Posts

GenAI Adoption Is Growing, but Data Security Remains a Concern

Generative AI (Gen AI) is becoming a regular part of business operations. Employees are using AI tools to write content, analyze information, solve problems, and improve productivity. But as AI usage grows, so does the risk of sensitive data being shared without proper protection. AI Usage Is Increasing According to Check Point’s August report, high-risk Gen AI prompts fell to their lowest level in several months. However, overall AI usage continued to rise. The average enterprise user generated 106 prompts in August , compared with 95 in July and around 78 in June. This shows that while some organizations may be improving their awareness and security controls, the growing use of AI is creating more opportunities for sensitive information to be entered into AI tools. The Risk Is Still Widespread The report found that: 86% of organizations regularly using Gen AI were affected by high-risk prompt activity. Organizations used an average of seven different AI tools . About 1 in every 43 p...

You don't have to hack the company!!

What if hackers don't need to break into your company to steal your customers' data? That's exactly what makes the recent Pokémon Center incident interesting. Instead of directly compromising Pokémon Center's systems, attackers targeted its trusted third-party logistics provider, CEVA Logistics . What Happened? Pokémon Center uses CEVA Logistics to ship orders to customers in the United Kingdom and Germany . On July 30 , CEVA informed Pokémon Center that it had experienced a cyberattack. While Pokémon Center itself was not directly hacked, customer information handled by the logistics provider was potentially exposed. The incident also caused disruptions to shipping and order fulfillment, including delays and cancellations. What Data Was Exposed? The potentially affected information included: Names Email addresses Phone numbers Shipping addresses Order information However, payment card details and Pokémon Center account credentials were not part of the exposed informati...

New Call Forwarding Scam in India: How Fraudsters Can Steal Your OTPs Without Asking for an OTP

Beware! A Dangerous Call Forwarding Scam Is Targeting Indian Smartphone Users Cyber scams in India are evolving every day, and fraudsters are finding new ways to steal money from unsuspecting users. One scam that has gained attention involves call forwarding , allowing criminals to receive your OTPs without ever asking you for them. Many victims are shocked because they never shared an OTP, never clicked a suspicious link, and never installed any unknown app. Yet, money disappears from their bank account. So how does this happen? How the Scam Works Imagine you've ordered something online and you're away from home. You need to contact the delivery executive, so you call the number shown in the app or sent via SMS. Sometimes, scammers impersonating delivery personnel or posing as customer support may ask you to dial a number that begins with codes such as *21* or other call forwarding codes, claiming it is required to contact the delivery agent or verify your identity. The momen...

🚨 Generative AI Phishing Attacks in 2026: How AI is Making Cybercrime More Dangerous

Introduction: The Rise of AI-Powered Cyber Threats The year 2026 has introduced powerful advancements in artificial intelligence, but along with innovation comes new cybersecurity risks. Generative AI tools are now being exploited by cybercriminals to create highly convincing phishing attacks, fake login pages, and malicious websites at unprecedented speed. As AI technology becomes more accessible, users must understand that everything online cannot be trusted without proper verification and research. 🤖 How Hackers Use Generative AI for Phishing Attacks Generative AI platforms allow attackers to create realistic websites and content with minimal effort. By using simple prompts such as: 👉 “Build a website that looks exactly like Okta but isn’t the same,” hackers can generate fake login portals that closely mimic legitimate services. These AI-generated phishing sites are designed to: Steal login credentials Capture authentication tokens Trick users into revealing sensitive info...

Elon Musk’s X Faces French Police Raid

Introduction Elon Musk’s social media platform X (formerly Twitter) is under intense scrutiny in Europe after French authorities launched a major investigation into alleged algorithmic bias, data practices, and AI-related concerns. The situation escalated recently when French police raided X’s offices in Paris, marking a significant development in the growing regulatory pressure on Big Tech companies operating within the European Union. This investigation highlights broader debates around artificial intelligence, content moderation, data ethics, and free speech — all of which are shaping the future of social media platforms worldwide. Why Did French Police Raid X? According to reports, the Paris prosecutor’s cybercrime unit conducted the raid as part of an ongoing investigation that began in early 2025. Authorities are examining whether X or its executives engaged in: Suspected abuse or manipulation of algorithms Fraudulent data extraction practices Potential violations of...

