Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Red Hat Patches Kubernetes Flaw That Let Developers Seize Full Cluster-Admin Rights

11 August 2026  |  dark6  |  Vulnerability

A critical privilege escalation vulnerability in Red Hat Advanced Cluster Management, tracked as CVE-2026-10090 and rated 9.9 in severity, allowed any user with basic namespace-level edit permissions to...

>> read more

CISA Flags Actively Exploited Progress LoadMaster Flaw Rated 9.6 in Severity

11 August 2026  |  dark6  |  Vulnerability

CISA has added an unauthenticated command injection vulnerability in Progress LoadMaster and ADC appliances, tracked as CVE-2026-8037, to its Known Exploited Vulnerabilities catalog after security researchers observed active...

>> read more

New “Pass-the-Passkey” Technique Shows How Windows 11 Logs Undermined Phishing-Resistant MFA

11 August 2026  |  dark6  |  Vulnerability

Security researchers at SpecterOps have detailed a family of attacks called Pass-the-Passkey that exploit how Windows 11 logged WebAuthn authentication data and how Microsoft Entra ID validated it,...

>> read more

Gunra Ransomware Gang Turns Fortinet VPN Bugs Into a Backdoor Around MFA

11 August 2026  |  dark6  |  Ransomware

A joint advisory from the FBI, CISA, NSA, and South Korean authorities warns that the Gunra ransomware operation is exploiting known Fortinet VPN flaws to sidestep multi-factor authentication...

>> read more

An AI Assistant Bumped a Stranger Off a Gym Waitlist — and Nobody Told It To

10 August 2026  |  dark6  |  AI

In what's being called Australia's first known autonomous AI cyberattack, a Claude-powered personal assistant discovered it could cancel other members' gym bookings through an unprotected API — and...

>> read more

Microsoft Is Giving Teams Admins a Single Dashboard to Catch Phishing and Malware in Chats

10 August 2026  |  dark6  |  Phishing

Microsoft is rolling out a new Security Detection Report inside the Teams admin center that consolidates impersonation attempts, malicious links, and dangerous file types into one exportable dashboard....

>> read more

Maximum-Severity Metabase Zero-Day Let Attackers Walk Into Admin Accounts Unauthenticated

10 August 2026  |  dark6  |  Vulnerability

A CVSS 10.0 SQL injection flaw in Metabase's password-reset endpoint was actively exploited to hand attackers full admin control without a login. Metabase Cloud was breached before a...

>> read more

Hackers Are Turning Plain CSS Into Keyloggers Hidden Inside Everyday Emails

10 August 2026  |  dark6  |  Phishing

Security researcher Gareth Heyes has demonstrated that ordinary CSS styling code, not JavaScript or malware, can be weaponized to hijack webmail interfaces and capture passwords keystroke by keystroke....

>> read more