Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Compromised Tensorlake npm Release Spreads Shai-Hulud Worm Through Developer Systems

9 October 2026  |  dark6  |  Malware

A malicious Tensorlake npm release executed during installation, harvested developer and cloud secrets, and used worm-like techniques to threaten downstream projects. Teams that installed version 0.5.144 should treat...

>> read more

Critical NetScaler Memory Flaw Exposes SAML Appliances to Remote Code Execution

9 October 2026  |  dark6  |  Vulnerability

Citrix has released urgent updates for a critical NetScaler ADC and Gateway memory-overflow vulnerability with a CVSS 9.5 rating. Exposure depends on the appliance build and whether it...

>> read more

Fake Rabby and OKX Wallet Clones Found Stealing Crypto Seed Phrases via Firefox Add-ons

9 October 2026  |  dark6  |  Malware

Researchers at Socket.dev uncovered 16 malicious Firefox extensions posing as Rabby Wallet and OKX Wallet that quietly captured recovery phrases and private keys and sent them to attacker-controlled...

>> read more

Nine-Day Scanning Surge Targets Unpatched Hikvision Cameras Across Ukraine

9 October 2026  |  dark6  |  Vulnerability

GreyNoise logged a sharp nine-day spike in scanning and exploitation attempts against internet-exposed Hikvision cameras in Ukraine, almost all aimed at the four-year-old, maximum-severity CVE-2021-36260 command injection flaw....

>> read more

DarkSword Exploit Service Uses Coruna Malware to Steal iPhone Wallet Recovery Phrases

9 October 2026  |  dark6  |  Spyware

Researchers uncovered exposed infrastructure showing how DarkSword and Coruna turn iPhone exploitation into a commercial wallet-theft service. The toolkit injects modules into wallet apps and searches photos and...

>> read more

FBI Seizes Seven Domains Supporting Flax Typhoon Scanning and Phishing Operations

9 October 2026  |  dark6  |  Cybercrime

U.S. authorities seized seven domains linked to scanning, phishing, malware delivery, and persistence tools allegedly operated by China-based Integrity Technology Group. The disruption affects infrastructure associated with Flax...

>> read more

Password-Free Login Flaw in Sungrow’s Solar Cloud Platform Could Have Enabled Grid-Wide Disruption

9 October 2026  |  dark6  |  Vulnerability

A business-logic flaw in Sungrow's iSolarCloud platform let attackers authenticate into any customer account using only an email address, with no password required and no login alert sent....

>> read more

Microsoft Teams to Add Third-Party Deepfake Detection as Synthetic-Media Attacks Escalate

9 October 2026  |  dark6  |  AI

Microsoft plans to roll out synthetic audio and video detection in Teams starting November 2026, routing meeting media through certified third-party providers to flag possible deepfakes. The move...

>> read more