Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Grok AI Chatbot Tricked Into Leaking Private Chats Through Encrypted Prompt Injection

22 August 2026  |  dark6  |  AI

Security researchers at Adversa AI found a zero-click flaw in xAI's Grok that hides malicious instructions inside encrypted text to steal names, locations, and chat history. The attack...

>> read more

Unauthenticated File Upload Flaw in Elementor Pro Opens Door to Remote Code Execution

22 August 2026  |  dark6  |  Vulnerability

A critical vulnerability tracked as CVE-2026-32475 lets unauthenticated attackers upload malicious PHP files through the Elementor Pro Forms widget, potentially leading to full remote code execution on affected...

>> read more

Chinese Threat Group Automates Web Server Attacks at Scale Using AI Agents, Cisco Talos Warns

22 August 2026  |  dark6  |  Cybercrime

Cisco Talos has tracked a Chinese-speaking group known as UAT-10147 using AI-generated scripts and playbooks to automate reconnaissance and exploitation across roughly 170,000 URLs. The campaign hit government,...

>> read more

New Espionage Campaign ‘SilkParasite’ Hits Central Asian Governments With Five Undocumented Malware Tools

22 August 2026  |  dark6  |  Malware

Researchers have uncovered SilkParasite, a cyberespionage operation using spear-phishing and five previously unseen malware families to target government bodies across Central Asia. The campaign favors cloud-based command channels...

>> read more

Microsoft Confirms Entra ID Zero-Day Was Exploited Before the Fix Went Live

21 August 2026  |  dark6  |  Vulnerability

Microsoft has disclosed CVE-2026-69836, a maximum-severity deserialization flaw in Entra ID that attackers exploited in the wild before the company silently patched it server-side. There is no customer...

>> read more

How One Phishing Email Let Attackers Bypass MFA and Redirect a Company’s Vendor Payments

21 August 2026  |  dark6  |  Phishing

An HR-themed phishing lure led a finance employee to a fake Microsoft 365 login that stole an authenticated session cookie, letting attackers bypass MFA entirely. Over the following...

>> read more

Researchers Show How a Signed Windows Defender Driver Could Be Turned Against Security Tools

21 August 2026  |  dark6  |  Vulnerability

Check Point researchers reverse-engineered Microsoft Defender's BTR.sys driver and found that its undocumented transaction protocol could be reproduced to disable antivirus and EDR products from the Windows kernel...

>> read more

Hijacked Rust Crates With 244 Million Downloads Turned Into Malware Delivery Pipeline

21 August 2026  |  dark6  |  Malware

A typosquatted Rust package quietly hijacked two popular crates, arrayref and append-only-vec, to run an infostealer during ordinary builds. The attack hid inside an automatically-executed build script, leaving...

>> read more