Showing posts with label Cyber Security Advisory. Show all posts
Showing posts with label Cyber Security Advisory. Show all posts

Sunday, February 8, 2026

Cybersecurity’s Inflection Point: Claude 4.6 and the End of "Security by Obscurity"

In an era where digital infrastructure is the backbone of modern society, a quiet revolution has just taken place within the code that keeps our world turning. On 5 February 2026, the artificial intelligence firm Anthropic unveiled its latest powerhouse, Claude Opus 4.6. While the public was busy testing its creative writing and conversational quirks, Anthropic’s "Frontier Red Team" was putting the model through a far more gruelling trial: an autonomous hunt for the "ghosts in the machine"—those hidden security flaws that have eluded human eyes for decades.

The results, released this past Thursday, are nothing short of a watershed moment for global cybersecurity. The model identified and helped validate more than 500 high-severity vulnerabilities in widely used open-source software, highlighting the rapidly expanding role of AI in safeguarding—or potentially threatening—our digital lives.

For years, the gold standard for finding software bugs was a technique called "fuzzing." Imagine a machine gun firing millions of random data points at a piece of software, hoping one of them causes a crash. It is effective, but it is also blind. It cannot understand why a program fails; it only knows that it did.

Claude Opus 4.6 has changed the game by replacing brute force with human-like reasoning. Instead of guessing, the AI "read" the code. It studied the history of past mistakes (Git commits) and deduced where similar patterns of failure might still be lurking.

The Anatomy of the Hunt

To test this, researchers placed Claude in a "sandboxed" virtual environment—a digital cage where it could use standard developer tools like debuggers and compilers, but had no special instructions. It wasn't told where to look; it simply explored.

Traditional fuzzing is often a high-resource "shotgun" approach, whereas Claude Opus 4.6 offers a logical, code-analysis method. While the old way relies on zero understanding of logic, this new AI has a deep grasp of algorithm intent. This makes the search more targeted and efficient, uncovering deep architectural flaws that random data "bombardment" would miss.

The Hit List: Where the Flaws Were Found

The model didn't just find minor glitches; it identified hundreds of critical issues in the internet's most essential "plumbing." These are the open-source libraries that handle everything from your printer settings to your secure identity cards.

Read Also: Everyone have curosity who will win tonight ? India vs USAlive match

1. Ghostscript (The PDF Powerhouse)

Ghostscript is the engine behind many PDF and PostScript utilities. Claude discovered a stack buffer underflow—a type of flaw that can lead to system crashes or even allow attackers to take control of a machine. What’s remarkable is that this flaw was found by "reading" old security patches and spotting a similar, unpatched weakness in a different part of the code.

2. OpenSC (The Smart Card Key)

If you use a smart card for work or secure login, you likely rely on OpenSC middleware. Claude identified buffer overflow risks by spotting a pattern of successive string operations—risky code sequences that human reviewers had overlooked for years.

3. CGIF (The GIF Processor)

This was perhaps the most "human" discovery. To find a heap overflow in this GIF library, the AI had to understand the LZW compression algorithm. It wasn't just looking for a crash; it understood the mathematical logic of how a GIF is built and found an "edge case" where the logic failed. This is a vulnerability that traditional tools often miss because they require a very specific, logical sequence of steps to trigger.

The Human Element: Why We Aren't Redundant

Anthropic was quick to point out that this wasn't a solo effort. Every single one of the 500+ vulnerabilities was manually reviewed by human experts to eliminate false positives or "hallucinations"—where the AI imagines a bug that isn't actually there.

Many of these open-source projects are kept alive by small teams of volunteers who don't have the budget for a full-time security staff. By pairing Claude’s tireless speed with human intuition, the team could provide accurate, ready-to-use patches to the community, strengthening the foundations of the web for everyone.

The Dual-Use Dilemma: A Double-Edged Sword

There is, however, a darker side to this breakthrough. If an AI can find 500 bugs to help fix them, a malicious actor could use the same technology to find 500 bugs to exploit them. Anthropic calls this the "inflection point." The barrier to entry for high-level cyberattacks is dropping, as AI begins to outperform even expert human researchers in speed and scale.

To counter this "dual-use" risk, Anthropic has introduced "cyber-specific probes"—internal monitors that watch the model’s activity. If the AI begins to show signs of generating malicious exploit code rather than defensive research, the system is designed to intervene in real-time.

Read Also: Sustainability in Your Pocket: The 6,000mAh MarvelRedefining the Indian Entry-Level

Looking Ahead: The Future of Digital Defence

The release of Claude Opus 4.6 suggests that the "defender’s advantage" might finally be returning. For decades, hackers only had to find one hole, while defenders had to plug every single one. Now, with AI capable of scanning millions of lines of code with the nuance of a senior engineer, we may be entering an era where software is "secure by design" from the moment it is written.

The ghosts in the machine are being hunted. And for the first time, the hunters are faster than the shadows they chase.

By - Aaradhay Sharma 

Friday, January 16, 2026

Inside the RAM Crisis: Why Memory Chips Are Now More Valuable Than the PCs They Live In

If you thought graphics cards were once the hottest loot in tech thefts, 2026 has a new villain of the moment — RAM. In a bizarre yet telling incident reported on a Korean public forum, a thief broke into an office, shattered the tempered glass of a desktop PC, and walked away with just one thing: the memory modules. The computer itself? Left untouched.

Welcome to the era where RAM sticks can be worth more than the PC they’re installed in.

A Crime That Explains the Crisis

The stolen hardware consisted of four 32GB Micron RAM modules — small, light, easy to pocket, and shockingly valuable. With memory prices soaring, replacing them now costs far more than when the system was insured. The company’s insurer, according to the victim, is struggling to compensate because today’s RAM prices are wildly higher than even a few months ago.

From a criminal’s point of view, it was a smart move. Full PCs are bulky, traceable, and difficult to resell. RAM, on the other hand, is discreet, universally compatible, and fetches premium prices on the secondary market. Forum commenters noted that the thief clearly knew exactly what they were looking for — and why.

