Cyber Security
CISA Issues 24-Hour Patch Alert Over Check Point VPN Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent 24-hour directive following the discovery of a high-risk vulnerability in Check Point VPN products, warning that active exploitation is already underway and posing serious risks to global digital infrastructure.
The agency has ordered all federal departments to immediately apply security patches or isolate affected systems, citing the vulnerability as a potential gateway for large-scale cyberattacks.
Critical Flaw Added to CISA’s KEV Catalog
CISA has officially added the vulnerability, identified as CVE-2026-50751, to its Known Exploited Vulnerabilities (KEV) catalog. The classification confirms that attackers are actively exploiting the flaw in real-world scenarios.
The security gap affects certain Check Point remote access VPN and mobile access systems. Cybersecurity experts warn that it can allow attackers to bypass authentication controls and gain unauthorized access to sensitive networks.
Legacy VPN Systems Especially at Risk
Security analysts say the vulnerability is particularly dangerous for organizations using older configurations, especially those relying on outdated IKEv1 key exchange protocols or lacking strong certificate-based authentication.
Systems with legacy VPN setups are considered highly exposed, as attackers may be able to hijack sessions and infiltrate internal networks without detection.
Patch Released as Exploitation Activity Increases
Check Point released a security update on June 8 and confirmed that exploitation attempts were detected as early as May 7. The company reported a rise in malicious activity targeting vulnerable systems over recent weeks.
While only a limited number of organizations have officially reported breaches so far, cybersecurity specialists warn that the risk remains severe due to ongoing exploitation efforts across multiple threat actors.
Ransomware Group Activity Raises Global Concern
Security reports indicate that some intrusion attempts may be linked to the Qilin ransomware group, known for high-profile attacks involving data encryption and ransom demands. This connection has intensified concerns about potential widespread misuse of the vulnerability.
CISA has urged agencies to take immediate containment measures, including system isolation where patching is not yet possible, to prevent unauthorized access and lateral movement within networks.
Experts Warn of Growing VPN Security Risks
Cybersecurity analysts emphasize that VPNs remain a prime target for attackers due to their role in remote access and enterprise connectivity. Once compromised, they can provide deep access into corporate and government systems.
Experts stress that timely patching, continuous monitoring, and stronger authentication protocols are essential to reducing exposure to such attacks.
Call for Stronger Patch Management Practices
The incident highlights ongoing challenges in global cybersecurity readiness, particularly in rapid response to zero-day and actively exploited vulnerabilities. Analysts warn that delays in patch deployment often provide attackers with critical windows to infiltrate systems.
CISA’s directive underscores the importance of immediate patch management as a frontline defense in protecting sensitive infrastructure from evolving cyber threats.
Artificial Intelligence
San Francisco Orders Apple, Google to Pull AI ‘Nudify’ Apps in 28 Days
San Francisco City Attorney David Chiu has issued cease-and-desist notices to Apple and Google, directing both technology companies to remove a number of AI-powered “nudify” applications from their app stores within 28 days or risk potential civil penalties under California law.
The legal notices target 13 applications—eight available on Apple’s App Store and five on Google Play—that authorities say can generate non-consensual, sexually explicit AI images of real people using ordinary photographs without their permission.
California Cites Deepfake Laws in Enforcement Action
According to the City Attorney’s Office, the action relies on two California laws designed to address the misuse of artificial intelligence for creating intimate deepfake content.
One statute makes it a criminal offence to knowingly facilitate or recklessly assist in the creation of non-consensual intimate deepfakes. Another law, enacted in 2025, allows civil action against digital platforms that continue to host or distribute such applications after receiving formal notice, potentially exposing app stores to legal liability.
Officials argue that Apple and Google were previously informed about the presence of these applications but allegedly allowed them to remain available while continuing to process in-app purchases.
Chiu stated that beyond any financial benefit earned through platform commissions, the apps have the potential to cause significant emotional, psychological, and reputational harm to victims whose images are manipulated without consent.
Research Report Prompted Wider Scrutiny
The legal action follows reports published by the Tech Transparency Project, a nonprofit research organization that documented the availability of AI “nudify” applications on major app marketplaces.
