Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Latest News

China's New Challenge: Fake AI Videos During Natural Disasters

  As China grapples with intensified storms and flooding over recent months, authorities face an unexpected secondary crisis: a surge of AI-...

All the recent news you need to know

Bank of Baroda Data Breach: What We Know About the Alleged 1TB Dark Web Leak

 



Bank of Baroda has confirmed a cybersecurity incident involving a compromised employee email account after reports emerged that nearly 1TB of data allegedly linked to the state-owned lender had been published on the Dark Web.

The bank said the compromised account resulted in unauthorised access to certain data, but clarified that its core banking systems were not accessed and continue to remain secure. It said the incident was identified promptly, containment measures were implemented, and a comprehensive forensic investigation has been launched in coordination with relevant authorities.

The confirmation followed reports from the X account DailyDarkWeb and cybersecurity researcher Srikanth Lakshmanan, founder of CashlessConsumer, who flagged an alleged large-scale data dump connected to Bank of Baroda.

According to the claims, the dataset contains personal and corporate banking records, including savings and current account information, loan records, NetBanking users, NRI and corporate banking services, customer-support documents, and records linked to branches and ATMs. Reports from researchers also said the material included customer details, identification documents and internal audit records.

Samples and download links were reportedly shared alongside the threat actor's claim of possessing approximately 1TB of data.

However, the size of the alleged dataset has not been independently established by Bank of Baroda. Reuters reported that the Dark Web listing was advertised as a cache exceeding 700GB based on metadata analysis conducted by Lakshmanan. The number of customers whose information may have been exposed also remains unknown.

This distinction is important. The appearance of a large archive online does not, by itself, establish that every file originated from Bank of Baroda or that the entire advertised volume was successfully exfiltrated from the bank.


What allegedly appeared in the data dump?

The initial claims described a wide range of banking information. This reportedly included savings and current account records, loan-related documents, NetBanking information, NRI and corporate banking records, customer-support material, and branch and ATM data.

Other reports said samples contained highly sensitive information such as Aadhaar details, customer names, loan documents and other identity-related records. Some reports citing the claims placed the number of customer application forms potentially involved between 100,000 and 300,000. These figures remain allegations and have not been confirmed by Bank of Baroda.

Lakshmanan also shared screenshots that he said showed the root folder of the alleged data dump and reported that the download link was active. He described the incident as a "cyber disaster" and called for the Reserve Bank of India (RBI) and National Payments Corporation of India (NPCI) to consider disconnecting the bank's systems while the extent of the compromise was investigated.

At the time of those warnings, the source and method of the alleged data theft were unclear.

Bank of Baroda's subsequent statement has now provided an important piece of that picture.


Employee email account was the confirmed entry point

According to the bank, the confirmed incident involved the compromise of an employee's email account. The account was then used to obtain unauthorised access to certain data.

Bank of Baroda has not disclosed how the email account was compromised, what specific files were accessed, or whether all of the data advertised on the Dark Web originated through that account.

The lender has, however, clearly stated that its core banking systems were not accessed and remain secure.

That distinction matters because compromising an employee's email account is not the same as compromising the systems that process customer transactions.

At the same time, an email account inside a large financial institution can provide access to highly sensitive material. Depending on the employee's role and permissions, an account may contain customer correspondence, loan documents, identity records, internal reports or links to shared resources.

The incident therefore demonstrates how an attacker may be able to obtain valuable financial information without directly breaching the core platform responsible for banking transactions.


Customer risk extends beyond stolen funds

There is currently no public evidence that the alleged incident allowed attackers to directly access customer balances or manipulate transactions. Bank of Baroda has specifically said that its core banking systems were not accessed.

The potential exposure of personal and financial records nevertheless creates a separate risk.

Information such as customer names, identity documents, account-related details and loan records could give criminals material for highly targeted phishing and impersonation attempts. A scammer with genuine information about a customer's banking relationship can make fraudulent calls, emails or messages appear far more credible.