Why RAM Prices Have Gone Off the Rails

This isn’t your usual boom-and-bust semiconductor cycle. The current RAM shortage is being driven by a structural shift in the memory industry, largely powered by AI.

The explosive growth of AI models has created an insatiable demand for High-Bandwidth Memory (HBM), a specialized form of DRAM essential for AI accelerators in data centers. To chase higher margins, memory giants like Samsung, SK Hynix, and Micron have redirected massive portions of their production capacity away from consumer DDR4 and DDR5 RAM and toward HBM.

At the same time, manufacturers are being cautious. After burning their fingers during the 2022–2023 downturn, they’re reluctant to expand standard DRAM capacity too quickly. Add to that the fact that pandemic-era inventory buffers have completely dried up — and you have a perfect storm.

Read Also : boAt Reinvents the TWS Game with Nirvana Crown: India’s First Truly Interactive Earbuds Case

Consumers Feel the Heat

For everyday users, the impact is brutal. Consumer RAM prices have quadrupled in some markets, outpacing price hikes seen in CPUs, GPUs, or storage. High-capacity modules — including 128GB and 256GB sticks — are now selling for thousands of dollars.

This price shock has even changed how people think about PCsecurity. Some users are ditching glass side panels for solid metal cases, while others are physically locking down systems to prevent internal component theft.

What Happens Next?

Industry analysts warn that relief won’t come soon. With AI demand still accelerating, the RAM crunch could stretch into 2027 or even 2028. Until then, memory will remain expensive, scarce — and, apparently, tempting enough to steal.

Read Also : India’s Cybersecurity Wake-Up Call: Why 2026 Is the YearEnterprises Must Rethink Defence

In 2026, RAM isn’t just a component anymore. It’s currency.

By Aaradhay Sharma

Tuesday, January 13, 2026

India’s Cybersecurity Wake-Up Call: Why 2026 Is the Year Enterprises Must Rethink Defence

India’s digital economy is racing toward the $1 trillion mark, but cybercriminals are moving even faster. As businesses digitise at scale, attackers are no longer relying on brute force or random scams—they’re using AI, automation, and deep intelligence to strike with precision.

According to the India Cyber Threat Report 2026 by Seqrite, Indian organisations were hit with a staggering 265.52 million cyberattacks in the past year—that’s one new attack every 12 seconds. The message is clear: reactive security is broken. In 2026, survival depends on predictive, intelligence-driven defence.

Here are the five major cybersecurity trends reshaping how enterprises protect themselves.

1 AI-Powered Phishing Is Beating Humans and Machines

Phishing has evolved from obvious scam emails into highly personalised, AI-crafted messages that feel alarmingly real. These attacks mirror internal emails, reference real projects, and exploit job roles and live events.

Security experts at Barracuda Networks warn that such attacks routinely bypass traditional filters and awareness training. The new defence? Adaptive email security, real-time threat intelligence, and continuous risk scoring—not once-a-year training slides.

2 Ransomware Is No Longer a One-Time Attack

Today’s ransomware doesn’t just lock files—it moves in stages. Attackers steal data, encrypt systems, threaten public leaks, and often return for repeat extortion.

Threat data from Seqrite Labs shows ransomware activity at historic highs, with attackers deliberately targeting cloud workloads, identity systems, and backups. Enterprises are now prioritising immutable storage, network segmentation, and rapid recovery plans to stay operational.

3 Shadow AI Is the New Shadow IT—And Far More Dangerous

The rise of autonomous AI agents has quietly created a new risk: Shadow AI. These tools can copy themselves, evolve, and access sensitive data—often without leaving audit trails.

The result? Companies know data leaked, but can’t trace which AI did it or why. This “exposure without visibility” is becoming one of the most urgent enterprise risks of 2026.

Read Also:Stolen PAN Numbers Fuel a New Wave of Financial Fraud AcrossIndia

4 Quantum Threats Are No Longer Theoretical

Cybersecurity leaders now call 2026 the post-quantum inflection point. With “harvest-now, decrypt-later” attacks already underway, encrypted data stolen today could be broken tomorrow.

Forward-thinking enterprises are shifting to crypto-agility, ensuring they can rapidly switch encryption standards when quantum-safe algorithms become mandatory.

5 Zero Trust Grows Smarter—and More Aggressive

Security has moved from static defence to continuous AI-driven testing. Zero Trust 2.0 now extends into applications and AI systems themselves, treating AI agents as identities that must be monitored, restricted, and sandboxed.

Read Also: CrowdStrike Acquires SGNL to Bring Real-Time IdentitySecurity Into the AI Era

At the same time, geopolitical tensions are driving “geopatriation”—the migration of sensitive workloads to sovereign and regional clouds to ensure data residency, compliance, and national security alignment.

By Aaradhay Sharma

Monday, January 12, 2026

Seqrite Taps Terrabyte Group to Power Its Southeast Asia Cybersecurity Push

Seqrite, the global enterprise cybersecurity arm of Quick Heal Technologies, has taken a decisive step in expanding its Southeast Asia footprint by appointing Terrabyte Group as its Regional Distributor. The strategic partnership was formalised with the signing of a Memorandum of Understanding (MoU) at AISS 2025 in New Delhi, underscoring Seqrite’s long-term commitment to the fast-growing ASEAN cybersecurity market.

Under the agreement, Terrabyte Group will spearhead the distribution of Seqrite’s comprehensive cybersecurity portfolio across Singapore, Indonesia, Thailand, the Philippines, Vietnam, and Malaysia. The move builds on Terrabyte’s strong regional presence, deep market understanding, and proven track record in delivering enterprise-grade technology solutions across diverse and complex markets.

A Unified Answer to Rising Cyber Threats     

As Southeast Asia’s digital economy accelerates, organisations across the region are grappling with increasingly sophisticated cyber threats. Ransomware, Trojans, and identity-based attacks are evolving at a pace that traditional, siloed security tools can no longer contain—often compounded by human error and fragmented visibility.