A report released in January 2026 identified numerous apps capable of generating synthetic intimate images, while a follow-up investigation in April 2026 alleged that many of those applications remained available and continued generating revenue. The report also claimed that some apps carried age ratings that could make them accessible to younger users despite their intended functionality.
Apple and Google Respond
Following the legal notices, both companies confirmed they had taken action against some of the identified applications.
Google said it had suspended all five apps named in the notice from Google Play, citing violations of its policies governing sexually explicit content.
Apple stated that its App Store guidelines prohibit applications designed to create or distribute pornographic material. The company said it had removed three of the identified apps, terminated the associated developer accounts, and was continuing discussions with the developers of the remaining applications over alleged policy violations.
AI Deepfake Platforms Face Growing Legal Pressure
The latest enforcement effort forms part of a broader campaign by San Francisco authorities to combat the misuse of artificial intelligence for creating non-consensual intimate imagery.
City officials have previously pursued legal action against websites offering similar AI-based image-generation services. Researchers have also raised concerns that major online platforms may inadvertently contribute to the spread of such tools by allowing advertising or promotional content that directs users to them.
Meanwhile, debate continues at the federal level over stronger legal protections for victims of AI-generated intimate imagery. While proposed legislation such as the DEFIANCE Act seeks to expand victims’ ability to pursue civil claims, California’s existing laws provide broader mechanisms for holding online platforms accountable in certain circumstances.
Authorities have increasingly warned that the misuse of generative AI extends beyond synthetic imagery. According to federal law enforcement data, AI-enabled fraud contributed to hundreds of millions of dollars in financial losses during 2025, highlighting the growing challenge regulators face in addressing emerging forms of digital abuse.
Cyber Security
Karnataka Holds State-Level Workshop to Strengthen Government Cybersecurity
Bengaluru: The Karnataka government has conducted a state-level cybersecurity workshop aimed at strengthening protection of government data, improving cyber resilience and securing the state’s expanding digital governance infrastructure.
The workshop brought together more than 80 senior officials from over 30 government departments, boards, corporations and agencies to discuss strategies for building stronger cybersecurity frameworks across state systems.
Officials Discuss Future-Ready Cyber Defence
The programme was organised by the Department of Personnel and Administrative Reforms (e-Governance) in collaboration with the Centre for e-Governance, CySecK (Centre of Excellence for Cybersecurity Karnataka), and the National e-Governance Division.
Held in Bengaluru on July 10, the event featured discussions on strengthening government cybersecurity practices and improving coordination between departments.
The workshop was inaugurated by Pankaj Kumar Pandey, IAS, Principal Secretary to the Government in the Department of Personnel and Administrative Reforms (e-Governance), along with Dr Avinash Menon Rajendran, IAS, Managing Director of the Karnataka Innovation and Technology Society.
Officials highlighted the importance of protecting citizen information and ensuring secure operation of government digital platforms.
Focus on Cyber Resilience and e-Governance Security
Key sessions, including discussions on “Karnataka Cyber-Ready for the Future” and “Cyber Resilience for e-Governance,” focused on developing a coordinated approach to safeguard public digital systems.
Experts discussed challenges related to government infrastructure, including the security of the State Data Centre, Karnataka State Wide Area Network and other critical technology platforms.
Participants reviewed existing cybersecurity initiatives and explored additional measures required to strengthen protection against evolving cyber threats.
Technical Sessions Cover Advanced Security Measures
The workshop included six thematic sessions covering important areas such as:
- Risk-based cybersecurity monitoring
- State Data Centre security
- Karnataka State Wide Area Network protection
- Security Operations Centre (SOC) operations
- State Computer Security Incident Response Team (CSIRT) mechanisms
- Cybersecurity preparedness and response planning
Officials also discussed emerging security approaches, including secure-by-design principles, Zero Trust architecture, data classification practices and readiness for the Digital Personal Data Protection framework.
Joint Action Plan Prepared for Stronger Cyber Framework
The discussions concluded with the creation of a Joint Action Plan outlining key recommendations and implementation strategies for improving cybersecurity across Karnataka’s government departments.
