Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

ASUS Rushes Out Router Patch After Discovery of Unauthenticated Remote Command Execution Flaw

23 July 2026  |  dark6  |  Vulnerability

ASUS has issued firmware updates for a high-severity vulnerability, tracked as CVE-2026-13385, that could let remote attackers run arbitrary commands on widely deployed router models without authentication. Security...

>> read more

RefluXFS: A Nine-Year-Old Race Condition in Linux’s XFS Filesystem Opens a Silent Road to Root

23 July 2026  |  dark6  |  Vulnerability

Qualys researchers have disclosed RefluXFS (CVE-2026-64600), a race condition in the Linux kernel's XFS copy-on-write path that lets a local, unprivileged user seize root access while leaving no...

>> read more

HermeticReader: How a Bug in Adobe’s PDF Browser Extension Could Expose WhatsApp Chats to Any Website

23 July 2026  |  dark6  |  Privacy

Researchers at Guardio Labs disclosed a flaw in the Adobe Acrobat Chrome extension, installed on roughly 329 million browsers, that let a malicious website silently read a victim's...

>> read more

Iran’s Cyber Playbook Shifts From Loud Attacks to Patient, Long-Term Access

23 July 2026  |  dark6  |  Cybercrime

A new SentinelOne assessment finds Iran-linked hacking groups increasingly favor quiet, persistent access over destructive attacks, planting footholds in cloud accounts, IT suppliers, and industrial systems that could...

>> read more

Fake Game Downloads Are Quietly Installing Amatera Stealer Through a Disguised RenPy Loader

22 July 2026  |  dark6  |  Malware

A malware campaign is hiding behind fake games, cracks, and mods to install Amatera Stealer, a multi-stage infostealer that harvests browser credentials, messaging data, and cryptocurrency wallets. The...

>> read more

PhantomEnigma: How a Malware Crew Turned Brazilian Government Sites Into Trusted Malware Hubs

22 July 2026  |  dark6  |  Malware

A campaign tracked as PhantomEnigma has compromised more than 20 official Brazilian government websites, using them to host and deliver malware that passes email authentication checks and slips...

>> read more

Chrome’s Latest Patch Closes 12 Security Holes, Nine of Them Rated High Severity

22 July 2026  |  dark6  |  Vulnerability

Google has shipped a new Stable Chrome release fixing 12 vulnerabilities, nine of them high severity, touching core components like V8, ANGLE, and the GPU stack. Several of...

>> read more

Unauthenticated Attackers Are Actively Exploiting a ServiceNow Sandbox-Escape Flaw

22 July 2026  |  dark6  |  Vulnerability

A critical ServiceNow vulnerability that lets unauthenticated attackers break out of the platform's scripting sandbox is now being exploited in the wild. ServiceNow has shipped patches, but self-hosted...

>> read more