Seqrite positions itself squarely at this challenge. As a full-stack cybersecurity company powered by AI and machine learning, Seqrite delivers end-to-end protection across the entire enterprise attack surface. Its portfolio spans Endpoint Protection, Endpoint Detection and Response (EDR), Extended Detection and Response (XDR), Zero Trust Network Access (ZTNA), Data Privacy and Governance, Mobile Device Management (MDM), BYOD security, Managed Detection and Response (MDR), alongside advanced malware analysis and real-time threat intelligence.

Together, these capabilities provide enterprises with continuous monitoring, cross-layer visibility, secure access control, and rapid, coordinated incident response—aligned with modern Cybersecurity Mesh Architecture principles.

Strengthening Cyber Defences Across ASEAN

For Terrabyte Group, the partnership significantly enhances its cybersecurity offering, enabling enterprises in Southeast Asia to adopt scalable, integrated, and regulation-ready security frameworks—from core endpoint defence to advanced data and identity protection.

Roy Toh, CEO of Terra International, noted that the collaboration reflects a shared vision for long-term cyber resilience in the region. “Partnering with Seqrite allows us to bring unified, AI-driven cybersecurity solutions—particularly EDR, XDR, and MDM—to enterprises seeking better visibility, faster response, and stronger overall security,” he said.

Echoing this sentiment, Dr Sanjay Katkar, Joint Managing Director of Quick Heal Technologies, emphasised Seqrite’s mission to simplify enterprise cybersecurity without sacrificing depth. “Through this partnership with Terrabyte, we are extending our full-stack, AI-powered security capabilities across Southeast Asia—helping organisations build a unified, resilient defence against modern cyber risks,” he said.

With this alliance, Seqrite and Terrabyte Group are set to play a pivotal role in shaping a more secure digital future for Southeast Asia’s rapidly evolving enterprise landscape.

BY- Nirosha Gupta 

Friday, January 9, 2026

Noida Institute of Engineering & Technology (NIET), Greater Noida, announced a collaboration with Salesforce

 Noida Institute of Engineering & Technology (NIET), Greater Noida, announced a collaboration with Salesforce, to establish a Tableau Lab, with an aim to build data literacy and analytical skills among students. This pioneering initiative addresses India's growing demand for data-skilled professionals by offering students hands-on experience with Tableau, the AI-first analytics platform that turns data into action. The lab will focus on agentic analytics, enabling students to go beyond simple visualization to build expertise in business intelligence and turn trusted insights into autonomous action.

Salesforce will co-design a curriculum to create the Tableau Lab, grounded in the vision of democratizing analytics through AI-first capabilities, while providing comprehensive faculty training. The curriculum will create an immersive learning environment featuring Tableau Agent, bringing conversational AI to the forefront of the student experience. Through lectures, tutorials, and practical exercises, students will master natural language data exploration and learn to utilize Q&A calibration to tune AI responses for accuracy.

Romil Agarwal, VP, Sales, Salesforce India, said, “For a nation as vast and diverse as India, data is more than just information—it’s the very language of our progress. The ability to harness an agentic data landscape, where AI doesn't just show us insights but proactively acts upon them, is one of the most critical skills for the future. India’s vast talent pool holds immense potential, and initiatives like the Tableau Lab are empowering students to master these agentic workflows, unlocking their potential to become the next generation of leaders. We are thrilled to collaborate with NIET to inspire and equip these young professionals to drive meaningful, autonomous impact across industries.”

 Dr. Neema Agarwal, Additional Managing Director, NIET Greater Noida, said, "At NIET, we are committed to equipping our students with the skills and mindset to lead in a data-driven world. The Tableau Lab initiative is a part of our commitment to integrating cutting-edge technology with industry-aligned education. By collaborating with Salesforce, we are giving our students the opportunity to explore new ways of thinking with data, develop analytical confidence, and embrace innovation and insight as drivers of real-world impact."

She added, “Salesforce and Tableau offer cutting-edge AI and analytics capabilities through platforms like Agentforce and Tableau Next. Their solutions also provide enterprise-grade security and scalability powered by Salesforce Hyperforce and Data Cloud. This partnership ensures students gain access to these latest innovations, preparing them for the future of work.”

 Dr. Vinod M Kapse, Director, NIET Greater Noida, shared, “This partnership strengthens NIET’s goal of bridging the gap between academic learning and industry expectations. Collaborations with global technology leaders like Salesforce enables us to offer students internships, live projects, and industry-recognised certifications, significantly enhancing their employability. With platforms like Tableau Cloud and Data Cloud, we can build scalable, secure, and AI-powered learning environments that support personalized learning paths, real-time feedback, and performance tracking.”

Dr. Anil Kumar Ahlawat, Director (Academics), NIET Greater Noida, said, “Data analytics and visualization have become essential to decision-making across every industry. The Tableau Lab will therefore be accessible to students across all programs and degree levels—from undergraduate to postgraduate and research - ensuring broad-based exposure to these critical skills. Our collaboration with Salesforce and Tableau reflects NIET’s commitment to aligning education with the evolving demands of the digital economy. By integrating these platforms into our curriculum, we are giving students hands-on experience in CRM, cloud technologies, data visualization, and analytics - skills that are in high demand across sectors including IT, finance, healthcare, and retail.”

 
The Tableau Lab reflects NIET's commitment to preparing students for a data-driven future by embedding analytics literacy across disciplines. For Salesforce, it demonstrates the company's commitment to closing the data skills gap and building a workforce ready to harness the power of data and AI. This collaboration exemplifies how academia and industry can unite to cultivate data culture, analytical thinking, and innovation in an increasingly AI-driven world.

By Advik Gupta

· Verify senders and links. Don't trust discounts or order notifications from emails or messages. Always double-check the sender

 Ransomware detections in the B2B sector increased due to a single dominant actor. The number of unique users in the Retail & E-commerce sector who encountered ransomware detections increased by 152% in 2025 compared to 2023 (Nov 2024 – Oct 2025 vs. Nov 2022 – Oct 2023). The most significant growth occurred during the 2024-2025 period and is largely attributable to the rapid spread of the Trojan-Ransom.Win32.Dcryptor family, which became highly prevalent across the retail and e-commerce sector in some of the analyzed markets. This malware is a trojanized ransomware variant that leverages the legitimate DiskCryptor utility to encrypt disk partitions on victim systems.

