Cyber Law, Policy & Regulation

TRAI Finalised Spam Rules Barring Call Apps From Blanket-Blocking 140 and 1600 Series Numbers

India's telecom regulator finalised anti-spam rules that stop call-management apps such as Truecaller from blanket-blocking the 140 and 1600 number series, while adding AI-based flagging and charges for application-to-person calls. Compliance duties shift toward telecom operators.

india telecom spam regulation
Cybercrime, Fraud & Underground Markets

ShinyHunters Defaced the Clop Leak Site and Took Its Onion Service Private Keys

ShinyHunters exploited an unauthenticated upload flaw in Grav CMS to deface Clop's Tor leak site, claiming full server access plus theft of source code, plugins, logs and the onion service private keys. The crew gave Clop 72 hours before threatened extortion.

shinyhunters clop ransomware leak-site
Nation-State Attacks & Cyber Espionage

Russian Authorities Reported Attacks on Voting Systems During Parliamentary Elections

Russian authorities reported multiple attacks against electronic voting systems and communication lines as voters went to the polls in a three-day parliamentary election. Officials said the attempts were repelled without altering results, offering no attribution or technical detail.

breach-claimed russia election-security ddos
Data Breaches & Exposures

National Cancer Centre Singapore Mailing List Exposed Patients' Identities

An event invitation sent by the National Cancer Centre Singapore placed recipients in a visible address field, revealing the identities of patients to one another. The disclosure prompted privacy complaints over the handling of health-related contact lists.

breach-confirmed healthcare singapore data-exposure
Software & Supply Chain Attacks

TanStack npm Compromise Let an Attacker Copy 170 CrowdSec Private Repositories

CrowdSec disclosed that an attacker used the account of a recently departed employee to copy about 170 of the French security company's private GitHub repositories in May, following the TanStack npm package compromise. Offboarding gaps kept the access alive.

supply-chain npm github offboarding
Software & Supply Chain Attacks

WeaselBiscuit Stealer Reached Developers Through 13 Malicious npm Packages

Researchers found 13 npm packages delivering WeaselBiscuit, a previously undocumented JavaScript stealer built to harvest Chrome extension storage. The targeting of extension data put wallet and session material from developer machines within the operator's reach.

supply-chain npm infostealer
Nation-State Attacks & Cyber Espionage

Joint Advisory Tied North Korea's WaterPlum to 30,000 Infected Devices and 10.7 Million Dollars in Stolen Crypto

The FBI, Defense Department and partners in Japan, Australia and Germany described WaterPlum, a North Korean crew that infected at least 30,000 devices across 100 countries between December 2025 and July 2026. Operators drained about 7,000 wallets via fake job interviews.

breach-confirmed north-korea crypto-theft joint-advisory fake-jobs
Data Breaches & Exposures

Insecure P3 Global Intel Platform Exposed More Than 93,000 US Military Tips

An investigation into the Navigate360 breach found roughly 94,000 unclassified but sensitive tips submitted through US military P3 Global Intel apps and portals left accessible. Reporters found no evidence that affected submitters had been notified.

breach-confirmed military united-states data-exposure
Cyber Law, Policy & Regulation

Vietnam, Laos, Pakistan and Argentina Acted on North Korean IT Worker Findings

A United Nations follow-up report found Vietnam, Laos, Pakistan and Argentina had taken meaningful steps against North Korean IT worker networks flagged in an earlier study. The assessment marked the first measurable state response to the sanctions-evasion scheme.

north-korea sanctions united-nations it-workers
Privacy Rights & Data Protection

UK Security Assessment Found Police Data on Microsoft Cloud at Risk of Foreign Compromise

An official UK security assessment concluded that large volumes of sensitive police data stored on a Microsoft cloud platform sat at potential risk of compromise by hostile hackers and by US government access demands. The finding reopened data sovereignty questions for policing.

data-sovereignty united-kingdom cloud policing
Nation-State Attacks & Cyber Espionage

Transparent Tribe Deployed a Rust Backdoor Using Private GitHub Repositories for Command and Control

Pakistan-aligned Transparent Tribe, also tracked as APT36, targeted Indian government and defence entities with a new Rust backdoor that used private GitHub repositories as its command channel. Routing traffic through a trusted developer platform blunted network detection.

breach-confirmed apt36 pakistan india backdoor
Ransomware, Malware & Destructive Attacks

New Settra Ransomware Variant Struck Retail and Manufacturing Targets

Huntress detailed Settra, a newly identified ransomware variant deployed in two separate intrusions against retail and manufacturing organisations. The analysis documented post-compromise tradecraft including credential harvesting, lateral movement and defence evasion carried out well before the encryption stage.

ransomware manufacturing retail
Insider Threats, Data Theft and Whistleblowers

Insider Leak of 1,894 Records From South Korea's Raon Accelerator Went Undetected for Four Years

An insider removed 1,894 internal records from Raon, South Korea's heavy ion accelerator project built with a 1.5 trillion won state budget, and the exfiltration went unnoticed for four years. The lapse exposed weak monitoring around a flagship national research programme.

insider-threat south-korea research data-theft
Software & Supply Chain Attacks

Plugin4Shell Zero-Click Flaw Reached Claude Code, Codex, GitHub Copilot and Gemini CLI

A shared zero-click remote code execution weakness let repository owners swap pinned plugin code across four major AI coding agents, giving an attacker the agent's full reach into developer environments. Two of the four affected products remained unpatched at disclosure.

supply-chain ai-agents remote-code-execution developer-tools
AI Governance & Regulation

Governor Newsom Ordered California to Build Independent AI Oversight and Study a Model Kill Switch

California Governor Gavin Newsom signed an executive order directing an expert group to deliver a plan within two months for stronger state AI safety law, including independent third-party safety plans for frontier developers and a possible emergency model shutdown mechanism.

ai-governance california executive-order frontier-ai