The state government said the initiative reflects its commitment to developing a secure and reliable digital governance ecosystem through collaboration, knowledge sharing and continuous capacity building.
Cybersecurity experts have increasingly stressed that government institutions need proactive security measures as public services become more dependent on digital platforms and interconnected systems.
Cyber Security
No More SMS Codes: Vodafone’s New SIM-Based Fraud Defence Explained
New Delhi: Vodafone has launched its next-generation Number Verify 2.0 service, a mobile network-based authentication technology designed to replace traditional SMS-based one-time passwords (OTPs) with a more secure SIM-based verification system.
The service has initially been introduced in Germany, the Netherlands and the United Kingdom, with Vodafone planning a wider global rollout for enterprise customers.
The new technology aims to provide businesses with a faster and more secure method of confirming mobile identities while reducing risks associated with phishing, SIM-swap attacks and OTP-related fraud.
How SIM-Based Verification Works
Unlike SMS OTP systems, where users manually enter a code received through text messages, Number Verify 2.0 verifies a mobile number directly through the telecom network.
The system checks whether the mobile number is genuinely connected to the user’s SIM card and device. The verification process works through communication between the mobile operating system, telecom network systems and secure authentication servers.
After receiving user consent, the service generates a secure verification response that can be shared with authorised businesses such as banks, retailers and digital platforms.
Vodafone said the approach provides stronger protection because it relies on network-level confirmation and SIM-based security rather than simply confirming that someone has access to a text message.
Why SMS OTP Systems Face Growing Security Concerns
SMS-based OTP authentication has been widely used for account registration, login verification and digital payments for years. However, cybersecurity experts have increasingly raised concerns about its limitations.
Traditional OTP systems may not detect whether a user’s session has been compromised through phishing websites, malware, fake apps or social engineering attacks.
Cybercriminals have also exploited OTP systems through SIM-swap fraud, where attackers attempt to transfer a victim’s mobile number to another SIM card, allowing them to intercept authentication messages.
Vodafone said businesses also face rising costs from automated fraud attempts, including artificially generated OTP requests designed to overload verification systems.
Industry Moves Towards Network-Based Authentication
Vodafone’s announcement comes amid wider industry efforts to develop stronger mobile identity solutions.
Network-based verification services are gaining attention as telecom operators explore alternatives to SMS authentication. The technology behind Number Verify 2.0 follows the CAMARA industry standard, allowing developers to integrate the service across multiple markets as operator support expands.
The company said the initial rollout focuses on Android devices, while broader device compatibility and wider operator participation will determine how quickly the technology achieves large-scale adoption.
Experts Highlight Need for Multi-Layer Security
Cybercrime expert and former IPS officer Prof. Triveni Singh said OTP-based authentication has increasingly become a target for criminals using SIM-swap attacks, phishing campaigns, malware and advanced social engineering techniques.
He said SIM-based verification could strengthen digital identity protection but should work alongside other security measures such as multi-factor authentication, behavioural risk analysis and continuous cybersecurity monitoring.
Experts believe that stronger cooperation between telecom operators, banks, fintech companies and regulators will be essential as digital payments and online services continue to expand.
While network-based verification could reduce dependence on SMS codes, cybersecurity professionals say no single technology can completely eliminate fraud risks. A combination of secure authentication systems, user awareness and proactive threat detection remains critical.
-
Business3 years agoPot Odor Does Not Justify Probable Cause for Vehicle Searches, Minnesota Court Affirms
-
Business3 years agoNew Mexico cannabis operator fined, loses license for alleged BioTrack fraud
-
Business3 years agoAlabama to make another attempt Dec. 1 to award medical cannabis licenses
-
Business3 years agoWashington State Pays Out $9.4 Million in Refunds Relating to Drug Convictions
-
Business3 years agoMarijuana companies suing US attorney general in federal prohibition challenge
-
Business3 years agoLegal Marijuana Handed A Nothing Burger From NY State
-
Business3 years agoCan Cannabis Help Seasonal Depression
-
Blogs3 years agoCannabis Art Is Flourishing On Etsy