Phishing activity in the online retail segment stood out. Despite being a long-established attack technique, phishing remains highly prevalent in the context of online purchasing. From November 2024 through to October 2025, Kaspersky products blocked 6,651,955 attempts to access phishing links targeting users of online stores, payment systems, and delivery services. Of these attempts, 50.58% targeted online shoppers, 27.3% impersonated payment systems, and 22.12% targeted users of delivery companies.

Sales seasons continue to do the work for attackers. Seasonal peaks in online shopping consistently provide attackers with predictable opportunities to scale user-focused attacks. Periods of heightened promotional activity lower user vigilance and allow familiar phishing and spam scenarios to blend into legitimate marketing traffic, increasing their overall effectiveness.

Predictions: what retail & e-commerce cybersecurity might face in 2026

Chatbots are likely to become a common product discovery tool across online marketplaces. Unlike traditional search, conversational interfaces encourage users to share more detailed, natural-language requests, revealing preferences, constraints, and contextual information. This shift expands the privacy attack surface, as platforms accumulate richer user profiles through chat interactions. As a result, chatbot logs may become as sensitive as transactional data, increasing the risks of over-collection, misuse, or exposure of personal information.

"Search itself is changing, including how people look for products online. In 2025, there was a gradual shift from simple keyword queries to more conversational and visual ways of finding what to buy. As these models rely on broader user input, careful handling of the data involved will remain an important consideration for maintaining user trust,” – comments Anna Larkina, Web data and privacy analysis expert at Kaspersky.

Changes in taxes and trade rules might be exploited in online fraud. Modifications in taxes, import duties, and cross-border trade rules are likely to be used as lures in phishing campaigns and fraudulent online stores, promoting unrealistically cheap offers or claims of avoided fees. As pricing and fee rules continue to evolve across markets, it may lower vigilance, increasing the effectiveness of such schemes, particularly against small and mid-sized retailers.

 

AI-powered shopping assistants are expected to increasingly operate outside retail platforms, embedding themselves into browsers, mobile apps, and third-party services. While designed to simplify navigation and price discovery, these tools shift data collection beyond the retailer’s perimeter, creating new and less visible privacy risks. To function effectively, external AI shopping agents require continuous access to user behavior, including browsing activity, search intent, location context and product interactions across multiple sites. This enables the aggregation of detailed behavioral profiles outside the direct control of both users and retail platforms, increasing the risks of over-collection, opaque data usage, and unintended exposure.

Image-based product search might become a new challenge in privacy risks. Previously, the main privacy concern around user images in e-commerce was limited to photos voluntarily shared in product reviews. However, image-based product search is expected to make photo uploads a routine part of the shopping experience across major retail platforms. While this feature improves product discovery, it also increases the risk of unintended exposure of personal data. User-submitted images may contain faces, home environments, or sensitive details, such as names, phone numbers, or addresses visible on shipping labels or packaging, making secure processing, data minimization, and limited retention critical requirements for retailers. The full KSB retail and e-commerce report is available by link.

Kaspersky experts recommend the following to keep safe:

· Guard your privacy with smart tools. Be cautious about what you share and avoid uploading personal images or details in queries. Your interactions help build a profile used for ads and service improvements.

· Verify senders and links. Don't trust discounts or order notifications from emails or messages. Always double-check the sender's address and manually type the store's website URL into your browser instead of clicking on any links you receive.

· Research the store before buying. If you're shopping at a new or unfamiliar online store, take a moment to check its legitimacy: look for customer reviews, ensure the website address is spelled correctly, and confirm that the site pages look professional and polished.

· Monitor your card transactions regularly. Fraudulent charges can slip through unnoticed. Make it a habit (e.g., once a week) to log into your online banking or mobile app to review all recent transactions. If you spot anything suspicious, block your card and contact your bank immediately.

· Adopt a proactive security approach to protect against malware and data theft. Use reliable cybersecurity software like Kaspersky Premium to prevent infections and scan your device regularly. If you discover an infected app, remove it immediately and do not reinstall it until a confirmed, clean update is released. Complement this by managing sensitive data securely: avoid storing passwords or recovery phrases in your photo gallery or notes; instead, use a dedicated, trusted password software such as Kaspersky Password Manager.

For retail & e-commerce organizations we recommend:

· Protect corporate infrastructure against a wide range of threats, including phishing and ransomware. Use solutions from the Kaspersky Next product line that provide real-time protection, threat visibility, investigation and advanced response capabilities. If a company lacks cybersecurity workers, it can adopt managed security services such as Kaspersky Managed Detection and Response (MDR) and / or Incident Response that covers the entire incident management cycle – from threat identification to continuous protection and remediation

By Advik Gupta 

Monday, January 5, 2026

Cyberattacks in 2026 will no longer look like blunt-force digital assaults.

Cyberattacks in 2026 will no longer look like blunt-force digital assaults. Instead, they will behave, adapt, and even reason like humans.

That is the central warning in Seqrite’s India Cyber Threat Report 2026, released on January 5, where the enterprise cybersecurity arm of Quick Heal Technologies flags a new class of attacks it calls “cognitive threats.” These AI-driven intrusions signal a decisive break from the mass-scale, automated malware campaigns that dominated 2025.

According to the report, threat actors are now deploying autonomous AI systems capable of imitation, learning, and decision-making—blurring the line between human attackers and machines.

From Automation to Imitation

What makes cognitive threats fundamentally different is their human-like precision. Rather than relying on predefined scripts, these attacks operate with minimal human supervision, adjusting tactics in real time and blending seamlessly into normal digital behaviour.

One of the most concerning developments highlighted in the report is the rise of AI-generated digital twins. Using generative models, attackers can now recreate a person’s writing style, voice, and even video presence. These replicas are being weaponised for social engineering—making fraudulent emails, calls, and video messages almost indistinguishable from legitimate communication.

Malware That Evolves as It Attacks

Seqrite notes that modern AI-enabled malware is no longer static. These threats can alter their own signatures on the fly, dynamically change attack vectors, and persist inside systems by continuously adapting to security responses.

