Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Feds Sound Alarm on Active Hacking Campaign Targeting Siemens S7 PLCs Nationwide

20 August 2026  |  dark6  |  Vulnerability

NSA, CISA, the FBI, DOE and EPA have jointly warned that hackers are actively scanning for and probing Siemens S7-series PLCs across U.S. critical infrastructure. The campaign favors...

>> read more

CISA Gives Agencies Until August 21 to Patch Actively Exploited Windows VPN Flaw

20 August 2026  |  dark6  |  Vulnerability

CISA has added a double-free memory corruption bug in Microsoft's Internet Key Exchange service extensions to its Known Exploited Vulnerabilities catalog after confirming active attacks, giving federal agencies...

>> read more

How T-Mobile’s Security Team Cut a Cable to Physically Kick Salt Typhoon Off Its Network

20 August 2026  |  dark6  |  Cybercrime

Newly reported details describe how T-Mobile's security team tracked Chinese state-linked hackers from Salt Typhoon to a compromised router at a third-party data center in 2024 — and...

>> read more

Citrix Patches Critical NetScaler Flaw That Lets Attackers Skip the Login Screen Entirely

20 August 2026  |  dark6  |  Vulnerability

Citrix has patched two new NetScaler ADC and Gateway vulnerabilities, including a 9.3-severity authentication bypass that can let remote attackers slip past login controls on SSL VPN, ICA...

>> read more

Breach at France’s Tax Authority Exposes Financial Records of Nearly 680,000 People

19 August 2026  |  dark6  |  Databreach

France's Directorate General of Public Finances has confirmed that attackers used compromised employee and third-party credentials to access tax records belonging to roughly 678,000 individuals and businesses. No...

>> read more

CISA Sounds Alarm on Medusa Ransomware After 500+ Critical Infrastructure Hits

19 August 2026  |  dark6  |  Ransomware

CISA, the FBI, and HHS have jointly updated their advisory on the Medusa ransomware-as-a-service operation, which has now hit more than 500 critical infrastructure organizations spanning healthcare, education,...

>> read more

Critical MLflow Flaw Lets Attackers Steal Cloud Credentials via Webhook Redirects

19 August 2026  |  dark6  |  Vulnerability

A critical server-side request forgery flaw in MLflow, tracked as CVE-2026-64849 with a 9.3 CVSS score, lets unauthenticated attackers abuse the platform's webhook-testing endpoint to reach cloud metadata...

>> read more

Fake CAPTCHA Prompts on Hacked WordPress Sites Fuel Global StopAndProtect Malware Botnet

19 August 2026  |  dark6  |  Malware

Researchers have uncovered a sprawling campaign, dubbed StopAndProtect, that has hijacked thousands of poorly maintained WordPress sites to serve as rotating command-and-control infrastructure. Fake CAPTCHA prompts trick visitors...

>> read more