Author: Debolina Barik
Debolina Barik is a cybersecurity journalist at CyberNexora News, covering data breaches, ransomware attacks, malware threats, phishing scams, and emerging cybersecurity trends across India and globally. She focuses on delivering accurate, timely, and actionable security news for businesses and individuals.
Introduction: HoneyMyte CoolClient Rootkit — Why It Matters HoneyMyte CoolClient Rootkit highlights a significant change in the group’s Windows malware toolkit. The HoneyMyte CoolClient Rootkit reportedly uses a kernel-level rootkit to hide malicious processes, files, registry entries and command-and-control (C2) activity, making routine detection and forensic analysis harder. The activity has targeted organizations in Pakistan, Mongolia, Myanmar and Russia, including government entities. Kaspersky has documented updated CoolClient campaigns and a related HoneyMyte kernel-mode rootkit used to strengthen stealth. What is HoneyMyte? HoneyMyte is a cyber-espionage threat actor associated with Mustang Panda and other tracking names. The HoneyMyte CoolClient Rootkit is…
Introduction: Penetration Testing Cost Dubai — Why It Matters penetration testing cost Dubai varies because businesses do not all need the same security assessment. In 2026, pricing is shaped by testing type, number of assets, system complexity, testing depth, tester expertise and reporting requirements. Market estimates put focused web application testing at about AED 8,000–55,000, while external network testing can range from roughly AED 12,000–75,000. Broader VAPT engagements for mid-sized organizations can reach AED 35,000–90,000, while enterprise and red-team assessments may cost considerably more. These are indicative market ranges, not fixed tariffs. Businesses should compare what each quote includes before…
Introduction: Apple macOS Screen Sharing Flaw — Why It Matters Apple macOS Screen Sharing Flaw is significant because it can undermine authentication in a remote-access service. Under vulnerable conditions, an attacker may authenticate without valid credentials and obtain unauthorized access. The vulnerability carries a CVSS score of 9.8 and affects macOS Screen Sharing. Reported attacks targeted systems where TCP port 5900 was accessible from the internet. Apple has released security updates, but unpatched systems remain at risk. What Caused the Incident? CVE-2026-65400 is an authentication issue in Screen Sharing. Apple said the weakness was addressed by improving state management so…
Introduction: Microsoft August Patch — Why It Matters Microsoft August Patch delivered a major security update on August 11, 2026, addressing around 400 vulnerabilities across Microsoft products. The release includes 42 vulnerabilities rated Critical and several zero-day issues, making the update an important priority for Windows users and organizations. One of the most significant flaws is CVE-2026-68820, which Microsoft identified as actively exploited. Security researchers have linked the vulnerability to attacks in which attackers can use a Windows kernel driver weakness to elevate privileges. The scale of the release means security teams need to do more than simply deploy updates.…
Introduction: Cybersecurity Compliance UAE — Why It Matters Cybersecurity compliance UAE is becoming more structured as national and sector regulators strengthen requirements for data protection, encryption, cyber resilience and assurance. In 2026, the UAE’s National Encryption Policy and National Cyber Security Accreditation Program (NCAP) add important layers to cybersecurity compliance UAE. The rules vary by sector, location, data handled and regulatory relationships. What Is the UAE Cybersecurity Compliance Framework? No single cybersecurity rule applies identically to every organisation. Businesses may need to map federal, emirate-level and sector-specific requirements. The Personal Data Protection Law (PDPL) provides a federal framework for protecting…
Introduction: SAP Commerce Cloud Exploit — Why It Matters SAP Commerce Cloud Exploit activity has reportedly moved from disclosure to exploitation attempts. The vulnerability, CVE-2026-58231, carries a CVSS 10.0 score and can allow an unauthenticated attacker to achieve arbitrary code execution. SAP published the fix on August 11, 2026. Defused Cyber honeypot telemetry reportedly detected exploitation attempts three days later, highlighting how quickly attackers can target critical enterprise flaws after patches become available. What is SAP Commerce Cloud? SAP Commerce Cloud Exploit concerns an enterprise commerce platform supporting digital storefronts, product management, customer experiences, and related business processes. A compromise…
Introduction: Dysphoria Botnet — Why It Matters Dysphoria Botnet is drawing attention after reporting indicated that roughly 296,000 internet-connected devices may have been compromised. The affected ecosystem includes routers, cameras, gateways and embedded Linux equipment used for DDoS. CNCERT and QiAnXin/XLab separately reported that Dysphoria became active in March 2026 and had exceeded 200,000 devices in their analysis. The 296,000 figure should therefore be treated as a reported estimate rather than an independently verified global count. What is the Dysphoria Botnet? Dysphoria is an IoT-focused botnet designed to turn compromised internet-connected systems into remotely controlled nodes. It evolved from the…
Introduction: PDPL Breach Notification — Why It Matters Saudi Arabia’s Personal Data Protection Law (PDPL) sets a defined process for qualifying personal-data breaches. The PDPL breach notification requirement can require a Controller to notify the competent authority within 72 hours of becoming aware of an incident when it may harm personal data, a Data Subject, or their rights and interests. PDPL Breach Notification: The 72-Hour Rule Under Article 24, a Controller must notify the competent authority within no more than 72 hours of becoming aware of a personal-data breach if the incident potentially causes harm to personal data or a…
Introduction: Citrix NetScaler CVE-2026-8452 — Why It Matters Citrix NetScaler CVE-2026-8452 is a high-severity memory overflow vulnerability affecting NetScaler ADC and NetScaler Gateway appliances. Citrix disclosed the flaw on June 30, 2026, assigning it a CVSS 4.0 score of 8.8. The vulnerability can be exploited remotely without authentication when an affected appliance is configured as a Gateway or AAA virtual server. Official advisories describe the impact as unpredictable or erroneous behavior and denial of service. Claims that the flaw provides reliable root-level remote code execution should therefore be treated cautiously unless independently verified. Citrix NetScaler CVE-2026-8452: What Caused the Vulnerability?…
Introduction: HACKERAI Malware — Why It Matters HACKERAI Malware is a newly identified malware framework that reportedly uses GitHub Gists as a command-and-control (C2) channel. According to research attributed to Acronis, it can retrieve attacker instructions and upload stolen information through legitimate GitHub services, helping malicious traffic blend with normal cloud activity. The campaign reportedly targeted telecom, government, defense, energy, and critical infrastructure organizations across South Asia. Victims were approached through fake telecom services, government updates, VPN tools, and software installers. Who Is Behind HACKERAI? Acronis researchers identified HACKERAI alongside related malware families called PATCHCORD and SHEETCORD. The activity has…