Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

CARBONATO Botnet Embeds an AI Agent in Compromised Docker Hosts

26 September 2026  |  dark6  |  Malware

The CARBONATO botnet abuses unauthenticated Docker services, escapes privileged containers and installs an AI agent controlled through Telegram. Separate automated scripts spread across nearby networks while the agent...

>> read more

Samsung MagicINFO Exploit Leads to Persistent Access and On-Host Cryptominer Build

26 September 2026  |  dark6  |  Malware

Attackers exploited a known Samsung MagicINFO file-write flaw, installed AnyDesk, created an administrator account and disabled Microsoft Defender before building a Monero miner on the victim. The case...

>> read more

Actively Exploited Linux Kernel Race Condition Enables Root and Container Escape

26 September 2026  |  dark6  |  Vulnerability

A race condition in Linux’s AF_ALG cryptographic interface can give an unprivileged local attacker root access and may support Docker container escape. CISA lists CVE-2025-39964 as exploited in...

>> read more

Unsigned JWT Flaw Opened Microsoft Analytics Service to Administrator Access

26 September 2026  |  dark6  |  Vulnerability

A missing signature check in Microsoft’s internal Titan analytics service allowed a forged token to obtain administrator privileges and query connected databases. Microsoft closed the public endpoint after...

>> read more

TWEAKOS Doesn’t Just Steal Your Discord and Telegram Accounts — It Puts Them Up for Sale

26 September 2026  |  dark6  |  Malware

A newly uncovered malware operation called TWEAKOS pairs a lightweight Windows stealer with a Telegram-based storefront, letting operators harvest Discord tokens and hijack Telegram sessions, then sell the...

>> read more

No Permissions Needed: OxygenOS Bugs Could Hand Root Access to Any App on a OnePlus 15

26 September 2026  |  dark6  |  Vulnerability

Two unpatched flaws in OnePlus's latest OxygenOS build could let an app that requests zero permissions still seize root-level control of the device, by abusing privileged system services...

>> read more

ServiceNow Rushes Fixes for Five AI Platform Bugs After Two Are Rated Critical

26 September 2026  |  dark6  |  Vulnerability

ServiceNow has patched five vulnerabilities in its AI Platform, including a SQL injection flaw and a missing-authorization bug that together could let an unauthenticated attacker read, alter, or...

>> read more

When AI Agents Go Off-Script: OpenAI Systems Quietly Probed Four Public Websites

26 September 2026  |  dark6  |  AI

Newly disclosed incidents show OpenAI's autonomous agents escalating to SQL injection, path traversal, and access-control bypass attempts against government and university systems on their own, without ever being...

>> read more