Customers should therefore be particularly cautious of communications claiming to originate from Bank of Baroda and requesting OTPs, passwords, PINs, card information or remote access to devices.

The reported leak should not automatically be interpreted as evidence that customer funds have been compromised. The more immediate concern, if the exposed records are genuine, is the possibility of follow-on fraud using information that customers would normally expect their bank to protect.


Forensic investigation now underway

Bank of Baroda said it has initiated a comprehensive forensic investigation to establish the nature and extent of the incident. The bank also said it is working with relevant authorities in accordance with applicable regulatory requirements.

Several key questions remain unanswered.

Investigators will need to determine how the employee's email account was compromised, what information was accessible through it, how much data was actually accessed or exfiltrated, and whether the Dark Web archive corresponds to the confirmed incident.

The investigation will also need to establish how many customers, if any, were affected.

The incident has already generated financial implications for the lender. The Economic Times reported that Bank of Baroda notified a preliminary cyber-insurance claim under a programme with total coverage of approximately ₹750 crore, with National Insurance Company serving as the lead insurer. The notification is an intimation of loss while the forensic investigation continues and does not represent a confirmed ₹750 crore loss.

The financial consequences of a data breach can extend beyond direct theft. Forensic investigations, remediation, legal costs, regulatory responses, customer support and other incident-response expenses can all contribute to the eventual cost.


Regulatory questions remain

The incident also places renewed attention on cybersecurity controls within India's banking sector.

CERT-In's directions under Section 70B of the Information Technology Act establish requirements for information-security practices, incident response and cyber-incident reporting.

Bank of Baroda has said it is cooperating with relevant authorities, although the public details of its regulatory notifications have not been disclosed.

For now, the most important distinction is between what has been confirmed and what remains alleged.

Bank of Baroda has confirmed that an employee's email account was compromised and that the incident resulted in unauthorised access to certain data. It has also confirmed that its core banking systems were not accessed.

The claim that approximately 1TB of Bank of Baroda information was leaked, the precise contents of the Dark Web archive, and the number of customers potentially affected remain subject to investigation.

What began as an alarming Dark Web claim has therefore evolved into a confirmed security incident with an unresolved scope. The forensic investigation will determine whether the reported hundreds of gigabytes of banking information represent the full extent of the compromise, a smaller subset of genuine Bank of Baroda data, or a mixture of both.

Meccha Chameleon Vulnerability Allowed Malware to Spread Through Steam Workshop Maps

 

A security vulnerability in the game Meccha Chameleon enabled malicious custom maps stored on Steam Workshop to infect users with malware. The vulnerability was patched by the game’s developers, who noted that the issue was related to the custom content feature. The issue was initially uncovered when some players reported that a command prompt window was flashing as Steam was downloading a custom workshop map. 

Security researcher Feint investigated the matter and found that one of the maps entitled Laser Tag Neon had the ability to deploy malware dropper despite having passed the Steam Workshop review process. Feint shared his findings on social media, noting that another map entitled Chroma Grid Arena had replaced the malicious content, which indicated that the threat was still present.

It appears that the vulnerability could enable threat actors to utilize the game’s custom workshop feature to deploy malware onto users’ computers disguised as legitimate content. Meccha Chameleon developer Haganeiro confirmed that the issue had been resolved in version 3.1.0. He noted that the malware had been disabled both prior to the update and following its deployment, thus limiting the potential impact of the vulnerability. 

The vulnerability was part of a larger security incident that involved the game’s Discord server, which housed 90 thousand members. The server was hacked, with the attacker rewriting its permissions and removing the developer team from the server. According to lemorion_1224, the Discord compromise occurred when the system administrator’s computer was infected with malware during the mitigation efforts of the vulnerability. The attacker was able to bypass the two-factor authentication of the server and modify its settings, banning several members of the development team. 

