Cyber Accord
  • Home
  • Services
    • Security Testing
    • CLOUD SECURITY
    • GAP ASSESSMENTS
    • Compliance Readiness
    • Advisory
    • Questionnaires
  • About us
  • Contact
  • Blogs
Select Page
pnpm 11 Turns On Minimum Release Age by Default to Reduce npm Supply Chain Risk

pnpm 11 Turns On Minimum Release Age by Default to Reduce npm Supply Chain Risk

Cyber Security

The npm ecosystem has long been a target for supply chain attacks, where threat actors exploit the open nature of public package registries to push malicious code into developer environments. With pnpm 11, the package manager takes a direct step to address this...
FreeBSD DHCP Client Vulnerability Enables Remote Code Execution as Root

FreeBSD DHCP Client Vulnerability Enables Remote Code Execution as Root

Cyber Security

The FreeBSD Project has released a critical security advisory addressing a severe flaw in its default IPv4 DHCP client. Tracked as CVE-2026-42511, this vulnerability allows a local network attacker to execute arbitrary code as root, granting them complete control over...
Trellix Source Code Breach – Hackers Gain Unauthorized Access to Repository

Trellix Source Code Breach – Hackers Gain Unauthorized Access to Repository

Cyber Security

Cybersecurity giant Trellix has disclosed a significant security incident involving unauthorized access to a portion of its source code repository. The company confirmed the breach in an official statement published on its website, stating it immediately engaged...
Attackers Abuse Google AppSheet, Netlify, and Telegram in Facebook Phishing Campaign

Attackers Abuse Google AppSheet, Netlify, and Telegram in Facebook Phishing Campaign

Cyber Security

A sophisticated cybercriminal operation dubbed “AccountDumpling” has compromised approximately 30,000 Facebook accounts worldwide. Discovered by Guardio Labs, this Vietnamese-linked campaign abuses Google’s AppSheet platform to bypass traditional email security...

Critical Wireshark Vulnerabilities Let Attackers Execute Arbitrary Code Via Malformed Packets

Cyber Security

Wireshark, the world’s most widely used open-source network protocol analyzer, has released a major security update addressing over 40 vulnerabilities, several of which enable arbitrary code execution through malformed packet injection or malicious capture files....
Cursor AI Extension Access Developer Tokens Leads to Full Credential Compromise

Cursor AI Extension Access Developer Tokens Leads to Full Credential Compromise

Cyber Security

A high-severity access-control vulnerability (CVSS 8.2) in Cursor, a widely used AI-powered coding environment. The flaw uncovered by LayerX has allowed any installed extension to access a developer’s API keys and session tokens secretly. This results in total...
« Older Entries
Next Entries »

Recent Posts

  • Five Progress LoadMaster Vulnerabilities Let Attackers Execute Commands and Gain Root Access
  • PyPI Blocks New File Uploads on 14-Day-Old Releases to Prevent Package Poisoning Attacks
  • AI Tool for Penetration Testers and Bug Hunters to Automate Workflows
  • Foxit Updater Vulnerability Gives Standard Users SYSTEM-Level Control of Windows Devices
  • Microsoft Detects 7.6 Billion Email Phishing Threats as Teams Vishing Attacks Increases 10-Fold

Categories

  • Cyber Security
CyberAccord | All Rights Reserved | 2025