Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

FortiGate Exploit Opens Broadband Provider to Credential Theft and Network Pivoting

15 September 2026  |  dark6  |  Cybercrime

Researchers uncovered infrastructure indicating that attackers exploited a FortiGate SSL-VPN weakness during an intrusion targeting Thailand’s 3BB broadband provider. The operation combined perimeter access, privilege escalation, credential theft...

>> read more

Cisco Email Gateway Zero-Day Gives Remote Attackers Root Control

15 September 2026  |  dark6  |  Vulnerability

Cisco is warning that attackers are exploiting a critical Secure Email Gateway zero-day to execute commands as root without authentication. Organizations should isolate management interfaces, apply Cisco’s remediation...

>> read more

Malicious Twitch Extension Leaks OAuth Tokens From 30,000 Browser Users

15 September 2026  |  dark6  |  Malware

A Twitch helper extension installed by about 30,000 Chrome and Firefox users was found sending active account tokens through operator-controlled servers. The incident shows how a seemingly convenient...

>> read more

Mass Scanning of Exposed Vite Servers Targets AWS and Azure Secrets

15 September 2026  |  dark6  |  Vulnerability

Attackers are automatically probing internet-accessible Vite development servers for environment files, cloud credentials and infrastructure secrets. F5 telemetry recorded about 32,000 raw events in August, highlighting the risk...

>> read more

StyleSmuggler Zero-Day Leaves Every Current Magento and Adobe Commerce Store Exposed to Takeover

14 September 2026  |  dark6  |  Vulnerability

A newly disclosed zero-day dubbed StyleSmuggler lets attackers hijack Magento Open Source and Adobe Commerce stores by smuggling PHP code through routine GraphQL requests and triggering it via...

>> read more

Exploited Zero-Days and Perimeter Flaws Put Patch Triage Under Pressure

14 September 2026  |  dark6  |  Vulnerability

This week’s security picture is dominated by exploited Windows and Chrome zero-days, dangerous flaws in perimeter products and increasingly automated attack operations. Defenders need risk-based patch sequencing, exposure...

>> read more

Fraudulent Government Request Exposes Revolut KYC Records and Transaction Histories

14 September 2026  |  dark6  |  Databreach

Revolut disclosed that a fraudulent request sent from an official government email domain led to the release of highly sensitive customer records. The incident shows why authenticated email...

>> read more

Dell ObjectScale CVSS 10 Flaw Exposes Enterprise Storage to Remote Takeover

14 September 2026  |  dark6  |  Vulnerability

Dell has fixed a maximum-severity ObjectScale vulnerability that could let an unauthenticated remote attacker execute code on exposed storage systems. Organizations should upgrade quickly, reduce management-plane exposure and...

>> read more