Npav Lab
-
Read moreMulti-factor authentication (MFA) remains an important security layer, but it cannot stop every phishing attack. A recent campaign shows how attackers can steal Microsoft login details and session cookies even after a victim completes MFA.
-
Read moreA fake delivery message can easily look genuine, especially when it says your parcel is delayed because of an incorrect address. Rajasthan Police has warned users about scammers impersonating India Post, Speed Post and courier companies to steal payment and banking details.
-
Read moreAttackers are using fake ChatGPT Custom GPTs to trick users into installing a remote access trojan (RAT), according to security firm Huntress. The campaign reportedly used sponsored Google results for “chatgpt” to promote malicious Custom GPTs named “Plus 5.6.” Users who interacted with the fake GPT were directed to a fraudulent backup website and then shown a fake Cloudflare-style CAPTCHA.
-
Read moreA recent audit of a data breach at France’s tax administration shows how stolen employee passwords can lead to serious data exposure without highly sophisticated hacking. According to France’s cybersecurity agency ANSSI, attackers likely obtained several dozen staff passwords through infostealer malware on personal devices. Two internal portals reportedly relied only on passwords, allowing attackers to access them using compromised employee credentials.
-
Read moreSecurity researchers have analysed RatHat, an Android banking trojan that uses a web-based control panel to manage infected devices. According to Cleafy, newer versions reportedly use Google's Gemini API to assess intercepted messages and estimate which victims may have higher-value bank accounts.
-
Read moreCitrix has confirmed active exploitation of two critical vulnerabilities in NetScaler ADC and NetScaler Gateway. The flaws were being exploited as zero-days, meaning attacks were already taking place before fixes were available. For Indian organisations using NetScaler for remote access, this makes immediate patching a priority.
-
Read moreA North Korea-linked threat actor known as Jade Sleet has been linked to a cyberattack on an Indian IT services company, highlighting how attackers can target developers to gain access to wider business infrastructure.
-
Read moreA recent case investigated by Delhi Police shows how dangerous APK fraud can be. A Delhi man reportedly lost ₹6.57 lakh after clicking an SMS link and installing a malicious APK file. Police traced part of the stolen money and arrested three people allegedly involved in moving the fraud funds through cards and banking channels.
-
Read moreMicrosoft has taken down EvilTokens, an AI-powered phishing-as-a-service (PhaaS) platform linked to more than 12,000 compromised email inboxes across 10,000+ organizations worldwide.
-
Read moreIranian hackers use Telegram-controlled Windows malware to steal data, capture screenshots and record audio. Learn how to stay protected from cyber espionage.