Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

UAC-0099 Refines MATCHBOIL Malware With Cloudflare-Hidden Servers to Hit Ukrainian Organizations

10 October 2026  |  dark6  |  Malware

ESET researchers have detailed how the UAC-0099 threat group has evolved its MATCHBOIL downloader with Cloudflare-concealed command servers, stronger code obfuscation, and anti-analysis checks. Victims span transportation, manufacturing,...

>> read more

Warden Stealer-as-a-Service Expands to Target Browser Vaults, Crypto Wallets, and AI Agent Tokens

10 October 2026  |  dark6  |  Malware

A fast-growing Rust-based information stealer called Warden Stealer is spreading through ClickFix lures, malicious ads, cracked software, and fake game cheats. Sold as a malware-as-a-service kit, it bypasses...

>> read more

CastleStealer Malware Adds Remote Shell Access After Cracking Chrome’s Cookie Protection

10 October 2026  |  dark6  |  Malware

CastleStealer, a C#-based information stealer first spotted in April, has gained the ability to bypass Chrome's App-Bound Encryption and hand its operators a remote shell on infected Windows...

>> read more

Telegram Desktop Patches High-Severity IPC Bug That Enabled One-Click Account Hijacking

10 October 2026  |  dark6  |  Vulnerability

A public proof-of-concept exposed a high-severity Telegram Desktop flaw that let a single crafted link outside the app read local session files and hijack a victim's account. Telegram...

>> read more

Trojanized Terraform Provider Delivers Cross-Platform Backdoors to Developers

10 October 2026  |  dark6  |  Malware

A malicious Terraform provider masquerading as an AWS plugin delivers FLATROOF and ROOFDECK malware across macOS, Linux, and Windows. The campaign targets developer and CI/CD environments where cloud...

>> read more

GhostAction Hijacks 346 GitHub Repositories to Harvest CI/CD Secrets

10 October 2026  |  dark6  |  Cybercrime

The GhostAction campaign used compromised maintainer accounts to inject credential-stealing GitHub Actions workflows into 346 repositories. The malicious automation collected CI/CD secrets and searched full Git histories, creating...

>> read more

Public AnyDesk Exploit Puts Unpatched Linux Hosts at Risk of Root Takeover

10 October 2026  |  dark6  |  Vulnerability

Public exploit code for the AnyPwn flaw can target AnyDesk 8.0.2 on Linux before authentication and execute commands with root privileges. Administrators should install version 8.0.3 or later,...

>> read more

AT&T’s $177 Million Settlement Resolves Claims From Two Massive Data Breaches

10 October 2026  |  dark6  |  Databreach

A federal judge has approved AT&T’s $177 million settlement covering two 2024 breaches that exposed personal information and communications metadata. The agreement closes the litigation without an admission...

>> read more