Wednesday , September 9 2026
India

India orders Apple and other phone makers to preload a gov.t app

India’s Department of Telecommunications has given phone makers 90 days to pre-install a state-owned app on new devices and push it to current phones through software updates, according to Reuters. This order was sent to manufacturers like Apple, Samsung, Vivo, Oppo, and Xiaomi on November 28th.

The state-owned Sanchar Saathi app is currently on the App Store and Google Play Store, but this order will require it to remain active and cannot be deleted. The app allows users to block and track lost or stolen phones using their IMEI, and report potential fraud messages.

FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

An ongoing attack is focused on FortiGate firewalls. Hackers use a serious flaw to install a special Node.js remote access...
Read More
FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

Microsoft Patch Tuesday September 2026 Fixed 973 Flaws Fixed, 2 Zero-Days

Microsoft shared its September 2026 security updates on September 8. These updates fix 973 flaws, including two serious issues that...
Read More
Microsoft Patch Tuesday September 2026  Fixed 973 Flaws Fixed, 2 Zero-Days

A single call: ShinyHunters Gained Access to 6 Million Customers’ Records

A single phone call caused one of the biggest data breaches in Dutch history. In early February 2026, the big...
Read More
A single call: ShinyHunters Gained Access to 6 Million Customers’ Records

The first zero-click worm to spread through WeChat calls across iOS and Android

A worm called “WeWorm” can spread through WeChat voice calls on iOS and Android. It takes over a target's WeChat...
Read More
The first zero-click worm to spread through WeChat calls across iOS and Android

USA Bimbo Bakeries Confirms Data Stolen in Oracle EBS Zero-Day Attack

Bimbo Bakeries USA has confirmed that hackers stole employee data by exploiting a zero-day vulnerability in Oracle’s E-Business Suite (EBS). In...
Read More
USA Bimbo Bakeries Confirms Data Stolen in Oracle EBS Zero-Day Attack

ALERT
Roundcube Webmail fixes 12 security flaws, including zero-click XSS and SSRF bypass

Roundcube Webmail has given security updates for its 1.6 LTS and 1.7 branches. These updates fix 12 problems that could...
Read More
ALERT  Roundcube Webmail fixes 12 security flaws, including zero-click XSS and SSRF bypass

New HOOKEDGE Backdoor Deployed by Hackers in European Espionage

Russian-backed hacker group BlueDelta, also known as APT28, Fancy Bear, and Forest Blizzard, has used a small Windows backdoor called...
Read More
New HOOKEDGE Backdoor Deployed by Hackers in European Espionage

Hackers Exploiting MikroTik RouterOS Flaw Gaining Network Access

Attackers are misusing MikroTik routers through their Secure Shell (SSH) service, which can be accessed from the internet, to take...
Read More
Hackers Exploiting MikroTik RouterOS Flaw Gaining Network Access

CrowdStrike launches SafeMind, the first agentic cybersecurity solution for defenders

CrowdStrike launched CrowdStrike SafeMind, a set of special security models and tools from the CrowdStrike Cyber Superintelligence Lab. The SafeMind...
Read More
CrowdStrike launches SafeMind, the first agentic cybersecurity solution for defenders

Claude, DeepSeek, and Qwen AI agents combinedly used to hit gov.t across Asia

Chinese-speaking hackers have added Claude, Qwen, and DeepSeek to their hacking system to automate cyberattacks on governments and other targets...
Read More
Claude, DeepSeek, and Qwen AI agents combinedly used to hit gov.t across Asia

Apple’s iOS users in India remain few, but their sales reached a record $9 billion in September. Google has also started selling Pixel phones online in India this year, and both companies have boosted local device manufacturing.

Nikhil Pahwa, founder of tech policy analysis company Medianama, said the order was “bad news” for mobile phone users and their privacy. “Legally, one can argue that your mobile phone is your personal space, and this is an invasion of your personal space. It’s where we have our most private conversations and exchange sensitive information with people we trust. How do we know this app isn’t used to access files and messages on our device? Or a future update won’t do that? This is clearly an invasion of our privacy. Remember how govt exempts itself from much of the Data Protection Law. This explains why,” Pahwa said. The order is valid even for devices being imported into the country, or still in pre-sales transit.

The direction has been given under Telecommunications (Telecom Cyber Security) Rules, 2024, and its further amendments.

Cybernews reported, “Apple however does not plan to comply with the directive and will tell the government it does not follow such mandates anywhere in the world as they raise a host of privacy and security issues for the company’s iOS ecosystem, said two of the industry sources who are familiar with Apple’s concerns. They declined to be named publicly as the company’s strategy is private.

“Its not only like taking a sledgehammer, this is like a double-barrel gun,” said the first source.”

Will it Go the Way of Russia’s MAX?

India has followed Russia’s example by requiring the pre-installation of a local messenger app called MAX on all smartphones, tablets, computers, and smart TVs sold in the country from September 1, 2025. Critics worry the app may track users, but state media has denied these claims.

Russian authorities have since announced partial restrictions on voice and video calls in messaging apps Telegram and WhatsApp to counter criminal activity, with state communications watchdog Roskomnadzor threatening to block WhatsApp completely if the messaging platform fails to comply with Russian law.

Source: Jyotiraditya M. Scindia X post

latest update:

In a statement shared on X on December 2, 2025, India’s telecom minister Jyotiraditya M. Scindia said “this is a completely voluntary and democratic system” and that “users may choose to activate the app and avail its benefits, or if they do not wish to, they can easily delete it from their phone at any time.”

India’s New Login Rules for WhatsApp, Telegram & Other Messaging Apps

Check Also

FalconFlank

CrowdStrike’s ‘FalconFlank’ zero-day allows SYSTEM privileges

An unnamed security expert known as “Nightmare Eclipse” shared a CrowdStrike Falcon zero-day exploit called …