This adaptive persistence allows cognitive threats to evade traditional endpoint detection tools, which are still largely designed to recognise known patterns rather than evolving behaviour.

More critically, attackers are beginning to target the AI ecosystem itself. Development frameworks and orchestration tools—such as workflow-based AI platforms—are emerging as new attack surfaces, marking the early stages of direct assaults on AI infrastructure.

Rethinking Cyber Defence for 2026

To counter this shift, Seqrite argues that enterprises must move beyond reactive security and build what it terms “cognitive resilience.”

Key priorities include:

Identity as the Security Core: With network boundaries increasingly irrelevant, identity becomes the primary control point. Continuous authentication, Zero Trust architectures, and persistent MFA are essential.

Predictive Intelligence Over Alerts: Organisations need AI-powered threat intelligence that connects signals across endpoints, cloud environments, and networks—detecting intent, not just anomalies.

Machine-Speed Response: Defensive systems must be capable of autonomous decision-making, using generative AI and contextual correlation to neutralise threats faster than humans can react.

Securing the AI Stack: Internal AI models require integrity checks, adversarial testing, and protection against data poisoning to prevent manipulation from within.

Building a Human Firewall: As deepfake scams and hyper-personalised phishing increase, employee awareness becomes a frontline defence. Training must evolve to address deception that looks and sounds convincingly real.

A New Cyber Reality

Seqrite’s assessment makes one thing clear: cybersecurity in 2026 is no longer just a technical problem—it is a cognitive one. As attackers adopt AI systems that can observe, learn, and impersonate, defenders must respond with equal intelligence, autonomy, and foresight.

By Aaradhay Sharma

X Tightens the Screws on Illegal Content After India’s Warning

 Elon Musk-owned social media platform X has signalled a tougher stance on illegal and offensive content, announcing that it will swiftly remove unlawful material and permanently suspend accounts responsible for posting it. The platform also said it will cooperate with local governments and law enforcement agencies wherever required.

The announcement came through X’s Global Government Affairs account, just hours after the company clarified that users who exploit its AI chatbot Grok to generate illegal content will face the same penalties as those who upload such material directly.

The move follows a strong directive from India’s Ministry of Electronics and Information Technology (MeitY), issued on January 2, ordering X to immediately take down all vulgar, obscene and unlawful content, particularly material generated using Grok. The ministry warned that failure to comply could invite legal action under Indian law.

According to government officials, authorities had identified multiple instances of vulgar, obscene and otherwise unlawful content circulating on X, raising concerns about violations of local regulations.


Responding publicly to the issue, Musk posted on X:

“Anyone using Grok to make illegal content will suffer the same consequences as if they upload illegal content,”

in reply to a post flagging “inappropriate images”.

X’s Global Government Affairs team later reinforced this position, stating that the platform already takes firm action against illegal material, including Child Sexual Abuse Material (CSAM).

“We take action against illegal content on X by removing it, permanently suspending accounts, and working with local governments and law enforcement as necessary,” the statement said.

The company also shared a link to its platform rules, clarifying that while X allows consensually produced and distributed adult nudity or sexual behaviour, such content must be clearly labelled and must not be prominently displayed.

The latest crackdown underscores the growing scrutiny on AI-generated content and signals that platforms like X are under increasing pressure to align their moderation practices with local laws—especially as generative AI tools become more widely used.

BY: Nirosha Gupta

Saturday, January 3, 2026

Acronis Accelerates Cybersecurity Momentum With AI, Research, and MSP-First Innovation

Acronis, a global cybersecurity and data protection company, is rapidly strengthening its position in the cyber protection landscape by combining artificial intelligence, advanced threat research, and a growing ecosystem of partners. With cyber threats becoming faster, more automated, and increasingly AI-driven, Acronis is doubling down on practical, real-world security designed specifically for managed service providers (MSPs).

At the core of this momentum is Acronis’ platform-led approach, which prioritises operational simplicity for MSPs while delivering enterprise-grade protection. By integrating security, data protection, and management into a single platform, Acronis enables service providers to scale security services efficiently, improve margins, and reduce the complexity typically associated with modern cyber defence.

Threat Research Driving Smarter Security

A major driver behind Acronis’ security advancements is the Acronis Threat Research Unit (TRU). In 2025 alone, TRU published 17 in-depth research reports that examined emerging malware families, ransomware operations, and evolving attack techniques. These insights not only inform Acronis’ own product development but also contribute to the wider cybersecurity community.

Key research highlights from the year include investigations into live FileFix campaigns using steganography, the rapid rise of SafePay ransomware targeting MSPs, the DragonForce cartel’s expanding operations, and the growing misuse of Electron-based gaming applications to distribute credential stealers. TRU also tracked the evolution of Chaos RAT from an open-source project into a fully weaponised threat.

Industry Recognition Confirms Market Leadership

Acronis’ strategy has been repeatedly validated by leading analyst firms and peer review platforms. The company was named a Champion in the Canalys Global Cybersecurity Matrix (Q1 2025), with analysts highlighting its MSP-centric strategy and ease of doing business. Frost & Sullivan placed Acronis among the Leaders in its 2025 Endpoint Security Radar, citing strong innovation and growth potential.

IDC further reinforced this position by recognising Acronis as a Leader in the Cyber-Recovery MarketScape for the second time, while G2’s Winter 2025 Grid Report ranked Acronis among the top endpoint protection providers based on customer feedback and performance.

Expanding Security Capabilities Through Rapid Innovation

Acronis continues to enhance its security portfolio with new tools aimed at improving visibility, response, and automation. Recent launches include Security Posture Management for Microsoft 365, EDR augmentation for Microsoft Defender Antivirus, expanded use of Intel® Threat Detection Technology, and the release of SIEM Connector 2.0.

The company has also strengthened protections against human-centric risks through Collaboration Security and Security Awareness Training. To simplify adoption, Acronis Cyber Protect Cloud now offers bundled licensing for Protected Workspace, Microsoft 365 Protection, and Cyber Resilience—allowing MSPs to customise offerings without adding operational overhead.

