Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Microsoft Fixes CVSS 10 Azure AI Foundry Privilege-Escalation Flaw

19 September 2026  |  dark6  |  Vulnerability

Microsoft has remediated a maximum-severity authentication flaw in Azure AI Foundry that could allow an unauthenticated network attacker to gain elevated privileges. The cloud-side fix is complete, but...

>> read more

BragJack Lets Malicious Extensions Command AI Browser Agents Across Trusted Channels

19 September 2026  |  dark6  |  AI

Researchers showed that a malicious browser extension can hijack privileged communication paths used by AI assistants in five Chromium-based environments. The BragJack technique can force agent actions without...

>> read more

Click2Shell Chain Turns One Malicious Link Into WordPress Server Takeover

19 September 2026  |  dark6  |  Vulnerability

WordPress has fixed a theme-preview weakness that can silently install an attacker-selected theme when an administrator opens a crafted link. Paired with unsafe pre-activation code in a theme,...

>> read more

How a Hijacked Thai College Webpage Became a Funnel Into an Illegal Online Casino

19 September 2026  |  dark6  |  Cybercrime

Fraud investigators at ADEX traced suspicious ad traffic back to a compromised page on a Thai academic institution's website that Google had indexed and ranked highly, then quietly...

>> read more

CISA’s Latest Advice for Defenders: Lay Traps for Hackers Before They Even Get In

19 September 2026  |  dark6  |  Cybercrime

CISA has published new guidance urging organizations to seed their networks with fake credentials, decoy systems and honeytokens so that any attacker who slips past perimeter defenses trips...

>> read more

OpenAI Caught Its Own Models Stealing API Keys and Faking Data During Training Runs

19 September 2026  |  dark6  |  AI

OpenAI has disclosed six internal incidents in which models under reinforcement-learning training went looking for ways around blocked tasks — one located and used an exposed API key...

>> read more

How AI Cracked Its Maker: Claude Opus 5 Helped Researchers Breach OpenAI’s Own Forum

19 September 2026  |  dark6  |  Vulnerability

Security researchers at Hacktron used Anthropic's newly released Claude Opus 5 to build a working exploit for a memory-corruption bug in the image library behind OpenAI's community forum,...

>> read more

FBI Seizes NightmareStresser Domains After Hundreds of Thousands of DDoS Attacks

19 September 2026  |  dark6  |  Cybercrime

The FBI and Canadian authorities have disrupted NightmareStresser, a DDoS-for-hire service blamed for hundreds of thousands of attacks since 2022. The domain seizures are part of Operation PowerOFF...

>> read more