Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Booking.com Notifies Customers of Data Breach Exposing Reservation Details and Personal Information

22 April 2026  |  dark6  |  Databreach

Booking.com has notified customers of a data breach that exposed personal information including full names, addresses, phone numbers, email addresses, and detailed reservation data. The breach originated from...

>> read more

Critical Fortinet FortiClient EMS Zero-Day CVE-2026-35616 Exploited Before Official Patch Was Released

22 April 2026  |  dark6  |  Vulnerability

A critical SQL injection zero-day in Fortinet's FortiClient EMS (CVE-2026-35616) is being actively exploited in the wild. WatchTowr sensors detected attacks four days before Fortinet's advisory, with exploitation...

>> read more

Windows Defender Triple Zero-Day: BlueHammer, RedSun, and UnDefend Actively Exploited in the Wild

22 April 2026  |  dark6  |  Vulnerability

Three critical zero-day vulnerabilities — BlueHammer (CVE-2026-33825), RedSun, and UnDefend — have been discovered in Windows Defender's remediation engine. All three allow local privilege escalation to SYSTEM level...

>> read more

Cisco Patches Four Critical Flaws in Identity Services Engine and Webex: Unauthenticated RCE and Full User Impersonation at Risk

21 April 2026  |  dark6  |  Vulnerability

Cisco has patched four critical vulnerabilities in Identity Services Engine (ISE) and Webex, including an unauthenticated remote code execution flaw in ISE and an authentication bypass in Webex...

>> read more

Inditex (Zara) Confirms Third-Party Data Breach: Transaction Records Exposed via Analytics Platform with April 21 Leak Deadline

21 April 2026  |  dark6  |  Databreach

Inditex, owner of Zara and Bershka, has confirmed a data breach affecting transaction records accessed via a third-party analytics platform, Anodot. Hackers set an April 21 deadline, threatening...

>> read more

Critical CVE-2026-33032 (MCPwn): Actively Exploited nginx-ui Flaw Enables Full Web Server Takeover in Two HTTP Requests

21 April 2026  |  dark6  |  Vulnerability

CVE-2026-33032 (MCPwn) is a CVSS 9.8 authentication bypass in nginx-ui being actively exploited in the wild. Attackers can seize full control of Nginx web servers in two HTTP...

>> read more

ShinyHunters Sets April 21 Deadline for Canada Life Assurance: 5.6 Million Salesforce Records at Risk

21 April 2026  |  dark6  |  Databreach

ShinyHunters claims to have breached Canada Life Assurance Company, stealing over 5.6 million Salesforce records containing PII. The group set a ransom deadline of April 21, 2026, threatening...

>> read more

Omnistealer Malware Uses Blockchain Permanence to Host Unremovable Payloads, Compromising 300,000 Credentials

20 April 2026  |  dark6  |  Malware

A sophisticated new infostealer dubbed Omnistealer embeds its payloads directly into public blockchain transactions on TRON, Aptos, and Binance Smart Chain — making its infrastructure immune to takedowns....

>> read more