Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

CISA Orders Forensic Checks as Three Linux Kernel Flaws Face Active Exploitation

20 September 2026  |  dark6  |  Vulnerability

CISA has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog and ordered covered agencies to patch and investigate exposed systems. The flaws affect kernel TLS,...

>> read more

TanStack Supply-Chain Breach Exposes 170 Private CrowdSec Repositories

20 September 2026  |  dark6  |  Databreach

CrowdSec says attackers cloned roughly 170 private GitHub repositories after stealing an OAuth token through the TanStack npm supply-chain compromise. The incident remained hidden for months and highlights...

>> read more

Gemini Security Test Escaped Its Sandbox and Reached Three Real Companies

20 September 2026  |  dark6  |  AI

Google confirmed that Gemini accessed systems at three real companies after a cybersecurity evaluation mistakenly left internet access enabled and used a fictional company name that matched a...

>> read more

ENCFORGE Ransomware Targets the Models, Datasets and Vector Stores Behind AI

20 September 2026  |  dark6  |  Ransomware

The JADEPUFFER threat actor has progressed from improvised database destruction to ENCFORGE, ransomware built to encrypt AI models, datasets and vector indexes. Defenders need runtime detection and recovery...

>> read more

Microsoft Fixes CVSS 10 Azure AI Foundry Privilege-Escalation Flaw

19 September 2026  |  dark6  |  Vulnerability

Microsoft has remediated a maximum-severity authentication flaw in Azure AI Foundry that could allow an unauthenticated network attacker to gain elevated privileges. The cloud-side fix is complete, but...

>> read more

BragJack Lets Malicious Extensions Command AI Browser Agents Across Trusted Channels

19 September 2026  |  dark6  |  AI

Researchers showed that a malicious browser extension can hijack privileged communication paths used by AI assistants in five Chromium-based environments. The BragJack technique can force agent actions without...

>> read more

Click2Shell Chain Turns One Malicious Link Into WordPress Server Takeover

19 September 2026  |  dark6  |  Vulnerability

WordPress has fixed a theme-preview weakness that can silently install an attacker-selected theme when an administrator opens a crafted link. Paired with unsafe pre-activation code in a theme,...

>> read more

How a Hijacked Thai College Webpage Became a Funnel Into an Illegal Online Casino

19 September 2026  |  dark6  |  Cybercrime

Fraud investigators at ADEX traced suspicious ad traffic back to a compromised page on a Thai academic institution's website that Google had indexed and ranked highly, then quietly...

>> read more