Connect with us

Cybersecurity

India’s Semiconductor Boom Brings a New Cybersecurity Challenge

Published

on

India’s push to establish a stronger semiconductor industry is attracting significant investment, but the country’s growing role in the global chip supply chain is also creating new cybersecurity, geopolitical and supply-chain challenges.

Industry leaders and Union Electronics and Information Technology Minister Ashwini Vaishnaw have highlighted the need for stronger cyber defenses and greater supply-chain resilience as India expands its semiconductor manufacturing and design capabilities.

The potential risks extend beyond fabrication plants. Semiconductor companies rely on specialized equipment, software, intellectual property, suppliers, digital manufacturing systems and international logistics networks, creating multiple points that could be targeted or disrupted.

India’s Semiconductor Growth Creates New Security Challenges

As India develops capabilities across semiconductor design and manufacturing, its exposure to global geopolitical and cybersecurity risks is also increasing.

Vaishnaw has warned that geopolitical developments must be closely monitored as India becomes more involved in designing and manufacturing advanced electronic components. He has also discussed cybersecurity concerns with semiconductor companies and deep-tech startups.

The minister has urged businesses to prepare for cyberattacks and other disruptions that could affect manufacturing facilities, research activities, supply chains and critical infrastructure.

The concern is particularly significant because semiconductor production is strategically important to industries ranging from automobiles and telecommunications to energy, consumer electronics and artificial intelligence.

Global Semiconductor Supply Chains Remain Vulnerable

Semiconductor manufacturing depends on a complex international network. Companies require advanced production equipment, electronic design automation software, intellectual property, wafers, chemicals, materials, packaging services and testing capabilities from suppliers across multiple countries.

Ashok Chandak, president of the India Electronics and Semiconductor Association and SEMI India, has pointed to geopolitical tensions, cyberattacks and supply disruptions as major challenges for the industry.

Heavy dependence on a limited number of suppliers or countries can increase the impact of export restrictions, transportation problems, technology controls and sudden price increases.

Because semiconductor production cannot easily be separated from global supply networks, completely eliminating these risks is difficult. Instead, companies need contingency plans that allow them to continue operating when critical supplies or technologies become unavailable.

Supplier Diversification Could Strengthen India’s Resilience

One approach is to reduce excessive dependence on a single supplier, country or technology provider for critical semiconductor inputs.

This could involve identifying alternative suppliers, testing replacement equipment and materials in advance, and maintaining appropriate inventories of components that are difficult to obtain quickly.

India could also expand technology partnerships with multiple trusted international partners rather than relying heavily on one external source.

At the same time, domestic capabilities could be developed in areas where local production is economically and technologically practical. These areas include semiconductor equipment, specialized materials, chemicals, electronic design automation, chip intellectual property, packaging technologies and manufacturing processes.

Such diversification would not eliminate international dependencies, but it could give companies more options during geopolitical or commercial disruptions.

Cyberattacks Could Disrupt Semiconductor Manufacturing

Semiconductor facilities increasingly depend on connected digital manufacturing equipment and operational technology, making cybersecurity a critical component of factory operations.

A successful cyberattack could potentially interrupt production, compromise manufacturing systems, steal proprietary chip designs or expose sensitive corporate information.

The threat can also originate outside the factory. Equipment manufacturers, maintenance providers, software suppliers and other third parties can introduce security risks that eventually affect connected manufacturing environments.

Potential entry points include compromised equipment, malicious firmware, infected removable media and outdated operating systems.

For this reason, cybersecurity needs to be considered throughout the lifecycle of factory equipment—from procurement and installation to maintenance, upgrades and eventual replacement.

Semiconductor Industry Standards Offer a Security Framework

The semiconductor industry already has several cybersecurity standards that can help manufacturers improve their defenses.

SEMI E187 establishes baseline cybersecurity requirements for semiconductor manufacturing equipment, covering areas such as operating systems, network security, endpoint protection and monitoring.

