Saturday , September 12 2026

Centre issues alert as Indonesian hacker group targets 12,000 Indian websites

A cyber attack group from Indonesia has been allegedly targeting 12,000 government websites in India, according to a cybersecurity alert issued by the Centre.

The alert, accessed by Moneycontrol, was issued by the Ministry of Home Affairs’ Indian Cybercrime Coordination Centre (I4C) on Thursday.

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Palo Alto Networks has revealed a serious flaw in PAN-OS. It may let a remote attacker without a password run...
Read More
Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Critical Check Point VPN flaws allow remote code execution attacks

Check Point Software has revealed and fixed two major VPN flaws, CVE-2026-85102 and CVE-2026-85103. Both have a top CVSS score...
Read More
Critical Check Point VPN flaws allow remote code execution attacks

Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Cisco has said that a serious security flaw CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being used...
Read More
Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

A Russian-speaking hacker has used artificial intelligence like never before. They sent out hundreds of AI agents to find and...
Read More
Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Six Chinese AI companies ran large-scale attacks on American AI models since late 2024, according to U.S. cybersecurity and intelligence...
Read More
CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

An unknown security expert called Nightmare Eclipse has drops a new Microsoft Defender flaw called "ShieldCrash" right after Microsoft released...
Read More
Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

cPanel has shared CVE-2026-67401, a serious SQL injection flaw in EmailTrack. This flaw could allow attackers with permission to take...
Read More
cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

An ongoing attack is focused on FortiGate firewalls. Hackers use a serious flaw to install a special Node.js remote access...
Read More
FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

Microsoft Patch Tuesday September 2026 Fixed 973 Flaws Fixed, 2 Zero-Days

Microsoft shared its September 2026 security updates on September 8. These updates fix 973 flaws, including two serious issues that...
Read More
Microsoft Patch Tuesday September 2026  Fixed 973 Flaws Fixed, 2 Zero-Days
“It has been reported that websites of state and central government are potentially being targeted,” the alert said while urging concerned government officials to take preventive measures.

Last year, a massive ransomware attack crippled the systems of All India Institute of Medical Science (AIIMS) rendering its centralised records inaccessible, apart from other hospital services.

Overall, the Indian government recorded 19 ransomware attacks against various government organisations in 2022, nearly three times the number recorded the previous year.

The I4C alert said that an Indonesian “hacktivist” group was launching denial of service (DoS) and distributed denial of service (DDoS) attacks. DDoS attacks refer to the intentional paralysing of a computer network by flooding it with data sent simultaneously from many individual computers.

The alert also said that the hacktivist group had released a list of government websites that it claims to be targeting, which included state and Central government websites.

“”Post this alert, government employees need to ensure that they do not fall for social engineering attacks; do not click on unknown emails or links, which can compromise security of such websites. They also ensure that all software updates are up-to-date,” Anand Prakash, founder and CEO of cybersecurity firm Pingsafe said.

Last year, a Malaysia hacktivist group targeted Indian government websites over a political turmoil that erupted over comments made against Prophet Muhammad.

Malaysian hacktivist group DragonForce targeted several Indian government websites including that of the Indian Embassy in Israel (indembassisrael[.]gov[.]in), National Institute of Agricultural Extension Management (manage[.]gov[.]in).

Govt’s guidelines to secure websites

Recently the government released the third version of Guidelines for India Government Websites (GIGW 3.0), which as the name suggests, provides guidelines to officials on how to safely, and securely, develop, maintain, and manage not just government websites, but also portals and mobile applications.

It recommended that developers should encrypt passwords, ensure software and plugins are up-to-date, connection strings, tokens, and keys. Website cookies should also be secure, it added.

It also urged developers to not give website backend access to too many high-level employees.

“Administrative privileges are given thinking those would be used carefully. Although this is the ideal situation, it is not always the case. Unfortunately, employees do not think about website security when logging into the Servers or the CMS,” the guidelines said.

“Instead, their thoughts are on the task at hand. If they make a mistake or overlook an issue, this can result in a significant security issue,” the GIGW 3.0 said, adding that it was vital to ensure employees have experience in handling back-end of websites before they gain access.

Check Also

India: C-DOT Launches 14 Local Quantum-Safe Technologies

India is making its communication systems safer and stronger by launching 14 local quantum products. …