Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

AI Infrastructure Needs Automatic Containment as Attacks Accelerate Beyond Human Response

13 September 2026  |  dark6  |  AI

AI-connected environments can let autonomous attacks progress faster than analyst-led response processes can contain them. Security leaders should redesign controls around isolation, short-lived identities, behavioral sequences and tested...

>> read more

Crafted PNGs and RTSP Playlists Expose VLC Users to Memory Corruption and Data Leaks

13 September 2026  |  dark6  |  Vulnerability

Two VLC Media Player flaws can trigger heap corruption through a malicious PNG or leak process memory through a hostile RTSP server. Versions 3.0.0 through 3.0.23 are affected,...

>> read more

Plesk Backup Restore Race Opens a Path From Customer Access to Linux Root

13 September 2026  |  dark6  |  Vulnerability

A race condition in Plesk Obsidian’s Backup Manager can let a low-privileged hosting customer cross tenant boundaries and ultimately obtain root access on Linux servers. Administrators should install...

>> read more

Cloud and SaaS Resilience Starts With Identity, Dependency Mapping and Tested Recovery

13 September 2026  |  dark6  |  Privacy

Cloud and SaaS adoption has replaced a clear network perimeter with overlapping identity and supplier dependencies. Organizations can limit cascading failures by mapping concentration risk, prioritizing exposed systems,...

>> read more

Russia-Aligned Group Tests Prompt Injection to Blind AI Malware Scanners

12 September 2026  |  dark6  |  AI

A Russia-aligned campaign used a malicious script comment designed to trigger an AI model’s safety refusal and interrupt malware analysis. The GuardBreaker technique, found in a MATCHBOIL delivery...

>> read more

Mantax Otax Android Ransomware Adds Screen Spying, OTP Theft and Covert Photos

12 September 2026  |  dark6  |  Ransomware

New Android malware called Mantax Otax combines file encryption with surveillance, credential theft, screen recording and covert camera access. The campaign relies on sideloaded APKs and appears focused...

>> read more

Critical CSF Flaw Exposes cPanel Servers to Unauthenticated Command Execution

12 September 2026  |  dark6  |  Vulnerability

A critical flaw in ConfigServer Security & Firewall can let remote attackers execute commands through its optional MESSENGER service without logging in. Administrators using CSF 14.00 through 16.29...

>> read more

CISA Flags CVSS 10 GitLab File-Read Flaw Under Active Attack

12 September 2026  |  dark6  |  Vulnerability

CISA says attackers are exploiting a critical GitLab path-traversal vulnerability that can expose arbitrary server files without authentication. Organizations should patch immediately, review access logs, and treat exposed...

>> read more