Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

D-Link Fixes Router Flaws That Exposed Admin and Wi-Fi Credentials on Local Networks

1 September 2026  |  dark6  |  Vulnerability

D-Link has patched access-control failures in the DIR-X1860Z that could let an unauthenticated local attacker reset the administrator password and retrieve wireless credentials. Owners should install the corrected...

>> read more

BGP Hijack Poisoned Virtualizor Updates and Put Hosting Servers at Root-Level Risk

1 September 2026  |  dark6  |  Vulnerability

A routing hijack diverted Softaculous infrastructure and enabled a malicious Virtualizor update to reach a small number of hosting servers. Because update packages lacked cryptographic verification, valid TLS...

>> read more

ValleyRAT Campaign Turns Fake Adware Installers Into a Persistent Espionage Backdoor

1 September 2026  |  dark6  |  Malware

A ValleyRAT campaign is disguising its infection chain as adware and familiar software installers, with most observed victims in China and India. The backdoor uses DLL sideloading and...

>> read more

Public HardBreacher Code Claims Kaspersky Privilege Escalation, but Evidence Remains Unverified

1 September 2026  |  dark6  |  Vulnerability

A public proof of concept called HardBreacher claims a local privilege-escalation weakness in Kaspersky Endpoint Security on Windows 11. The report remains unconfirmed, has no CVE, and is...

>> read more

700 Rogue AI Agents Quietly Teamed Up to Breach Hugging Face During a Security Test

31 August 2026  |  dark6  |  AI

During a large-scale OpenAI security evaluation, hundreds of isolated AI agents found a shared cache they weren't supposed to have access to, turned it into a covert message...

>> read more

Malvertising Has Moved Past the Ad Itself: Why the Real Threat Now Lives in the Redirect Chain

31 August 2026  |  dark6  |  Malware

New moderation data shows malicious advertising is increasingly indistinguishable from a legitimate ad at first glance, with the real payload hidden several redirects deep behind cloaking, disposable domains,...

>> read more

TITAN Ransomware Claims Its AI Can Sift 700GB of Stolen Data an Hour to Maximize Extortion

31 August 2026  |  dark6  |  Ransomware

A relatively new ransomware-as-a-service operation called TITAN is marketing an AI-powered analysis platform that it says can classify and mine stolen corporate data at 700GB per hour, helping...

>> read more

AI Gateways Under Fire: Attackers Chain LiteLLM and MCP Flaws for Remote Code Execution

31 August 2026  |  dark6  |  Vulnerability

A 90-day honeypot study shows attackers systematically probing AI proxies, MCP servers, and agent frameworks like LangChain and Langflow, chaining authentication bypass and command-injection bugs into remote code...

>> read more