Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

How a Crafted SVG File Could Have Handed Attackers SYSTEM Access on Microsoft’s Bing Servers

25 July 2026  |  dark6  |  Vulnerability

Three critical, now-patched vulnerabilities in Microsoft's infrastructure show how an everyday image upload feature in Bing Images became a path to remote code execution as NT AUTHORITY\SYSTEM. Researchers...

>> read more

Certighost Flaw Let Ordinary Users Impersonate Domain Controllers and Seize Active Directory

25 July 2026  |  dark6  |  Vulnerability

A newly patched Active Directory Certificate Services bug, dubbed Certighost, let any low-privileged domain user trick a certificate authority into treating a rogue machine as a real Domain...

>> read more

Cl0p Affiliates Are Breaching PTC Windchill Servers to Steal Product Blueprints Before Extortion

25 July 2026  |  dark6  |  Ransomware

Cl0p-linked attackers are chaining an unauthenticated information disclosure bug with a critical deserialization flaw in PTC Windchill and FlexPLM to steal engineering and product-design data from manufacturers, automakers,...

>> read more

Fake Claude Desktop Ads on Bing Are Delivering SectopRAT to Corporate Networks

25 July 2026  |  dark6  |  Malware

A campaign dubbed FakeAgent used paid Bing search ads and a malicious public Claude Artifact to trick corporate employees into installing a disguised remote access trojan. At least...

>> read more

Next.js Ships Emergency Fixes for Nine Flaws, Including High-Severity SSRF and Auth Bypass Bugs

24 July 2026  |  dark6  |  Vulnerability

Vercel has patched nine security vulnerabilities in Next.js, the widely used React framework, covering server-side request forgery, a middleware authentication bypass, denial-of-service conditions, and data-exposure issues. Four of...

>> read more

Chaos Ransomware’s New msaRAT Tool Hijacks Chrome and Edge as a Stealth Command Channel

24 July 2026  |  dark6  |  Ransomware

Cisco Talos has identified msaRAT, a Rust-based tool tied to the Chaos ransomware group that quietly launches Chrome or Edge in headless mode and turns the browser into...

>> read more

Sloppy Server Configuration Unmasks JadeProx Espionage Campaign and Its TriBack Malware Loader

24 July 2026  |  dark6  |  Malware

Researchers at Group-IB stumbled onto an active espionage operation, now tracked as JadeProx, after its operators left a staging server's directory listing wide open. The exposed files revealed...

>> read more

Alleged 160-Million-Record Decathlon Customer Database Surfaces on Cybercrime Forum

24 July 2026  |  dark6  |  Databreach

A threat actor is advertising what they claim is a Decathlon customer database of roughly 160 million records on an underground forum, seeking cryptocurrency payment. Decathlon has not...

>> read more