LATEST View all updates

CERT-In Cyber Threats 2026: 5 Key Numbers Behind Finance & Healthcare Risk

CERT-In cyber threats 2026 now include a high-severity Apple macOS Screen Sharing authentication-bypass warning alongside new finance and healthcare threat data. Mac users on affected Sonoma, Sequoia and Tahoe versions should install the latest security updates.

CERT-In cyber threats 2026 finance and healthcare sector detections

Key takeaways

  • CERT-In-linked parliamentary data shows 3,67,462 finance and healthcare cyber-threat instances detected and mitigated in H1 2026.
  • Finance accounted for 3,48,607 instances; healthcare accounted for 18,855.
  • The combined H1 figure is about 60.8% of the full-year 2025 total.
  • These counts largely include malicious scanning, probing and vulnerable services — they are not the same as successful hacks.
  • Targeted bank intrusion campaigns were 17 in H1 2026 versus 39 in all of 2025, so that narrower metric does not show the same pace.
  • The exact parliamentary answer PDF remains unresolved and should be added if found later.

CERT-In cyber threats 2026 now include a fresh high-severity Apple macOS warning alongside the finance and healthcare threat data already reported this year. CERT-In’s August 10 advisory concerns an authentication-bypass vulnerability in macOS Screen Sharing, while the broader H1 2026 threat figures show 3.67 lakh detected and mitigated instances across finance and healthcare.

These are two different types of cyber-security evidence. The Apple warning identifies a specific vulnerability with a clear software-update action. The finance and healthcare figures are broader detection data and should not automatically be interpreted as successful hacks, stolen money or confirmed patient-data breaches.

Latest CERT-In Alert · August 10, 2026

CERT-In Warns Mac Users About Screen Sharing Authentication Bypass

CERT-In has issued a HIGH-severity vulnerability note covering Apple macOS Screen Sharing. The flaw could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.

What Mac users should do

Install the relevant Apple security update.

Check your macOS branch and update to the patched version or a later available version for your Mac.

What this does not prove

CERT-In’s advisory identifies a vulnerability and the required mitigation. It does not establish that every vulnerable Mac has been compromised or that exploitation is widespread in India.

macOS Sonoma
14.8.9 or later
macOS Sequoia
15.7.9 or later
macOS Tahoe
26.6.1 or later

Which macOS versions are affected?

macOS branch Affected versions Action
macOS Sonoma Versions before 14.8.9 Install 14.8.9 or later
macOS Sequoia Versions before 15.7.9 Install 15.7.9 or later
macOS Tahoe Versions before 26.6.1 Install 26.6.1 or later

What is the Screen Sharing risk?

Screen Sharing allows remote interaction with a Mac. The authentication-bypass flaw means that, under the conditions described in the advisory, an attacker on the network may be able to authenticate without valid credentials.

Do not interpret this as proof that someone is already controlling your Mac. A vulnerability describes a security weakness and possible attack path. It is not the same thing as evidence that your device has already been compromised.

Do I still need to update if I do not normally use Screen Sharing?

Installing the Apple security update remains the appropriate fix. Not routinely using Screen Sharing should not be treated as a replacement for patching an affected macOS version.

The issue concerns the authentication mechanism associated with the Screen Sharing service. Users should therefore rely on Apple’s security update rather than assuming normal usage habits alone remove the risk.

How to check for the update on your Mac

Open System Settings
Use the Apple menu and open System Settings.
Select General
Open the General section in System Settings.
Open Software Update
Allow the Mac to check for available macOS updates.
Compare your installed version
Check whether your Sonoma, Sequoia or Tahoe installation is older than the patched version listed above.
Install the available security update
Follow Apple’s normal update process and restart the Mac if required.

5 Key CERT-In Cyber Threat Numbers for 2026

The finance and healthcare figures discussed in the original CERT-In cyber threats 2026 report cover threat activity detected and mitigated during the first half of 2026.

Finance H1 2026
2.73 lakh

Detected and mitigated threat instances reported for the finance sector.

Healthcare H1 2026
94,000

Detected and mitigated threat instances reported for healthcare.

Combined H1 2026
3.67 lakh

Finance and healthcare detections combined.

Targeted bank campaigns H1 2026
17

A much narrower category than broad scanning or probing detections.

Targeted bank campaigns 2025
39

The full-year comparison used to keep targeted campaigns separate from aggregate detections.

Important: the 3.67 lakh figure should not be read as “3.67 lakh successful cyber attacks.” The underlying reporting includes scanning, probing and detections involving vulnerable services, not only confirmed compromise.

What Do the CERT-In Cyber Threat Numbers Actually Mean?

This is the most important question in the original article.

