Author: Debolina Barik

Debolina Barik is a cybersecurity journalist at CyberNexora News, covering data breaches, ransomware attacks, malware threats, phishing scams, and emerging cybersecurity trends across India and globally. She focuses on delivering accurate, timely, and actionable security news for businesses and individuals.

Introduction: FatFs Vulnerabilities — Why It Matters Security researchers have disclosed a series of newly identified flaws collectively referred to as FatFs Vulnerabilities 2026, highlighting potential security risks affecting millions of embedded and Internet of Things (IoT) devices worldwide. According to security researchers at runZero, seven vulnerabilities tracked as CVE-2026-6682 through CVE-2026-6688 impact FatFs, one of the world’s most widely adopted FAT/exFAT filesystem drivers used in embedded systems. The vulnerabilities carry CVSS scores ranging from 4.6 (Medium) to 7.6 (High). While none are rated Critical, researchers warn that successful exploitation may enable remote code execution, memory corruption, denial-of-service attacks, data…

Read More

Introduction: Microsoft KB5095189 OOBE Update — Why It Matters Microsoft has officially released the Microsoft KB5095189 OOBE Update, a cumulative update designed to improve the Out-of-Box Experience (OOBE) for Windows 11 versions 24H2 and 25H2. Released on June 23, 2026, the update focuses exclusively on enhancing the initial device setup process rather than introducing new features or security fixes. The Microsoft KB5095189 OOBE Update aims to provide a smoother first-time setup by improving region selection, Microsoft account configuration, privacy settings, and overall provisioning reliability. Unlike traditional Windows updates, KB5095189 is only delivered during the OOBE phase when a device is…

Read More

Introduction: Aadhaar PAN Dark Web Leak — Why It Matters The Aadhaar PAN Dark Web Leak has renewed concerns about the growing trade of stolen identity documents on cybercriminal marketplaces. According to cybersecurity researchers, stolen Aadhaar and PAN card details continue to circulate across dark web forums, increasing the likelihood of identity theft, financial fraud, and targeted phishing attacks. The Aadhaar PAN Dark Web Leak does not point to a newly confirmed breach of government databases. Instead, researchers warn that identity documents obtained through previous data breaches, phishing campaigns, malware infections, fraudulent KYC collections, and other unauthorized sources remain actively…

Read More

Introduction: Kairos Data-Theft Extortion — Why It Matters The Kairos Data-Theft Extortion case has drawn significant attention after researchers revealed that a U.S. government entity reportedly paid $1 million (approximately 9.44 BTC) to prevent stolen data from being leaked. Unlike traditional ransomware campaigns that encrypt files, investigators found no evidence of encryption, suggesting the attackers relied solely on stealing sensitive information and threatening to publish it unless a ransom was paid. According to research based on leaked negotiation chats and blockchain analysis, the attack allegedly resulted in the theft of more than 2 terabytes of government data, including roughly 1.6…

Read More

Introduction: Bad Epoll Vulnerability — Why It Matters A newly disclosed Linux kernel vulnerability, dubbed Bad Epoll Vulnerability, has raised significant concerns across the cybersecurity community. Tracked as CVE-2026-46242, the flaw allows an unprivileged local attacker to escalate privileges and obtain root access on affected Linux servers, desktops, and Android devices. Security researchers report that the vulnerability originates from a race condition combined with a use-after-free (UAF) bug within Linux’s epoll subsystem. Because epoll is deeply integrated into the Linux kernel, the vulnerable functionality cannot simply be disabled, leaving millions of systems dependent on timely security updates. The discovery is…

Read More

Introduction: Ransomware-as-a-Service — Why It Matters Ransomware-as-a-Service has transformed ransomware from a technically demanding cybercrime into a profitable criminal business model that almost anyone with malicious intent can access. Instead of developing sophisticated malware from scratch, attackers can now subscribe to or lease ready-made ransomware platforms, dramatically lowering the barrier to launching devastating cyberattacks. The growing popularity of Ransomware-as-a-Service has fueled some of the world’s most disruptive ransomware campaigns. Security researchers report that modern RaaS operations function much like legitimate software companies, offering subscription plans, affiliate programs, technical support, and even customer service to cybercriminals. This evolution has made ransomware…

Read More

Introduction: North Korea npm Packages — Why It Matters The North Korea npm Packages campaign has exposed yet another sophisticated software supply chain threat targeting the global developer community. Security researchers recently discovered multiple malicious npm packages impersonating legitimate Rollup polyfill libraries in an attempt to compromise software developers and steal valuable credentials. The North Korea npm Packages campaign highlights how trusted open-source repositories are increasingly being abused to compromise software developers worldwide. According to security researchers, the fake packages were carefully crafted to resemble trusted open-source dependencies, making them difficult to identify during routine dependency reviews. Once installed, they…

Read More

Introduction: NetNut Residential Proxy Network — Why It Matters Google has announced a significant disruption of the NetNut Residential Proxy Network, a large-scale infrastructure reportedly built on more than two million compromised home devices worldwide. The operation was carried out by Google’s Threat Intelligence Group (GTIG) with assistance from the FBI, Lumen Technologies, and several cybersecurity partners. The NetNut Residential Proxy Network allegedly transformed everyday internet-connected devices—including smart TVs and streaming boxes—into proxy exit nodes that enabled cybercriminals to disguise their online activity. According to Google, the network supported password-spraying attacks, cyber espionage campaigns, and other malicious operations while hiding…

Read More

Introduction: Why the CISA SimpleHelp Authentication Bypass Vulnerability Matters The CISA SimpleHelp Authentication Bypass Vulnerability has emerged as a critical cybersecurity concern after the U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that the flaw is being actively exploited in real-world attacks. The vulnerability, tracked as CVE-2026-48558, affects SimpleHelp deployments configured to use OpenID Connect (OIDC) authentication and could allow attackers to bypass authentication controls without valid credentials. Following reports of active exploitation, CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog on June 29, 2026, warning that organizations using affected SimpleHelp servers should take immediate action. The…

Read More

Introduction: UPI Fraud — Why It Matters India’s Unified Payments Interface (UPI) has transformed digital payments by enabling instant bank-to-bank transfers with just a smartphone. However, its growing popularity has also made it a prime target for cybercriminals. UPI Fraud continues to rise as scammers employ increasingly sophisticated tactics to trick users into authorizing fraudulent transactions instead of hacking banking systems. Rather than exploiting weaknesses in the technology itself, most fraudsters manipulate users through phishing, fake QR codes, impersonation, fraudulent customer support numbers, and social engineering. According to guidance issued by the National Payments Corporation of India and the Reserve…

Read More