Bahl noted that continuous cybersecurity audits will become essential from 2026
India’s cybersecurity agency warns of a fast-spreading npm supply chain worm, urging startups and ITes firms to secure credentials and audit dependencies.
The new MSME-specific framework offers a minimum cybersecurity baseline, complementing July’s sweeping audit mandate for all organisations.
Audit checklist includes evaluation of AI systems, software inventories, and cyber risk management across ministries and PSUs
Annual audits now expected across public and private sector entities, AI tools to be evaluated through AIBOM disclosures
The granularity required may not be feasible across all AI projects. Also, the guidelines fall short of addressing broader ethical or social dimensions -- crucial for building trust in public-facing systems.
CERT-In noted a surge in ransomware attacks, service disruptions, website defacements, data leaks, and malware activity as India and Pakistan clashed
Unlike conventional ransomware attacks that focus solely on monetary gains, these incidents involve data encryption, exfiltration, and public leaks to serve broader agendas.
The study found that smart cities in western, central and northern India were primarily affected by trojans such as Avalanche-Andromeda and Gamaru, leaving them vulnerable to cyber attacks
The advisory also warns about the role of AI in automating attacks, stating that artificial intelligence “can be used to automate attacks, analyse large datasets for vulnerabilities, and create very convincing phishing content".
Insecure Direct Object Reference (IDOR) vulnerabilities are a hidden flaw in web applications that can expose sensitive data to unauthorised users with just a small tweak in a URL.
CERT-In has issued serious warning for Android phones and tablets. The government body has also asked to update their device as soon as possible.
A simple Google search recently exposed websites leaking citizens' Aadhaar details, raising alarms about data privacy and security as India prepares to enforce its new Digital Personal Data Protection Act.
CERT-In has found some security issues in one of the D-Link routers that can put your personal data at risk.
Following the $230-million security breach in one of its multisig wallets and losing 45% of its holding assets, WazirX’s founder and CEO Shetty is in talks with global peers for support or finding a potential buyer.
Cert-In has graded the severity rating as “critical” and issued some tips for Microsoft Windows users who might be facing the “blue screen of death” on their systems.
The Indian Computer Emergency Response has warned users of multiple security vulnerabilities in Microsoft Edge which could be attacked by hackers to compromise your PCs.
CERT-In said that the two applications, USB Pratirodh and AppSamvid, were using weak cryptographic algorithms.
The vulnerabilities impact various Samsung devices, such as the Galaxy S23 series, Galaxy Flip 5, Galaxy Fold 5 and other Samsung devices running Android versions 11, 12, 13 and 14.
When compared to 2021, although CERT-In tackled marginally lesser number of cybersecurity incidents in 2022, data showed that phishing and malware attacks in India increased largely in the previous year
The majority of cyber attacks on APIs deployed in the Indian financial sector was due to security misconfiguration, the joint white paper by CERT-In, Mastercard, and CSIRT-Fin said
This marks the latest development in the year-long controversy surrounding several VPN companies, including Surfshark, that have removed their Indian servers, pledging non-compliance with CERT-In directions.
Last year's CERT-In directions mandated service providers including those offering virtual private networks (VPN) to maintain customer logs for a period of 5 years
AI language-based models such as ChatGPT have been misused for creating malwares, phishing campaigns and also for clearing examinations of prestigious institutions and top universities
This CERT-In report has come at a time when Indian government websites have been reported of being targeted by Indonesian hacktivists, and few months after All India Medical Institute of Medical Sciences suffered a major ransomware breach that rendered several of its services inaccessible.