Independent Testing Validates Security Performance

Acronis’ security effectiveness has been independently verified through multiple industry benchmarks. SE Labs awarded Acronis XDR an AAA rating after achieving 100% detection accuracy and a 98% overall accuracy score. AV-Test recognised the platform as a Leader in Advanced Threat Protection, while MITRE ATT&CK Evaluations highlighted its high-quality detections with minimal alert noise—an important advantage for MSP operations.

Strengthening the Ecosystem With Integrations and MSSP Support

Beyond product innovation, Acronis is expanding its ecosystem through strategic partnerships and programs. A new native integration with Fortinet FortiGate allows MSPs to deploy unified, end-to-end security for customers of all sizes. Additionally, the Acronis MSSP Program enables managed security service providers to deliver MDR services using the Acronis platform as certified regional partners.

“Security momentum isn’t just about releasing new features—it’s about protection that actually works at scale,” said Gerald Beuchelt, Chief Information Security Officer at Acronis. “By combining threat intelligence, rapid innovation, and strong partnerships, we help MSPs stay ahead of attackers instead of constantly reacting to them.”

Looking Ahead

Acronis plans to further expand the use of generative AI and automation across its platform to make cyber protection more autonomous and easier to manage at scale. The company is also preparing to address emerging attack vectors, including GenAI-powered threats, by translating ongoing TRU research directly into new security capabilities.

With a sustained focus on research-driven innovation, ecosystem growth, and MSP enablement, Acronis continues to set the direction for modern cyber protection in an increasingly complex threat environment.

By Aaradhay Sharma

Phishing Goes Visual: Malicious QR Code Attacks Explode, Kaspersky Warns

Cybersecurity firm Kaspersky has flagged a sharp rise in phishing attacks that rely on malicious QR codes, warning that cybercriminals are increasingly turning to the tactic to bypass traditional email security filters. The company recorded a dramatic jump in detections—from 46,969 cases in August to 249,723 by November—marking a surge of more than five times in just three months.

According to Kaspersky, QR codes are becoming a preferred weapon for attackers because they are inexpensive to deploy and effective at hiding harmful links. Many email security tools struggle to analyse images, allowing QR-based threats to slip through undetected.

These QR codes are typically placed directly in email messages or hidden inside PDF attachments, a method that serves two purposes: disguising the malicious link and nudging recipients to scan it using smartphones. Mobile devices, especially personal ones used for work emails, often lack the same level of security controls as corporate desktops, making them an easier target.

The company observed that malicious QR codes are being used across both large-scale phishing campaigns and more focused, targeted attacks. Once scanned, the codes can redirect victims to counterfeit login pages mimicking Microsoft accounts or internal company portals, harvesting usernames, passwords, and other sensitive information.

In other cases, attackers pose as HR departments, sending emails that urge employees to view or sign documents such as leave schedules or termination lists. These messages ultimately funnel users to fake authentication pages designed to steal credentials. Another growing tactic involves bogus invoices or purchase confirmations delivered via PDF attachments. Victims are sometimes encouraged to call phone numbers listed in the documents, combining QR phishing with voice-based social engineering to deepen the attack.

Such campaigns prey on familiarity and trust in everyday workplace communications, often resulting in compromised accounts, data leaks, and financial losses.

“QR-code-based phishing has emerged as one of the most successful attack techniques this year, particularly when embedded in PDFs or masked as legitimate business messages like HR alerts,” said Roman Dedenok, Anti-Spam Expert at Kaspersky. “The sharp rise in November shows how attackers are exploiting this low-cost method to target employees on mobile devices, where security protections are frequently weaker.”

To counter the growing threat, Kaspersky advises organizations to strengthen email security with solutions capable of detecting image-based attacks. Tools such as Kaspersky Security for Mail Server can help protect corporate email systems against spam, phishing, business email compromise, QR code threats, and other email-borne risks.

By Aaradhay Sharma

Friday, January 2, 2026

European Space Agency Probes Cyber Breach After 200GB of Internal Data Allegedly Stolen

The European Space Agency (ESA) has acknowledged a cybersecurity incident that affected a small portion of its digital infrastructure, confirming on December 30, 2025, that several science-related servers were breached. As of January 2, 2026, the agency says a detailed forensic probe is still underway to fully understand the scope of the intrusion.

What Happened

Early signs of the breach surfaced on December 26, after claims appeared on the underground forum BreachForums. A hacker operating under the alias “888” alleged responsibility, stating they maintained unauthorized access to ESA systems for nearly a week beginning around December 18.

Systems and Data Exposure

According to ESA, the incident was confined to a very limited number of externally hosted servers that sit outside its main corporate network. These systems were reportedly used for collaborative engineering and research activities rather than mission-critical operations.

The attacker claims to have exfiltrated around 200 GB of internal data, allegedly including:

Private source code repositories hosted on Bitbucket

CI/CD workflow files and Terraform-based infrastructure scripts

API keys, access tokens, and embedded credentials

Internal technical documentation, SQL database files, and confidential records

ESA has emphasized that these servers did not contain classified information or sensitive mission data, and there is currently no indication that core operational systems were impacted.

ESA’s Response

Following detection, ESA launched a comprehensive security investigation to identify affected assets, lock down vulnerabilities, and prevent further unauthorized access. Relevant partners and collaborators have been notified as part of standard incident response procedures.

A Pattern of Cyber Threats

This breach comes just a year after a separate cyber incident in December 2024, when ESA’s online retail platform was compromised by a credit card–skimming attack—highlighting the growing cybersecurity challenges faced even by high-profile space and research organizations.

By - Aaradhay Sharma

A New UPI Scam You’ve Probably Never Heard Of — And It Can Empty Your Account Without OTPs or Links

India’s Unified Payments Interface (UPI) has made digital payments fast, simple, and nearly universal. From street vendors to large retailers, millions rely on it every day. But as UPI becomes more deeply woven into daily life, fraudsters are quietly developing smarter and more subtle ways to exploit it.

One such method, now surfacing across the country, is the “Jumped Deposit” scam—a form of fraud that doesn’t involve fake links, malware apps, or even OTP theft. Instead, it cleverly manipulates users into authorising payments themselves, using entirely legitimate UPI features.

