Google has introduced a passive sign-in feature for YouTube, allowing users to stay logged in across devices without actively entering their credentials.
MeitY Secretary S. Krishnan emphasized the government's commitment to enhancing India's cybersecurity framework, highlighting the risks associated with rapid digitization. He noted the emergence of vulnerabilities exposed by platforms like Mythos and the importance of addressing these gaps. Ongoing discussions with U.S. counterparts focus on regular cybersecurity exercises and monitoring. Regarding the Tata Electronics cyber breach, the government is investigating, with preliminary findings suggesting no significant loss. Additionally, Krishnan mentioned that MeitY is reviewing feedback on username features for messaging platforms, specifically that WhatsApp has delayed its rollout until further discussions. MeitY is also examining Meta's response to the Child Sexual Abuse Material issue and is considering standardized regulations for all messaging applications.
A security researcher known as Nightmare Eclipse has revealed a new unpatched vulnerability in Windows, named LegacyHive, which is a local privilege escalation flaw in the Windows User Profile Service. This vulnerability allows attackers to access and load user hives of other accounts, including administrators. Nightmare Eclipse has provided proof-of-concept exploit code that works on systems with Microsoft's July 2026 patches. The exploit initially did not require user credentials but now necessitates them for accessing other hives. Nightmare Eclipse has previously disclosed over half a dozen zero-day vulnerabilities affecting Microsoft products. Microsoft has not yet acknowledged the LegacyHive exploit.
In digital communication, traditional messaging platforms act as persistent archives of user data, including accounts, devices, contacts, and interactions, which can hinder the essence of communication. While end-to-end encryption enhances privacy, it does not eliminate data retention. Amnesia is a concept that proposes a messaging platform emphasizing temporary communication with no permanent accounts or conversation histories. The initial prototype allows users to create one-time sessions using QR codes, ensuring that all data is destroyed once the session ends. Each session generates unique identity keys, preventing credential reuse and session token theft. The system does not retain any conversation history, reinforcing the principle that once a session is terminated, the data is irretrievable. Amnesia's relay facilitates communication without retaining user accounts or histories, and its design minimizes durable information to reduce risks. The project is currently an architectural concept and an early prototype, not ready for production or sensitive communications.
Security researcher Chaotic Eclipse has released a proof-of-concept exploit called LegacyHive, which targets a vulnerability in the Windows User Profile Service. The exploit requires standard user credentials and a third username, potentially an administrator account. It can mount the target user hive in the current user classes root and is designed to reduce the risk of public exploitation. The exploit works across all supported desktop and server versions of Windows, including those updated with the July 2026 Patch Tuesday release. Microsoft is investigating the findings related to LegacyHive.
Microsoft has patched 622 vulnerabilities, including two privilege escalation flaws in SharePoint Server (CVE-2026-56164, CVSS score: 5.3) and Active Directory Federation Services (CVE-2026-56155, CVSS score: 7.8), which are actively exploited threats. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has included these vulnerabilities in its Known Exploited Vulnerabilities catalog, requiring Federal Civilian Executive Branch agencies to implement fixes by specified deadlines.
CISA has also noted active exploitation of several SharePoint Server vulnerabilities, including CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164, which allow unauthorized access to vulnerable instances. CVE-2026-56164 enables attackers to send crafted network requests to access functions that should require authorization, leading to privilege escalation without prior authentication. Additionally, CVE-2026-55040 (CVSS score: 9.1) allows remote unauthenticated attackers to bypass authentication on a vulnerable SharePoint server, enabling unauthorized operations.
Meta-owned WhatsApp has responded to the Indian government's notice concerning its proposed "username" feature, which aims to allow users to communicate without sharing phone numbers. The Indian government expressed concerns about potential risks such as online fraud and impersonation. WhatsApp requested more time to address these issues and confirmed that the feature will not launch in India until discussions are complete. The Ministry of Information Technology is currently reviewing WhatsApp's submission. Other messaging platforms, including Telegram and Signal, have also received similar notices. WhatsApp plans to implement measures to mitigate impersonation risks, such as allowing only legitimate owners to claim high-profile names and requiring users to know exact usernames to initiate contact. The platform will limit the number of new contacts an account can reach and provide information about the sender's account status when a user receives a message via a username.
A segment of Google Pixel users is experiencing issues with the Google Recorder app, specifically that recordings are failing to save. A user on the Google Pixel subreddit reported that the app initiates recordings but does not store them, and several other users have confirmed similar experiences. Despite attempts to troubleshoot, such as clearing the app's cache and restarting devices, the issue persists for some users. However, others report that the app functions correctly on their devices. A poll on the subreddit shows that 60% of respondents are having issues with the app.
Zoho-owned messaging app Arattai has disabled its Username feature to comply with regulatory changes, as stated by Zoho founder Sridhar Vembu. The decision reflects concerns over digital privacy and security amid evolving regulations. The Indian government has issued notices to WhatsApp, Signal, and Telegram regarding their usernames feature, instructing them to refrain from rolling it out until proper consultations are conducted. Digital advocacy groups, like the Internet Freedom Foundation, criticize the government's approach as an overreach into private companies' operational decisions. WhatsApp has addressed user concerns by releasing a FAQ related to impersonation, scams, and unwanted contacts.
WhatsApp is introducing a feature that allows users to communicate without sharing their phone numbers by creating unique usernames. This feature aims to enhance privacy and security, enabling users to connect solely by exchanging usernames. Users will receive notifications when the feature becomes available in their countries, and creators, small businesses, and organizations can claim usernames they use on other Meta platforms. Usernames will be limited to 35 characters, and high-profile individuals will not be able to register their names. Despite these changes, experts express concerns about WhatsApp's overall privacy practices, as the platform collects extensive metadata for marketing purposes. Users' phone numbers will still be required to create an account, and there will be no public username directory. Kunal Shah has been appointed as the new head of WhatsApp, succeeding Will Cathcart.