Saturday , June 20 2026
Telegram

India Drops Bombshell Rule
India’s New Login Rules for WhatsApp, Telegram & Other Messaging Apps

The Indian government now requires messaging apps such as WhatsApp, Telegram, and Signal to work only when linked to an active SIM card. This regulation, issued by the Department of Telecommunications on November 28, aims to combat increasing cyber fraud and secure digital communication.

Telecommunication Cybersecurity Amendment Rules, 2025, take effect immediately but allow 90 days for compliance. The rules classify certain apps as Telecommunication Identifier User Entities (TIUEs) and require them to undergo verification like telecom companies to combat fraud, spam, and cybercrime.

CISA: Splunk flaw under active exploit, patch by Sunday

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has asked federal agencies to protect their systems by Sunday from a...
Read More
CISA: Splunk flaw under active exploit, patch by Sunday

Texas data breach exposes 3 million driver’s licenses

The Texas Parks and Wildlife Department (TPWD) revealed a data leak at its license system provider. This leak exposed private...
Read More
Texas data breach exposes 3 million driver’s licenses

Critical Cisco ISE Vulnerability Enables Remote Code Execution

Cisco has revealed critical security flaws in its Identity Services Engine (ISE). These flaws could let attackers run harmful code...
Read More
Critical Cisco ISE Vulnerability Enables Remote Code Execution

F5 Patches NGINX Flaw for Code Execution and DoS Attacks

F5 has shared a security warning about serious flaws in NGINX. These issues could let attackers run any code and...
Read More
F5 Patches NGINX Flaw for Code Execution and DoS Attacks

FortiBleed: 70,000 Fortinet Firewalls Compromised Globally

A vast cyber spying operation called “FortiBleed” has quietly compromised more than 73,932 different Fortinet firewall URLs in 194 countries....
Read More
FortiBleed: 70,000 Fortinet Firewalls Compromised Globally

New Rokarolla Android malware hits 217 banking and crypto apps

A new Android banking trojan called Rokarolla is hitting 217 banking and cryptocurrency apps with a wide range of 137...
Read More
New Rokarolla Android malware hits 217 banking and crypto apps

Phishing Campaign Exploits Legitimate Microsoft Login Flow

Attackers are using Microsoft’s OAuth 2.0 Device Authorization Grant (device code) flow in a campaign to take control of Microsoft...
Read More
Phishing Campaign Exploits Legitimate Microsoft Login Flow

ALERT
Cisco SD-WAN Zero-Day, FortiSandbox and cPanel flaws exploited in attacks

Cisco on Monday told customers about a new SD-WAN product flaw used in attacks. The flaw, called CVE-2026-20262, is a...
Read More
ALERT  Cisco SD-WAN Zero-Day, FortiSandbox and cPanel flaws exploited in attacks

“Panthalassa” builds floating AI data centers powered by ocean waves

Every American data center story these days follows almost the same pattern. Someone has the chips, someone has the cash,...
Read More
“Panthalassa” builds floating AI data centers powered by ocean waves

Critical Wazuh Vuln Enables Alert Tampering and Evidence Deletion

A critical security flaw has affected the open-source security community. Recently, complete details and working exploit code were shared online....
Read More
Critical Wazuh Vuln Enables Alert Tampering and Evidence Deletion

According to the notice, these communication apps must ensure within 90 days that their services remain “continuously” linked to the SIM card used during registration. They must block access if the SIM is not present in the device – a technical requirement known as SIM binding. Additionally, web- based versions of these apps, such as WhatsApp Web, must log out users periodically, with sessions not exceeding six hours.

“It has come to the notice of Central Government that some of the app based communication services that are utilizing mobile number for identification of its customers… allow users to consume their services without availability of the underlying SIM within the device posing challenge to telecom cyber security as it is being misused from outside the country to commit cyber-frauds,” DoT stated in its notice.

What does the mandate require?

Continuous SIM Binding: Applications must verify the link between the customer’s registered phone number, SIM card, and device. If the SIM is removed, inactive, or deactivated, the application should be disabled until it is re-validated.

Restrictions on Web Versions: Users will be automatically logged out of web access/desktop every 6 hours; they must then verify their SIM presence by re-scanning the QR code through the mobile app.

Timeline: Platforms must implement changes within 90 days and report compliance to DoT within 120 days. Non-compliance may lead to service restrictions.

Affected Apps: WhatsApp, Telegram, Signal, Snapchat, ShareChat, JioChat, Arattai, and Josh are the most popular communication apps in India. Currently, these apps continue to work indefinitely after initial verification, even without an active SIM.

Why This Change? Official Rationale and Context?

Fraud Prevention: Cybercriminals exploit SIM-independent access to commit scams with spoofed numbers, financial fraud, and spamming. COAI notes that this causes traceability issues as fraudsters use apps even after swapping their SIM cards.

Telecom Cybersecurity: Aligned OTT applications with banking standards, for example; therefore, treating mobile numbers as the digital ID of India to make them more accountable.

Check Also

73 Microsoft Packages Compromised in Password Stealer Attack

GitHub disabled 73 repositories in four Microsoft groups: Azure, Azure-Samples, Microsoft, and MicrosoftDocs. Each repo …