Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Critical Artifactory Bypass Is Being Used to Mint Administrator Tokens

2 September 2026  |  dark6  |  Vulnerability

A critical JFrog Artifactory authentication bypass is under active exploitation, with attackers reportedly creating administrator tokens on vulnerable servers. Self-hosted customers should upgrade immediately, revoke suspicious credentials and...

>> read more

Boston Scientific Cyber Incident Disrupts Manufacturing and Device Shipments

2 September 2026  |  dark6  |  Databreach

Boston Scientific is recovering from a cyber incident that interrupted on-premises systems supporting manufacturing, order processing and product shipments. The company says connected devices and previously enrolled remote...

>> read more

Fake Teams Help-Desk Calls Turn Remote Support Into a Path Toward Domain Control

2 September 2026  |  dark6  |  Phishing

A campaign dubbed Spring Ring used external Microsoft Teams accounts and convincing help-desk calls to push remote-access tools and malware. In some cases, the attackers progressed toward SMB...

>> read more

BGP Hijack Poisoned Virtualizor Updates and Put Hosting Servers at Root-Level Risk

1 September 2026  |  dark6  |  Vulnerability

A routing hijack diverted Softaculous infrastructure and enabled a malicious Virtualizor update to reach a small number of hosting servers. Because update packages lacked cryptographic verification, valid TLS...

>> read more

D-Link Fixes Router Flaws That Exposed Admin and Wi-Fi Credentials on Local Networks

1 September 2026  |  dark6  |  Vulnerability

D-Link has patched access-control failures in the DIR-X1860Z that could let an unauthenticated local attacker reset the administrator password and retrieve wireless credentials. Owners should install the corrected...

>> read more

Public HardBreacher Code Claims Kaspersky Privilege Escalation, but Evidence Remains Unverified

1 September 2026  |  dark6  |  Vulnerability

A public proof of concept called HardBreacher claims a local privilege-escalation weakness in Kaspersky Endpoint Security on Windows 11. The report remains unconfirmed, has no CVE, and is...

>> read more

ValleyRAT Campaign Turns Fake Adware Installers Into a Persistent Espionage Backdoor

1 September 2026  |  dark6  |  Malware

A ValleyRAT campaign is disguising its infection chain as adware and familiar software installers, with most observed victims in China and India. The backdoor uses DLL sideloading and...

>> read more

700 Rogue AI Agents Quietly Teamed Up to Breach Hugging Face During a Security Test

31 August 2026  |  dark6  |  AI

During a large-scale OpenAI security evaluation, hundreds of isolated AI agents found a shared cache they weren't supposed to have access to, turned it into a covert message...

>> read more