BlackRock Scam Explained: How a Telecom Giant Fell for a Phishing & Investment Fraud

Who is BlackRock? BlackRock is a renowned global firm with major operations in New York and London. While it is often associated with finance, in this context we refer to BlackRock’s telecommunication partnerships and its global influence—similar to what Airtel holds in India. However, unlike Airtel, BlackRock recently became a victim of a massive investment and phishing scam. Phishing and Investment Scam: What Happened? According to reports, Indian-origin telecom executive Bankim Brahmbhatt has been linked to an alleged multi-million-dollar fraud involving BlackRock. Here’s how the scam is believed to have unfolded: Brahmbhatt reportedly approached BlackRock claiming he had substantial investments from companies that were mutually associated with the firm. By building trust and maintaining regular communication with BlackRock, he managed to secure a loan of nearly $500 million . To support the claim, spoofed emails were allegedly sent to BlackRock from addresses mimicking o...

The Dark Side of the Internet: Understanding Online Bullying and Abuse

Introduction Nowadays, even children have the technology that was once only accessible to industry giants and MNC's. The difference is of maturity. This technology was once used to be for a good because as it was in safe hands, but as of now, it is seen that the the tech, the internet or the social media has both pros and cons.  If used in a good way, this may take us to reach great heights, but if used wrongly it may lead to paths which are unethical. Cyberbullying is one of the most used malpractices across the globe. What is Cyberbullying? - The practice of bullying a person or an organization by sending messages, mails or social media content of an intimidating, mocking or threatening nature. We don't know what kind of pressure of is on the person or organization who is facing cyberbullying until and unless we are a victim.  Real Life Example We already have some cases where people have some it. One of the case I recently came across is about an employee working in an MNC ...

Emerging Cyber Crime !!

 In India, cyber crime has emerged a lot. From password hacking to national cyber crime, Cyber crime has evolved a lot. Nowadays money is been transferred by hackers to their account from people accounts unknowingly that this is a crime . This type of Hacking or Hijacking of money of people's bank accounts by hackers is a cyber crime which must be reported in the cyber cell. In India it can be reported on the contact number 1930. MY OWN EXAMPLE Speaking about the last week, my father received a call which said - ' we are speaking from khufiya(undercover) agency, is it your son, he is going to be kidnapped and it can be stopped if my father gave the ransom amount', here my father scolded them knowing that this is a fraud call. But he took notice and asked about me from my mother. After I got to know about this, knowing this is a scam call I reported this in cyber cell (1930). Cyber cell not only takes action on the report but also spread awareness about such incidents. Again...

Find out what the Dark Web is and How you can access it ?

Image
 Dark Web is a World Wide Web content that exists on dark net ( network that use the internet but require a specific software ). Deep and Dark web are applications of integral internet features to provide privacy and anonymity. Is it safe to use Dark Web? A person with an ordinary knowledge about techy things should never go to Dark web because he will not be able to protect his own identity. Hackers are looking for such people who are noob. After getting into dark web they can steal your identity and use it for their work and it may be an illegal work too. And why you want to browse the dark web,there's no need. You may also get some virus in your device and your all data can be hacked in just few minutes. Difference between Deep Web and Dark Web- The deep web contains internet content you can't find through search engines, while the dark web is a hidden network that requires a special browser to access. Surface Web The portion of world wide web that is readily available to th...

Dumpster Diving

 The government's nodal agency CERT-In has warned against 'Dumpster Diving', which refers to fraudsters searching through a person or an organisation's trash to obtain sensitive or valuable information for malicious activities. It suggested using a shredder to destroy documents, installing security cameras or employing security personnel and disposing electronic devices properly to avoid misuse. What is dumpster diving? Dumpster Diving is a Physical Attack in which a person recovers trash in hopes of finding sensitive information that has been merely discarded in whole rather than being run through a shredder, incinerated, or otherwise destroyed. Technique A cyber attack where the attacker gets their hands on sensitive documents or data you carelessly threw into the trash bin. Solutions to it- ·        Know why someone target dumpsters on your property. ·        Light up the waste collection area. ·  ...

NETWORK SCANNING

  NETWORK Scanning ·        Network scanning refers to a set of procedures used for identifying hosts, ports and services in a network. ·        Network scanning is one of the components of intelligence gathering which can be used by an attacker to create a profile of the target organization. The purpose of scanning is to discover exploitable communications channel, probe as many listeners as possible, and track the ones that are responsive for an attacker’s particular needs. Types of scanning ·        Port scanning – Lists the open ports and services. ·        Network scanning – Lists the active hosts and services. ·        Vulnerability scanning – shows the presence of known weaknesses. SCANNING TOOLS ·        Nmap ·        Hping3 ·    ...

