Cybersecurity threats are getting worse. AI is now being used to automate attacks. Supply chains are being poisoned. Legitimate tools are being weaponized. The latest cybersecurity news today shows a landscape that is more dangerous than ever. China-linked attacks target university mail servers. AI-driven ransomware called JADEPUFFER emerged in July. Video phishing campaigns steal Microsoft 365 passkeys.
At the same time, regulation is tightening. India's DPDP Act moves toward enforcement. The EU Cyber Resilience Act starts 24-hour reporting in September 2026. China's amended Cybersecurity Law increases penalties. This article covers the major attacks, regulatory changes, and what businesses need to do right now.
Major Cyber Attacks Making Headlines
China-Linked Attacks on Universities
- Security researchers reported that a China-linked threat actor, tracked as UNK MassTraction, exploited a vulnerability in Roundcube mail servers belonging to physics and engineering staff at US and Canadian universities.
- The attacks enabled credential theft and persistent remote control. The activity was intended to use compromised mail servers to pivot into wider campus networks .
AI-Driven Ransomware Emerges
A new threat dubbed JADEPUFFER emerged on July 1, 2026. This was an LLM-driven extortion operation. The threat actor exploited an exposed Langflow service to gain access, harvest credentials, and establish persistence. They then pivoted to a production environment, seized control of configuration services and databases, encrypted and deleted critical data, and left a ransom demand .
This is a significant development. It shows that AI is now being used to automate and scale ransomware attacks.
Video Phishing Targets Microsoft 365 Passkeys
A financially motivated cybercrime actor, tracked as O-UNC-066, has been conducting a video phishing campaign since at least April 2026. The campaign targets Microsoft 365 users across multiple industries globally. The actor uses operator-controlled phishing kits to hijack passkey enrolment, stealing credentials and MFA tokens via phone-based social engineering .
CitrixBleed 2 Exploitation Leads to Ransomware
An initial access broker exploited CVE-2025-5777, also named CitrixBleed 2, to hijack valid Citrix NetScaler session tokens. This bypassed multi-factor authentication. Attackers escalated privileges, established persistence via legitimate remote access tools, and in the most advanced case deployed DragonForce ransomware .
Developer Tools Compromised
The FBI issued a FLASH alert about a group called TeamPCP. This group poisoned trusted developer tools to steal cloud credentials, spread malware through software updates, and extort victims. Multiple AsyncAPI repositories were compromised and used to publish malicious npm package versions that installed the Miasma RAT, targeting global users and CI/CD environments .
Government Agency Pays $1M to Extortion Group
A US government agency paid $1 million to Kairos, a data extortion group. Kairos focuses on data theft and extortion rather than traditional ransomware encryption. Ransom-ISAC reconstructed the full attack chain .
Read More: How To Secure Remote Workforce From Cyber Attacks

Latest Cybersecurity News Today in India
DPDP Act Compliance Milestones
India's Digital Personal Data Protection Act, 2023, and the Digital Personal Data Protection Rules, 2025, are moving through a phased implementation .
Key dates:
-
November 13, 2025: Institutional framework came into force, establishing the Data Protection Board of India .
-
November 13, 2026: Consent Manager framework (Rule 4) comes into force .
-
May 13, 2027: Substantive compliance framework (Rules 3, 5-16, 22, 23) comes into force .
The Delhi Government has issued an office memorandum requiring all departments to review their systems, applications, databases, and contractual arrangements involving personal data processing and ensure compliance within the prescribed timelines .
Weaknesses in India's Cybersecurity System
A MediaNama investigation highlighted ten problems with India's cybersecurity system. Key issues include:
- Compliance certificates have replaced actual security. Experts say "reasonable security measures" under the IT Act have been interpreted to mean adherence to standards like ISO 27001 and SOC 2. But these certificates do not guarantee real security. One expert noted, "There are a number of certificate mills where you pay 10,000 rupees and you get your SOC2 and ISO certificate" .
- Checklist auditing. Auditors tick boxes without verifying whether vulnerabilities were actually patched. The SOC telemetry lives in one tool while the audit evidence pack lives in a separate spreadsheet. The two are joined only for the audit .
- Lack of accountability for auditors. Unlike financial auditing, where auditors face liability for negligence, there is no similar consequence mechanism for cybersecurity auditors in India .
CERT-In Powers
CERT-In is the national nodal agency for cybersecurity in India. It has the authority to call for information and give directions to service providers, intermediaries, data centres, and bodies corporate. Failure to respond to CERT-In's information requests can lead to monetary penalties and imprisonment for up to one year .

