Friday , July 31 2026
Telegram

India Drops Bombshell Rule
India’s New Login Rules for WhatsApp, Telegram & Other Messaging Apps

The Indian government now requires messaging apps such as WhatsApp, Telegram, and Signal to work only when linked to an active SIM card. This regulation, issued by the Department of Telecommunications on November 28, aims to combat increasing cyber fraud and secure digital communication.

Telecommunication Cybersecurity Amendment Rules, 2025, take effect immediately but allow 90 days for compliance. The rules classify certain apps as Telecommunication Identifier User Entities (TIUEs) and require them to undergo verification like telecom companies to combat fraud, spam, and cybercrime.

EDIC Propose to invest $2 billion in an AI data center in Bangladesh

Many groups from different countries want to build AI data centers in Bangladesh. Countries like the UK, Japan, and South...
Read More
EDIC Propose to invest $2 billion in an AI data center in Bangladesh

NVIDIA BlueField Flaw Enables Code Execution Attacks

NVIDIA has revealed a big flaw with its BlueField DPUs and ConnectX networking systems. This issue could let attackers run...
Read More
NVIDIA BlueField Flaw Enables Code Execution Attacks

Massive customer data from India’s Bank of Baroda surfaced online

India's leading state-owned lender Bank of Baroda acknowledged Monday a security incident after reports that approximately 1 terabyte of customer...
Read More
Massive customer data from India’s Bank of Baroda surfaced online

Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

CISA has put the Fortinet FortiOS vulnerability CVE-2025-68686 in its list of known exploited flaws after ongoing attacks. The flaw...
Read More
Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

OpenAI's CEO Sam Altman says that AI has reached a big milestone. The technology can now make itself better, leading...
Read More
Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

Shinyhunters claimed and set deadline to publish E&Y data

ShinyHunters has publicly claimed responsibility for the Ernst & Young (EY) data breach. The group posted a message on their...
Read More
Shinyhunters claimed and set deadline to publish E&Y data

Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Nvidia and over 30 tech firms started a group on Monday to create open-source AI tools for protecting against cyber...
Read More
Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Google Search Results Reportedly Show Claude AI Shared Chats

Claude's share links from Anthropic showed up in public search results. This raised new privacy worries for users who shared...
Read More
Google Search Results Reportedly Show Claude AI Shared Chats

“PentesterFlow” AI Automation Tool for Penetration Testers and Bug Hunters

PentesterFlow is a new open-source AI tool for command lines. It is made for penetration testers and bug bounty hunters....
Read More
“PentesterFlow” AI Automation Tool for Penetration Testers and Bug Hunters

Jailbreak works against AI Models GPT-5.6, Claude Opus 5, and Fable, Claims Researcher

A famous AI red team expert claimed developing a universal jailbreak that can work against top large language models, like...
Read More
Jailbreak works against AI Models GPT-5.6, Claude Opus 5, and Fable, Claims Researcher

According to the notice, these communication apps must ensure within 90 days that their services remain “continuously” linked to the SIM card used during registration. They must block access if the SIM is not present in the device – a technical requirement known as SIM binding. Additionally, web- based versions of these apps, such as WhatsApp Web, must log out users periodically, with sessions not exceeding six hours.

“It has come to the notice of Central Government that some of the app based communication services that are utilizing mobile number for identification of its customers… allow users to consume their services without availability of the underlying SIM within the device posing challenge to telecom cyber security as it is being misused from outside the country to commit cyber-frauds,” DoT stated in its notice.

What does the mandate require?

Continuous SIM Binding: Applications must verify the link between the customer’s registered phone number, SIM card, and device. If the SIM is removed, inactive, or deactivated, the application should be disabled until it is re-validated.

Restrictions on Web Versions: Users will be automatically logged out of web access/desktop every 6 hours; they must then verify their SIM presence by re-scanning the QR code through the mobile app.

Timeline: Platforms must implement changes within 90 days and report compliance to DoT within 120 days. Non-compliance may lead to service restrictions.

Affected Apps: WhatsApp, Telegram, Signal, Snapchat, ShareChat, JioChat, Arattai, and Josh are the most popular communication apps in India. Currently, these apps continue to work indefinitely after initial verification, even without an active SIM.

Why This Change? Official Rationale and Context?

Fraud Prevention: Cybercriminals exploit SIM-independent access to commit scams with spoofed numbers, financial fraud, and spamming. COAI notes that this causes traceability issues as fraudsters use apps even after swapping their SIM cards.

Telecom Cybersecurity: Aligned OTT applications with banking standards, for example; therefore, treating mobile numbers as the digital ID of India to make them more accountable.

Check Also

Bad Epoll

“Bad Epoll” 0-Day Vulnerability Allows Root Access on Linux Servers, Android Devices

A new Linux flaw called “Bad Epoll” (CVE-2026-46242) lets regular users get root access on …