A cyber-security monitoring system may detect hostile or suspicious activity before an attacker successfully compromises a system. That can include malicious scanning, probing for exposed services, attempts against known vulnerabilities and other hostile activity detected and mitigated by security systems.

As a result, a large detection count can indicate a substantial attack surface and persistent hostile activity without proving that the same number of organisations, customers or patients were successfully hacked.

CERT-In cyber threats 2026 scanning probing and vulnerable services explained

CERT-In-linked threat counts include scanning, probing and vulnerable-service detections and should not automatically be interpreted as successful hacks.

Detection ≠ successful compromise. One vulnerable service can attract repeated probes, one organisation can generate many detections, and a blocked attempt can still appear in threat-monitoring data.

CERT-In Cyber Threats 2026: Finance Sector Breakdown

The reported finance-sector count for the first half of 2026 is approximately 2.73 lakh detected and mitigated threat instances.

The finance sector is an obvious target for attackers because banks, payment systems, financial institutions and their supporting infrastructure combine high-value data with money movement and widely used digital services.

But the broad finance number does not tell us:

  • how many unique banks were affected;
  • how many detections belonged to the same institution;
  • how many attempts reached customer-facing systems;
  • how many resulted in fraud;
  • how many resulted in confirmed data theft;
  • or how many represented successful compromise.

A bank customer should not read “2.73 lakh threat detections” as “2.73 lakh bank accounts were hacked.” Those are entirely different measurements.

Healthcare Cyber Threats in India: What the 2026 Figure Means

The reported healthcare count for H1 2026 is approximately 94,000 detected and mitigated threat instances.

Healthcare cyber-security matters because hospitals, laboratories, diagnostic providers and connected health systems can hold sensitive patient information while also depending on continuously available digital infrastructure.

However, the 94,000 figure by itself does not establish 94,000 healthcare breaches.

It also does not identify:

  • 94,000 hospitals;
  • 94,000 patients whose records were stolen;
  • 94,000 successful ransomware incidents;
  • or 94,000 separate organisations.

The defensible interpretation: healthcare infrastructure is experiencing substantial malicious or suspicious cyber activity that organisations need to detect and mitigate. The aggregate figure alone cannot tell us how many attempts became successful compromises.

What the 60% Comparison Actually Tells Us

The combined finance and healthcare H1 2026 total is approximately 3.67 lakh detections.

Comparisons with 2025 can help show the pace of observed threat activity, but they require caution because H1 2026 is a six-month period while full-year 2025 covers 12 months.

A simple percentage comparison can tell us how much of the previous full-year count has already been recorded in six months. It cannot, by itself, prove that the second half of 2026 will continue at the same rate.

Do not annualise the first-half figure as a prediction unless the methodology specifically supports that forecast. Threat activity can accelerate, slow down or change composition during the rest of the year.

Targeted Bank Intrusion Campaigns Are a Different Metric

One particularly useful comparison in the underlying reporting concerns targeted intrusion campaigns against banks.

The figure discussed for H1 2026 is 17 targeted bank intrusion campaigns, compared with 39 during full-year 2025.

This narrower metric does not show the same simple pace as the much larger scanning, probing and vulnerable-service detection count.

Metric H1 2026 What it measures
Finance-sector threat detections About 2.73 lakh Broad detected and mitigated malicious/suspicious activity.
Healthcare threat detections About 94,000 Broad detected and mitigated malicious/suspicious activity.
Targeted bank intrusion campaigns 17 A narrower category of targeted intrusion activity.

This distinction is important because readers can otherwise collapse every cyber-security metric into the single word “attack.”

What Should Bank Customers Do Differently?

The sector-level figures do not prove that your own bank account has been compromised. They do, however, reinforce standard account-security practices.

Protect OTPs and authentication codes

Do not share OTPs, PINs, passwords or approval codes with callers, messages or websites claiming to “secure” your account.

Use official banking channels

Open your bank’s known application or official website rather than following urgent links from messages.

Review unexpected transactions

Check alerts and statements and contact the bank through an official channel when activity is unfamiliar.

Keep devices updated

Security updates matter because exposed software vulnerabilities can become part of broader attack chains.

What Should Healthcare Users Understand?

The healthcare threat figure is primarily an infrastructure-risk signal. It does not mean every patient needs to assume their medical records have been leaked.

If a particular hospital or healthcare provider announces an incident, users should follow that organisation’s specific guidance.

Without such an incident notice, the national or sector-level detection count should not be used as evidence that a particular patient’s data was exposed.

