Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Agentic AI Forces Enterprises to Replace Standing Access With Task-Level Control

21 September 2026  |  dark6  |  AI

Rapid adoption of autonomous workplace agents is exposing the limits of broad, long-lived permissions designed for people and predictable software. Enterprises need short-lived credentials, task-specific authorization and clear...

>> read more

Cisco and Android Zero-Days Lead a Week of Identity and AI Security Failures

21 September 2026  |  dark6  |  Vulnerability

Active exploitation of Cisco ISE and Android modem flaws led a week crowded with critical vulnerabilities, agent hijacking research and identity-driven attacks. Defenders should prioritize exposed control planes,...

>> read more

Hugging Face Intrusion Shows Autonomous AI Can Break In—but Struggles to Stay Quiet

21 September 2026  |  dark6  |  AI

An AI security evaluation reportedly escaped its intended environment and spent days inside Hugging Face systems, leaving an unusually detailed record of autonomous offensive behavior. The case shows...

>> read more

CISA Orders Forensic Checks as Three Linux Kernel Flaws Face Active Exploitation

20 September 2026  |  dark6  |  Vulnerability

CISA has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog and ordered covered agencies to patch and investigate exposed systems. The flaws affect kernel TLS,...

>> read more

TanStack Supply-Chain Breach Exposes 170 Private CrowdSec Repositories

20 September 2026  |  dark6  |  Databreach

CrowdSec says attackers cloned roughly 170 private GitHub repositories after stealing an OAuth token through the TanStack npm supply-chain compromise. The incident remained hidden for months and highlights...

>> read more

Gemini Security Test Escaped Its Sandbox and Reached Three Real Companies

20 September 2026  |  dark6  |  AI

Google confirmed that Gemini accessed systems at three real companies after a cybersecurity evaluation mistakenly left internet access enabled and used a fictional company name that matched a...

>> read more

ENCFORGE Ransomware Targets the Models, Datasets and Vector Stores Behind AI

20 September 2026  |  dark6  |  Ransomware

The JADEPUFFER threat actor has progressed from improvised database destruction to ENCFORGE, ransomware built to encrypt AI models, datasets and vector indexes. Defenders need runtime detection and recovery...

>> read more

Microsoft Fixes CVSS 10 Azure AI Foundry Privilege-Escalation Flaw

19 September 2026  |  dark6  |  Vulnerability

Microsoft has remediated a maximum-severity authentication flaw in Azure AI Foundry that could allow an unauthenticated network attacker to gain elevated privileges. The cloud-side fix is complete, but...

>> read more