Secure Bulletin Navigating the cyber sea with knowledge
Home > Categoria > Vulnerability
Latest news

New WordPress Flaw Turns a Failed Login Attempt Into Full Server Takeover

9 August 2026  |  dark6  |  Vulnerability

A newly disclosed WordPress vulnerability, dubbed XSS2Shell and tracked as CVE-2026-64638, chains a decade-old parsing quirk in the login page into full remote code execution, putting an estimated...

>> read more

18-Year-Old Linux Kernel Bug Lets Attackers Seize Full Root and Break Out of Containers

9 August 2026  |  dark6  |  Vulnerability

A newly disclosed use-after-free vulnerability nicknamed SCTPhantom, tracked as CVE-2026-64564, traces back to Linux kernel code written in 2007 and lets a local attacker escalate to full root...

>> read more

Researchers Find Matching RCE Flaws in Claude Code, Gemini CLI and Codex Coding Agents

9 August 2026  |  dark6  |  Vulnerability

Security researcher Elad Meged has uncovered a strikingly similar vulnerability pattern across AI coding agents from Anthropic, Google, and OpenAI, all traceable to how each vendor's surrounding 'harness'...

>> read more

Thousands of Exposed Rockwell PLCs Leave US Water Utilities Open After Multi-State Attack Wave

8 August 2026  |  dark6  |  Vulnerability

A wave of attacks against U.S. water and wastewater utilities has renewed scrutiny of how many industrial controllers sit exposed to the open internet. Forescout researchers count over...

>> read more

Cisco Rushes Fixes for Near-Maximum-Severity Flaws in Catalyst SD-WAN

6 August 2026  |  dark6  |  Vulnerability

Cisco has patched five vulnerabilities in Catalyst SD-WAN Software, three of them scoring 9.9 out of 10 on the CVSS scale. There is no evidence of active exploitation...

>> read more

One Click, Total Takeover: The RCE Bug That Hid Inside Cursor, VS Code, and Google Antigravity

5 August 2026  |  dark6  |  Vulnerability

Security researchers at AISLE uncovered a one-click remote code execution flaw shared by Cursor, Microsoft VS Code, and Google Antigravity, all three built on the same underlying codebase....

>> read more

Six Ways to Break Flowise: New RCE Chain Puts AI Workflow Servers at Risk

5 August 2026  |  dark6  |  Vulnerability

Security researchers at Elttam disclosed six separate remote code execution flaws in the Flowise AI workflow platform, spanning CSV processing, sandboxed JavaScript, and database configuration. Several of the...

>> read more

SolarWinds Patches Critical Authentication Bypass That Could Unlock Help Desk Portals Without a Login

4 August 2026  |  dark6  |  Vulnerability

SolarWinds has fixed a critical, CVSS 9.8-rated flaw in Web Help Desk that could let attackers bypass SAML single sign-on entirely. Organizations running SAML-based SSO on the platform...

>> read more