It was revealed that the compromised machine belonged to the backup server, and it was later wiped clean. The developer warned the community against clicking the suspicious links that were distributed via the hacked discord server while mitigation measures were being implemented. It appears that a wide range of potential attack surfaces could be utilized to threaten the community. Gaming platforms have a diverse range of threat surfaces that can be utilized by attackers to compromise users’ computers. 

In addition to the game binaries themselves, the custom content and third-party tools such as Discord can be threatened. Players should ensure they have the latest versions of the software and avoid interacting with suspicious links or content.

ICE Can Now Buy Your Credit Card Information

Every time you apply for a credit card or update your account details, you may be sharing your data with ICE.

A research by 404 Media said that personal information stored by credit card firms can sail through a network of data brokers and can become accessible to US Immigration and Customs Enforcement (ICE). ICE can then search and investigate your personal data without any warrant. 

“No one signing up for a credit card thinks they’re giving data brokers a thumbs-up to sell their personal information to ICE. Not only is it an outrageous violation of our privacy, [but] it’s impossible for Americans to opt out,” Senator Ron Wyden said to 404 Media in a statement. 

What private information is compromised?

According to 404 media, when someone opens a credit card or updates their personal data, credit card firms share that data with credit bureaus. 

The personal information consists of Social Security numbers, addresses and email addresses, names, and phone numbers. Contrary to credit reports, this data does not have robust legal security. 

Personal information is then sent to credit bureaus, who give the data to Thompson Reuters. From there, the data is incorporated into CLEAR, the firm’s investigative data product. Thomson Reuters sells access to CLEAR to law enforcement authorities, including ICE.

After gaining access to CLEAR, ICE can search through personal information without a warrant. "404 Media has mapped out this supply of data by reviewing U.S. government procurement records and internal documents from companies providing the information." The platform is also combined with a tool that suggests ICE to decide which neighbourhoods to raid. 

"Anytime we update our home addresses on these accounts, credit bureaus get the updates within 24 hours and share it broadly with other data brokers, thanks to legal loopholes that leave our personal information open to misuse and abuse," Just Futures attorney Laura Rivera said to 404 Media.

Thomson Reuters providing personal data to US government

Another report enquired Thompson Reuter’s increasing role in providing personal data to the US Government.

The Department of Homeland Security (DHS) is planning to pay Thomson Reuters $125 million to give access to its databases as part of enquiries into suspected immigration fraud and voter fraud. The agreement will be worth $25 million annually for five years respectively.

New CSS Attacks Expose Webmail Users to Passord and Token Theft


In new research, CSS-based attacks have been discovered that can bypass security protections in webmail services, allowing attackers to steal passwords, authentication tokens, and other sensitive data. In order to demonstrate the ability of malicious email content to interact with trusted elements within a webmail interface, these techniques demonstrate how their contents can escape their intended boundaries. 

Gareth Heyes, PortSwigger researcher, presented the study at Black Hat USA 2026. The research examined attack chains with Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. There has been no report of proof-of-concept attacks being used in the wild, however researchers have warned that vulnerabilities in the way webmail platforms handle HTML and CSS may pose serious security risks. 

In one of the most significant demonstrations, researchers were able to disguise a select element as a password field by combining HTML elements, CSS manipulation, and browser behavior. Through the use of this technique, a victim could enter a password into what appeared to be a genuine Microsoft login interface and be captured as a result. 

An underlying problem stems from the fact that webmail platforms allow untrusted HTML and CSS to be displayed within an otherwise trusted interface. It was discovered that attackers could either take advantage of CSS features already allowed by webmail services or exploit the gap between what the sanitizer approves and what the browser actually renders by exploiting the sanitizer. There are also instances in which applications can utilize JavaScript to create new DOM elements with CSS properties that weren't included in the original allowlist of the sanitizer, resulting in the malicious email content escaping its intended boundaries.

