Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Critical Ruby on Rails Flaw Lets Attackers Steal Server Secrets Through Image Uploads

30 July 2026  |  dark6  |  Vulnerability

A critical vulnerability in Rails' Active Storage component, tracked as CVE-2026-66066, allows unauthenticated attackers to read arbitrary files — and potentially achieve remote code execution — on applications...

>> read more

Researchers Show How a Hidden Prompt Can Turn Word Copilot Into a Self-Spreading AI Worm

30 July 2026  |  dark6  |  AI

A newly disclosed weakness in Microsoft Copilot for Word shows how invisible text buried in a document can hijack the AI assistant, quietly alter content, and copy itself...

>> read more

Fake CAPTCHA Pages Are Now Tricking Mac Users Into Installing Password-Stealing Malware

30 July 2026  |  dark6  |  Malware

Kaspersky has documented a ClickFix campaign now targeting macOS users, luring them into pasting a Terminal command that quietly installs Atomic Stealer (AMOS). The malware harvests browser passwords,...

>> read more

FBI Warns Russian State Hackers Are Tricking Signal Users Into Handing Over Backup Keys

30 July 2026  |  dark6  |  Cybercrime

The FBI says Russian intelligence-linked hacking clusters are impersonating Signal support to trick high-value targets — officials, military personnel, journalists, and Ukrainian leadership — into revealing their backup...

>> read more

Foxit’s Own Update Service Can Be Turned Into a SYSTEM-Level Backdoor on Windows

27 July 2026  |  dark6  |  Vulnerability

A privilege-escalation flaw in Foxit PDF Reader's updater, tracked as CVE-2026-57239, lets an attacker who already has a foothold on a Windows machine ride the update service all...

>> read more

Five-Year-Old Bugs in a JSON Parser Open a Code Execution Hole in Self-Managed GitLab

27 July 2026  |  dark6  |  Vulnerability

Researchers chained two long-dormant memory-safety bugs in Ruby's Oj JSON parser to achieve remote code execution on self-managed GitLab instances, using nothing more than an ordinary commit and...

>> read more

A Booby-Trapped Git Repository Can Quietly Leak Files Through Claude Code, Researchers Show

27 July 2026  |  dark6  |  AI

Security firm Tego AI says an ordinary-looking repository file can trick Anthropic's Claude Code into reading a file from outside the project and silently including it in its...

>> read more

JetBrains Patches a Wave of Critical Flaws Across IntelliJ IDEA and TeamCity

27 July 2026  |  dark6  |  Vulnerability

JetBrains has released fixes for a critical remote-code-execution flaw in IntelliJ IDEA and four high-severity vulnerabilities in TeamCity, including a critical RCE reachable through malicious Git repository configuration....

>> read more