Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Public Exploit Code Raises Urgency Around Critical Atlassian File-Read Flaw

8 October 2026  |  dark6  |  Vulnerability

A proof-of-concept exploit is now public for CVE-2026-21589, a critical, unauthenticated file-read flaw affecting Jira, Confluence, Bitbucket, and other self-managed Atlassian Data Center products. In certain Crowd-connected setups...

>> read more

Fake Cloudflare Verification Pages Used to Push LUNEXSTEALER Malware on 100+ Hacked Sites

8 October 2026  |  dark6  |  Malware

Ukraine's CERT-UA is tracking a campaign, dubbed UAC-0277, that has compromised more than 100 legitimate websites to show visitors a convincing but fake Cloudflare verification screen. Clicking through...

>> read more

Breach at Discord Bot Provider Double Counter Exposes Data on Millions of Users

8 October 2026  |  dark6  |  Databreach

An intrusion into Double Counter, a third-party company behind a popular Discord moderation bot, let an attacker pull tens of millions of user records and briefly hijack the...

>> read more

Pwn2Own Ireland 2026: Researchers Cash In on 32 Zero-Days Across Samsung, Oracle, and AI Platforms

8 October 2026  |  dark6  |  Vulnerability

On the opening day of Pwn2Own Ireland 2026, competing research teams chained together 32 previously unknown vulnerabilities across flagship phones, AI services, and smart-home gear, collecting $388,500 in...

>> read more

South Korean Church Breaches Expose More Than One Million Congregant Records

8 October 2026  |  dark6  |  Databreach

Attackers penetrated two major South Korean churches through a web shell, leaked credentials and broken authorization controls, exposing records tied to more than one million congregants. The intrusions...

>> read more

CyberXero Uses AI Agent Swarms to Scale WordPress Intrusions and Target Ukrainian Energy

8 October 2026  |  dark6  |  Cybercrime

A Russian-speaking initial-access broker known as CyberXero used dozens of AI agents alongside PentAGI and Cobalt Strike to automate web attacks and conduct targeted reconnaissance. Exposed operator files...

>> read more

Attackers Hijack Three Country-Code Registries to Obtain Rogue HTTPS Certificates

8 October 2026  |  dark6  |  Cybercrime

Attackers compromised the .gh, .sl and .as domain registries and exploited DNS control to obtain unauthorized HTTPS certificates for Google and other organizations. Chrome blocked known certificates, but...

>> read more

SonicWall Fixes Maximum-Severity SMA1000 Flaw Allowing Pre-Login Internal Requests

8 October 2026  |  dark6  |  Vulnerability

SonicWall has patched four SMA1000 vulnerabilities, led by a CVSS 10 pre-authentication SSRF flaw that can turn an exposed appliance into a proxy for internal requests. Organizations must...

>> read more