Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Trojanized 7-Zip Installers Hide Downloaders Inside Extraction Code

30 September 2026  |  dark6  |  Malware

Researchers found malware loaders concealed inside modified 7-Zip self-extracting code, while a genuine application installer provided a convincing decoy. The technique can defeat reviews that inspect only extracted...

>> read more

North Korea-Linked Malware Uses Ethereum Transfers to Rotate Command Servers

30 September 2026  |  dark6  |  Spyware

A North Korea-linked campaign is encoding command-server locations in Ethereum recipient addresses, giving cross-platform malware a resilient recovery channel. The operation targets developers with fake recruitment tasks and...

>> read more

Octopus Server Deserialization Bug Opens Deployment Systems to Code Execution

30 September 2026  |  dark6  |  Vulnerability

A high-severity Octopus Server vulnerability lets sufficiently privileged authenticated users execute code through malicious JSON. There is no workaround, making upgrades urgent for self-hosted deployment environments that hold...

>> read more

OpenSSL DTLS Flaw Can Expose Heap Memory and Crash Network Services

30 September 2026  |  dark6  |  Vulnerability

OpenSSL has patched a high-severity DTLS flaw that can disclose adjacent heap data in plaintext or crash an affected process. Organizations should locate both system and bundled OpenSSL...

>> read more

Knockoff ‘Jev AI’ Storefronts Are Charging Up to 11x Markup — And Quietly Routing Your Prompts Through Someone Else’s Servers

29 September 2026  |  dark6  |  Phishing

Within days of the Jev AI model's public launch, scammers registered lookalike storefronts that resell legitimate API access at inflated prices while funneling every prompt through third-party infrastructure...

>> read more

A Cybercrime Crew’s Automated Hacking Platform Was Left Exposed — And So Was Its Entire Playbook

29 September 2026  |  dark6  |  Cybercrime

Threat hunters at ThreatMon stumbled onto an unsecured server tied to a group linked to Blackhatsect0r, exposing more than 16,000 stolen credentials, nearly half a million target URLs,...

>> read more

Researchers Turn Everyday File-Change Alerts Into a Silent Spy Tool on Every Major OS

29 September 2026  |  dark6  |  Privacy

Academic researchers have shown that the routine file-notification systems built into Linux, Windows, and macOS can be abused to track keystrokes, browsing habits, and more — with no...

>> read more

SharePoint Code-Injection Bug Joins CISA’s Must-Patch List After Real-World Attacks

29 September 2026  |  dark6  |  Vulnerability

CISA has added a Microsoft SharePoint code-injection flaw, CVE-2026-65660, to its Known Exploited Vulnerabilities catalog after confirming it is being used in live attacks. The agency gave federal...

>> read more