SEMI E188 addresses the risk of malware entering manufacturing facilities during equipment delivery, installation, maintenance and servicing. SEMI E191 focuses on communicating the cybersecurity status of computing devices connected to factory networks.

Indian semiconductor companies could also use established frameworks and standards such as ISO/IEC 27001, IEC 62443 and the NIST Cybersecurity Framework, alongside applicable CERT-In requirements.

Security measures could include:

  • Comprehensive inventories of IT and operational technology assets
  • Risk classification of critical systems
  • Continuous network monitoring
  • Regular vulnerability assessments
  • Penetration testing and independent security audits
  • Incident reporting and response procedures
  • Reliable backup and disaster-recovery systems
  • Multi-factor authentication
  • Privileged-access management
  • Encryption for sensitive information
  • Data-loss prevention controls

These protections should also extend to third-party software, equipment, firmware, design tools and service providers.

India Expands Its Semiconductor Ecosystem

India’s semiconductor strategy is moving beyond assembly, testing and packaging toward a broader ecosystem covering chip design, fabrication, equipment, materials, research and workforce development.

The Union Cabinet approved the second phase of the semiconductor programme, known as Semicon 2.0, in July 2026 with an allocation of ₹12,750 crore.

The first phase led to approval for 12 semiconductor projects involving investments of more than ₹1.66 lakh crore. According to information cited in the report, five projects associated with companies including Micron, Kaynes and CG Semi had entered commercial production.

The government has also reported investment commitments of approximately ₹1 lakh crore under the programme’s second phase.

Vaishnaw has said India aims to develop semiconductor capabilities supporting a wide range of products, including automotive systems, power electronics, televisions, refrigerators and other consumer and industrial applications.

The government’s broader strategy also includes developing research and manufacturing capabilities in areas such as display technologies.

Intellectual Property Will Be a Critical Security Target

As India’s semiconductor ecosystem grows, protecting physical factories alone will not be enough.

Chip designs, engineering databases, intellectual property, manufacturing recipes, supplier systems and connected production equipment could all become targets for cybercriminals or other threat actors.

Companies will therefore need visibility across their entire digital and supply-chain environments.

Continuous monitoring could help organizations identify potential problems involving supplier concentration, export controls, technology restrictions, cyber incidents, logistics interruptions and financial difficulties among critical suppliers.

Resilience May Matter More Than Complete Self-Sufficiency

India’s semiconductor ambitions are closely connected with economic security and several strategic industries, including telecommunications, automobiles, energy, defense and artificial intelligence.

As the country becomes more integrated into global semiconductor networks, resilience will become increasingly important.

The objective does not necessarily have to be complete self-sufficiency. Instead, India can focus on developing an ecosystem capable of continuing operations despite cyberattacks, supply shortages, export restrictions, logistics problems or geopolitical disruptions.

For semiconductor manufacturers, cybersecurity and supply-chain planning will therefore need to become continuous processes rather than one-time compliance exercises.

The Road Ahead for India’s Chip Industry

India’s semiconductor expansion presents significant opportunities, but its success will depend not only on investment and manufacturing capacity.

Protecting intellectual property, securing connected equipment, diversifying suppliers and preparing for cyber incidents will be equally important.

As factories and technology networks become more interconnected, a weakness in a supplier, software platform or piece of manufacturing equipment could potentially affect a much larger part of the ecosystem.

Building cybersecurity and operational resilience into India’s semiconductor strategy from the beginning could therefore become an important part of maintaining the country’s long-term chip ambitions.

Continue Reading
Advertisement
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Cybersecurity

73% of Americans Say AI Companies Are Not Doing Enough on Safety

Published

on

By

A large majority of Americans believe artificial intelligence companies need to do more to prevent potentially serious harm from increasingly powerful AI systems, according to a new national survey.

The poll found that 73% of respondents were concerned that AI companies had not implemented enough safeguards to protect society from serious risks. The findings also indicate declining public confidence in the technology’s impact and limited support for allowing AI companies to regulate themselves without stronger government involvement.

