameworks and work together to improve undersea cable security through the Quad Partnership for Cable Connectivity and Resilience. The partnership also includes collaboration on semiconductor research, critical minerals, and trade diversification.

Australia-India PACTS Expands Critical Technology Collaboration

The second pillar focuses on critical technologies, with Australia and India planning to strengthen cooperation in artificial intelligence, telecommunications, biotechnology, advanced materials, and space technologies.

The framework also supports the development of international standards for trustworthy AI and encourages collaboration between academic institutions and industry to promote responsible AI deployment. The two countries will also explore joint research, investment initiatives, and commercial partnerships in emerging technologies to strengthen long-term economic security across the Indo-Pacific.

Australia-India Prioritises Cybersecurity

A major component of the partnership is Australia India cybersecurity cooperation. Under the third pillar, both governments will work together to counter cybercrime, deter malicious cyber activity, strengthen cyber policy coordination, and protect critical infrastructure.

The framework proposes a consolidated bilateral mechanism for cyber and ICT cooperation, expanded engagement in United Nations cyber processes, increased trade opportunities for cybersecurity businesses, and practical workshops involving government agencies and industry stakeholders.

The partnership will also establish a cyber technology skills incubator to promote knowledge exchange and workforce development.

Australia-India PACTS Advances Digital Resilience

The fourth pillar focuses on digital resilience across the Indo-Pacific. Australia and India will collaborate on trusted Digital Public Infrastructure initiatives and promote scalable digital solutions that support connectivity, healthcare, education, renewable energy, critical infrastructure, and digital transformation.

The partnership also seeks to expand pilot projects that help countries across the region build adaptable digital ecosystems while strengthening regional capabilities.

Defence Research and Governance Framework

The fifth pillar strengthens defence science collaboration through joint research, innovation partnerships, and greater engagement between Australia's Defence Science and Technology Group and India's Defence Research and Development Organisation.

Areas of cooperation include maritime surveillance, advanced materials, defence innovation, and stronger links between defence start-up ecosystems.

The Australia-India PACTS will be jointly overseen by the Australian Deputy Secretary of the International and Security Group within the Department of the Prime Minister and Cabinet and the Indian Deputy National Security Advisor. Annual Senior Officials Meetings will review progress, assess emerging cyber and technology risks, and identify future collaborative projects under each pillar.

With the launch of Australia-India Partnership on Cyber, Critical Technologies and Supply Chains (PACTS), both countries have outlined a long-term roadmap that brings together cybersecurity, critical technologies, supply chain resilience, digital resilience, and defence cooperation under a single strategic framework aimed at strengthening security and technology collaboration across the Indo-Pacific.

Residential Proxy Risks: Understanding Google’s Latest Action Against 2 Million Strong NetNut

Google announced that it helped take down NetNut, a 2 million strong malicious residential proxy network. The incident highlights the growing risks posed by residential proxy networks that quietly conscript consumer devices into services used by cybercriminals and nation-state actors alike.

The post Residential Proxy Risks: Understanding Google’s Latest Action Against 2 Million Strong NetNut appeared first on The Security Ledger with Paul F. Roberts.

Law enforcememt operation disrupted Malicious Residential Proxy Networks NetNut

Google disrupted NetNut, a major proxy network that routed internet traffic through compromised home devices used by cybercriminals.

Google has disrupted NetNut, one of the world’s largest residential proxy networks. The service routed internet traffic through home devices, allowing customers to hide their real location and identity.

“Today, in coordination with the FBI, Lumen, and others, Google took action against the NetNut residential proxy network, also known as Popa.” reads the Google’s announcment. “This action builds on our disruption of the IPIDEA proxy network that took place in January 2026, and is a continuation of Google’s objective to dismantle malicious residential proxy networks.”

While proxy services have legitimate uses, networks like NetNut are also widely abused by cybercriminals for fraud, account takeovers, web scraping, and other malicious activities.

NetNut is composed of approximately 2 million compromised home devices. It turns smart TVs, streaming boxes, and other consumer devices into proxy nodes, allowing cybercriminals and espionage groups to hide their identity. Owners often have no idea their devices are being misused, exposing their home networks to additional threats while their internet connections can be abused for hacking, password spraying, fraud, and DDoS attacks.

“In a single week during June 2026, GTIG observed 316 distinct threat clusters using suspected NetNut exit nodes, including cybercriminal and espionage groups. These bad actors can use NetNut to mask their origin IP address when accessing victim environments, accessing their own infrastructure, and conducting password spray attacks.” states the announcement. “Furthermore, when a consumer device becomes an exit node, unauthorized network traffic passes through it.”

Google warns users to avoid apps that promise money for sharing “unused bandwidth” or internet access, as they are often used to build malicious proxy networks. Download apps only from trusted stores, review VPN and proxy permissions, and keep security features like Google Play Protect enabled. When buying connected devices such as TV boxes, choose reputable brands and verify they are Play Protect certified to reduce the risk of compromise.

“While point-in-time disruptions are a critical tool to protect our users, continued and coordinated effort is needed to reduce malicious proxy networks in the long run.” concludes the announcement. “We encourage mobile platforms, ISPs, and other tech platforms to continue sharing intelligence and to take direct action to block malicious C2 infrastructure.”

Cybersecurity firms involved in the investigation linked NetNut to Alarum Technologies, although the company denies operating a botnet and says users consent to bandwidth sharing. Researchers dispute that claim, reporting no clear user consent in tested apps. Google’s disruption has weakened NetNut by removing millions of compromised devices, but warns the threat remains because many proxy providers resell the same infrastructure. Experts believe the takedown will significantly disrupt cybercriminals while also reducing abuse tied to large DDoS botnets.

“Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account,” Omer Weiss, legal counsel for NetNut parent Alarum Technologies, said in a written statement, as reported by KrebsOnSecurity.

Synthient founder Benjamin Brundage recently reported he believes the operation is a major setback for cybercriminals, especially after Google’s earlier action against IPIDEA, NetNut’s main competitor, significantly weakened another key source of residential proxy infrastructure.

“As KrebsOnSecurity has warned repeatedly, most of the no-name TV streaming boxes for sale on the major e-commerce websites either come pre-installed with residential proxy software, or require the installation of proxy SDKs in order to use the device for its stated purpose (streaming pirated movies, sporting events and TV shows).” concludes KrebsOnSecurity. “Google’s advice here is sound: When it comes to TV boxes, stick to name brands from reputable manufacturers, and then be sparing and judicious with any apps you choose to install.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, botnet)

Sunil Varkey Joins Hexaware Technologies as EVP & CISO

Sunil Varkey

Sunil Varkey has been appointed as Executive Vice President (EVP) and Chief Information Security Officer (CISO) at Hexaware Technologies, where he will lead the company's information security strategy, governance, risk management, and enterprise resilience initiatives. The appointment marks the latest leadership role for the cybersecurity veteran, who brings more than three decades of experience across global enterprises and multiple industry sectors. Based in Chennai, India, and operating in a hybrid work model, Varkey will be responsible for strengthening enterprise cybersecurity governance, risk management frameworks, and overall security strategy at Hexaware Technologies. His appointment was announced in June 2026.

Sunil Varkey to Lead Cybersecurity Strategy at Hexaware Technologies

In his new role, Sunil Varkey will oversee key areas including information security governance, enterprise risk management, and resilience initiatives. His responsibilities align with Hexaware Technologies' broader technology and growth objectives as the company continues to support large-scale digital transformation programs for clients worldwide. Hexaware Technologies delivers technology-led services across application development, cloud services, automation, data analytics, and enterprise IT operations. The company serves organizations across multiple industries and supports digital modernization initiatives at scale. Varkey's appointment comes as organizations continue to focus on strengthening cybersecurity programs and managing digital risks across increasingly complex technology environments.

More Than 30 Years of Cybersecurity Leadership Experience

Varkey brings over 30 years of experience in cybersecurity leadership spanning banking, telecommunications, IT services, manufacturing, and enterprise technology sectors. His professional experience extends across India, the Middle East, and the United States. His areas of expertise include cybersecurity governance, risk and compliance (GRC), security architecture, incident response, DevSecOps, cloud security, privacy management, cyber defense, business continuity management, security operations, and AI security. Prior to joining Hexaware Technologies, Varkey served as Cyber Security Consultant and Advisor at TAHAKOM in Riyadh, Saudi Arabia, from June 2023 to March 2025. In that role, he worked alongside the organization's CISO to enhance cybersecurity resilience and strengthen security posture. Before TAHAKOM, he held the position of Vice President and Chief Technology Officer for EMEA and APJ at Forescout Technologies Inc. between April 2021 and November 2022. Based in Dubai, he focused on IT/OT security strategy, enterprise cybersecurity advisory services, and product positioning across global markets.

Leadership Roles Across Global Organizations

Between March 2020 and January 2021, Varkey served as Managing Director and Global Head of Cyber Security Assessments and Testing at HSBC in Hyderabad. He led a team of approximately 300 professionals responsible for penetration testing, threat modeling, vulnerability management, and third-party security risk assessments. Earlier, from December 2018 to February 2020, he worked as CTO and Security Strategist for the Middle East, Africa, and Eastern Europe region at Symantec. His responsibilities included developing cybersecurity strategies for enterprise, government, industrial, and financial sector organizations. His career also includes senior leadership positions such as Global CISO at Wipro, CISO for Security and Privacy at Idea Cellular, and Vice President of Security Engineering at Barclays. Additionally, he held global security leadership roles at GE Capital, Genpact, Paramount Computer Systems, and other multinational organizations.

Focus on Governance, Risk Management, and Enterprise Resilience

Throughout his career, Varkey has overseen cybersecurity functions covering governance, compliance, strategy, security engineering, incident response, privacy, cloud security, cyber defense, and enterprise resilience. His experience includes leading security programs for organizations with large-scale user bases and complex operational environments. At Wipro, he served as Global CISO for a technology company supporting more than 200,000 end users. At Idea Cellular, he led security and privacy initiatives for a telecom operator with approximately 120 million subscribers. With his appointment, Hexaware Technologies adds a cybersecurity leader with extensive experience in building and scaling security programs across global enterprises. The move underscores the company's continued focus on strengthening cybersecurity operations, governance frameworks, and digital risk management capabilities as part of its ongoing technology initiatives.

Acronis Cyber Protect Cloud adds support for Windows on ARM devices

Windows on ARM is becoming increasingly relevant for business endpoints. Newer ARM-based Windows laptops are built for mobility, long battery life, quiet operation and on-device AI workloads. Acronis Cyber Protect Cloud now supports Windows on ARM devices for the core services MSPs need first: Backup, anti-malware, self-protection, remote management and cyber scripting.

The pivotal point of IT: Why service delivery models must change in the AI-first era

At Acronis, the shift to move AI into daily operations has been years in the making. Our focus on AI began well before generative AI entered the mainstream, with early investment in machine‑learning capabilities in 2015. On May 13, 2026, Acronis will host a live virtual broadcast, The pivotal point of IT: Building services for the AI‑first era, focused on addressing this exact challenge.

❌