🇮🇳 India Regulatory Feed
India Regulatory Updates
Live circulars, advisories and policy updates from RBI, SEBI, CERT-In, MeitY, NPCI, and IRDAI — relevant to cybersecurity and data protection compliance.
215 updates
In every MFA rollout, there will come a time where you think you are closing in on "done", and some automation to list what's left would be handy. Something quicker than scrolling through the web interface through thousands of accounts ...
 This is that method.
 Also, remember when we discussed yesterday about the beta graph commands in the Microsoft.Graph.Beta library? We'll use one of those beta commands here!
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
One thing that folks never seem to do after "going to the CLOOOOUUUUD" is to look at their logs, logs that they would have checked daily when things were on premise.
 One log that really bears looking at is the log of successful and failed logins. the call for that is:
Building on the last diary on Using MS Graph and Powershell, let's look at "Risky" logins.
Microsoft Graph is a newer API that is meant to replace several others.  OK, it's at version 2.3.9, so it's not all that new, but it's new enough that lots of folks (and commercial tools) aren't using it yet.   It allows you to Get and Set info from/to M365, Entra Users and Entra managed machines for starters.  Let's dig in!
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-72529 TrueConf Server Missing Authentication for Critical Function Vulnerability
CVE-2026-72530 TrueConf Server Code Injection Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-ri
View CSAF
Summary
Successful exploitation of this vulnerability could allow a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory, potentially leading to unauthorized access to the application and connected systems.
The following versions of Johnson Controls Simplex Incident Manager are affected:
Simplex Incident Manager <=V2.01 (CVE-2026-27875)
CVSS
Vendor
Equipment
Vulnerabilities
v3 5.8
Johnson Controls Inc.
Johnson Controls Simplex Incident Manager
Cleartext Storage of Sensitive Information in Memory
Background
Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Ireland
Vulnerabilities
Expand All +
CVE-2026-27875
The Simplex Incident Manager application stores user credentials (such as passwords and authentication tokens) in an unencryp
Use safeguards, sandboxing and active oversight to realise the benefits of autonomous systems while limiting the unintended activity.
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Cloud providers typically expose a REST API at 169.254.169.254 that allows code running on virtual machines to retrieve machine-specific data. Some of the data is more or less harmless, such as the region the machine is running in or its MAC and IP addresses. However, the service may also be used to retrieve credentials for IAM roles and service account tokens.
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-64849 MLflow Server-Side Request Forgery Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must che
Executive summary
Note: This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content in this advisory should be understood and applied as one subset of the wider threat landscape.
Top Mitigations
Inventory all Siemens S7 Series programmable logic controllers (PLCs)
Apply critical security patches
Ensure PLCs are not accessible from the Internet
Strengthen access controls
Monitor for unauthorized activity
Harden PLC services, protocols, and ladder logic integrity
Hunt for anomalies that may indicate a compromise
The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Energy (DOE), and Environmental Protection Agency (EPA)—hereafter re
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View CSAF
Summary
Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument. If a user is tricked to run one of the impacted application binary with a malicious string, an attacker could leverage the vulnerability to perform remote code execution in the context of the current process. Siemens has released new versions for the affected products and recommends to update to the latest versions.
The following versions of Siemens Simcenter Nastran are affected:
Simcenter Femap vers:intdot/<2606 (CVE-2026-59086)
Simcenter Nastran vers:intdot/<2606 (CVE-2026-59086)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.8
Siemens
Siemens Simcenter Nastran
Stack-based Buffer Overflow
Background
Critical Infrastructure Sectors: Critical Manufacturing, Defense Industrial Base, Energy, Healthcare and Public Health, Transportation Systems
Countries/Areas Deployed: Worldwide
Company Headquarters Loc
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition or execute arbitrary code.