Public Concern About AI Is Rising

The four-day survey found that 73% of participants believed AI companies had not gone far enough in establishing protections against serious societal harm.

At the same time, 39% said artificial intelligence was having a negative impact on society, up from 36% in the previous month. That represented the highest level recorded in the survey series.

Only 11% viewed AI’s impact as positive, while the remaining respondents were either uncertain or did not provide an answer.

The results reflect growing public debate as AI systems become more capable and increasingly integrated into workplaces, businesses and everyday services.

Americans Show Limited Confidence in Industry Self-Regulation

The survey also indicated that many Americans want a stronger government role in establishing AI safety requirements.

Most respondents supported a significant role for federal authorities in setting standards for AI safety, reflecting concerns about whether technology companies can effectively oversee their own development and risk-management practices.

The issue has become a major part of the broader discussion surrounding artificial intelligence, particularly as companies deploy increasingly capable models and autonomous systems.

Majority Support Slowing AI Development

The poll found that 55% of respondents considered slowing AI development to be a good thing.

By comparison, 13% said slowing development would be negative, while the remaining participants were unsure or did not answer.

The survey also found that approximately 69% had followed reports about major AI companies calling for a slowdown in development amid concerns about safety and oversight.

The findings highlight an ongoing debate over whether AI development is advancing faster than the safeguards designed to manage its potential risks.

Cybersecurity and Privacy Remain Major Concerns

Public concern about AI is not limited to long-term questions about the technology. Cybersecurity, privacy and potential misuse are also contributing to the debate.

The survey report pointed to incidents involving increasingly autonomous AI agents as an example of the challenges facing developers.

One concern is that AI systems capable of interacting with external tools, networks and services could potentially behave in unexpected ways or be misused by attackers.

At the same time, supporters of AI point to potential benefits including increased productivity, scientific research, healthcare applications and improvements across financial and industrial sectors.

AI Researchers Also Raise Safety Concerns

Warnings from people working within the AI research community have added to the public discussion.

Some researchers have expressed concerns about the consequences of increasingly capable AI systems and questioned whether existing safety measures will be sufficient as models become more autonomous and powerful.

These concerns have contributed to a broader debate about the pace of AI development and the responsibility of companies building advanced systems.

However, the potential economic and scientific benefits of AI continue to drive significant investment and research, making the balance between innovation and safety an ongoing issue.

Safety Takes Priority Over Global AI Competition for Many Americans

The survey also examined whether Americans place greater importance on developing AI safely or maintaining U.S. leadership in global AI competition.

According to the findings, 73% said safe and responsible AI development was more important, while 23% placed greater importance on ensuring the United States remains ahead of other countries in AI development.

The result suggests that, among those surveyed, concerns about safety outweighed concerns about maintaining an international technological advantage.

Survey Details

The poll was conducted online among 1,277 U.S. adults.

It reported a margin of error of approximately three percentage points in either direction.

Because the survey represents a snapshot of public opinion at a particular point in time, attitudes toward AI may change as new technologies, regulations and high-profile incidents emerge.

Public Debate Over AI Is Evolving

The survey points to a growing tension between rapid advances in artificial intelligence and public expectations for stronger safeguards.

AI systems are increasingly being used for work, research, communication and decision-making, while concerns about cybersecurity, privacy, misuse and autonomous behavior continue to develop.

The findings suggest that many Americans want technological progress to continue while placing greater emphasis on safety and accountability.

As AI capabilities expand, the debate is likely to focus increasingly on whether regulatory frameworks and industry safeguards can keep pace with the technology.

Continue Reading

Cybersecurity

Three Indians Hacked OpenAI With Help From Rival AI Claude

Published

on

By

Three Indian cybersecurity researchers used Anthropic’s Claude AI models to uncover and demonstrate security weaknesses affecting systems connected to OpenAI, highlighting how advanced artificial intelligence can significantly accelerate vulnerability research.