What makes this scam especially dangerous is that everything appears genuine—right up to the moment money disappears from your account.

What Exactly Is the ‘Jumped Deposit’ Scam?

Unlike conventional frauds where criminals try to pull money out of your account directly, this scam begins by putting money into your bank account first.

Here’s how it starts:

A scammer sends a UPI transfer—often ₹5,000 or more—into your account.

Soon after, you receive a call or message claiming the transfer was accidental.

The sender politely asks you to “return” the money.

Since the amount is actually credited, most people assume it’s a genuine mistake and try to help. That trust is precisely what the scammer exploits.

How the Scam Traps You Step by Step

The fraud hinges on confusion about how UPI works:

1 Unexpected Credit

You receive a legitimate-looking UPI credit. No alerts, no red flags.

2 Follow-Up Call or Message

The sender contacts you, sounding anxious or urgent, asking for the money back.

3 Fake “Refund” Setup

While you’re checking your balance or transaction history, the scammer sends a “collect” or payment request.

4 The Critical Mistake

Believing the request is part of the refund or balance verification process, you enter your UPI PIN.

5 Money Is Debited

By entering your PIN, you unknowingly approve a debit, often for an amount much larger than what was originally credited.

🔴 Important truth many users don’t know:

👉 UPI never requires a PIN to receive money.

👉 A PIN is needed only when money leaves your account.

Why This Scam Works So Well

No fake apps or phishing links

No OTP requests

No malware

Uses real UPI transactions

Exploits user goodwill and urgency

Because everything appears official, victims don’t realize they’ve been scammed until it’s too late.

How to Stay Safe from the Jumped Deposit Scam

Don’t Act Immediately

If you receive an unexpected UPI credit, wait at least 15–30 minutes before opening your app. Many fraudulent requests expire automatically.

Use the “Wrong PIN” Trick

If you must open your UPI app immediately, intentionally enter the wrong PIN once. This cancels any active debit requests without moving money.

Remember This Golden Rule

No refund, balance check, or incoming payment ever needs a UPI PIN.

Talk to the Bank — Not the Caller

Always verify unexpected credits through official bank customer care, not through numbers shared by the sender.

Ignore Pressure Tactics

Scammers rush you so you don’t think. Slow down. Legitimate mistakes can wait.

If You’ve Already Been Scammed — Act Fast

Time is critical. The sooner you respond, the better your chances of recovery.

🔹 Inform Your Bank Immediately

Request a transaction freeze and lodge a fraud complaint.

🔹 Report to Cybercrime Authorities

File a complaint at the National Cyber Crime Reporting Portal or visit your nearest cybercrime police station.

🔹 Alert Your UPI App Provider

Use the in-app support section or NPCI grievance system to report the fraud officially.

By - Aaradhay Sharma

Thursday, January 1, 2026

New Call Forwarding Scam Alert: How Fraudsters Hijack Your Phone Using Simple USSD Codes

Indian cyber authorities have flagged a growing phone-based scam that allows criminals to secretly divert your calls—without installing any app, clicking a link, or using the internet. The trick relies entirely on USSD call forwarding codes, a legitimate telecom function that most users rarely think about.

What’s Really Happening Behind the Scam

Fraudsters are exploiting human trust rather than technology loopholes. The attack starts with a convincing phone call and ends with complete control over a victim’s financial alerts and verification calls.

Step 1: Fake Identity

Scammers typically pose as delivery executives or courier partners, claiming an urgent issue with a parcel that needs “quick confirmation.”

Step 2: Psychological Pressure

The caller insists the problem must be resolved immediately and guides the victim to dial a “verification” code—often framed as a routine delivery check.

Step 3: Silent Call Diversion

The victim is asked to dial a USSD sequence such as *21*, *61*, or *67* followed by the scammer’s number. This instantly activates call forwarding.

Step 4: Complete Takeover

Once enabled, all incoming calls—including bank verification calls, OTP confirmations, and security alerts—are redirected to the fraudster. With this access, criminals can:

Approve banking transactions

Reset account passwords

Hijack WhatsApp, Telegram, and email accounts

Why This Scam Is Especially Dangerous

According to India’s cybercrime authorities, this fraud is difficult to detect because:

USSD commands work offline and execute instantly

Phones often do not show alerts when call forwarding is enabled

No malware or suspicious app is involved

Antivirus and spam filters are largely ineffective

Most victims realise something is wrong only after money is withdrawn or accounts are locked.

Official Safety Advisory: What You Must Do

The National Cybercrime Threat Analytics Unit (TAU), under I4C and the Ministry of Home Affairs, recommends the following precautions:

Never dial USSD codes shared by unknown callers—especially those starting with *21, *61, or *67

If you suspect call diversion, immediately dial ##002# to cancel all call forwarding

Always verify delivery-related issues directly through official courier websites or customer care numbers

Keep a close watch on bank statements and account alerts

Report incidents immediately via:

Cybercrime helpline: 1930

National Cyber Crime Reporting Portal

Key Takeaway

This scam proves that not all cyber frauds rely on apps, links, or hacking tools. Sometimes, a single phone call and a simple code are enough to compromise your financial security.

Staying safe now depends less on software—and more on awareness.

By - Aaradhay Sharma

Digital gifts go mainstream: Half of holiday shoppers plan virtual presents, Kaspersky report finds

 Digital gifting is quickly becoming a holiday staple, with nearly half of shoppers planning to give virtual presents this Christmas, according to a new report by cybersecurity firm Kaspersky. Streaming subscriptions, gaming credits, and personalized digital greetings are emerging as the most popular choices for the 2025–26 holiday season.

As daily life continues to move online, digital gifts are no longer a novelty. Ahead of the holiday shopping rush, Kaspersky conducted a global survey to understand how consumers are embracing virtual gifting—and which options are winning hearts.

The findings show that only 25% of respondents still prefer physical gifts exclusively and have no plans to switch. Meanwhile, 32% already give digital presents, 16% are open to trying them for the first time, and 28% expect to adopt digital gifting in the near future, though not this year.


