Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Apache HTTP Server 2.4.69 Fixes 20 Flaws Across CGI, WebDAV and Proxy Modules

2 October 2026  |  dark6  |  Vulnerability

Apache HTTP Server 2.4.69 addresses 20 vulnerabilities that can cause code execution, memory corruption, crashes, data exposure or authentication problems under particular configurations. Administrators should upgrade, but risk-based...

>> read more

Antino Backdoor Hides Its Entire Command Channel Inside Microsoft 365

2 October 2026  |  dark6  |  Spyware

A China-linked espionage campaign has deployed a Rust backdoor whose native command-and-control workflow runs through Outlook and OneDrive. Cisco Talos found roughly 350 compromised endpoints across eight countries,...

>> read more

Warlock Ransomware Turns SharePoint Servers Into Gateways to Essential Services

2 October 2026  |  dark6  |  Ransomware

A China-linked operator is exploiting on-premises SharePoint flaws to deploy Warlock ransomware across water, telecom, government and education organizations. Recent intrusions show how web shells, stolen machine keys,...

>> read more

Actively Exploited FortiMail Zero-Day Lets Attackers Write Files Without Login

2 October 2026  |  dark6  |  Vulnerability

Fortinet says attackers are exploiting a critical FortiMail flaw that permits unauthenticated file writes through crafted web requests. With patches still pending for several branches at disclosure, administrators...

>> read more

Star Blizzard’s RedFlick Phishing Chain Targets More Than 100 Organizations

1 October 2026  |  dark6  |  Phishing

A Russia-linked operation is using attachment-free opening messages before sending encrypted archives that deploy the CosmicPulse backdoor. More than 100 organizations, particularly those involved with Ukraine-related policy and...

>> read more

CopyEscape Flaw Turns Docker File Copies Into a Route to Host Root

1 October 2026  |  dark6  |  Vulnerability

A flaw in Docker’s archive extraction path can let a hostile container write beyond the destination chosen for a file copy. On Linux systems where the command runs...

>> read more

How a Single Poisoned Package Can Hand Attackers the Keys to Your Cloud

1 October 2026  |  dark6  |  Malware

A new Qualys analysis ties together a string of 2025–2026 software supply chain campaigns — from the Shai-Hulud worm to malicious Ruby gems and Go modules — showing...

>> read more

Cloudflare’s New Certificate Design Aims to Make Quantum-Safe HTTPS Actually Practical

1 October 2026  |  dark6  |  Privacy

Cloudflare is building a certificate authority around a new 'Merkle Tree Certificate' format designed to deliver post-quantum website authentication without bloating every TLS handshake. Early tests show a...

>> read more