Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Leaked AWS Administrator Key Fuels Costly LLMjacking Through Bedrock and Marketplace

4 September 2026  |  dark6  |  Cybercrime

A leaked AWS IAM key with administrator privileges allowed an attacker to create a new identity, activate premium AI models and bill inference usage to the victim. The...

>> read more

Phantom Deal Fraud Uses Fake M&A Secrecy to Push a €626,000 Wire Transfer

4 September 2026  |  dark6  |  Phishing

The Phantom Deal campaign impersonates executives and advisers, then uses a polished NDA to isolate employees from normal approval channels. One documented attempt sought a €626,735.45 transfer and...

>> read more

QR-Code Phishing Reaches Record Levels as Attackers Shift Credential Theft to Phones

4 September 2026  |  dark6  |  Phishing

ESET says QR-code phishing accounted for about 11% of detected phishing email in the first half of 2026, with roughly 100,000 detections per month. By moving victims from...

>> read more

Attackers Are Already Probing a Critical Flaw in Sangoma’s Switchvox VoIP Platform

4 September 2026  |  dark6  |  Vulnerability

A critical, unauthenticated SQL injection flaw in Sangoma Switchvox is being actively probed in the wild just weeks after a patch became available. With thousands of phone systems...

>> read more

Inside ‘The Gentlemen’: The Ransomware Operation That Can Take Down a Network Before Lunch

4 September 2026  |  dark6  |  Ransomware

A ransomware-as-a-service operation dubbed 'The Gentlemen' by researchers is compromising networks and detonating encryption in as little as 24 hours, methodically disabling backups and security tooling before attackers...

>> read more

A Popular WordPress Backup Plugin’s Flaw Puts 5 Million Sites One Restore Away From Takeover

4 September 2026  |  dark6  |  Vulnerability

A high-severity SQL injection flaw in the All-in-One WP Migration and Backup plugin, installed on more than five million WordPress sites, can be triggered through the platform's own...

>> read more

Critical VMware Workstation and Fusion Bugs Let Attackers Break Out of the Virtual Machine

4 September 2026  |  dark6  |  Vulnerability

Broadcom has patched two vulnerabilities in VMware Workstation and Fusion that allow an attacker with access to a guest virtual machine to execute code on the underlying host,...

>> read more

GitSpawn Turns Booby-Trapped Repositories Into Silent Code Execution Across AI Coding Tools

3 September 2026  |  dark6  |  Vulnerability

GitSpawn weaknesses allow specially prepared project folders to execute local commands when AI coding agents perform routine Git checks. Several vendors have patched variants, but researchers say four...

>> read more