Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Mantax Otax Android Ransomware Adds Screen Spying, OTP Theft and Covert Photos

12 September 2026  |  dark6  |  Ransomware

New Android malware called Mantax Otax combines file encryption with surveillance, credential theft, screen recording and covert camera access. The campaign relies on sideloaded APKs and appears focused...

>> read more

Critical CSF Flaw Exposes cPanel Servers to Unauthenticated Command Execution

12 September 2026  |  dark6  |  Vulnerability

A critical flaw in ConfigServer Security & Firewall can let remote attackers execute commands through its optional MESSENGER service without logging in. Administrators using CSF 14.00 through 16.29...

>> read more

CISA Flags CVSS 10 GitLab File-Read Flaw Under Active Attack

12 September 2026  |  dark6  |  Vulnerability

CISA says attackers are exploiting a critical GitLab path-traversal vulnerability that can expose arbitrary server files without authentication. Organizations should patch immediately, review access logs, and treat exposed...

>> read more

State-Backed Hackers Exploit Cisco Firewall Flaws for Root Access and Malware Deployment

11 September 2026  |  dark6  |  Vulnerability

Attackers are actively abusing two Cisco Secure Firewall Management Center vulnerabilities, including a maximum-severity authentication bypass. Cisco says state-sponsored operators and a ransomware affiliate have used the flaws...

>> read more

CISA Adds Exploited Citrix NetScaler Authentication Bypass to Urgent Fix List

11 September 2026  |  dark6  |  Vulnerability

CISA has added CVE-2026-19490, a critical Citrix NetScaler authentication bypass, to its Known Exploited Vulnerabilities catalog. Internet-facing ADC and Gateway deployments supporting remote access should apply Citrix updates...

>> read more

Claude Misuse Report Shows AI Agents Automating Exploits, Malware Changes and Intrusions

11 September 2026  |  dark6  |  AI

Anthropic says state-backed groups, cybercriminals and hacktivists misused Claude to automate attack chains, develop exploits and adapt malware. The cases show that AI agents can compress specialist work...

>> read more

Phishing Campaign Builds Fake Login Pages Inside Browsers After Trusted Microsoft Redirects

11 September 2026  |  dark6  |  Phishing

A phishing campaign chains DocuSign-themed calendar invitations, Microsoft redirects and browser blob URLs to display credential-stealing pages assembled in local memory. The method reduces reliance on a conventional...

>> read more

AI Agent Swarm Exploits PaperCut Flaws Across 440 Servers Worldwide

10 September 2026  |  dark6  |  Vulnerability

A Russian-speaking operator used hundreds of autonomous AI agents to compromise 440 PaperCut servers across 48 countries. Although only a fraction reached domain administrator, the campaign shows how...

>> read more