A CERT-In Empanelled Auditing Organization
Newsletter
Home/Newsletter
Newsletter

The SICHERTEN cyber & compliance briefing.

Our monthly briefing on the attacks, the regulatory moves and the wider security news that matter to regulated organisations in India. Current issue: September 2026.

Issue: September 2026 · Last updated 1 October 2026

Compiled from public reporting and official sources. Items marked alleged or reported were, at the time of writing, not officially confirmed by the named organisation or regulator. This briefing is for awareness, verify against primary sources before acting on any item.

September 2026

Cyberattacks & breaches

Notable incidents disclosed or reported in September 2026, spanning healthcare, government, transport and SaaS.

05 Sep 2026Extortion · ShinyHunters · Healthcare

ShinyHunters claims 284 million records from McKesson

McKesson disclosed an incident through an SEC Form 8-K in late August after discovering it on 25 August. The ShinyHunters group claimed roughly 284 million patient-related records and demanded about $55 million, but told reporters the figure is a raw count of database rows, not unique individuals, and that it had not finished analysing the data. McKesson has not confirmed the scale.

Why it matters: Claimed figures are routinely inflated and unverified. The SEC 8-K cadence and extortion theatre now shape the first 72 hours of a healthcare incident as much as the forensics do.

Source: BleepingComputer

29 Sep 2026Data breach · Government · 3M+

Pentagon personnel agency breach exposes 3 million people

The US Defense Manpower Data Center confirmed attackers accessed a file-sharing server for roughly nine months, exposing sensitive personal data on more than three million people. Notification letters were dated 18 September, and those affected were offered credit monitoring.

Why it matters: Nine months of undetected access to a file-sharing server is a logging and monitoring failure, exactly the controls CERT-In’s log-retention and reporting rules exist to force.

Source: Cybersecurity News

08 Sep 2026Third-party · Healthcare · API

Stolen vendor credentials used to copy patient data at Veradigm

Healthcare-technology firm Veradigm (formerly Allscripts) disclosed in an SEC Form 8-K that an attacker obtained credentials from a third-party vendor’s environment for a Veradigm customer-services API, then used that access to copy patient data, including some Social Security numbers. A group calling itself The Gentlemen claimed about 3.5 million records.

Why it matters: Your vendor’s breach becomes your breach. API access tied to vendor credentials needs the same rotation, scoping and monitoring as your own.

Source: HIPAA Journal

18 Sep 2026Data breach · SaaS · 23.6M

Gyazo breach exposes 23.6 million user records

The screenshot service Gyazo (operated by Helpfeel) confirmed an attacker exploited a flaw in its image-upload server on 11 September, running arbitrary commands and exposing about 23.62 million user records including password hashes, authentication tokens and session IDs, plus metadata on hundreds of millions of images. The route was fixed by 12 September and payment data was not affected.

Why it matters: Exposed authentication tokens enable account takeover long after passwords are reset. Token invalidation belongs in every breach playbook.

Source: BleepingComputer

29 Sep 2026Ransomware · Transport · Japan

Ransomware hits Japanese rail group Keio; Tokyo Metro also breached

Keio Corporation confirmed a ransomware attack on a group server on 26 September that disrupted business systems, mainly its hospitality division, while train operations continued. In a separate incident the same weekend, Tokyo Metro disclosed unauthorised access to roughly 59,000 members’ email addresses.

Why it matters: Transport and hospitality operators straddle IT and operational technology; ransomware that forces a network shutdown is a resilience and continuity test, not only a data-privacy one.

Source: BleepingComputer

September 2026

Regulatory watch

What is live on the India compliance calendar this month across RBI, SEBI, IRDAI, DPDP and CERT-In.

Sep 2026DPDP · Consent Managers

DPDP clock: the Consent Manager milestone is weeks away

With the DPDP Rules phased in, the 12-month provisions, including the Consent Manager framework and Board registration, commence on 13 November 2026, ahead of the full compliance deadline of 13 May 2027. Data Fiduciaries should be standardising consent records and designing for interoperability now.

