Cyber Accord
  • Home
  • Services
    • Security Testing
    • CLOUD SECURITY
    • GAP ASSESSMENTS
    • Compliance Readiness
    • Advisory
    • Questionnaires
  • About us
  • Contact
  • Our Blogs
Select Page
TCLBANKER Malware Targets Users Through Self-Propagating WhatsApp and Outlook Worm Modules

TCLBANKER Malware Targets Users Through Self-Propagating WhatsApp and Outlook Worm Modules

Cyber Security

A highly sophisticated Brazilian banking trojan named TCLBANKER, tracked under the campaign REF3076, this malware represents a major update to the older Maverick and SORVEPOTEL families. It stands out because it uses a fake, signed Logitech installer to infect systems...
Dirty Frag Linux Vulnerability Let Attackers Gain Root Privileges on most Linux Distributions

Dirty Frag Linux Vulnerability Let Attackers Gain Root Privileges on most Linux Distributions

Cyber Security

Dirty Frag is a newly disclosed, CVE-pending Linux kernel local privilege escalation (LPE) vulnerability that chains two separate page-cache write flaws, the xfrm-ESP Page-Cache Write and the RxRPC Page-Cache Write, to achieve root access on virtually all major Linux...
Massive 2.45B-Request DDoS Attack Used 1.2 Million IPs to Evade Rate Limits

Massive 2.45B-Request DDoS Attack Used 1.2 Million IPs to Evade Rate Limits

Cyber Security

Distributed Denial of Service (DDoS) campaign targeted a large-scale user-generated content platform, unleashing over 2.45 billion malicious requests in just five hours. Rather than relying on brute-force methods, the attackers distributed traffic across 1.2 million...
Ransomware and Data Extortion Groups Intensify Targeting of Aviation and Aerospace Sector

Ransomware and Data Extortion Groups Intensify Targeting of Aviation and Aerospace Sector

Cyber Security

The aviation and aerospace sector has become one of the most actively targeted industries by ransomware operators and data extortion groups in 2025 and 2026. From passenger-processing platforms to satellite-dependent navigation systems, attackers are finding that...
pnpm 11 Turns On Minimum Release Age by Default to Reduce npm Supply Chain Risk

pnpm 11 Turns On Minimum Release Age by Default to Reduce npm Supply Chain Risk

Cyber Security

The npm ecosystem has long been a target for supply chain attacks, where threat actors exploit the open nature of public package registries to push malicious code into developer environments. With pnpm 11, the package manager takes a direct step to address this...
FreeBSD DHCP Client Vulnerability Enables Remote Code Execution as Root

FreeBSD DHCP Client Vulnerability Enables Remote Code Execution as Root

Cyber Security

The FreeBSD Project has released a critical security advisory addressing a severe flaw in its default IPv4 DHCP client. Tracked as CVE-2026-42511, this vulnerability allows a local network attacker to execute arbitrary code as root, granting them complete control over...
Trellix Source Code Breach – Hackers Gain Unauthorized Access to Repository

Trellix Source Code Breach – Hackers Gain Unauthorized Access to Repository

Cyber Security

Cybersecurity giant Trellix has disclosed a significant security incident involving unauthorized access to a portion of its source code repository. The company confirmed the breach in an official statement published on its website, stating it immediately engaged...
Attackers Abuse Google AppSheet, Netlify, and Telegram in Facebook Phishing Campaign

Attackers Abuse Google AppSheet, Netlify, and Telegram in Facebook Phishing Campaign

Cyber Security

A sophisticated cybercriminal operation dubbed “AccountDumpling” has compromised approximately 30,000 Facebook accounts worldwide. Discovered by Guardio Labs, this Vietnamese-linked campaign abuses Google’s AppSheet platform to bypass traditional email security...

Critical Wireshark Vulnerabilities Let Attackers Execute Arbitrary Code Via Malformed Packets

Cyber Security

Wireshark, the world’s most widely used open-source network protocol analyzer, has released a major security update addressing over 40 vulnerabilities, several of which enable arbitrary code execution through malformed packet injection or malicious capture files....
Cursor AI Extension Access Developer Tokens Leads to Full Credential Compromise

Cursor AI Extension Access Developer Tokens Leads to Full Credential Compromise

Cyber Security

A high-severity access-control vulnerability (CVSS 8.2) in Cursor, a widely used AI-powered coding environment. The flaw uncovered by LayerX has allowed any installed extension to access a developer’s API keys and session tokens secretly. This results in total...
« Older Entries
Next Entries »

Recent Posts

  • Malicious RVTools Installer Abuses Sectigo Certificate to Bypass SmartScreen Warnings
  • SBI Warns of Scammers are Sending Fake Messages Claiming Your YONO App Will be Deactivated
  • GitLab Suspends Windows Exploit Researcher Nightmare-Eclipse After GitHub Ban
  • New 7-Zip Vulnerabilities Let Attackers Execute Arbitrary Code and Compromise Systems
  • Hackers Use Browser-Locking CypherLoc Kit to Push Fake Microsoft Support Calls

Categories

  • Cyber Security
CyberAccord | All Rights Reserved | 2025