Author: Debolina Barik
Debolina Barik is a cybersecurity journalist at CyberNexora News, covering data breaches, ransomware attacks, malware threats, phishing scams, and emerging cybersecurity trends across India and globally. She focuses on delivering accurate, timely, and actionable security news for businesses and individuals.
Introduction: Why Fake Trading Apps Scam Matters Cybercriminals reportedly stole ₹7,061 crore from Indian investors over the past year through fraudulent investment and trading applications. The Fake Trading Apps Scam highlights how scammers are exploiting people’s interest in stock markets and online investing by creating apps that closely resemble legitimate trading platforms. According to reports, these scams commonly begin through social media advertisements, WhatsApp groups, Telegram channels, or unsolicited investment messages that promise guaranteed profits, exclusive IPO access, or “expert” stock recommendations. Once victims invest, fake profits are displayed to encourage larger deposits before the fraudsters disappear. How Fake Trading…
Introduction: Starbucks Data Breach — Why It Matters Starbucks Data Breach has surfaced online after a threat actor allegedly claimed to possess and sell a database containing 176 million unique user records. The database was reportedly advertised on a well-known cybercrime forum by a user operating under the alias “anes2010.” According to the claims, the dataset was extracted in June 2026 and is being offered for $400, with sample records allegedly provided to support the listing. At the time of writing, Starbucks has not confirmed the alleged breach, and no independent verification has established that the dataset is authentic. Therefore, all…
Introduction: Russian Bulletproof Hosting Case — Why It Matters The Russian Bulletproof Hosting Case highlights a major international cybercrime investigation after U.S. federal prosecutors charged three Russian nationals for allegedly operating hosting infrastructure that enabled ransomware, phishing, malware distribution, and other cybercriminal activities. According to prosecutors, the seven-year investigation links the alleged operation to more than $62 million in losses affecting victims worldwide. The defendants are accused of operating Media Land LLC and ML.Cloud LLC, companies allegedly providing “bulletproof hosting” services designed to resist abuse complaints and law enforcement takedowns. The charges remain allegations, and the defendants are presumed innocent…
Introduction: Passkeys Replacing Passwords — Why It Matters Passkeys Replacing Passwords is one of the biggest shifts in online security in recent years. Instead of relying on passwords that can be stolen, guessed, or reused, passkeys provide a safer way to sign in using biometric authentication such as fingerprints, Face ID, Windows Hello, or a device PIN. Technology companies including Apple, Google, Microsoft, Amazon, PayPal, and GitHub have adopted passkeys as part of their move toward passwordless authentication. According to the FIDO Alliance’s State of Passkeys Report, billions of passkeys are already being used worldwide, showing that passwordless authentication is…
Introduction: Instagram and Facebook Outage — Why It Matters Instagram and Facebook Outage disrupted access to two of the world’s most widely used social media platforms on July 19, 2026, leaving thousands of users unable to access essential services. Reports quickly spread across multiple countries as users experienced login failures, feed refresh errors, messaging problems, and difficulties posting new content. The disruption appeared to affect users globally rather than being limited to a single region. According to outage monitoring platform Downdetector, thousands of complaints were submitted within a short period, indicating a widespread service interruption. Although complaint volumes gradually declined…
Introduction: Hugging Face AI Breach — Why It Matters The Hugging Face AI Breach has become one of the most significant cybersecurity incidents highlighting the growing capabilities of autonomous artificial intelligence in offensive cyber operations. According to Hugging Face, attackers exploited vulnerabilities within its production infrastructure before the intrusion was detected and contained using the company’s own AI-powered forensic analysis platform. The Hugging Face AI Breach is particularly notable because the attack allegedly involved autonomous AI capable of executing multiple attack stages with minimal human intervention. The incident demonstrates how AI is rapidly transforming both cyber defense and cyber offense,…
Introduction: Report Cybercrime in India — Why It Matters Cybercrime continues to rise across India, affecting individuals, businesses, and government organizations through phishing scams, UPI fraud, identity theft, investment scams, ransomware attacks, and social media account compromises. As digital payments and online services become increasingly common, knowing how to Report Cybercrime in India has become an essential part of protecting personal and financial information. The Government of India has strengthened its cybercrime response framework by introducing multiple reporting mechanisms, including the 1930 Cyber Crime Helpline, the National Cyber Crime Reporting Portal, and the recently introduced e-Zero FIR initiative for verified…
Introduction: wp2shell RCE Vulnerability — Why It Matters A newly disclosed wp2shell RCE Vulnerability has emerged as one of the most severe security threats ever discovered in WordPress Core. The critical vulnerability reportedly allows attackers to achieve Remote Code Execution (RCE) on vulnerable websites without authentication, potentially placing more than 500 million WordPress installations at risk. Security researcher Adam Kues of Searchlight Cyber’s Assetnote team discovered the flaw, which combines a REST API batch-route confusion vulnerability with SQL Injection to achieve full server compromise. Because the exploit works against a default WordPress installation without requiring plugins, themes, or user credentials,…
What Is the OWASP Top 10 for Agentic AI — and Why It Matters The OWASP Top 10 for Agentic AI is a security framework, released by OWASP in December 2025, that identifies the ten most critical security risks affecting autonomous AI agent systems. Unlike traditional LLM security guidance, it focuses on AI agents that can plan tasks, use external tools, communicate with other agents, and perform real-world actions with minimal human intervention. The complete framework and supporting documentation are available through the OWASP Agentic AI Project, which explains each risk category and recommended security controls. As organizations rapidly deploy…
Introduction: Prompt Injection Attacks — Why It Matters Artificial intelligence is transforming the modern workplace, with businesses increasingly relying on AI assistants to summarize documents, answer customer queries, generate code, analyze data, and automate routine tasks. However, security researchers are warning that Prompt Injection Attacks have emerged as one of the most dangerous threats facing enterprise AI systems. Unlike traditional cyberattacks that exploit software vulnerabilities, Prompt Injection Attacks manipulate the instructions followed by Large Language Models (LLMs). By embedding hidden commands inside emails, websites, documents, or code repositories, attackers can trick AI assistants into ignoring their original instructions and performing…