Wednesday , September 9 2026
Telegram

India Drops Bombshell Rule
India’s New Login Rules for WhatsApp, Telegram & Other Messaging Apps

The Indian government now requires messaging apps such as WhatsApp, Telegram, and Signal to work only when linked to an active SIM card. This regulation, issued by the Department of Telecommunications on November 28, aims to combat increasing cyber fraud and secure digital communication.

Telecommunication Cybersecurity Amendment Rules, 2025, take effect immediately but allow 90 days for compliance. The rules classify certain apps as Telecommunication Identifier User Entities (TIUEs) and require them to undergo verification like telecom companies to combat fraud, spam, and cybercrime.

FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

An ongoing attack is focused on FortiGate firewalls. Hackers use a serious flaw to install a special Node.js remote access...
Read More
FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

Microsoft Patch Tuesday September 2026 Fixed 973 Flaws Fixed, 2 Zero-Days

Microsoft shared its September 2026 security updates on September 8. These updates fix 973 flaws, including two serious issues that...
Read More
Microsoft Patch Tuesday September 2026  Fixed 973 Flaws Fixed, 2 Zero-Days

A single call: ShinyHunters Gained Access to 6 Million Customers’ Records

A single phone call caused one of the biggest data breaches in Dutch history. In early February 2026, the big...
Read More
A single call: ShinyHunters Gained Access to 6 Million Customers’ Records

The first zero-click worm to spread through WeChat calls across iOS and Android

A worm called “WeWorm” can spread through WeChat voice calls on iOS and Android. It takes over a target's WeChat...
Read More
The first zero-click worm to spread through WeChat calls across iOS and Android

USA Bimbo Bakeries Confirms Data Stolen in Oracle EBS Zero-Day Attack

Bimbo Bakeries USA has confirmed that hackers stole employee data by exploiting a zero-day vulnerability in Oracle’s E-Business Suite (EBS). In...
Read More
USA Bimbo Bakeries Confirms Data Stolen in Oracle EBS Zero-Day Attack

ALERT
Roundcube Webmail fixes 12 security flaws, including zero-click XSS and SSRF bypass

Roundcube Webmail has given security updates for its 1.6 LTS and 1.7 branches. These updates fix 12 problems that could...
Read More
ALERT  Roundcube Webmail fixes 12 security flaws, including zero-click XSS and SSRF bypass

New HOOKEDGE Backdoor Deployed by Hackers in European Espionage

Russian-backed hacker group BlueDelta, also known as APT28, Fancy Bear, and Forest Blizzard, has used a small Windows backdoor called...
Read More
New HOOKEDGE Backdoor Deployed by Hackers in European Espionage

Hackers Exploiting MikroTik RouterOS Flaw Gaining Network Access

Attackers are misusing MikroTik routers through their Secure Shell (SSH) service, which can be accessed from the internet, to take...
Read More
Hackers Exploiting MikroTik RouterOS Flaw Gaining Network Access

CrowdStrike launches SafeMind, the first agentic cybersecurity solution for defenders

CrowdStrike launched CrowdStrike SafeMind, a set of special security models and tools from the CrowdStrike Cyber Superintelligence Lab. The SafeMind...
Read More
CrowdStrike launches SafeMind, the first agentic cybersecurity solution for defenders

Claude, DeepSeek, and Qwen AI agents combinedly used to hit gov.t across Asia

Chinese-speaking hackers have added Claude, Qwen, and DeepSeek to their hacking system to automate cyberattacks on governments and other targets...
Read More
Claude, DeepSeek, and Qwen AI agents combinedly used to hit gov.t across Asia

According to the notice, these communication apps must ensure within 90 days that their services remain “continuously” linked to the SIM card used during registration. They must block access if the SIM is not present in the device – a technical requirement known as SIM binding. Additionally, web- based versions of these apps, such as WhatsApp Web, must log out users periodically, with sessions not exceeding six hours.

“It has come to the notice of Central Government that some of the app based communication services that are utilizing mobile number for identification of its customers… allow users to consume their services without availability of the underlying SIM within the device posing challenge to telecom cyber security as it is being misused from outside the country to commit cyber-frauds,” DoT stated in its notice.

What does the mandate require?

Continuous SIM Binding: Applications must verify the link between the customer’s registered phone number, SIM card, and device. If the SIM is removed, inactive, or deactivated, the application should be disabled until it is re-validated.

Restrictions on Web Versions: Users will be automatically logged out of web access/desktop every 6 hours; they must then verify their SIM presence by re-scanning the QR code through the mobile app.

Timeline: Platforms must implement changes within 90 days and report compliance to DoT within 120 days. Non-compliance may lead to service restrictions.

Affected Apps: WhatsApp, Telegram, Signal, Snapchat, ShareChat, JioChat, Arattai, and Josh are the most popular communication apps in India. Currently, these apps continue to work indefinitely after initial verification, even without an active SIM.

Why This Change? Official Rationale and Context?

Fraud Prevention: Cybercriminals exploit SIM-independent access to commit scams with spoofed numbers, financial fraud, and spamming. COAI notes that this causes traceability issues as fraudsters use apps even after swapping their SIM cards.

Telecom Cybersecurity: Aligned OTT applications with banking standards, for example; therefore, treating mobile numbers as the digital ID of India to make them more accountable.

Check Also

India: C-DOT Launches 14 Local Quantum-Safe Technologies

India is making its communication systems safer and stronger by launching 14 local quantum products. …