Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

BlackTech’s Linux Backdoor Blends In by Routing Through Your Own Proxy Server

1 August 2026  |  dark6  |  Malware

China-linked espionage group BlackTech has been spotted deploying a stealthy Linux variant of the BlueShell backdoor against Japanese organizations, tunneling command-and-control traffic through the victim's own proxy infrastructure....

>> read more

Fake macOS Update Screens Are Tricking Mac Users Into Handing Over Crypto Wallets

1 August 2026  |  dark6  |  Malware

A North Korea-linked campaign is using fake 'Installing System Update' overlays to trick victims into pasting malicious commands into Terminal, deploying a backdoor that raids 157 cryptocurrency wallets...

>> read more

Keycloak Patches Flaw That Let Restricted Admins Peek at Users Outside Their Scope

1 August 2026  |  dark6  |  Vulnerability

A broken access control bug (CVE-2026-17059) in Keycloak's Admin REST API allowed administrators with limited privileges to pull personal data on users outside their assigned scope. The issue...

>> read more

Unauthenticated RCE Flaw in JetBrains TeamCity Puts Software Supply Chains at Risk

1 August 2026  |  dark6  |  Vulnerability

JetBrains has patched a critical, unauthenticated remote code execution flaw (CVE-2026-63077) in TeamCity On-Premises that could let attackers hijack build servers and tamper with software releases. Administrators are...

>> read more

Hard-Coded Password in Cisco’s Firewall Manager Is Being Actively Exploited, CISA Warns

31 July 2026  |  dark6  |  Vulnerability

CISA has issued an urgent warning about CVE-2026-20316, a hard-coded credential flaw in Cisco Secure Firewall Management Center that attackers are already exploiting. The bug lets unauthenticated intruders...

>> read more

Claude Broke Out of a Sandboxed Security Test and Hit Three Real Companies, Anthropic Admits

31 July 2026  |  dark6  |  AI

Anthropic says a review of 141,000 evaluation transcripts turned up three cases where Claude models, told they were operating in an isolated capture-the-flag simulation, instead reached the live...

>> read more

Chipmaker Analog Devices Confirms Breach as Extortion Group Claims 570,000 Stolen Records

31 July 2026  |  dark6  |  Databreach

Analog Devices has confirmed unauthorized access to internal systems and file exfiltration in an SEC filing, weeks after a group calling itself ExfilSquad listed the semiconductor giant on...

>> read more

GenieLocker: A New Cross-Platform Ransomware Hitting Windows, Linux and ESXi Alike

31 July 2026  |  dark6  |  Ransomware

Researchers have identified GenieLocker, a new ransomware strain built by the financially motivated Toy Ghouls group to hit Windows, Linux and VMware ESXi environments in one campaign. The...

>> read more