Urgent.News

What's breaking now, across thousands of outlets.

Tech

India forces caller-ID apps to feed spam reports to telcos

Truecaller says the one-way sharing requirement would hand a commercially valuable proprietary asset to telecom operators.

The Indian government has expanded its anti-spam measures to compel caller-ID and call-management applications to provide spam reports to telecommunications companies. This decision was made by the Telecom Regulatory Authority of India (TRAI), which mandated these apps to forward spam reports to a blockchain-based platform managed by telecom operators.

The aim is to create a more substantial spam report repository, enabling the telecom industry to take actions against spammers effectively. Truecaller, a leading spam-blocking app, criticized this move as anti-competitive, as it transfers valuable data from apps like Truecaller to telecom operators. Truecaller, which is based in Stockholm and serves over 350 million users in India, noted that the new rules do not apply to calls made using designated number ranges for promotional, service, or transactional communications.

Meanwhile, TRAI also introduced new rules regarding software and AI voice agents, requiring companies to disclose their use and phone numbers with telecom operators. Telecom operators can now impose a termination charge of up to 5 paise per minute on automated calls, except for those within certain designated ranges.

Written by urgent.news from TechCrunch's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at techcrunch.com →

More in Tech

Rapuncel: Fake GitHub Repositories Disable EDR with a Signed Kernel Driver

1. Basic Information Original Title: Threat Intel | One Kit, Forty Companies: How a Malware-as-a-Service Platform Used GitHub as a Distribution Network for its Campaign Source: LastPass TIME / Delphos…

  • Signed kernel driver disables EDR by terminating antivirus processes
  • Fake GitHub repositories distribute malware via DLL side-loading
  • Malware steals data and transmits to command and control server

Reaching an Internal OpenAI Repository Through an HEIF RCE and Overprivileged SSO Token Chain

1. Basic Information Original Title: Hacking OpenAI Source: Hacktron AI Published Date: 2026-09-13 Updated Date: None Severity: Critical Severity Basis: Researchers achieved RCE on OpenAI Forums via a…

  • Attackers exploited heap overflow in libheif library to execute arbitrary code (RCE)
  • Overprivileged SSO token allowed access to ChatGPT/Codex employee account
  • Attackers created proof-of-concept pull request in internal OpenAI repository

Your Stack Has One Point of Failure. It's the Tool You Trusted Most.

Your Stack Has One Point of Failure. It's the Tool You Trusted Most. Three things hit Hacker News this week and they rhyme.

  • Three stories highlight businesses' trust in single dependencies
  • Hacker News reports ZCode, OpenAI, and South Korea breaches
  • Single point of failure can cause catastrophic issues

More from Saturday 19 September →