yohanmanuja

former bug bounty hunter ,web pentester

Logo of Sanchar Saathi mobile app displayed on a smartphone overlaid on Indian flag background

India Pulls Back on “Sanchar Saathi” App Mandate Surveillance

India’s telecom ministry rescinded its controversial order forcing all new and existing smartphones to pre-install the government-run “Sanchar Saathi” app. The reversal follows widespread criticism over privacy risks, consent violations, and potential mass surveillance, raising fresh questions about digital rights and security oversight in a market of over a billion mobile users.

Read More
BRICKSTORM malware used in Chinese cyber operations targeting VMware vSphere and government networks

CISA Report on Chinese Operations: BRICKSTORM Malware

The latest Cybersecurity and Infrastructure Security Agency (CISA) advisory reveals that PRC-linked hackers use a backdoor called BRICKSTORM to gain long-term access to VMware vSphere and Windows environments, affecting government and IT networks. This article unpacks the attack chain, impacted sectors and critical defensive steps organizations should take now.

Read More
Cyberattack disrupting OnSolve CodeRED emergency alert systems used by U.S. public safety agencies

Crisis24’s OnSolve CodeRED Exposes Data and Disrupts Alerts

A cyberattack on Crisis24’s OnSolve CodeRED platform disrupted emergency alerts for cities, counties, police and fire agencies across the U.S. The INC Ransom group claims responsibility, with stolen resident data, clear-text passwords and a rollback to older backups now forcing agencies to rebuild their notification capabilities and review credential hygiene.

Read More
Fake Windows update blue screen used by the JackFix ClickFix attack to trick users into running malware from the Windows Run dialog

How the JackFix attack upgrades ClickFix social engineering

The JackFix attack marks the latest evolution of the ClickFix technique. By luring victims through fake adult sites into a full-screen Windows update screen, encoding Run-dialog commands, gating its payload URL, and dropping multiple infostealers through an obfuscated PowerShell script, JackFix sidesteps many earlier ClickFix mitigations and forces defenders to rethink how they handle browser-driven social engineering.

Read More