Author: Debolina Barik
Debolina Barik is a cybersecurity journalist at CyberNexora News, covering data breaches, ransomware attacks, malware threats, phishing scams, and emerging cybersecurity trends across India and globally. She focuses on delivering accurate, timely, and actionable security news for businesses and individuals.
Introduction: SD Pay Scam — Why It Matters SD Pay Scam has emerged as a major alleged investment fraud case in Gujarat after Amreli Police reportedly traced more than ₹635 crore in transactions linked to SD Pay, Apna Pay and several alleged shell companies. Police have arrested six accused and formed a Special Investigation Team (SIT) led by IPS officer Jayveer Gadhvi. The investigation reportedly covers investors across Ahmedabad, Gandhinagar, Mehsana, Surat and other parts of Gujarat. The alleged operation attracted users with daily cashback of 0.15% to 0.30%, referral incentives and digital payment features. Police reportedly recovered information relating…
Introduction: Bimbo Data Breach — Why It Matters Bimbo Data Breach has emerged as a significant enterprise security incident after Bimbo Bakeries USA reportedly discovered that files containing employee information had been stolen through a third-party vendor using Oracle E-Business Suite (EBS). According to the information provided, Bimbo Bakeries identified the incident on December 6, 2025, but confirmed the exposed information on August 19, 2026. The company subsequently filed a breach notification with the California Attorney General’s Office on September 4, 2026. The exposed file reportedly contained names and Social Security numbers. The Bimbo Data Breach also highlights the risks…
Introduction: Women Data Leak — Why It Matters Women Data Leak 2026 has raised serious privacy and cybersecurity concerns after reports claimed that personal information belonging to around 4 crore women across India is being offered for sale on the dark web. The reported dataset allegedly contains names, phone numbers, addresses and email IDs, creating potential risks of fraud, harassment and stalking. According to the available reports, 3,366 women from Gujarat were identified in the Women Data Leak dataset. Cybersecurity experts reportedly examined samples and found the information to be genuine and active, although the full origin and scope of…
Introduction: Magento StyleSmuggler 0-Day — Why It Matters Magento StyleSmuggler 0-Day is an actively exploited critical vulnerability affecting Magento Open Source and Adobe Commerce. Security firm Sansec disclosed the zero-day on September 5, 2026, after observing exploitation beginning on September 4. The flaw reportedly enables unauthenticated attackers to execute arbitrary PHP code remotely. The vulnerability is particularly concerning because Sansec reproduced the attack against clean Magento Open Source 2.4.7, 2.4.8 and 2.4.9 installations. One reported victim was running Magento 2.4.6-p15 with July and August security patches installed, showing that simply being current on available patches may not prevent exploitation. What…
Introduction: CrowdStrike SafeMind — Why It Matters CrowdStrike SafeMind marks CrowdStrike’s move toward purpose-built agentic AI that can actively test, detect and remediate cyber threats. The company unveiled SafeMind at Fal.Con 2026 in Las Vegas on September 1, introducing a system that combines offensive and defensive AI models in a continuous security feedback loop. Unlike conventional AI security tools that primarily analyze alerts or assist human analysts, SafeMind is designed to let AI-driven defenders challenge their own protections. CrowdStrike says the system brings together Red Tempest, an offensive model, and Blue Solano, a defensive model, with specialized security harnesses. What…
Introduction: Berlin Ransomware Attack — Why It Matters The Berlin Ransomware Attack has escalated into a major extortion incident after the Rhysida ransomware group claimed it stole 5.79 TB of data from Berlin’s state administration network. The group listed Berlin on its dark web leak site on August 28 and demanded 30 Bitcoin, reportedly worth around €2 million. The Berlin Ransomware Attack was traced to suspicious data outflows between August 7 and 12, while two affected Senate departments were isolated from the state network on August 14. Officials have refused to pay the ransom, and German law enforcement and security…
Introduction: ASUS Control Center Vulnerability — Why It Matters The ASUS Control Center Vulnerability tracked as CVE-2026-75754 is a critical security flaw affecting ASUS Control Center Enterprise. The vulnerability carries a maximum CVSS 4.0 score of 10.0 and affects versions up to and including 4.0.0.2. The flaw reportedly allows an unauthenticated remote attacker to obtain root-level access without user interaction. Because ASUS Control Center can manage servers, PCs and workstations, successful exploitation could extend beyond the management server itself. What Is ASUS Control Center Enterprise? ASUS Control Center Enterprise is an enterprise management platform designed to provide centralized monitoring and…
Microsoft Project Zenith: Why It Matters Microsoft has introduced Microsoft Project Zenith, a developer-focused Windows 11 experience designed for high-memory PCs capable of running large AI models locally. The initiative targets systems with at least 64 GB of unified memory and more than 250 GB/s of memory bandwidth. The goal is to give developers a ready-to-code environment where models with more than 30 billion parameters can run directly on the PC instead of relying entirely on cloud services. This could reduce dependence on metered cloud tokens while providing a more self-contained environment for AI experimentation and development. Microsoft announced Project…
Introduction: NodeStealer Malware — Why It Matters NodeStealer Malware has evolved from an information stealer into spyware-capable malware, according to Netskope Threat Labs. Researchers identified the upgraded Python-based variant in August 2026, adding keylogging, clipboard monitoring and screenshot capture. The malware can observe what victims type, copy and display on screen. Activity affected Asia and North America, with financial services among leading sectors. What is NodeStealer Malware? NodeStealer Malware is a Python-based information-stealing malware family tracked by Netskope since 2023. Earlier versions focused on browser data and Facebook credentials before expanding into Ads Manager and payment-related information. What Caused the…
Introduction: Invisible Unicode Phishing — Why It Matters Invisible Unicode Phishing has emerged as a major email-security concern after Microsoft researchers identified a high-volume phishing campaign using invisible Unicode tag characters to evade security detection. The campaign used finance-themed emails promoting loans, funding and credit, with activity reaching more than 2.3 million messages in a single day. The technique, known as ASCII smuggling, hides characters inside otherwise normal-looking words. Microsoft observed approximately 21,000 detections on February 8, 2026, followed by more than 1.3 million the next day. The activity remained elevated for roughly three months. What is Microsoft Security? Microsoft…