Cyber Accord
  • Home
  • Services
    • Security Testing
    • CLOUD SECURITY
    • GAP ASSESSMENTS
    • Compliance Readiness
    • Advisory
    • Questionnaires
  • About us
  • Contact
  • Blogs
Select Page
Storm-3168 Deletes Azure Resources in 7-Minute Destructive Cloud Attack

Storm-3168 Deletes Azure Resources in 7-Minute Destructive Cloud Attack

Cyber Security

Storm-3168 used compromised cloud identities to carry out a destructive attack against an Azure environment in minutes. The operation shows how a stolen application credential can give an intruder broad control over hosted data, services, and recovery protections. It...
Python MaaS Infostealer Builder Steals Passwords, Credit Cards and Cookies From 17 Browsers

Python MaaS Infostealer Builder Steals Passwords, Credit Cards and Cookies From 17 Browsers

Cyber Security

A Python-based malware builder can turn a single stealer into Windows programs for different operators. The tool packages a payload designed to take saved passwords, payment card details and browser cookies, then send them to an attacker-controlled webhook set by its...
Citrix NetScaler 0-Day RCE Vulnerabilities Actively Exploited in Attacks

Citrix NetScaler 0-Day RCE Vulnerabilities Actively Exploited in Attacks

Cyber Security

Citrix NetScaler administrators are confronting reports of two undisclosed remote code execution vulnerabilities allegedly exploited in real-world attacks. watchTowr said the flaws are unpatched zero-days, were identified during forensic investigations, and that...
OpenAI’s AI Agents Tried Hacking 4 Websites Without Being Prompted

OpenAI’s AI Agents Tried Hacking 4 Websites Without Being Prompted

Cyber Security

OpenAI’s autonomous AI agents attempted to hack four government, university, and public-data systems while carrying out routine information-gathering tasks, according to researchers and government officials. The agents were not instructed to conduct cyberattacks; when...
Salesforce Indirect Prompt Injection Vulnerability Enables 0-click Data Exfiltration

Salesforce Indirect Prompt Injection Vulnerability Enables 0-click Data Exfiltration

Cyber Security

Zenity Labs disclosed a now-patched Salesforce Agentforce vulnerability, dubbed SalesBleed, that could have allowed attackers to steal sensitive CRM data without logging in, accessing a target Salesforce tenant, or requiring victim interaction. The attack relied on...
« Older Entries
Next Entries »

Recent Posts

  • Vercel Confirms KVM Zero-Day VM Escape, Awards Researcher $50,000
  • Critical GitLab AI Gateway Vulnerability Enables Remote Code Execution Attacks
  • Kiteworks Patches 126 Vulnerabilities in Massive Security Update
  • Critical MikroTik RouterOS Flaw Lets Unauthenticated Attackers Execute Code as Root
  • AI Agent Finds Linux Kernel Bug That Turns a Tiny Memory Write Into Root Access

Categories

  • Cyber Security
CyberAccord | All Rights Reserved | 2025