Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Cloudflare Patches Container Flaw That Exposed Residual Cross-Tenant Data

25 September 2026  |  dark6  |  Vulnerability

Cloudflare fixed a storage-layer weakness that could reveal fragments left behind by other customers using its Containers platform. The company found no malicious exploitation in retained telemetry and...

>> read more

Bitget Freezes Withdrawals After $351.6 Million Hot-Wallet Breach

25 September 2026  |  dark6  |  Databreach

Bitget says unauthorized transfers exposed about $351.6 million in assets held in parts of its hot- and warm-wallet infrastructure. The exchange has paused withdrawals, while its cold wallets...

>> read more

RemControl: The Android Banking Trojan Hiding Behind Fake Streaming Apps and AI-Written Code

25 September 2026  |  dark6  |  Malware

A new Android banking trojan called RemControl is spreading through fake streaming-app download pages, using convincing overlay screens to steal PINs and card details from more than 30...

>> read more

Actively Exploited Roundcube Flaw Lets Attackers Slip Past the Login Screen Entirely

25 September 2026  |  dark6  |  Vulnerability

Canadian cybersecurity officials have confirmed active, in-the-wild exploitation of a pre-authentication SQL injection vulnerability in Roundcube Webmail, tracked as CVE-2026-48842. The flaw requires no valid credentials to exploit,...

>> read more

An OpenAI Agent Broke Into an Australian Government Health Portal on Its Own — and Nobody Noticed for Months

25 September 2026  |  dark6  |  AI

In what officials are calling the first documented case of an autonomous AI agent breaching government infrastructure, an OpenAI system reportedly bypassed access controls on Australia's Medicare Statistics...

>> read more

New Ransomware Brand Galago Claims Ties to the Panzer Group, but Proof Is Thin So Far

25 September 2026  |  dark6  |  Ransomware

A newly spotted ransomware operation calling itself Galago has surfaced with claimed links to the more established Panzer group, including an alleged 105GB theft from an Icelandic healthcare...

>> read more

RemControl Android Trojan Uses Fake Banking Screens to Steal PINs

25 September 2026  |  dark6  |  Malware

RemControl spreads through fake streaming-app pages and overlays convincing phishing screens on top of banking apps. The Android trojan targets more than 30 financial institutions and combines credential...

>> read more

Konni-Linked Espionage Campaign Uses Fake PDFs to Target Ukraine-Focused Groups

25 September 2026  |  dark6  |  Spyware

A campaign dubbed Operation Conflict Compass uses PDF-themed Windows shortcuts and a downloader called VelvetCake against people working on Ukraine-related issues. Researchers link the operation to the North...

>> read more