The researchers—Harsh Jaiswal, Mohan Pedhapati and Rahul Maini of cybersecurity startup Hacktron AI—reported their findings to OpenAI after identifying vulnerabilities that potentially exposed user accounts, connected services and parts of the company’s internal infrastructure.

OpenAI subsequently awarded the researchers a $6,500 bug bounty, equivalent to roughly ₹6.22 lakh.

Who Discovered the OpenAI Security Flaws?

The research team consisted of Harsh Jaiswal, founder of Hacktron AI; AI security researcher Mohan Pedhapati; and computer scientist Rahul Maini.

The researchers said their work was conducted as security research rather than an attempt to misuse the access they discovered.

Their investigation focused on systems connected to OpenAI accounts and ultimately revealed weaknesses involving a third-party platform used by the company.

The incident occurred in July, with the researchers later sharing details of their findings.

How Claude Assisted the Security Research

The team used Anthropic’s Claude models during different stages of the investigation.

Their initial focus was the OpenAI community forum, where ChatGPT and Codex users can communicate and authenticate using OpenAI accounts.

The researchers used Claude Opus 4.8 to examine the code of Discourse, the third-party platform powering the forum. Initial attempts to demonstrate the suspected weakness were unsuccessful.

The researchers then turned to Claude Opus 5, which had been released later that day. According to the team, the newer model was able to help them successfully demonstrate the vulnerability.

By the next day, they said they could access ChatGPT and Codex accounts belonging to some users of the community forum.

Access Extended Beyond OpenAI Accounts

The researchers said the compromised account access could potentially provide pathways into other applications connected to the same identities.

These included services such as email and Slack. Some affected accounts reportedly belonged to OpenAI employees and were linked to internal company services.

According to the researchers, access could potentially expose users’ ChatGPT conversations, including private or sensitive information.

The team subsequently discovered another weakness involving OpenAI’s single sign-on system. They said the issue enabled them to obtain authentication information associated with ChatGPT and Codex accounts belonging to OpenAI employees.

The researchers also reported gaining access to an internal OpenAI code repository.

AI Significantly Reduced the Research Time

One of the most notable aspects of the incident was the amount of time required to complete the research.

Pedhapati estimated that conducting comparable work without Claude could have taken approximately two to three months.

With AI assistance, however, the team said it completed the research in less than three days.

He suggested that newer AI models could potentially reduce the time required even further, with similar research potentially taking less than a day under some circumstances.

The researchers described this capability as a force multiplier, allowing experienced security professionals to perform complex analysis and vulnerability research considerably faster.

Third-Party Software Created an Indirect Attack Path

The research also demonstrates why organizations cannot focus exclusively on vulnerabilities in their own software.

The researchers reportedly gained access through a weakness in Discourse, a third-party service used by OpenAI for its community forum.

This highlights the security risks created by interconnected software ecosystems. An organization may have strong security controls around its primary infrastructure while remaining exposed through an external service, authentication provider or connected application.

Third-party dependencies can therefore become an important part of an organization’s overall attack surface.

AI Could Accelerate Both Defensive and Malicious Research

The incident raises broader questions about the role of advanced AI in cybersecurity.

AI models can help security researchers analyze code, identify weaknesses and automate parts of vulnerability research. However, similar capabilities could also potentially be used by malicious actors to speed up attacks.

The researchers warned that increasingly capable AI systems could make experienced attackers more effective while lowering some of the technical barriers faced by less-skilled threat actors.

This creates a difficult security environment in which defenders may gain new capabilities at the same time as attackers gain access to similar technological advantages.

Connected Accounts Are Becoming a Critical Security Risk

The case demonstrates that compromising a single account or third-party application can have consequences beyond the original system.

Employee identities, single sign-on systems, cloud applications, messaging platforms, source-code repositories and other connected services can create chains of access.

For technology companies handling sensitive user information and proprietary systems, securing these connections is therefore as important as protecting the core application itself.

AI Is Changing the Economics of Security Research

The speed reported by the Hacktron AI researchers illustrates how AI could change the economics of vulnerability discovery.

