CURRENT ACTIVITIES
|
Digital Threat Report 2025-26
(July 13, 2026)
CERT-IN, CSIRT-Fin and SISA have collaborated to launch the second edition of the Digital Threat Report 2025–26, as part of their continuous efforts to strengthen cybersecurity resilience across the Banking, Financial Services and Insurance (BFSI) sector. The report presents a comprehensive analysis of current and emerging cyber threats, along with relevant defense strategies and mitigation measures to help institutions enhance their preparedness, response capabilities and overall resilience. [More >>] |
| |
| |
|
Malware Campaign spreading through WhatsApp Attachments
(June 25, 2026)
It has been observed that a large-scale malware distribution campaign is targeting WhatsApp Desktop and WhatsApp Web users. The campaign distributes malicious Visual Basic Script (VBScript) files through direct messages on the platform. Threat actors leverage compromised WhatsApp accounts to send malicious attachments directly to victims, making the messages appear legitimate and significantly increasing the likelihood of successful compromise. [More >>] |
| |
| |
|
Potential Exposure of FortiGate Administrative and VPN Credentials (FortiBleed)
(June 18, 2026)
It has been reported that a large-scale credential exposure campaign, dubbed Forti Bleed, resulted in the compromise and exposure of credentials associated with Fortinet firewalls and VPN gateways. It involves a massive, active campaign where threat actors have compiled a verified database of working administrator and VPN credentials for tens of thousands of internet-facing FortiGate firewalls. The leaked dataset contains usernames, email addresses, plaintext passwords, and configuration-derived information tied to active Fortinet devices. [More >>] |
| |
| |
|
Guidelines regarding AI-Accelerated Vulnerability Protection and Response Requirements for Original Equipment Manufacturers (OEMs), and Technology Providers
(June 10, 2026)
[More >>] |
| |
| |
|
Multiple Software Supply Chain Attacks Targeting Open-Source Packages and Developer Tools
(April 02, 2026)
Multiple software supply chain compromises were reported in March 2026 affecting widely used developer tools and libraries across npm, PyPI, GitHub Actions, and container registries, including components associated with Checkmarx, Trivy, LiteLLM, Axios, Telnyx, and multiple npm packages linked to the CanisterWorm campaign. [More >>] |
| |
| |
|
Sophisticated RTO/eChallan themed Android Malware Campaign targeting Sensitive Information
(March 17, 2026)
CERT-In has received several reports of a malware campaign targeting Android users across India which impersonates the official Regional Transport Office (RTO) and government e-Challan notifications. Cybercriminals are using these fraudulent alerts to lure victims into installing a malicious application file, typically named "RTO Challan.apk", "RTO E Challan.apk", "MParivahan.apk" or similar variations. Once installed, this application functions as a multi-stage dropper malware designed to compromise the device, steal sensitive financial information, and facilitate unauthorised transactions. [More >>] |
| |
| |
|
Threat Actors exploiting Remote Code Execution Vulnerability in React Server Components
(December 15, 2025)
It has been reported that the threat actors are exploiting Remote Code Execution Vulnerability in React Server Components (CVE-2025-55182). [More >>] |
| |
| |
|
Threat Actors exploiting Buffer Overflow Vulnerability in D-Link routers
(December 10, 2025)
It has been reported that the threat actors are exploiting Buffer Overflow Vulnerability (CVE-2022-37055) in D-Link routers. [More >>] |
| |
| |
|
Threat Actors exploiting Missing Authorization check Vulnerability in SAP NetWeaver (Visual Composer development server)
(October 06, 2025)
It has been reported that the threat actors are exploiting Missing Authorization check Vulnerability (CVE-2025-31324) in SAP NetWeaver (Visual Composer development server). [More >>] |
| |
| |
|
Threat Actors exploiting Code Injection vulnerability in SAP S/4HANA (Private Cloud or On-Premise)
(September 11, 2025)
It has been reported that the threat actors are exploiting Code Injection Vulnerability (CVE-2025-42957) in SAP S/4HANA (Private Cloud or On-Premise). [More >>] |
| |
| |
|
Comprehensive Cyber Security Audit Policy Guidelines
(July 25, 2025)
These guidelines serve two purposes. Firstly, they assist organizations being audited (auditees) in preparing for audits, understanding requirements, and addressing deficiencies. This helps ensure that their cyber security measures align with industry standards and regulations, enabling proactive improvement of security practices. [More >>] |
| |
| |
|
White paper on "Transitioning to Quantum Cyber Readiness" --by CERT-In and SISA
(July 11, 2025)
CERT-In in collaboration with SISA has developed a White paper on "Transitioning to Quantum Cyber Readiness" to provide practical roadmap towards quantum transformations across sectors. This initiative ignites building resilience in the ICT infrastructures well in time with clarity and agility. [More >>] |
| |
| |
|
Good Practices for protecting Unmanned Aircraft Systems (UAS) against Cyber Security Threats
(April 18, 2025)
The rapid evolution of Unmanned Aircraft Systems (UAS) demand comprehensive cyber security posture to be adopted for safe and secure operations. There is a need for a multi-layered approach for UAS cyber resilience, encompassing secure-by-design principles, robust authentication mechanisms and a comprehensive incident response plan. [More >>] |
| |
| |
|
Digital Threat Report 2024 for the BFSI sector
(April 07, 2025)
"In a landmark initiative to strengthen cybersecurity resilience in the Banking, Financial Services, and Insurance (BFSI) sector, SISA, CERT-In, and CSIRT-Fin have collaborated to launch the Digital Threat Report 2024 for the BFSI sector, a comprehensive analysis of current and emerging cyber threats and defense strategies" [More >>] |
| |
| |
|
INDIA RANSOMWARE REPORT- 2024 by CERT-In
(March 25, 2025)
This report covers the ransomware latest tactics and techniques along with trends observed in the year-2024, specific to Indian cyber space. [More >>] |
| |
| |