Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

GitSpawn Turns Booby-Trapped Repositories Into Silent Code Execution Across AI Coding Tools

3 September 2026  |  dark6  |  Vulnerability

GitSpawn weaknesses allow specially prepared project folders to execute local commands when AI coding agents perform routine Git checks. Several vendors have patched variants, but researchers say four...

>> read more

TukTuk Malware Gives Ransomware Crews Cross-Platform Control and EDR-Killing Tools

3 September 2026  |  dark6  |  Ransomware

Researchers recovered a previously undocumented command-and-control framework linked to the Gentlemen ransomware ecosystem. TukTuk supports Windows and Linux agents, credential prompts, screen capture, remote commands, and preparation for...

>> read more

Lenovo ID Trust Flaw Opened About 5,000 Dropbox Accounts to Takeover

3 September 2026  |  dark6  |  Databreach

Dropbox says attackers compromised roughly 5,000 accounts by creating Lenovo IDs with victims’ email addresses and abusing a federated-login integration. The incident demonstrates why matching email claims cannot...

>> read more

Microsoft 365 Session Hijacking Campaigns Hide Behind Trusted Remote-Support Tools

3 September 2026  |  dark6  |  Phishing

Campaigns spanning the United States and Europe are combining adversary-in-the-middle phishing with legitimate remote-management software. Stolen session cookies can outlive password resets, forcing defenders to revoke tokens and...

>> read more

Fake Software Installers Are Quietly Disarming Microsoft Defender in New Silver Fox Campaign

3 September 2026  |  dark6  |  Malware

A Silver Fox-linked campaign is distributing counterfeit installers for brands like Razer, Microsoft Edge, and Kaspersky that use SYSTEM-level scheduled tasks to strip Microsoft Defender protections and delete...

>> read more

BREEZE COMET Hackers Use AI-Written Tools to Speed-Run Brazilian Bank Fraud

3 September 2026  |  dark6  |  Cybercrime

Google Cloud researchers detail how the financially motivated BREEZE COMET group has spent two years infiltrating Brazilian banks and retailers, combining social engineering and rogue hardware with generative-AI-assisted...

>> read more

High-Severity Cleo Harmony Bug Lets Attackers Forge Their Way to Admin Access

3 September 2026  |  dark6  |  Vulnerability

A high-severity flaw in Cleo Harmony's JWT refresh-token handling, tracked as CVE-2026-84115, lets remote attackers escalate privileges to admin level with a working exploit already public. Cleo has...

>> read more

New WhatsApp Video Call Trick Bypasses Android Lock Screens to Expose Your Photos

3 September 2026  |  dark6  |  Vulnerability

A newly disclosed WhatsApp flaw lets anyone answer a video call on a locked Android phone and, through the in-call background editor, browse the device's entire photo gallery...

>> read more