Password Hacking !!

  Password Cracking It is one of the most enjoyable hacks. The password cracking may not have a burning desire to hack the password of everyone. The actual password of the user is not stored in the well-designed password-based authentication system. Due to this, the hacker can easily access to user's account on the system. Types of Password Cracking ·        Non electronic: It doesn’t require technical knowledge. §   Social Engineering §   Shoulder Surfing §   Keyboard Sniffing §   Dumpster Diving ·        Active Online: An active attack is a network exploit in which a hacker attempts to make changes to data on the target. §   Dictionary attack §   Brute-Force attack §   Rule Based attack ·        Passive Online: A network attack in which a system is monitored and sometimes scanned for open ports and vulnerabilities. ·  ...

All about Keyloggers!!

  A keylogger, sometimes called a keystroke logger, is a type of surveillance technology used to monitor and record each keystroke on a specific computer. Consider it as a threat because… Keyloggers are often used as a spyware tool by cybercriminals to steal personally identifiable information (PII), login credentials and sensitive enterprise data. Keylogger tools for windows ·        All in One ·        Elite ·        Spytector Keylogger tools for MacOS ·        sentryPC ·        FlexiSPY ·        REFOG Keylogger Keylogger tool for Linux - Logkeys Types of keyloggers 1.    Hardware Keylogger ·        It is a physical device that is used for capturing keystrokes ·        For hardware keylogger one must hav...

What is Steganography?

Image
It is the technique of hiding secret data within an ordinary, non-secret file or message in order to avoid detection; the secret data is then extracted at its destination. ·        Technical steganography ·        Linguistic steganography Types of steganography ·        Text : It includes hiding data within the text files ·        Image : It can hiding the information by taking the cover object as image is defined as image steganography. In image steganography, pixel intensities are used to conceal the data ·        Audio : Audio Steganography is the technology of embedding information in an audio channel ·        Video : In this method, video (set of pictures) can be used as carrier for hiding the information ·        Network Protocol : It includes hiding the info...

All about ROOTKITS in Cyber Security !!

Rootkit is a software program, typically malicious, that provides privileged, root level access to a computer while concealing its presence on that machine. Rootkit tools (popular ones) ·        Purple Fox ·        MoonBounce ·        TDSS Rootkit types ·        Hypervisor rootkit: It takes advantage of the hardware virtualization and is installed between the hardware and the kernel acting as the real hardware. ·        Kernel rootkit: Kernel Rootkits are specifically designed to attack the core of your operating system and change its functioning. ·        Bootloader rootkit: The bootloader rootkit attacks the legit bootloader and replaces it with the hacked one so that attackers could control the system boot. ·        Application rootkit: Application Rootkits re...

Social Engineering And Attacks !

Image
Social engineering is the tactic of manipulating, influencing, or deceiving a victim in order to gain control over a computer system, or to steal personal and financial information. It uses psychological manipulation to trick users into making security mistakes or giving away sensitive information . Types of social Engineering attacks ·        Baiting: Attack where a scammer uses a false promise to lure a victim into trap ·        Scareware: Technique that aims to scare the victim into believing that they have a virus on their device ·        Pretexting: Technique that manipulates victim into divulging information ·        Phishing: Technique to trick users into doing something dangerous      Phishing is the most common type of Social Engineering Attacks Concepts of social engineering Social engineering heavily relies on the 5 principles established...

Cyber terms that You should Be Aware of !!

Image
Spyware Spyware is any software that installs itself on your computer and starts covertly monitoring your online behavior without your knowledge or permission. It is a kind of malware that secretly gathers information about a person or organization and relays this data to other parties, Virus A virus is a type of malicious software, or malware, that spreads between computers and causes damage to data and software. Trojan Horse A Trojan Horse is a type of malware that downloads onto a computer disguised as a legitimate program. VPN Most of you might be aware of it, but do not know the correct use of it. Let me explain- VPN (Virtual Private Network), a VPN is a method of connecting a series of computers and devices in a private encrypted network, with each users IP address being replaced by the VPN’s IP address. Users get Internet anonymity, making it difficult for hackers to attack. Ransomware Ransomware is type of malware from crypto virology that threatens to publis...