Author: Debolina Barik
Debolina Barik is a cybersecurity journalist at CyberNexora News, covering data breaches, ransomware attacks, malware threats, phishing scams, and emerging cybersecurity trends across India and globally. She focuses on delivering accurate, timely, and actionable security news for businesses and individuals.
Introduction: Bucket Hijacking Attack — Why It Matters A newly disclosed cloud attack technique known as Bucket Hijacking Attack has revealed a serious weakness in how several leading cloud providers route data to storage buckets. Security researchers demonstrated that attackers could silently redirect active cloud data streams—including audit logs, telemetry, backups, and replicated data—to storage buckets under their own control without interrupting the affected cloud services. The technique affects cloud environments that rely on globally unique bucket names, including Amazon Web Services (AWS), Google Cloud, and Microsoft Azure. Rather than exploiting software vulnerabilities, the attack abuses cloud storage naming behavior…
Introduction: GPT-5.6 Sol — Why It Matters OpenAI has introduced GPT-5.6 Sol, its newest flagship artificial intelligence model, through a limited preview available only to a select group of trusted organizations. The preview also includes two additional models—Terra and Luna—and forms part of an ongoing engagement with the U.S. government before a broader public release. Unlike previous launches that focused primarily on performance improvements, GPT-5.6 Sol places significant emphasis on cybersecurity. The model incorporates OpenAI’s most advanced safeguards against malicious use, including stronger protections against jailbreak attempts, offensive cyber requests, and misuse for harmful activities. At the same time, it…
Introduction: Claude Mythos 5 Redeployment — Why It Matters Claude Mythos 5 Redeployment marks a significant milestone in the use of advanced artificial intelligence for national cybersecurity. After a government-led review that began on June 12, 2026, Anthropic has officially confirmed that its most capable cybersecurity-focused AI model will once again be available to selected U.S. organizations responsible for protecting critical infrastructure. The announcement comes just over two weeks after access to the model was suspended for Project Glasswing partners while U.S. authorities evaluated the potential benefits and risks associated with deploying an AI system capable of autonomously discovering and…
TinyRCT Backdoor — Why It Matters A Chinese-speaking advanced persistent threat (APT) group has reportedly deployed a newly identified malware family known as TinyRCT Backdoor in cyber espionage operations targeting government agencies and critical infrastructure organizations across Southeast Asia. According to researchers, the campaign has been attributed to the threat actor CL-STA-1062, which shares operational similarities with the previously tracked group UAT-7237. The campaign demonstrates how sophisticated espionage actors continue to refine their toolsets by combining custom malware, stealthy persistence techniques, and legitimate administrative utilities. Researchers observed compromises affecting at least ten organizations between October and December 2025, highlighting continued…
Introduction: Pedit COW Exploit — Why It Matters A newly disclosed Linux kernel vulnerability, Pedit COW Exploit, is drawing significant attention across the cybersecurity community after researchers demonstrated that it can allow a local, unprivileged user to obtain full root access on affected systems. Tracked as CVE-2026-46331, the flaw resides in the Linux kernel’s traffic-control subsystem and has already been accompanied by a publicly available proof-of-concept (PoC), dramatically increasing the urgency for organizations to patch vulnerable systems. Unlike many privilege escalation vulnerabilities, Pedit COW Exploit does not modify executable files stored on disk. Instead, attackers manipulate cached copies of privileged…
Introduction: Miasma Malware npm Packages — Why It Matters The Miasma Malware npm Packages campaign has emerged as a sophisticated software supply chain attack targeting developers through malicious npm packages associated with the LeoPlatform and RStreams ecosystems. Instead of relying on traditional installation scripts, the attackers abuse the binding.gyp build configuration file to trigger hidden code execution through node-gyp, allowing the malware to bypass many automated security checks. The campaign demonstrates how threat actors continue evolving their techniques to compromise developer environments silently. Once executed, the malware steals credentials from numerous development platforms and cloud services, including GitHub, npm, PyPI,…
Windows 10 ESU: Why Microsoft’s Extension Matters Microsoft has officially announced that Windows 10 ESU will continue providing Extended Security Updates (ESU) for eligible consumer devices until October 12, 2027. The move extends Windows 10’s security coverage by an additional year beyond the previously announced October 2026 deadline, giving millions of users extra time to transition to Windows 11. The extension is particularly important because Windows 10 officially reached its end of support on October 14, 2025. Since then, devices running the operating system have relied on the Extended Security Updates program to continue receiving critical security patches. While Microsoft…
Introduction: AWS AiTM Phishing Kit — Why It Matters A sophisticated phishing campaign targeting AWS users has revealed how attackers continue to evolve beyond traditional credential theft. The newly identified AWS AiTM Phishing Kit enables threat actors to steal AWS console credentials and multi-factor authentication (MFA) codes in real time, allowing them to hijack authenticated sessions before security tokens expire. According to Datadog Security Labs, the campaign was active between June 19 and June 23, 2026, and specifically targeted a small number of high-value AWS users, primarily software engineers and engineering leaders in the United States. Instead of simply collecting…
Introduction: Why the Mistic Backdoor Matters A newly discovered stealth malware known as the Mistic Backdoor has emerged as a significant cybersecurity concern after researchers linked it to the KongTuke initial access broker (IAB). Active since April 2026, the malware has reportedly been deployed through malicious ClickFix campaigns alongside ModeloRAT, targeting organizations across multiple industries. Unlike traditional malware, the Mistic Backdoor is designed to remain hidden by executing malicious payloads entirely in memory, making detection significantly more difficult for conventional security tools. Researchers believe the malware is primarily used to establish long-term access before selling compromised networks to ransomware operators,…
Introduction: Lantronix EDS5000 Flaw — Why It Matters The Lantronix EDS5000 Flaw has become an urgent cybersecurity concern after the U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that attackers are actively exploiting the vulnerability in real-world attacks. The agency has added CVE-2025-67038 to its Known Exploited Vulnerabilities (KEV) Catalog, highlighting the immediate risk to organizations using affected Lantronix EDS5000 Series devices. The Lantronix EDS5000 Flaw is a critical command injection vulnerability with a CVSS score of 9.8. Successful exploitation allows attackers to execute arbitrary commands with root privileges through the device’s HTTP Remote Procedure Call (RPC) authentication process. Because…