Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Critical Next.js Flaws Put Windows Servers and AVIF Image Processing at Risk of RCE

27 August 2026  |  dark6  |  Vulnerability

Two critical Next.js vulnerabilities may enable unauthenticated remote code execution through Windows path handling and AVIF image processing. Vercel fixed both issues in Next.js 15.5.24 and 16.3.3, with...

>> read more

Ubiquiti Fixes 21 Critical UniFi Flaws Across Routers, Cameras and Access Systems

27 August 2026  |  dark6  |  Vulnerability

Ubiquiti has patched 21 critical vulnerabilities across a broad range of UniFi products, including flaws rated a maximum 10.0. The bugs enable outcomes including authentication bypass, command injection...

>> read more

CISA Flags Actively Exploited Gitea Flaw That Turns Repository Access Into Server Code Execution

27 August 2026  |  dark6  |  Vulnerability

CISA has added CVE-2026-60004 to its Known Exploited Vulnerabilities catalog after confirming attacks against Gitea servers. The flaw can let a repository writer plant a malicious Git hook...

>> read more

28,000 Public .git Folders Left AWS Keys, Stripe Tokens, and HR Files Wide Open, Researchers Find

27 August 2026  |  dark6  |  Databreach

A large-scale internet scan uncovered 28,000 publicly accessible .git directories exposing hundreds of live cloud and payment credentials, along with sensitive employee records — a reminder that scrubbing...

>> read more

Google Ships Chrome 152 With Fixes for 327 Flaws, Including 10 Critical Use-After-Free Bugs

27 August 2026  |  dark6  |  Vulnerability

Chrome 152 lands with 327 security fixes, ten of them rated critical and mostly tied to use-after-free memory bugs across components like ANGLE, Aura, and Chromecast. None are...

>> read more

Mirage2FA Phishing Kit Hijacks Microsoft 365 Sessions at 3,500+ Organizations, Sidestepping MFA Entirely

27 August 2026  |  dark6  |  Phishing

A phishing-as-a-service kit called Mirage2FA has compromised thousands of Microsoft 365 accounts by stealing live session cookies through an adversary-in-the-middle proxy, letting attackers walk past passwords and MFA...

>> read more

Iran-Linked Tortoiseshell Expands Espionage With TWOSTROKE Backdoor and Reverse SSH Tunnels

27 August 2026  |  dark6  |  Spyware

Researchers have linked new Windows malware and reverse SSH infrastructure to the Iran-associated Tortoiseshell threat group. The tools masquerade as a legitimate Windows library and support covert tunneling,...

>> read more

One Malicious Webpage Can Hijack Your AI Coding Agent Through an NVIDIA NemoClaw Flaw

27 August 2026  |  dark6  |  AI

A critical flaw in NVIDIA's NemoClaw tooling exposes a local AI inference server to the open network, letting a single malicious website hijack an AI agent via DNS...

>> read more