The following versions of CISA Malcolm are affected:
Malcolm <26.06.1 (CVE-2026-55676)
Malcolm <26.07.0 (CVE-2026-63133, CVE-2026-63134, CVE-2026-63177)
Malcolm <=26.07.1 (CVE-2026-19670, CVE-2026-19671)
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.8
CISA
CISA Malcolm
Allocation of Resources Without Limits or Throttling, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Unrestricted Upload of File with Dangerous Type, Incorrect Authorization, Improper Handling of Highly Compressed Data (Data Amplification)
Background
Critical Infrastructure Sectors: Information Technology
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-63133
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, safe-extract.py
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
CVE-2026-55040 Microsoft SharePoint Weak Authentication Vulnerability
CVE-2026-59310 Broadcom VMware vCenter Path Traversal Vulnerability
CVE-2026-65400 Apple macOS Improper Authentication Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after the much smaller macOS update that addressed the single screen-sharing vulnerability. This vulnerability did not affect iOS/iPadOS.
About 20 years ago, with macOS 10.5 (Leopard), Apple introduced screen sharing. Apple did not invent a new protocol for screen sharing. Instead, it used the established VNC protocol. VNC is a pretty simple, unencrypted protocol using TCP port 5900. Historically, the protocol used a simple global password for authentication. Apple adapted the protocol for its own use, but overall, left the VNC protocol itself alone.
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2025-62593 Ray-Project Ray Code Injection Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check w
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Wireshark release 4.6.8 fixes 28 vulnerabilities and 25 bugs.
View CSAF
Summary
Parasolid is affected by an out of bounds read vulnerability that could be triggered when the application reads files in X_T format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions.
The following versions of Siemens Parasolid are affected:
Parasolid V38.0 vers:intdot/<38.0.235 (CVE-2026-64629)
Parasolid V38.1 vers:intdot/<38.1.230 (CVE-2026-64629)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.8
Siemens
Siemens Parasolid
Out-of-bounds Read
Background
Critical Infrastructure Sectors: Critical Manufacturing
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Germany
Vulnerabilities
Expand All +
CVE-2026-64629
The affected applications contains an out of bounds read vulnerability while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current proces
View CSAF
Summary
Siemens License Server is affected by multiple vulnerabilities which could allow an attacker to elevate its privileges and read arbitrary files on the system. Siemens has released a new version for Siemens License Server (SLS) and recommends to update to the latest version.
The following versions of Siemens License Server (SLS) are affected:
Siemens License Server (SLS) vers:intdot/<5.1, vers:intdot/<5.3 (CVE-2026-69108, CVE-2026-69109)
CVSS
Vendor
Equipment
Vulnerabilities
v3 7.5
Siemens
Siemens License Server (SLS)
Incorrect Permission Assignment for Critical Resource, Path Traversal: '.../...//'
Background
Critical Infrastructure Sectors: Information Technology
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Germany
Vulnerabilities
Expand All +
CVE-2026-69108
The affected application is vulnerable to a local privilege escalation due to an insecure sudoers policy. This could allow an attacker to execute arbitrary commands and p
View CSAF
Summary
A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal functionality. Siemens has released new versions for the affected products and recommends to update to the latest versions.
The following versions of Siemens Desigo DXR and PXC Controllers are affected:
Desigo DXR2 vers:intdot/<01.21.233.16-7862 (CVE-2026-59693)
Desigo PXC3 vers:intdot/<01.21.233.16-7862 (CVE-2026-59693)
Desigo PXC4 vers:intdot/<02.21.194.36-2715 (CVE-2026-59693)
Desigo PXC5.E003 vers:intdot/<02.21.194.36-2715 (CVE-2026-59693)
Desigo PXC5.E24 vers:intdot/<02.21.194.36-2715 (CVE-2026-59693)
Desigo PXC7 vers:intdot/<02.21.194.36-2715 (CVE-2026-59693)
CVSS
Vendor
Equipment
Vulnerabilities
v3 4.3
Siemens
Siemens Desigo DXR and PXC Controllers
Improper Check for Unusual or Exceptional Conditions
Background
Crit
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to decrypt sensitive data, bypass authentication controls, gaining unauthorized access to read arbitrary files on the system, or gain unauthorized access to protected system resources.