Tasks that traditionally required substantial manual analysis and experimentation may increasingly be completed in a fraction of the time with capable AI assistance.

For defenders, this could mean faster vulnerability discovery and remediation. For attackers, the same acceleration could potentially shorten the window between identifying a weakness and attempting to exploit it.

As AI models become more capable, organizations may need to reassess how quickly they can detect, investigate and respond to newly discovered vulnerabilities.

Continue Reading

Cybersecurity

Patna Police Bust Suspected Cyber Fraud Network, Three Arrested

Published

on

By

Patna Cyber Police have busted an alleged organised cybercrime racket involved in digital arrest scams, financial fraud and online cheating, arresting three accused. Police said the suspects allegedly targeted victims across several states and were linked to a wider cybercrime network.

During the operation, investigators recovered six mobile phones, two laptops, three cheque books, two passbooks and five ATM cards, along with other electronic devices and banking documents.

Three Accused Arrested

The arrested accused have been identified as Gaurav Kumar, a resident of New Colony in Khagaul-Danapur; Adarsh Kumar of Transport Nagar; and Aman Raj of Kumhrar. According to police, the three were allegedly connected to an organised cybercrime network operating across different parts of the country. Preliminary investigation also revealed multiple complaints related to cyber fraud against them.

Cybercrime Complaints Helped Trace Suspects

Police said several complaints concerning the accused were found on the National Cybercrime Reporting Portal. Analysis of these complaints, along with digital evidence collected during the investigation, helped investigators trace the suspects and establish their alleged links with the racket.

Technical surveillance and examination of digital evidence played a key role in the investigation. Investigators analysed suspected mobile numbers, electronic devices and other digital activities before identifying and tracing the accused. The seized mobile phones and laptops have now been sent for detailed examination to identify additional suspects, victims and possible financial transactions.

Phones, Laptops And Banking Documents Seized

Police suspect that bank accounts and documents recovered from the accused may have been used to receive and transfer money obtained through cyber fraud. The three cheque books, two passbooks and five ATM cards are being examined to establish the flow of funds and identify accounts allegedly linked to the racket. Investigators are also examining the electronic devices for communication records, transaction details and other digital evidence.

How Digital Arrest Scams Work

The investigation is also focused on determining how the accused allegedly carried out digital arrest scams. In such frauds, cybercriminals typically impersonate police officers, central investigation agencies, bank officials or other government authorities and threaten victims with arrest or legal action. The victims are then kept under constant pressure through phone or video calls and are allegedly persuaded to transfer money on the pretext of verification, investigation or avoiding arrest.

FIR Registered, Investigation Expanded

An FIR has been registered at Patna Cyber Police Station, and the investigation has been expanded to determine the complete structure of the alleged network. The three accused were produced before a court and remanded to judicial custody. Police are now examining the seized electronic devices and banking records to establish the roles played by the accused and identify other members of the network.

Investigators are also trying to determine the total amount allegedly siphoned off by the racket and the number of victims who may have been targeted. Since complaints have surfaced from different parts of the country, authorities are examining whether the suspects were operating independently or as part of a larger network involving multiple handlers, bank accounts and money-transfer channels.

Expert Warns Against Digital Arrest Scams

Cybercrime expert and former IPS officer Prof. Triveni Singh said digital arrest scams combine technology with psychological manipulation. Victims are often kept under intense pressure and made to believe that immediate action is required to avoid arrest or other legal consequences. People should independently verify any such claim through the official contact details of the concerned department and should never transfer money merely because someone threatens them with arrest over a phone or video call.

Patna Cyber Police said the investigation remains underway. Further action will follow after the roles of other suspected members are established. Investigators are also analysing the digital and banking evidence recovered during the operation to determine the actual scale of the alleged fraud, trace the money trail and identify additional victims and associates connected to the network.

Continue Reading

Trending

Copyright © 2022 420 Reports Marijuana News & Information Website | Reefer News | Cannabis News