The Cyber Express Weekly Roundup: Claude Session Hijacking, PaperCut Exploits, and Enterprise Cyberattacks











Australia and India have unveiled the Australia-India PACTS, a new framework designed to deepen bilateral cooperation on cybersecurity, critical technologies, supply chain resilience, digital resilience, and defence research.
The new partnership replaces the 2020 Framework Arrangement on Cyber and Cyber Enabled Critical Technology Cooperation and aims to strengthen national security, economic growth, and regional stability across the Indo-Pacific.
The two countries said the Australia-India Partnership on Cyber, Critical Technologies and Supply Chains (PACTS) builds on two decades of research collaboration, operational coordination, and policy engagement. It also reflects their shared commitment to creating secure digital ecosystems while promoting trusted technology partnerships.
The Australia-India PACTS is structured around five pillars that will drive collaboration between governments, research institutions, universities, and the private sector. The framework is intended to increase two-way investment in emerging technologies while supporting innovation and the commercialisation of research.
The first pillar focuses on supply chain resilience by strengthening trusted technology supply chains and promoting secure trade. Both countries will establish a bilateral mechanism for trusted vendor frameworks and work together to improve undersea cable security through the Quad Partnership for Cable Connectivity and Resilience. The partnership also includes collaboration on semiconductor research, critical minerals, and trade diversification.
The second pillar focuses on critical technologies, with Australia and India planning to strengthen cooperation in artificial intelligence, telecommunications, biotechnology, advanced materials, and space technologies.
The framework also supports the development of international standards for trustworthy AI and encourages collaboration between academic institutions and industry to promote responsible AI deployment. The two countries will also explore joint research, investment initiatives, and commercial partnerships in emerging technologies to strengthen long-term economic security across the Indo-Pacific.
A major component of the partnership is Australia India cybersecurity cooperation. Under the third pillar, both governments will work together to counter cybercrime, deter malicious cyber activity, strengthen cyber policy coordination, and protect critical infrastructure.
The framework proposes a consolidated bilateral mechanism for cyber and ICT cooperation, expanded engagement in United Nations cyber processes, increased trade opportunities for cybersecurity businesses, and practical workshops involving government agencies and industry stakeholders.
The partnership will also establish a cyber technology skills incubator to promote knowledge exchange and workforce development.
The fourth pillar focuses on digital resilience across the Indo-Pacific. Australia and India will collaborate on trusted Digital Public Infrastructure initiatives and promote scalable digital solutions that support connectivity, healthcare, education, renewable energy, critical infrastructure, and digital transformation.
The partnership also seeks to expand pilot projects that help countries across the region build adaptable digital ecosystems while strengthening regional capabilities.
The fifth pillar strengthens defence science collaboration through joint research, innovation partnerships, and greater engagement between Australia's Defence Science and Technology Group and India's Defence Research and Development Organisation.
Areas of cooperation include maritime surveillance, advanced materials, defence innovation, and stronger links between defence start-up ecosystems.
The Australia-India PACTS will be jointly overseen by the Australian Deputy Secretary of the International and Security Group within the Department of the Prime Minister and Cabinet and the Indian Deputy National Security Advisor. Annual Senior Officials Meetings will review progress, assess emerging cyber and technology risks, and identify future collaborative projects under each pillar.
With the launch of Australia-India Partnership on Cyber, Critical Technologies and Supply Chains (PACTS), both countries have outlined a long-term roadmap that brings together cybersecurity, critical technologies, supply chain resilience, digital resilience, and defence cooperation under a single strategic framework aimed at strengthening security and technology collaboration across the Indo-Pacific.






