Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Breach at France’s Tax Authority Exposes Financial Records of Nearly 680,000 People

19 August 2026  |  dark6  |  Databreach

France's Directorate General of Public Finances has confirmed that attackers used compromised employee and third-party credentials to access tax records belonging to roughly 678,000 individuals and businesses. No...

>> read more

CISA Sounds Alarm on Medusa Ransomware After 500+ Critical Infrastructure Hits

19 August 2026  |  dark6  |  Ransomware

CISA, the FBI, and HHS have jointly updated their advisory on the Medusa ransomware-as-a-service operation, which has now hit more than 500 critical infrastructure organizations spanning healthcare, education,...

>> read more

Critical MLflow Flaw Lets Attackers Steal Cloud Credentials via Webhook Redirects

19 August 2026  |  dark6  |  Vulnerability

A critical server-side request forgery flaw in MLflow, tracked as CVE-2026-64849 with a 9.3 CVSS score, lets unauthenticated attackers abuse the platform's webhook-testing endpoint to reach cloud metadata...

>> read more

Fake CAPTCHA Prompts on Hacked WordPress Sites Fuel Global StopAndProtect Malware Botnet

19 August 2026  |  dark6  |  Malware

Researchers have uncovered a sprawling campaign, dubbed StopAndProtect, that has hijacked thousands of poorly maintained WordPress sites to serve as rotating command-and-control infrastructure. Fake CAPTCHA prompts trick visitors...

>> read more

Chinese APT Group Deploys Signed Kernel Rootkit to Hide ‘CoolClient’ Backdoor on Government Networks

18 August 2026  |  dark6  |  Malware

Researchers have exposed a HoneyMyte campaign that pairs the PlugX loader with a new backdoor called CoolClient, concealed by a digitally signed kernel rootkit driver. The malware has...

>> read more

Roundcube Patches Eleven Flaws, Including Remote Code Execution Reachable Through Spam-Learning Plugin

18 August 2026  |  dark6  |  Vulnerability

Roundcube 1.6.18 and 1.7.3 close eleven vulnerabilities, headlined by a remote code execution bug in the markasjunk plugin and two SSRF filter bypasses. No in-the-wild exploitation has been...

>> read more

Four Chained Flaws in Microsoft SCCM Let Any Domain User Seize Full Server Control

18 August 2026  |  dark6  |  Vulnerability

A newly disclosed exploit chain in Microsoft System Center Configuration Manager, tracked as CVE-2026-47301, lets a standard Active Directory user achieve remote code execution as SYSTEM on the...

>> read more

Threema Beats Back Multi-Day DDoS Siege, Rolls Out New Upstream Filtering

18 August 2026  |  dark6  |  Cybercrime

Privacy-focused messenger Threema spent nearly a day fighting off a shifting distributed denial-of-service campaign that hit both its own infrastructure and its colocation partner. No group has claimed...

>> read more