Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

StyleSmuggler Zero-Day Leaves Every Current Magento and Adobe Commerce Store Exposed to Takeover

14 September 2026  |  dark6  |  Vulnerability

A newly disclosed zero-day dubbed StyleSmuggler lets attackers hijack Magento Open Source and Adobe Commerce stores by smuggling PHP code through routine GraphQL requests and triggering it via...

>> read more

Exploited Zero-Days and Perimeter Flaws Put Patch Triage Under Pressure

14 September 2026  |  dark6  |  Vulnerability

This week’s security picture is dominated by exploited Windows and Chrome zero-days, dangerous flaws in perimeter products and increasingly automated attack operations. Defenders need risk-based patch sequencing, exposure...

>> read more

Fraudulent Government Request Exposes Revolut KYC Records and Transaction Histories

14 September 2026  |  dark6  |  Databreach

Revolut disclosed that a fraudulent request sent from an official government email domain led to the release of highly sensitive customer records. The incident shows why authenticated email...

>> read more

Dell ObjectScale CVSS 10 Flaw Exposes Enterprise Storage to Remote Takeover

14 September 2026  |  dark6  |  Vulnerability

Dell has fixed a maximum-severity ObjectScale vulnerability that could let an unauthenticated remote attacker execute code on exposed storage systems. Organizations should upgrade quickly, reduce management-plane exposure and...

>> read more

AI Infrastructure Needs Automatic Containment as Attacks Accelerate Beyond Human Response

13 September 2026  |  dark6  |  AI

AI-connected environments can let autonomous attacks progress faster than analyst-led response processes can contain them. Security leaders should redesign controls around isolation, short-lived identities, behavioral sequences and tested...

>> read more

Crafted PNGs and RTSP Playlists Expose VLC Users to Memory Corruption and Data Leaks

13 September 2026  |  dark6  |  Vulnerability

Two VLC Media Player flaws can trigger heap corruption through a malicious PNG or leak process memory through a hostile RTSP server. Versions 3.0.0 through 3.0.23 are affected,...

>> read more

Plesk Backup Restore Race Opens a Path From Customer Access to Linux Root

13 September 2026  |  dark6  |  Vulnerability

A race condition in Plesk Obsidian’s Backup Manager can let a low-privileged hosting customer cross tenant boundaries and ultimately obtain root access on Linux servers. Administrators should install...

>> read more

Cloud and SaaS Resilience Starts With Identity, Dependency Mapping and Tested Recovery

13 September 2026  |  dark6  |  Privacy

Cloud and SaaS adoption has replaced a clear network perimeter with overlapping identity and supplier dependencies. Organizations can limit cascading failures by mapping concentration risk, prioritizing exposed systems,...

>> read more