Google to Discontinue Dark Web Monitoring Tool by January 2026


Based on the official Google support page referenced, the Dark Web Report feature is being discontinued due to changes in the dark web landscape and resource allocation. The monitoring functionality will cease on January 15  2026  and all associated data will be permanently lost. This decision aligns with Google's strategic shift away from certain security features.

 

Microsoft Teams Introduces Call Flagging to Combat Malicious Callers

 


Microsoft Teams Introduces New Feature to Flag Malicious Calls: A Major Boost to Communication Security

Microsoft is preparing to roll out a powerful new security enhancement to its Teams platform, aimed at combating the growing threat of spam, phishing, and malicious calls targeting organizations. The upcoming feature, “Report a Suspicious Call,” will give users the ability to directly flag questionable calls — adding an extra layer of protection to everyday communication.

AWS IAM Eventual Consistency: The Overlooked Persistence Technique

 


Exploiting AWS IAM Eventual Consistency: The Persistence Risk Every Cloud Defender Must Understand

AWS Identity and Access Management (IAM) is often perceived as a strongly consistent and immediate-response system. However, like many globally distributed services, it actually operates on an eventual consistency model. While this design enables scalability across regions, it also introduces brief but dangerous windows that attackers can exploit to maintain persistence — even after defenders believe they have removed access.

Major Security Flaw Exposed 3.5 Billion WhatsApp Phone Numbers



WhatsApp had a massive security flaw that put phone numbers of 3.5 billion users at risk


A significant security vulnerability has recently been uncovered in WhatsApp's contact discovery feature, allowing researchers to scrape and identify a massive database of users. This incident highlights a major oversight in the platform's design and rate-limiting protocols.

RBI Mandates '.bank.in': Securing India's Digital Banking Ecosystem

 


RBI Mandates '.bank.in': A New Era for Secure Digital Banking

Key Takeaways:

  • The Reserve Bank of India (RBI) has made the '.bank.in' domain mandatory for all licensed banks in India.

  • This exclusive domain acts as a critical security filter to prevent banking fraud, especially phishing.

  • Only RBI-regulated institutions can register for the '.bank.in' domain, guaranteeing website authenticity.

  • Customers must now verify the URL ending to ensure they are on a legitimate bank portal.


VanHelsing Unleashed: The RaaS That Targets Windows, Linux, BSD, ARM and VMware ESXi

 


VanHelsing RaaS: a cross-platform ransomware that weaponizes affiliates to hit Windows, Linux, BSD, ARM and ESXi

VanHelsing has emerged as a sophisticated ransomware-as-a-service (RaaS) operation that changes the rules for cross-platform attackers. First observed on March 7, 2025, VanHelsing provides a fully packaged service to criminal affiliates: a $5,000 deposit to join, an 80% cut of ransom payments for affiliates, and a user-friendly control panel to orchestrate attacks across heterogeneous environments.

Hackers Abuse Cloudflare and Zendesk Pages in Sophisticated Phishing Campaign

 


Hackers Exploit Cloudflare and Zendesk Pages in Sophisticated Phishing Campaign to Steal User Credentials

A new wave of phishing attacks is exploiting the credibility of trusted cloud platforms like Cloudflare Pages and Zendesk to execute large-scale credential theft operations. Security researchers have uncovered an elaborate infrastructure of malicious domains designed to impersonate legitimate customer support portals, revealing an alarming escalation in the use of reputable cloud services for social engineering.

Google to Discontinue Dark Web Monitoring Tool by January 2026

Based on the official Google support page referenced, the Dark Web Report feature is being discontinued due to changes in the dark web lan...