The following versions of Johnson Controls Inc. Airwall are affected:
Airwall <=4.0.4 (CVE-2026-64887, CVE-2026-34492)
CVSS
Vendor
Equipment
Vulnerabilities
v3 6.8
Johnson Controls Inc.
Johnson Controls Inc. Airwall
Use of Hard-coded Cryptographic Key, External Control of File Name or Path
Background
Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Ireland
Vulnerabilities
Expand All +
CVE-2026-64887
A hardcoded password or cryptographic key was identified in the Airwall application. A hardcoded credential leads to a significant authe
View CSAF
Summary
Successful exploitation of this vulnerability could allow a low-privilege user or attacker to inject a persistent malicious payload via a crafted URL that executes in the context of other users' sessions, including administrators, potentially leading to session hijacking and unauthorized access.
The following versions of Johnson Controls Metasys are affected:
Metasys 12 vers:all/* (CVE-2026-34491)
Metasys 13 vers:all/* (CVE-2026-34491)
Metasys 14
Metasys 15
CVSS
Vendor
Equipment
Vulnerabilities
v3 8
Johnson Controls Inc
Johnson Controls Metasys
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Background
Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Ireland
Vulnerabilities
Expand All +
CVE-2026-34491
A low-privilege user can inject a malicious XSS p
View CSAF
Summary
Siveillance Video Management Servers contains a vulnerability that could allow a Remote Code Execution attack. Siemens has released new versions for the affected products and recommends to update to the latest versions.
The following versions of Siemens Siveillance Video are affected:
Siveillance Video V2023 R3 vers:intdot/<23.3.27 (CVE-2026-3014)
Siveillance Video V2024 R1 vers:intdot/<24.1.16 (CVE-2026-3014)
Siveillance Video V2025 vers:intdot/<25.1.15 (CVE-2026-3014)
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.1
Siemens
Siemens Siveillance Video
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Background
Critical Infrastructure Sectors: Critical Manufacturing, Communications, Commercial Facilities
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Germany
Vulnerabilities
Expand All +
CVE-2026-3014
Milestone has released a new version of XProtect® (and several cumulative patch updates) whi
View CSAF
Summary
Successful exploitation of this vulnerability could allow an attacker within Bluetooth range to manipulate brain stimulation parameters and override safety limits.
The following versions of Flow Neuroscience FL-100 are affected:
Flow Neuroscience FL-100
Halo Neuroscience FL-100
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.1
Flow Neuroscience
Flow Neuroscience FL-100
Use of Hard-coded Credentials
Background
Critical Infrastructure Sectors: Healthcare and Public Health
Countries/Areas Deployed: Worldwide
Company Headquarters Location: Sweden
Vulnerabilities
Expand All +
CVE-2026-18164
An undocumented hard-coded credential, shared by all device units, is authorized to bypass authentication. This allows an attacker within Bluetooth range to arbitrarilymanipulate brain stimulation parameters and state.
View CVE Details
Affected Products
Flow Neuroscience FL-100
Vendor:Flow Neuroscience
Product Version:Flow Neuroscience Flow Neuroscience FL-100: <July_20
View CSAF
Summary
Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling mechanisms. A local attacker could exploit these vulnerabilities to extract the master key, allowing them to decrypt project data or remove project passwords. The lack of password salting enables offline dictionary or brute-force attacks against the password hashes. Successful exploitation could result in unauthorized access to, or modification of, sensitive project logic and configurations. Siemens has released a new version for LOGO! Soft Comfort and recommends to update to the latest version.
The following versions of Siemens LOGO! Soft Comfort are affected:
LOGO! Soft Comfort vers:intdot/<9 (CVE-2026-57262, CVE-2026-57263)
CVSS
Vendor
Equipment
Vulnerabilities
v3 6.8
Siemens
Siemens LOGO! Soft Comfort
Use of Hard-coded Cryptographic Key, Use of a One-Way Hash without a Salt
Background
Critical Infrastructure Sectors: Commercial Facilitie
Sources
RBI
0
SEBI
0
CERT-In
0
MeitY
0
NPCI
0
IRDAI
0