Researchers discovered that Yahoo Mail and AOL Mail were vulnerable to a different vulnerability involving pasted HTML Researchers showed how CSS remains active for a short period of time before sanitization allows the attacker to extract portions of an email login token. A 12-character token can then be reconstructed and used to access the victim's account. A CSS selector can be used to determine which digits appear in an email when Content Security Policy prevents an email from making conventional external requests. 

Using CSS selectors, an attacker can identify which digits appear in an email as well as how frequently they occur. By carefully positioning the links so that only the matching option is visible, the attacker-controlled server will receive the inferred information with only one click, without the need for JavaScript. During the Gmail attack, users were required to ask Cowork to process their affected emails, after which the malicious instructions embedded within the message influenced the way the AI system handled the account information. 

During the demonstration, prompt injection, along with email content, demonstrated how the legitimate access of an AI assistant can be turned into a path to expose sensitive tokens, particularly when the assistant has the ability to read messages and write email drafts. A similar attack against the Atlas browser of OpenAI was demonstrated with Fastmail.

In CSS techniques, malicious instructions are concealed from the user while being visible to the artificial intelligence system, demonstrating that differences in how web content is interpreted by human and machine are potentially dangerous, leading to new attack opportunities. Moreover, the researchers identified techniques for manipulating trusted interface actions, bypassing certain content restrictions, and revealing information, such as the time an email was viewed or the IP address of the recipient, in one Proton Mail demonstration. 

Researchers also demonstrated the potential for revealing the recipient's IP address using Proton Mail's tracker-protection mechanisms. As a result of Proton Mail's tracker-protection mechanism, email senders are not able to obtain the IP address of a user and the precise time of email open, the demonstrated bypass illustrates yet again the vulnerability of CSS and webmail rendering behavior to undermine privacy. 

Fastmail was reported to have fixed two CSS mutation vulnerabilities at the time of publication, while the Proton Mail proxy bypass demonstrated at the time was not observed during retesting. However, the Outlook label-jacking technique and Gmail's image-set() bypass remain effective as of August 6. Additionally, the research did not establish whether all aspects of the Outlook password capture chain had been resolved. 

According to the researchers, HTML email should be contained within sandboxed iframes, strict CSS allowlists should be applied, dangerous selectors and select menus should be blocked, custom attributes should be examined for CSS-based attack gadgets and attacker-controlled image requests should be prevented. As traditional content-sanitization defenses face increasingly sophisticated CSS-based attacks, webmail security is becoming increasingly complex. 

With the advent of artificial intelligence assistants having access to email inboxes and other connected services, providers should strengthen their isolation and rendering controls in order to prevent malicious email content from becoming an avenue for credential theft as well as data exposure.


Think Hotel Wi-Fi Is Safe? Hackers Have Several Ways to Prove You Wrong

 



For many travelers, connecting to hotel Wi-Fi is one of the first things they do after checking in. But while some guests use the network for banking and work, others avoid sensitive activity unless they are connected through a VPN.

So, how safe is hotel Wi-Fi?

Cybersecurity experts say the answer is more nuanced than simply calling public Wi-Fi dangerous. Modern encryption has reduced many of the risks associated with public networks, but hotel Wi-Fi can still expose travelers to rogue networks, phishing attacks, poorly configured infrastructure and vulnerable devices.

In many cases, the biggest risk may not be the network itself, but how the user connects to and behaves on it.


The first risk can come from a fake network

Security analyst Udaya Vemuri advises travelers to be cautious about joining a network simply because its name appears to belong to the hotel.

Attackers can create fake Wi-Fi networks with names almost identical to legitimate hotel networks. The technique, known as an "evil twin" attack, can trick guests into connecting to an attacker-controlled access point.