Why it matters: The Consent Manager interface is not a last-minute integration. Firms that standardise consent capture and withdrawal early avoid a rebuild later.

Source: MeitY

Sep 2026IRDAI · Insurance

IRDAI 2026 cyber guidelines: first-year compliance underway

The IRDAI Information and Cyber Security Guidelines, 2026 (issued 6 April 2026) require compliance from the financial year that opened on 1 April 2026. Insurers and intermediaries are working through governance, assurance and audit obligations in their first cycle under the reissued guidelines.

Why it matters: First-year compliance is where gaps surface; board-level governance and independent assurance are the pieces most often left late.

Source: IRDAI

Sep 2026RBI · Banking

RBI 2026 Directions: find the one that applies to you

After the 31 July 2026 reset, the RBI framework is a set of entity-class Directions, one per class. The testing cadence is vulnerability assessment at least every six months and penetration testing at least annually for critical and DMZ-facing systems, cloud included; a tested system later breached through a missed vulnerability counts as a deficiency against the auditor.

Why it matters: The scope test is disjunctive and the VA cadence is twice a year, not annual. Mapping to the correct Direction is the first step for every regulated entity.

Source: Reserve Bank of India

Sep 2026CERT-In · Incident reporting

Active NetScaler exploitation puts the 6-hour clock in focus

With critical Citrix NetScaler flaws under active exploitation (see below), any confirmed compromise of an India-based system brings CERT-In’s six-hour incident-reporting obligation into play, alongside sector rules from RBI, SEBI or IRDAI.

Why it matters: A single intrusion can start several reporting clocks at once. A unified incident-response plan with regulator-specific annexes keeps you inside the tightest window.

Source: CERT-In

September 2026

General security & AI

Vulnerabilities, credential threats and AI-security developments worth a leadership read.

27 Sep 2026Vulnerability · Citrix · RCE

Two Citrix NetScaler zero-days exploited before patches existed

Citrix confirmed on 27 September that two critical NetScaler ADC and Gateway flaws, CVE-2026-88771 and CVE-2026-88772 (both CVSS 9.5), were being exploited in the wild, with CVE-2026-88771 allowing unauthenticated remote code execution on default configurations. CISA added both to its Known Exploited Vulnerabilities catalog with a 30 September deadline, and Citrix warned that patching alone does not remove the risk of prior compromise.

Why it matters: Internet-facing edge appliances remain the softest target. Patch immediately and hunt for signs of compromise, because a fix does not undo access already taken.

Source: SecurityWeek

28 Sep 2026Credentials · AI

Infostealers are exposing corporate AI accounts and API keys

Analysis of recent stealer-log data found infostealers harvesting corporate AI accounts, sessions and API keys, handing attackers access to sensitive data, compute and connected systems.

Why it matters: AI accounts and API keys are now crown-jewel credentials. Treat them like production secrets, with rotation, scoping and monitoring.

Source: Security Affairs

15 Sep 2026Supply chain · SaaS

Klue breach ripples across roughly 200 companies

A breach at market-research provider Klue exposed keys to its customers’ cloud services, letting attackers reach and extort close to 200 companies, several of them well-known security vendors.

Why it matters: One compromised SaaS provider can hand attackers the keys to hundreds of customers. Vendor cloud-key handling is a first-order supply-chain risk.

Source: TechCrunch

28 Sep 2026AI · Threats

Researchers trace an AI agent from research task to reconnaissance

Investigators documented an AI agent’s path from an ordinary research task into reconnaissance activity, part of a wider trend of AI agents being turned toward offensive use.

Why it matters: Autonomous agents lower the cost of reconnaissance at scale. Monitoring and guardrails for AI tooling now belong in the threat model.

Source: Security Affairs

Turn this month’s headlines into a plan.

Whether it’s a breach-response gap, a looming DPDP deadline or an urgent patch-and-test cycle, our CERT-In empanelled team can help you act on what matters.