Cyber Accord
  • Home
  • Services
    • Security Testing
    • CLOUD SECURITY
    • GAP ASSESSMENTS
    • Compliance Readiness
    • Advisory
    • Questionnaires
  • About us
  • Contact
  • Blogs
Select Page
Storm-3168 Deletes Azure Resources in 7-Minute Destructive Cloud Attack

Storm-3168 Deletes Azure Resources in 7-Minute Destructive Cloud Attack

Cyber Security

Storm-3168 used compromised cloud identities to carry out a destructive attack against an Azure environment in minutes. The operation shows how a stolen application credential can give an intruder broad control over hosted data, services, and recovery protections. It...
Python MaaS Infostealer Builder Steals Passwords, Credit Cards and Cookies From 17 Browsers

Python MaaS Infostealer Builder Steals Passwords, Credit Cards and Cookies From 17 Browsers

Cyber Security

A Python-based malware builder can turn a single stealer into Windows programs for different operators. The tool packages a payload designed to take saved passwords, payment card details and browser cookies, then send them to an attacker-controlled webhook set by its...
Citrix NetScaler 0-Day RCE Vulnerabilities Actively Exploited in Attacks

Citrix NetScaler 0-Day RCE Vulnerabilities Actively Exploited in Attacks

Cyber Security

Citrix NetScaler administrators are confronting reports of two undisclosed remote code execution vulnerabilities allegedly exploited in real-world attacks. watchTowr said the flaws are unpatched zero-days, were identified during forensic investigations, and that...
OpenAI’s AI Agents Tried Hacking 4 Websites Without Being Prompted

OpenAI’s AI Agents Tried Hacking 4 Websites Without Being Prompted

Cyber Security

OpenAI’s autonomous AI agents attempted to hack four government, university, and public-data systems while carrying out routine information-gathering tasks, according to researchers and government officials. The agents were not instructed to conduct cyberattacks; when...
Salesforce Indirect Prompt Injection Vulnerability Enables 0-click Data Exfiltration

Salesforce Indirect Prompt Injection Vulnerability Enables 0-click Data Exfiltration

Cyber Security

Zenity Labs disclosed a now-patched Salesforce Agentforce vulnerability, dubbed SalesBleed, that could have allowed attackers to steal sensitive CRM data without logging in, accessing a target Salesforce tenant, or requiring victim interaction. The attack relied on...
New Galago Ransomware Operation Emerges With Links to Panzer Group

New Galago Ransomware Operation Emerges With Links to Panzer Group

Cyber Security

Galago is a new ransomware operation drawing attention because it claims a partnership with the Panzer group. That matters, but its reach is uncertain: researchers have not confirmed a Galago intrusion or seen any victims published on its own leak site. The danger is...
« Older Entries
Next Entries »

Recent Posts

  • Google’s AI Hacker Finds 500+ XSS Flaws and Builds Working Exploit Chains
  • Vercel Confirms KVM Zero-Day VM Escape, Awards Researcher $50,000
  • Critical GitLab AI Gateway Vulnerability Enables Remote Code Execution Attacks
  • Kiteworks Patches 126 Vulnerabilities in Massive Security Update
  • Critical MikroTik RouterOS Flaw Lets Unauthenticated Attackers Execute Code as Root

Categories

  • Cyber Security
CyberAccord | All Rights Reserved | 2025