Author: Debolina Barik

Debolina Barik is a cybersecurity journalist at CyberNexora News, covering data breaches, ransomware attacks, malware threats, phishing scams, and emerging cybersecurity trends across India and globally. She focuses on delivering accurate, timely, and actionable security news for businesses and individuals.

Introduction: Azure AI Foundry Vulnerability — Why It Matters Azure AI Foundry Vulnerability is a critical Microsoft cloud security issue tracked as CVE-2026-85889, with a maximum CVSS score of 10.0. Microsoft disclosed the vulnerability on September 17, 2026, describing a missing authentication check affecting a critical function in Azure AI Foundry. The Azure AI Foundry Vulnerability could allow an unauthenticated attacker to elevate privileges remotely over a network without requiring user interaction. The vulnerability is classified as CWE-306, or Missing Authentication for Critical Function. For enterprises using AI development and deployment platforms, the disclosure highlights the importance of authentication controls…

Read More

Introduction: T-Mobile Rewards Phishing — Why It Matters T-Mobile Rewards Phishing is using fake SMS messages to convince recipients that their rewards points are about to expire. The campaign has been monitored since early May 2026 and uses urgent deadlines, invented point balances, and links leading to fraudulent websites. The messages impersonate T-Mobile and attempt to make recipients act before checking whether the notification is genuine. According to Malwarebytes, the campaign has generated more than 1,000 closely related message templates and used at least 81 domains over four months. How the T-Mobile Rewards Phishing Scam Works The campaign uses a…

Read More

Introduction: Docker Sandboxes Vulnerabilities — Why It Matters Docker Sandboxes Vulnerabilities include two security flaws that can weaken the isolation between an untrusted sandbox workload and the host system. Docker fixed the issues in Sandboxes 0.42.0, released on September 7, 2026. Docker identifies CVE-2026-77179 as Critical and CVE-2026-79994 as High. The vulnerabilities involve unsafe path handling, symbolic links and time-of-check-to-time-of-use (TOCTOU) conditions. The most serious issue affects macOS installations and could allow a malicious guest to escape its intended shared workspace and access host files. Organizations running untrusted repositories, third-party code or autonomous AI workloads should review their Docker Sandboxes…

Read More

Introduction: HEAVYGRAM Malware — Why It Matters HEAVYGRAM Malware is a Windows surveillance backdoor that uses Telegram accounts, bots, and groups as an attacker-controlled command-and-control channel. Group-IB reported its analysis on September 17, 2026, linking the operation to Handala Hack with moderate confidence. The campaign has been observed since fall 2023 and has reportedly targeted journalists, Iranian dissidents, and people opposing Iran’s government. Victims were socially engineered through messaging applications and sent malicious files disguised as legitimate programs or services. Who Is Behind HEAVYGRAM? Group-IB attributes HEAVYGRAM to Handala Hack with moderate confidence. The attribution is therefore an intelligence assessment…

Read More

Introduction: SparroWocky Backdoor — Why It Matters SparroWocky Backdoor is a newly reported malware campaign linked by ESET researchers to FamousSparrow, a cyberespionage group active since at least 2019. The activity has primarily focused on Latin America, with the backdoor observed at government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The campaign reportedly began using SparroWocky in August 2025. Researchers observed attackers exploiting internet-facing Microsoft Exchange servers for initial access before deploying the modular backdoor through techniques designed to keep malicious code hidden from conventional security controls. Who Is FamousSparrow? FamousSparrow is a China-aligned cyberespionage…

Read More

Introduction: CenterPoint Energy Data Breach — Why It Matters CenterPoint Energy Data Breach involves unauthorized access to personal information belonging to a portion of the utility company’s customer base. CenterPoint Energy disclosed the incident in a U.S. Securities and Exchange Commission (SEC) Form 8-K filing on September 14, 2026. The Houston-based energy company said it learned about an online post from a third party claiming to possess a dataset containing customer information. CenterPoint subsequently activated its cybersecurity incident response procedures and began investigating the reported exposure. According to the company filing, an unauthorized party accessed personal information through an internet-facing…

Read More

Introduction: BambooToken Malware — Why It Matters BambooToken Malware is an emerging multi-platform malware campaign that uses the lightweight Message Queuing Telemetry Transport (MQTT) protocol to communicate with compromised Windows and Linux systems. Researchers at Lumen Technologies’ Black Lotus Labs have linked the activity to attacks involving organizations across Asia and South America. The malware has reportedly been active since at least February 2023, with related activity detected as recently as July 2026. Researchers discovered samples on VirusTotal in early 2026, while the initial method used to gain access to targeted systems remains undetermined. The campaign stands out because it…

Read More

Introduction: WordPress Plugin Attacks — Why It Matters WordPress Plugin Attacks are drawing attention after threat actors reportedly exploited a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin to upload malicious PHP files and establish web shells. Wordfence said it has blocked more than 100,000 exploit attempts targeting the flaw since June 2026. The vulnerability, tracked as CVE-2026-27540 and rated CVSS 9.8, affects WooCommerce Wholesale Lead Capture versions up to and including 2.0.3.1. The development comes alongside disclosures of two other critical vulnerabilities in The Events Calendar, a WordPress plugin installed on more than 600,000 websites. Together, the incidents…

Read More

Introduction: Apple Security Update — Why It Matters Apple Security Update addresses 273 unique vulnerabilities across Apple’s major device and software platforms. The coordinated security rollout was released on September 14, 2026, covering iPhone, iPad, Mac, Apple Watch, Apple TV, Vision Pro, Safari, and Xcode. The update includes fixes for serious security weaknesses involving arbitrary code execution, privilege escalation, memory corruption, authentication, privacy controls, and web-content processing. Apple users and enterprise administrators should review the applicable updates and deploy them as soon as operationally possible. What Is Apple’s Security Update? Apple’s September 2026 security rollout spans multiple operating systems and…

Read More

Introduction: New Phishing Attacks — Why They Matter New Phishing Attacks are reportedly abusing trusted email infrastructure and URL-cloaking techniques to make malicious messages appear legitimate. Instead of relying on obviously suspicious sender addresses or attachments, campaigns are using familiar invoices, renewal notices, payment reminders, and banking alerts to direct recipients toward deceptive websites. The approach can move the malicious activity into the click path. A message may pass common email authentication checks, contain no attachment, and still redirect a victim through multiple stages before reaching a fraudulent destination. Virus Bulletin reported examples of this technique during its Q3 2026…

Read More