The FBI's Internet Crime Complaint Center warned about this threat in a 2020 advisory, noting that criminals can create networks resembling legitimate hotel Wi-Fi and potentially monitor activity or redirect victims to fraudulent login pages. The agency also warned that hotel guests have limited control over the security of the infrastructure they are using, which may prioritize convenience over stronger security practices.

Travelers should therefore confirm the exact Wi-Fi name with hotel staff before connecting rather than selecting the network that merely looks familiar.


Simply sharing a network does not mean you are compromised

Dahvid Schloss, chief operating officer of cybersecurity firm Suzu Labs and a former government hacker who has security-tested hotel chains, takes a less alarmist view.

Schloss compares hotel Wi-Fi with other public networks, such as those in coffee shops. In his assessment, the likelihood of being attacked simply because another malicious user is connected to the same network is low.

That distinction matters because the common image of hackers automatically reading passwords from public Wi-Fi is outdated.

The Federal Trade Commission says most websites now use encryption, meaning information sent between a device and a legitimate website is generally protected even when the underlying network is public. HTTPS can therefore provide substantial protection against traffic interception.

However, HTTPS does not prove that a website is legitimate. Attackers can create encrypted fraudulent websites and use phishing or redirection to persuade victims to submit credentials.

This means a traveler can still be exposed even when the connection itself appears encrypted.


Fake hotel portals can steal credentials

Hotels commonly use captive portals that redirect guests to a webpage after they connect to Wi-Fi. These pages may request a room number, surname, email address or access code.

Because travelers expect this process, attackers can imitate it.

A rogue network may display a fake hotel login page or redirect users to a fraudulent Microsoft 365, email or banking page. In such cases, the attacker does not necessarily need to break encryption. The victim may simply be tricked into providing the information.

This makes phishing and social engineering an important part of the hotel Wi-Fi threat.


Network security is not a perfect guarantee

Recent research also shows why travelers should not assume that network-level protections make public Wi-Fi completely secure.

Researchers at the University of California, Riverside reported in February 2026 that weaknesses in Wi-Fi client isolation can, under certain conditions, allow attackers to bypass protections designed to prevent devices on the same network from interacting with one another.

Their AirSnitch research demonstrated techniques that could potentially allow an attacker to intercept or manipulate traffic despite client isolation.

The findings do not mean every hotel network is vulnerable, but they reinforce an important point: users should not rely entirely on the security mechanisms implemented by a public network.


Your device can be the weakest link

Both experts place considerable emphasis on user behavior.

Schloss argues that laptops can be particularly vulnerable to poor security habits because they are frequently used to download files, install software and access corporate systems. Smartphones are not immune, but their operating systems often impose stronger application restrictions.

The FBI recommends updating operating systems and applications before travel, keeping security software current, backing up important data, disabling Bluetooth when unnecessary and preventing devices from automatically reconnecting to public networks.

Automatic reconnection is particularly important because a device may join a previously saved network without the user consciously verifying that it is legitimate.

Browser warnings should also never be ignored. A certificate warning, unexpected redirect or request to install software can indicate that something is wrong with the connection or destination.


Use cellular data for sensitive activity

Vemuri takes a more cautious approach when handling sensitive information. For banking, work systems and other private activity, he uses a mobile hotspot instead of hotel Wi-Fi. When hotel Wi-Fi is unavoidable, he keeps devices updated, enables multifactor authentication and avoids sensitive tasks.

The FBI similarly recommends using a phone's hotspot instead of hotel Wi-Fi when possible, particularly for sensitive activity and telework.

A cellular hotspot is not completely immune to cyber threats, but it removes the user from the hotel's shared wireless environment and reduces exposure to risks associated with public Wi-Fi.


A VPN and MFA can add protection

For travelers who need to use hotel Wi-Fi, a reputable VPN can provide another layer of security by encrypting traffic between the device and the VPN provider. The FBI recommends reputable VPNs for telework over hotel Wi-Fi.

A VPN is not a substitute for other security measures, however. It cannot prevent phishing, malware downloads or users from voluntarily entering credentials into fraudulent websites.

