Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

CVSS 10 WSO2 Authentication Bypass Threatens API Control Planes

17 September 2026  |  dark6  |  Vulnerability

WSO2 has disclosed CVE-2026-5430, a maximum-severity JWT authentication bypass affecting several API management products. Remote attackers could obtain privileged access without credentials, making rapid updates and a review...

>> read more

Critical Check Point Login Flaw Exposes Management Servers to Root Takeover

17 September 2026  |  dark6  |  Vulnerability

Check Point has issued an urgent fix for CVE-2026-91843, a remotely exploitable buffer overflow that can grant root privileges before authentication. Administrators should deploy and verify the LivePatch...

>> read more

CISA Orders Urgent ScreenConnect Response as Attackers Exploit Critical Flaw

17 September 2026  |  dark6  |  Vulnerability

CISA has confirmed active exploitation of a critical ConnectWise ScreenConnect authorization flaw and ordered rapid remediation for covered agencies. Organizations should patch immediately and investigate prior remote sessions,...

>> read more

Security Update Backfires: Windows 11 Patch Breaks Domain Trust, Locks Out Enterprise Users

17 September 2026  |  dark6  |  Vulnerability

Microsoft is investigating reports that the September Windows 11 cumulative update, KB5124008, is breaking Active Directory domain trust on some enterprise machines, blocking valid logins. The likely cause...

>> read more

Inside GhostCode: The Phishing Kit That Turns MFA Approval Into Account Takeover

17 September 2026  |  dark6  |  Phishing

A newly identified phishing kit called GhostCode hijacks Microsoft 365 accounts by abusing the OAuth device-code sign-in flow, letting victims unknowingly approve an attacker's device during a completely...

>> read more

Decade-Old Noodle RAT Resurfaces, Now Hunting Both Windows and Linux Systems Across Asia

17 September 2026  |  dark6  |  Malware

Check Point researchers have tracked renewed activity from Noodle RAT, a cross-platform backdoor linked to Chinese-speaking threat actors and shared across multiple APT and cybercrime groups. Victims span...

>> read more

CenterPoint Energy Confirms Customer Data Theft From Internet-Facing System

17 September 2026  |  dark6  |  Databreach

CenterPoint Energy says an unauthorized party accessed customer personal information through an internet-facing company system. Energy delivery remains unaffected, but the utility has not yet disclosed the number...

>> read more

For $250 a Month, Anyone Can Rent a Fully Featured Windows Spy Tool Called VectraRAT

17 September 2026  |  dark6  |  Malware

Researchers have uncovered VectraRAT, a subscription-based remote access trojan renting for as little as $250 a month that gives buyers keylogging, hidden-desktop control, and credential theft on infected...

>> read more