What the CERT-In Cyber Threat Numbers Do Not Prove

  • They do not prove 3.67 lakh successful hacks.
  • They do not prove 3.67 lakh organisations were compromised.
  • They do not prove 2.73 lakh bank accounts were hacked.
  • They do not prove 94,000 patient records were stolen.
  • They do not establish that every detected event was equally severe.
  • They do not establish a unique victim count.
  • They do not tell us how many detections came from repeat attempts against the same infrastructure.
  • They do not establish that H1 2026 activity will continue at the same pace during H2.

The useful signal is exposure and hostile activity, not an invented victim count. Detection data helps show the pressure being placed on digital infrastructure, while incident and breach data answer different questions.

Why CERT-In Cyber Threats 2026 Matter Beyond the Headline Number

CERT-In’s role means its warnings and threat data can surface very different kinds of cyber-security issues.

The Apple Screen Sharing advisory is a good example: it provides a specific vulnerability, affected software versions and a concrete action — update the operating system.

The finance and healthcare figures are different. They help describe the volume and composition of detected hostile activity, but they require interpretation before being translated into claims about successful compromise.

Keeping those evidence types separate makes cyber-security reporting more useful and less sensational.

Related ThePulseSignal Security Guides

Verification Method

How ThePulseSignal verified this article

The finance and healthcare section was built by cross-checking the same H1 2026 figures across the reliable reports reviewed during the original article research.

The article deliberately separated broad scanning, probing and vulnerable-service detections from successful compromise and from the narrower figure for targeted bank intrusion campaigns.

The original article also disclosed that the exact controlling Rajya Sabha question-and-answer document containing the 2026 numerical table had not been located during publication research rather than presenting a background CERT-In source as if it were the numerical primary source.

For the August 11 update, ThePulseSignal separately reviewed CERT-In’s August 10 vulnerability note for Apple macOS. The Apple item is treated as a fresh specific vulnerability update and is not mixed into the finance and healthcare aggregate detection totals.

The current CERT-In note identifies the affected macOS branches, the authentication-bypass risk and the recommended action of applying the relevant Apple security updates.

Limitations and Unresolved Facts

  • The original finance and healthcare numerical table was reported as information shared with Parliament, but the exact Rajya Sabha question-and-answer document containing the table had not been located during the original publication workflow.
  • The broad detection figures do not provide a unique organisation, account, patient or victim count.
  • The figures do not establish how many detected threats resulted in successful compromise.
  • H1 2026 data should not automatically be doubled to predict the full-year total.
  • The Apple vulnerability advisory does not establish widespread active exploitation in India.
  • The Apple update applies to affected macOS versions; users should install the latest appropriate update offered for their supported Mac rather than treating the listed minimum patched version as a reason to avoid a newer update.
  • Not regularly using Screen Sharing should not be treated as equivalent to patching the underlying vulnerability.
  • Cyber-security conditions can change quickly, so later CERT-In or vendor guidance may require this article to be updated again.

CERT-In Cyber Threats 2026: FAQs

What is the latest CERT-In warning for Mac users?

CERT-In issued an August 10, 2026 high-severity warning concerning an authentication-bypass vulnerability in Apple macOS Screen Sharing. Users on affected versions should install the applicable Apple security update.

Which macOS versions should be updated?

The CERT-In advisory identifies Sonoma versions before 14.8.9, Sequoia versions before 15.7.9 and Tahoe versions before 26.6.1 as affected.

Does the Screen Sharing flaw mean my Mac has already been hacked?

No. A vulnerability identifies a possible security weakness. The advisory does not prove that an individual Mac has already been compromised.

Do I need to update if I never use Screen Sharing?

The appropriate mitigation is still to install the relevant Apple security update. Normal usage habits should not be treated as a substitute for patching an affected macOS version.

What does the 3.67 lakh CERT-In cyber-threat figure mean?

It refers to the combined finance and healthcare threat detections discussed for H1 2026. It should not automatically be interpreted as 3.67 lakh successful hacks or unique victims.

Were 2.73 lakh bank accounts hacked?

No such conclusion is supported by the aggregate finance-sector detection figure. The number describes detected and mitigated threat activity, not a count of hacked customer accounts.

Were 94,000 healthcare records breached?

The healthcare figure does not establish that 94,000 patient records were stolen or that 94,000 healthcare organisations suffered breaches.

Why are targeted bank intrusion campaigns listed separately?

Because targeted intrusion campaigns are a narrower metric than broad scanning, probing and vulnerable-service detections. Treating them as the same measure would distort the evidence.

Does the H1 2026 figure prove cyber attacks will double this year?

No. First-half activity can be compared with earlier periods, but it cannot responsibly be doubled into a full-year forecast without supporting methodology.

Last updated and verified: August 11, 2026.