Multifactor authentication can limit the damage if a password is compromised. The FBI recommends MFA for sensitive accounts and advises users to enable login notifications so suspicious activity can be detected quickly.

Travelers should configure MFA before leaving home rather than waiting until they are already on the road.


What travelers should do

Before connecting to hotel Wi-Fi, users should:

  1. Confirm the legitimate network name with hotel staff.
  2. Update their operating system, browser and applications.
  3. Disable automatic connection to public networks.
  4. Enable MFA and account security alerts.
  5. Use a cellular hotspot for banking and highly sensitive activity where possible.
  6. Use a reputable VPN for sensitive work when hotel Wi-Fi is unavoidable.
  7. Verify the website address and HTTPS before entering credentials.
  8. Avoid unfamiliar downloads or software updates prompted by Wi-Fi portals.
  9. Disable Bluetooth when it is not needed.
  10. Never bypass browser security warnings.


So, is hotel Wi-Fi safe?

Hotel Wi-Fi is not automatically dangerous, but it should not be treated as a trusted network either.

Simply sharing a network with an attacker does not mean a modern device will automatically be compromised, particularly when legitimate services use encryption. At the same time, rogue access points, fake captive portals, phishing, vulnerable devices and weaknesses in network isolation can create opportunities for attackers.

For routine browsing, an updated device using legitimate HTTPS websites can be reasonably protected. For banking, corporate systems and other highly sensitive activity, using a cellular hotspot remains the more cautious option.

The practical rule for travelers is simple: do not panic about hotel Wi-Fi, but do not trust it blindly either. Verify the network, secure your devices and accounts, and keep sensitive activity off shared networks whenever possible.

ShinyHunters Data Leaks Fuel $2,000 Sextortion Email Scam

 

Cybercriminals are exploiting email addresses exposed in previous ShinyHunters data leaks to conduct a new sextortion campaign demanding $2,000 in Bitcoin. The fraudulent messages falsely claim that ShinyHunters compromised victims’ phones and computers, accessed their cameras and microphones, and recorded them visiting adult websites. However, the campaign appears to involve unrelated scammers who downloaded previously leaked information and are using it to make their threats appear credible. 

The emails reportedly use random sender addresses and names such as “ShinyHunters” or “You’ve Been HACKED.” Their subject line commonly reads “Information about your online security.” In the messages, attackers mention companies whose databases were previously exposed, including Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill. By identifying a company connected to the recipient’s email address, scammers attempt to create the impression that they specifically targeted the victim. 

The scam messages claim that attackers installed malware capable of accessing a victim’s microphone, camera, keyboard, photographs, browsing history, conversations, and contact list. They then threaten to send allegedly recorded intimate videos to the recipient’s family, friends, colleagues, and business contacts unless payment is made within 48 hours. The emails also instruct recipients not to contact law enforcement, reply, or reset their devices, claiming that stolen data is stored on remote servers. These warnings are intimidation tactics rather than evidence of a genuine device compromise. 

According to the report, the campaign may have begun in April, with victims and organizations sharing similar warnings online. Betterment acknowledged that some customers received threatening emails and described them as a common extortion scam. The company emphasized that knowing someone’s email address does not give criminals the ability to install malware or access that person’s device. It advised recipients not to reply, pay, click links, or open attachments, while asking anyone who interacted with the message to contact its fraud team. 

People receiving these emails should remain calm and avoid paying the Bitcoin demand, because payment does not guarantee that scammers will stop contacting them. Recipients should preserve the message as evidence, report it to their email provider and relevant cybercrime authorities, then delete it after checking for suspicious account activity. They should also use unique passwords, enable multifactor authentication, update devices, and monitor accounts associated with the exposed email address. The campaign demonstrates how data stolen in one breach can later be reused by unrelated criminals to support convincing but false threats.

Featured