Seventy percent of all sensitive data sitting in enterprise systems right now has not been accessed, used, or reviewed in years, according to a Data Risk report from 2021. It was never deleted when it should have been and, in a breach, it is just as exposed as everything else. For years, enterprises treated personal data as an asset to be collected first and governed later. More data meant better personalization, sharper analytics, stronger fraud models, and business intelligence. But in DPDP and cybersecurity, that equation is changing. Data without a clear purpose is no longer an asset. It is an attack surface.
India’s cyber risk environment makes this urgent. In 2025, CERT-In handled over 29.44 lakh cyber incidents. IBM’s 2025 breach research pegged the average cost of a data breach in India at ₹220 million, while the global average stood at USD 4.44 million. Verizon’s 2026 Data Breach Investigations Report found that 31% of breaches now start with software vulnerability exploitation, overtaking stolen credentials as the leading entry point.
What that figure means in practice is that attackers are no longer just looking for weak passwords. They are looking for unguarded data stores, and enterprises that hold more data than they need are giving attackers more to find.
This is why the Digital Personal Data Protection (DPDP) framework should not be viewed only as privacy compliance. It is also a cybersecurity reset. It forces enterprises to ask a fundamental security question: why are we holding this data in the first place?
Data minimization is not about doing less business. It is about reducing unnecessary exposure. Every extra field collected, every duplicated customer record, every old document retained beyond its purpose, and every vendor copy sitting outside the organization’s control expands the blast radius of a breach.
Security teams can encrypt systems and monitor networks, but they cannot fully protect data that the business does not know exists, no longer needs, or cannot justify.
DPDP and cybersecurity changes that conversation. Organizations must be able to explain what they collect, why they collect it, how long they keep it, whom they share it with, and when it must be deleted.
These are not just legal requirements. They are security design principles.
The law also carries serious consequences. Failure to maintain reasonable security safeguards can attract penalties of up to ₹250 crore, while failure to notify the Board or affected individuals of a personal data breach can attract penalties of up to ₹200 crore.
The most secure piece of personal data is the one you never collected unnecessarily. The second most secure is the one you deleted when its purpose was fulfilled.
For Indian enterprises, digital journeys have become data-heavy by default. Onboarding, lending, insurance, healthcare, ecommerce, and fraud prevention journeys may all have legitimate reasons to process personal data. The challenge is to distinguish necessary data from convenient data.
Cyber risk is no longer limited to firewalls and endpoint protection. It includes data hoarding, excessive access, old records, test data, unused integrations, shadow databases, and third-party copies.
When a breach happens, regulators, customers, and partners will not only ask how the attacker got in. They will ask why so much data was there to be exposed.
Data minimization reduces three risks.
Together, these three elements create a mature enterprise cybersecurity posture.
The hardest balancing act will be fraud prevention.
Banks, insurers, fintechs, marketplaces, and digital platforms need strong controls to detect synthetic identities, account takeover, mule activity, payment fraud, and suspicious behavior. But fraud prevention cannot become a blanket justification for collecting everything.
The way forward is not to weaken fraud controls. It is to make them sharper.
Purpose-bound fraud prevention means collecting only the data required for a specific risk decision, using it with clear controls, retaining it for a justified period, and restricting access to systems that genuinely need it.
Good security does not require unlimited data. It requires the right data, governed well.
This is where trust becomes a competitive advantage. Enterprises that can demonstrate why they collect data, how they protect it, and when they delete it will earn customer and partner confidence.
In a market where cyber threats are rising and regulatory scrutiny is increasing, trust will influence both customer choice and institutional credibility.
For boards and leadership teams, the question is no longer, “Are we DPDP compliant?”
The sharper question is, “Can we prove that our data practices reduce risk?”
Answering that question requires more than a compliance audit. It requires a live view of personal data across the enterprise: what exists, where it goes, who can access it, and whether it still needs to.
Privacy and security used to be treated as separate disciplines with separate teams, budgets, and agendas. That separation is no longer viable. A security team that does not know what personal data the business holds cannot protect it. A privacy team that does not have technical visibility into data flows cannot govern them.
DPDP is not asking enterprises to choose between innovation and protection. It is asking them to build digital systems where innovation does not depend on uncontrolled data accumulation.
For too long, “collect more” was seen as the safer business strategy. In the DPDP era, the safer cybersecurity strategy may be the opposite: collect with purpose, protect with discipline, and delete with confidence.
Data minimization is no longer a privacy checkbox. It is becoming one of the most practical security controls an enterprise can deploy.
(Disclaimer: The views and opinions expressed in this article are those of the author and do not necessarily reflect the official position of The Cyber Express. This article is published as part of our contributed content program and is intended for informational purposes only.)





In this weekly roundup from The Cyber Express, the global cybersecurity landscape in 2026 continues to shift rapidly as emerging technologies and evolving cyber threats reshape the digital environment. Governments are increasing oversight of artificial intelligence and data practices, while ransomware groups, nation-state actors, and cybercriminal networks are refining their tactics to target enterprises, critical infrastructure, and software supply chains.
This week’s developments highlight how modern cyber risks are becoming more interconnected across industries, with AI-driven attacks, ransomware operations, privacy concerns, and software supply chain compromises continuing to place pressure on organizations worldwide.
Cyber activity linked to artificial intelligence has intensified across the Americas during Q1 2026, with attackers increasingly leveraging AI-driven tools to scale ransomware campaigns, automate reconnaissance, and enhance social engineering operations. A scheduled webinar on May 28 by Cyble will bring together security specialists to examine emerging cyber trends, including ransomware evolution, nation-state activity, and defensive strategies to improve cyber resilience. Read more...