Young shoppers lead the digital gifting trend

Consumers aged 18–34 are driving the shift, with 63% planning to buy digital gifts this holiday season. Nearly half of them (46%) have already gifted something virtual. In contrast, older consumers aged 55 and above remain more traditional, with 46% saying they still prefer physical presents.

Streaming beats sweaters

Entertainment subscriptions top the list of digital gifts. Nearly two-thirds of respondents who have considered digital gifting said they would choose streaming services like Netflix or Spotify. Gaming credits and subscriptions ranked second at 40%, rising to 47% among younger users.

Other popular digital gifts include online courses (34%), e-book subscriptions (31%), and creative software such as Photoshop or Illustrator (28%). Digital wellness is also gaining traction, with 25% interested in fitness subscriptions, though mental wellness services like meditation or therapy platforms attracted less interest (17%).

Convenience comes with cyber risks

Kaspersky warns that the rise in digital gifting also increases cybersecurity risks. Fake online stores, phishing emails, and fraudulent subscription links often surge during the holiday season, especially as scammers use AI to create highly convincing fake websites and messages.

To stay safe, Kaspersky advises shoppers to double-check links, avoid suspicious offers, and use security solutions with AI-powered anti-phishing features to protect payments and personal data.

Virtual greetings gain popularity

Personalized video or audio greetings—such as messages from Santa Claus or celebrities—along with digital postcards, were chosen by 21% of respondents. While these gifts offer a personal touch, experts caution that some services collect excessive personal data, raising privacy concerns.

Security software emerges as a thoughtful gift

Interestingly, one in three respondents said they would like to give or receive cybersecurity products as gifts. Password managers, VPNs, and security software are increasingly seen as meaningful presents that offer protection and peace of mind.

“It’s encouraging to see growing interest in cybersecurity solutions as gifts. It shows that people now view digital protection as a form of care for their loved ones, not just a technical necessity,” said Marina Titova, Vice President for Consumer Business at Kaspersky.

About the study

The survey was conducted in November 2025 by Kaspersky’s market research center. It included 3,000 respondents across 15 countries, including India, the UK, Germany, China, the UAE, and South Africa.

BY- Nirosha Gupta

Wednesday, December 31, 2025

A December 2025 global study by Kaspersky, based on insights from 3,000 consumers

Digital presents are no longer a niche alternative—they are rapidly becoming a default choice for modern holiday shoppers. A December 2025 global study by Kaspersky, based on insights from 3,000 consumers, shows that one in every two shoppers now plans to gift something entirely virtual this Christmas, signalling a decisive shift away from physical-only gifting traditions.

What’s driving the change is not just convenience, but a redefinition of value. Consumers—especially younger generations—are prioritising access, experiences, and utility over tangible ownership.

What People Are Gifting Instead of Boxes and Wrapping Paper

Subscriptions dominate the digital gifting landscape in 2025. Entertainment services such as streaming and music platforms remain the top choice, selected by nearly two-thirds of respondents. Gaming-related credits and memberships follow closely, reflecting the continued rise of interactive entertainment economies.

Education and reading have also gone digital-first. Online learning platforms and e-books are increasingly viewed as meaningful gifts, especially for recipients seeking personal or professional growth.

Interestingly, digital wellness has emerged as a new gifting category. Fitness apps, mindfulness platforms, and mental health subscriptions are gaining traction, reinforcing the idea that self-care is now considered a gift worth giving.

Perhaps the most unexpected evolution: cybersecurity products as presents. A growing segment of consumers now sees password managers, VPNs, and security software as thoughtful, practical gifts—reflecting rising awareness of digital risks in everyday life.

A Clear Generational Divide

The report highlights a sharp age-based contrast in gifting behaviour.

Nearly two-thirds of consumers aged 18–34 plan to give digital gifts this season.

Among shoppers over 55, adoption drops dramatically, with fewer than one in three willing to move away from physical presents.

This divide underscores how digital-native generations associate value with immediacy and personalization, while older consumers still anchor gifting in tradition and tangibility.

Regional Momentum Accelerates Adoption

Digital gifting adoption is especially strong in the Middle East and parts of Africa:

Saudi Arabia leads the shift, with 70% of shoppers opting for virtual gifts.

The UAE follows closely at 65%, driven largely by younger residents.

South Africa shows steady momentum, with more than half of shoppers embracing digital presents.

These markets reflect broader trends of mobile-first commerce and high digital service adoption.

Personalisation Goes Virtual—but with Caveats

Beyond subscriptions, consumers are embracing personalised digital experiences. Custom holiday videos, celebrity messages, and digital postcards are becoming popular alternatives to traditional greeting cards.

However, Kaspersky warns that not all personalization platforms are safe. Some services request excessive personal data, creating privacy risks that shoppers may overlook in the festive rush.

The Dark Side of Digital Convenience

The surge in digital gifting has also opened new doors for cybercrime. Kaspersky researchers report a rise in AI-driven phishing campaigns designed to impersonate well-known subscription brands. These scams often peak during last-minute shopping periods, when consumers are more likely to act quickly and ignore warning signs.

Fake checkout pages, fraudulent renewal emails, and spoofed gift notifications are among the most common tactics used to steal payment credentials.

Expert advice: shoppers should rely on AI-powered security tools that can detect malicious links in real time, verify websites, and safeguard financial transactions.

Why Insight-Led Decisions Matter for Brands

As digital gifting reshapes consumer expectations, brands can no longer rely on intuition alone. This is where First Insight plays a critical role—helping retailers eliminate costly guesswork around product demand, pricing, and assortment strategies.

By embedding real consumer feedback into every decision, First Insight enables brands to:

Launch the right digital offerings faster

Price with confidence

Reduce overproduction and missed demand

Strengthen customer loyalty while protecting margins

In a market where preferences evolve at digital speed, insight—not instinct—has become the real competitive advantage.

By - Aaradhay Sharma

Samsung Fold 8 Ultra or Wide: Which Fits You?

Welcome Back to Techno Gadget!  Samsung has completely shaken up the foldable market with its 2026 flagship release. Launched on July 22, 20...