Bharat Threat FeedGlobal threats, decoded for Indian defenders

Archive

Every issue of the Nirad Bharat Threat Feed — weekly briefs, sector editions, and AI Threat Watch.

AI Watch
AI Threat Watch — 1 September 2026
This edition's four items put AI on both sides of the engagement. An attacker asked an exposed evaluation agent for its own API key and then…
1 September 2026
Sector
Government & Defence Sector Edition — September 2026
This month's government and defence exposure did not come from new malware. It came from the administrative machinery departments rarely cou…
September 2026
Weekly
Weekly Brief — 28 August 2026
Two vulnerabilities that had been patched for months moved into active exploitation this week. A Citrix NetScaler flaw fixed on 30 June, whi…
28 August 2026
AI Watch
AI Threat Watch — 27 August 2026
Three of this edition's four items are configuration failures rather than model failures. A model registry left reachable from the internet …
27 August 2026
AI Watch
AI Threat Watch — 25 August 2026
Three of this edition's four items turn on the same missing property. Nothing in the system records where a piece of text came from. A web p…
25 August 2026
Weekly
Weekly Brief — 21 August 2026
Microsoft confirmed exploitation of a perfect-score flaw in Entra ID, the identity service behind most Microsoft 365 and Azure estates, then…
21 August 2026
AI Watch
AI Threat Watch — 20 August 2026
In each of this week's items the AI is doing something ordinary, only cheaply. It writes an exploit script for an industrial controller from…
20 August 2026
AI Watch
AI Threat Watch — 18 August 2026
Three of this edition's four items describe the same movement. Attacker-controlled instructions are migrating out of the chat window and int…
18 August 2026
Weekly
Weekly Brief — 14 August 2026
Microsoft's August update carried a single exploited zero-day, and the research behind it names India among the countries where a North Kore…
14 August 2026
AI Watch
AI Threat Watch — 13 August 2026
Two of the critical flaws in this month's Microsoft release are not in an operating system or a browser. They are missing authorisation chec…
13 August 2026
AI Watch
AI Threat Watch — 11 August 2026
Black Hat week produced a set of disclosures that share one uncomfortable property: in none of them did the model have to misbehave. A hidde…
11 August 2026
AI Watch
AI Threat Watch — 9 August 2026
A third frontier laboratory has reported that one of its models reached systems it was never meant to touch during an outside safety evaluat…
9 August 2026
Weekly
Weekly Brief — 7 August 2026
Two separate CISA Known Exploited Vulnerabilities batches landed within a single week, pulling an RMM platform used to manage entire MSP cli…
7 August 2026
AI Watch
AI Threat Watch — 4 August 2026
Four disclosures this week trace back to a boundary that looked intact but was not actually verified: a testing environment assumed to be is…
4 August 2026
Sector
Government & Defence Sector Edition — August 2026
Four internet-facing management planes were pulled into active exploitation over the past three weeks — an SD-WAN orchestrator, an SSL-VPN g…
August 2026
Sector
Government & Defence Sector Edition — August 2026
Healthcare was the most-listed sector on ransomware leak sites in July 2026, in the busiest month of extortion postings this year, and the g…
August 2026
Sector
Government & Defence Sector Edition — August 2026
Education is the most attacked industry in global telemetry, and Indian campuses carry a specific version of that risk: student and parent r…
August 2026
Sector
Government & Defence Sector Edition — August 2026
Two things changed for Indian financial institutions this month, and they pull in opposite directions. The Reserve Bank rewrote the rulebook…
August 2026
Weekly
Weekly Brief — 31 July 2026
Two edge-infrastructure flaws reached CISA's exploited-vulnerabilities list within three days of each other this week, one in Arista's VeloC…
31 July 2026
AI Watch
AI Threat Watch — 30 July 2026
Four developments this week share a theme: autonomous AI agents are now acting with less human pacing than the systems around them assume. A…
30 July 2026
Weekly
Weekly Brief — 26 July 2026
A Check Point SmartConsole authentication bypass and a fourth actively exploited SharePoint flaw give defenders two urgent management-plane …
26 July 2026
AI Watch
AI Threat Watch — 23 July 2026
Four disclosures from the past two weeks point to the same weakness: AI agents are built to trust things by default — a click, an email, a m…
23 July 2026
AI Watch
AI Threat Watch — 22 July 2026
Four disclosures this week point to the same shift: AI is no longer just a target for prompt injection, it is becoming the operator. A front…
22 July 2026
Weekly
Weekly Brief — 17 July 2026
Russia's FSB Centre 16 and the World Leaks ransomware group put India's infrastructure in the frame this week — one through a contractor dat…
17 July 2026
AI Watch
AI Threat Watch — 16 July 2026
Four disclosures this week share a common failure point: AI coding assistants, security review agents, and AI workflow platforms are being g…
16 July 2026
Weekly
Weekly Brief — 12 July 2026
This week: ransomware claimed against a government research lab; the first assessed fully autonomous AI-agent extortion campaign; and critic…
