Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

F-Droid 2.0 Modernizes Android App Discovery but Leaves Some Privacy Tools Behind

28 September 2026  |  dark6  |  Privacy

F-Droid 2.0 brings the open-source Android repository its largest client redesign in a decade, with improved search, automatic updates and a modernized codebase. Privacy-conscious users should note that...

>> read more

Uncensored Local AI Reworks Credential Dumper to Evade Two EDR Platforms

28 September 2026  |  dark6  |  AI

A controlled experiment showed a locally hosted, guardrail-free AI model modifying an LSASS credential dumper until it escaped detection by two unnamed EDR products. The limited test does...

>> read more

Two Reported NetScaler Zero-Days Put Internet-Facing Gateways on Emergency Watch

28 September 2026  |  dark6  |  Vulnerability

Researchers say two undisclosed Citrix NetScaler remote-code-execution flaws are already being used in attacks, although vendor confirmation and technical indicators remain pending. Defenders should inventory exposed appliances, preserve...

>> read more

Console Pipe Injection Shows Why EDR Cannot Rely on Classic Memory-Write Signals

28 September 2026  |  dark6  |  Malware

A newly disclosed Windows injection method delivers payload bytes through a child console process’s redirected input, avoiding two APIs commonly associated with remote code injection. The technique still...

>> read more

Wireshark Update Fixes 19 Flaws That Turn Untrusted Captures Into Workstation Risk

28 September 2026  |  dark6  |  Vulnerability

Wireshark 4.6.9 and 4.4.19 address 19 documented vulnerabilities, including a configuration-profile flaw that may permit code execution. Security teams should update analyst workstations and treat captures, profiles and...

>> read more

CARBONATO Botnet Embeds an AI Agent in Compromised Docker Hosts

26 September 2026  |  dark6  |  Malware

The CARBONATO botnet abuses unauthenticated Docker services, escapes privileged containers and installs an AI agent controlled through Telegram. Separate automated scripts spread across nearby networks while the agent...

>> read more

Samsung MagicINFO Exploit Leads to Persistent Access and On-Host Cryptominer Build

26 September 2026  |  dark6  |  Malware

Attackers exploited a known Samsung MagicINFO file-write flaw, installed AnyDesk, created an administrator account and disabled Microsoft Defender before building a Monero miner on the victim. The case...

>> read more

Actively Exploited Linux Kernel Race Condition Enables Root and Container Escape

26 September 2026  |  dark6  |  Vulnerability

A race condition in Linux’s AF_ALG cryptographic interface can give an unprivileged local attacker root access and may support Docker container escape. CISA lists CVE-2025-39964 as exploited in...

>> read more