Regulatory Changes Taking Effect Worldwide
EU Cyber Resilience Act: 24-Hour Reporting Starts September 11, 2026
The European Commission published guidance on the Cyber Resilience Act in July 2026. The mandatory 24-hour vulnerability and incident reporting obligations begin September 11, 2026 .
Key requirements:
-
Manufacturers must notify actively exploited vulnerabilities and severe incidents within 24 hours (early warning), 72 hours (notification), and 14 days (final report) .
-
Fines can reach €15 million or 2.5% of global turnover .
-
The reporting obligations cover all products with digital elements, including those already on the market .
China's Amended Cybersecurity Law Takes Effect
China's amended Cybersecurity Law entered into force on January 1, 2026. The amendments increase penalties significantly and broaden extraterritorial enforcement .
Key changes:
- Fines for general cybersecurity breaches now range from RMB 10,000 to RMB 500,000, with aggravated circumstances reaching RMB 2 million .
- For particularly serious consequences, fines can reach RMB 10 million for network operators .
- The law now supports AI development, including AI security governance .
You May Also Read: How To Prevent Phishing Attacks At Home

EU Auditors Identify Flaws in Cyber Defenses
The European Court of Auditors published a report finding that EU nations have been slow to transpose cybersecurity directives into national laws. The audit criticized delays in the EU cybersecurity "shield" program, which has a budget of €1.4 billion. ENISA missed a February deadline for interoperability between cross-border cyber hubs .
Australia Advances Privacy Reforms
Australia released the Second Tranche Privacy Reforms on August 31, 2026. Key proposals include a 72-hour breach notification period, a new right to erasure on large digital platforms, and expanded definitions of sensitive information including precise geolocation tracking data .
The Bottom Line
Latest cybersecurity news today shows a threat landscape that is getting more sophisticated. AI is being used to automate attacks. Supply chains and developer tools are being poisoned. Legitimate services are being weaponized.
At the same time, regulation is tightening. India's DPDP Act is moving toward enforcement. The EU Cyber Resilience Act introduces 24-hour reporting. China's amended Cybersecurity Law increases penalties.
For businesses, the message is clear. Compliance certificates are not enough. Real security requires continuous monitoring, supply chain vigilance, and preparation for the new regulatory requirements.
FAQs
1. What are the biggest cyber attacks happening right now?
China-linked attacks on university mail servers, AI-driven ransomware (JADEPUFFER), video phishing targeting Microsoft 365 passkeys, CitrixBleed 2 exploitation leading to ransomware, and compromised developer tools spreading malware. These are the major active threats .
2. What is the DPDP Act compliance deadline in India?
Phased deadlines. Consent Manager framework comes into force November 13, 2026. Substantive compliance framework comes into force May 13, 2027. Businesses should prepare now .
3. What is the EU Cyber Resilience Act?
It is EU regulation requiring manufacturers of digital products to meet cybersecurity standards. The 24-hour reporting obligations for vulnerabilities and incidents start September 11, 2026. Fines reach €15 million or 2.5% of global turnover .
4. What did the EU auditors find?
EU nations are slow to implement cybersecurity directives. The cybersecurity shield program faces delays. ENISA missed deadlines for cross-border cyber hub interoperability. Information sharing has weaknesses .
5. What is wrong with India's cybersecurity system?
Compliance certificates have replaced actual security. Checklist auditing misses real vulnerabilities. Auditors face no accountability. Companies treat cybersecurity as a cost, not a priority. These are the key issues .
6. What is JADEPUFFER?
An AI-driven extortion operation. It exploited an exposed Langflow service to gain access, harvested credentials, and pivoted to production databases. It encrypted and deleted critical data and left a ransom demand .
7. What is CitrixBleed 2?
A vulnerability (CVE-2025-5777) in Citrix NetScaler that allows session token hijacking, bypassing MFA. Attackers used it to escalate privileges and deploy DragonForce ransomware .
8. What should businesses do right now?
Prepare for DPDP compliance if operating in India. Review vendor contracts. Implement data mapping and breach response protocols. For EU market products, prepare for CRA reporting obligations starting September 2026. Test defenses against AI-driven and supply chain attacks.