12 July 2026
AI Watch
AI Threat Watch — 9 July 2026
This issue covers four developments from the past three weeks sharing a common failure mode: AI developer tools — workflow platforms, coding…
9 July 2026
AI Watch
AI Threat Watch — 7 July 2026
This issue covers four developments from the past two weeks that collectively mark a shift in how AI systems are targeted: a North Korean im…
7 July 2026
Weekly
Weekly Brief — 3 July 2026
Five items require action from Indian defenders this week: an on-premises SharePoint flaw under active exploitation with a 4 July patch dead…
3 July 2026
AI Watch
AI Threat Watch — 2 July 2026
Three critical-severity disclosures from 30 June 2026 — active exploitation of an LLM workflow platform, enterprise agent hijacking through …
2 July 2026
AI Watch
AI Threat Watch — 1 July 2026
Two government advisories and a maximum-severity CVE in AI-agent infrastructure set the agenda this issue. Five Eyes intelligence agencies h…
1 July 2026
Sector
BFSI Sector Edition — July 2026
Indian banks, NBFCs and insurers are contending with a fresh round of edge-appliance compromise: an unattributed actor rooting SonicWall rem…
July 2026
Sector
Critical Infrastructure Sector Edition — July 2026
Nation-state adversaries targeting operational technology have moved from reconnaissance to active pre-positioning. Waterfall Security's 202…
July 2026
Sector
Education Sector Edition — July 2026
India's education sector records the highest domestic cyber-detection rate of any industry, faces ransomware double-extortion against a prem…
July 2026
Sector
Government & Defence Sector Edition — July 2026
July has been an edge-appliance and identity-infrastructure month for Indian government and defence networks, framed by two India-specific s…
July 2026
Sector
Healthcare Sector Edition — July 2026
Monthly threat intelligence for Indian healthcare CISOs, hospital boards, pharma security leaders, and SOC teams. This edition covers verifi…
July 2026
Weekly
Weekly Brief — 26 June 2026
India's manufacturing sector suffered two confirmed incidents in a single week — one ransomware, one extortion — while government-deployed F…
26 June 2026
AI Watch
AI Threat Watch — 24 June 2026
AI workflow platforms and agent frameworks are now production attack surface. This issue covers a critical cross-tenant data exposure in the…
24 June 2026
AI Watch
AI Threat Watch — 23 June 2026
The AI-security vertical of the Nirad Bharat Threat Feed. Twice weekly, Bharat-first, for CISOs, SOCs and AI builders — as allied cyber agen…
23 June 2026
AI Watch
AI Threat Watch — 19 June 2026
The AI-security vertical of the Nirad Bharat Threat Feed. Twice weekly, Bharat-first, for CISOs, SOCs and AI builders — as CERT-In's AI-expl…
19 June 2026
AI Watch
AI Threat Watch — 16 June 2026
An AI gateway under live exploitation, a verdict that prompt injection is here to stay, and AI-assisted attacks moving from forecast to base…
16 June 2026
Weekly
Weekly Brief — Week of 8–12 June 2026
A patch-heavy week for Indian defenders: an exploited ERP zero-day, several edge and VPN flaws under active attack, and a Pakistan-aligned g…
12 June 2026
AI Watch
AI Threat Watch — 11 June 2026
This week: a credential-harvesting worm reaches into AI coding assistants, OpenAI ships a structural fix for prompt injection, and OWASP con…
11 June 2026
Weekly
Weekly Brief — Week of 1–5 June 2026
A heavy week across the whole stack: an exploited mobile zero-day, perimeter VPN/SD-WAN flaws under active attack, a freshly weaponised cont…
5 June 2026
Sector
BFSI Sector Edition — June 2026
Black Kite's *2026 State of Financial Services Report* (3 June) frames a two-front year: Q1 2026 direct ransomware attacks on financial inst…
June 2026
Sector
Critical Infrastructure Sector Edition — June 2026
Monthly intelligence for Indian critical-infrastructure CISOs, SOCs and boards. This edition tracks pre-positioning by China-nexus actors, G…
June 2026
Sector
Education Sector Edition — June 2026
Monthly threat intelligence for Indian higher-education and schooling CISOs, SOC leads, and governing boards. This edition tracks a destruct…
June 2026
Sector
Government & Defence Sector Edition — June 2026
For CISOs, SOC leads and security leadership across Indian central/state government, defence and public-sector bodies. The picture is contin…
June 2026
Sector
Healthcare Sector Edition — June 2026
Monthly threat intelligence for Indian healthcare CISOs, SOC leads and hospital boards. This edition covers verified developments from appro…
June 2026
Weekly
Weekly Brief — Week of 25–29 May 2026
Global threats decoded for Indian defenders, plus the India-targeted picture. Week of 25–29 May 2026.
29 May 2026
Weekly
Weekly Brief — Week of 18–22 May 2026
Week of 18–22 May 2026 · Global threats decoded for Indian defenders, plus India-targeted activity
22 May 2026
Weekly
Weekly Brief — 15 May 2026
A rare quiet Patch Tuesday masked a louder week underneath it: SAP HotNews flaws reaching CVSS 9.6, a fourth-generation self-replicating npm…
15 May 2026
Weekly
Weekly Brief — 8 May 2026
Global threats decoded for Indian defenders: a perimeter firewall under live attack, a one-command root flaw in nearly every Linux box, and …
8 May 2026