Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

FBI Investigates Jobs Portal Intrusion as ShinyHunters Claims Sensitive Data Theft

23 September 2026  |  dark6  |  Databreach

The FBI is investigating unauthorized activity involving FBIjobs.gov after a defacement and expansive breach claims attributed to ShinyHunters. Some sample records reportedly matched real people, but the alleged...

>> read more

Actively Exploited F5 BIG-IP OAuth Zero-Day Enables Unauthenticated RCE

23 September 2026  |  dark6  |  Vulnerability

F5 is warning that attackers are exploiting a critical BIG-IP APM zero-day that can provide unauthenticated remote code execution on certain OAuth authorization-server deployments. Organizations should identify exposed...

>> read more

105 Minutes of Stolen Access Turned a Trusted npm Package Into a Multi-Stage Malware Loader

23 September 2026  |  dark6  |  Malware

Attackers hijacked a maintainer account for just 105 minutes to slip a hidden loader into a popular npm package, abusing legitimate publishing infrastructure so the poisoned release carried...

>> read more

Maximum-Severity Flaw in D-Link Routers Lets Attackers Take Over Devices With No Login Required

23 September 2026  |  dark6  |  Vulnerability

A stack-based buffer overflow in D-Link's DIR-822A router, rated a perfect CVSS 10.0, can be triggered remotely with no authentication and no user interaction, and a working public...

>> read more

Suspected Chinese-Speaking Hackers Chain Two WordPress Bugs to Loot a Government Database

23 September 2026  |  dark6  |  Databreach

A likely Chinese-speaking threat actor strung together two WordPress vulnerabilities to breach at least 49 organizations in 29 countries, with one Western government agency losing 18,566 records, including...

>> read more

Check Point Confirms In-the-Wild Attacks on Critical Management Server Zero-Day

23 September 2026  |  dark6  |  Vulnerability

A critical, pre-authentication flaw in Check Point's Management Server software was exploited in the wild weeks before a fix existed, letting attackers upload and run code on systems...

>> read more

Linux KVM/arm64 Flaw Breaks VM Isolation and Exposes Host Memory

23 September 2026  |  dark6  |  Vulnerability

CVE-2026-89775 can leave stale writable mappings available to an ARM64 guest when KVM nested virtualization is enabled, creating a path to host-memory access and VM escape. Operators should...

>> read more

Low-Cost AI Agent Campaign Steals 600,000 Payment Cards From Retailers

23 September 2026  |  dark6  |  Cybercrime

Researchers reconstructed a campaign in which open-source AI agents autonomously scanned and exploited online retailers for an average reported cost of $25.46 per completed scan. The operation allegedly...

>> read more