Secure Bulletin Navigating the cyber sea with knowledge
Home > Categoria > Vulnerability
Latest news

Security Teams Face a Week of Zero-Days, Router Intrusions and AI-Accelerated Attacks

8 September 2026  |  dark6  |  Vulnerability

A packed week of security disclosures combined active browser and commerce exploitation with router espionage, identity failures and faster AI-assisted intrusions. Defenders should use the converging signals to...

>> read more

Critical ASUS Control Center Chain Opens Managed Fleets to Root Takeover

8 September 2026  |  dark6  |  Vulnerability

A CVSS 10.0 flaw chain in ASUS Control Center Enterprise can reportedly give an unauthenticated network attacker a root shell and control of centrally managed devices. Organizations should...

>> read more

MikroTik RouterOS Flaw Under Active Attack Grants Unauthenticated Shell Access

8 September 2026  |  dark6  |  Vulnerability

Attackers are exploiting a RouterOS weakness that can reportedly provide unauthenticated shell access through exposed services, including SSH. MikroTik users should install the fixed releases now, audit every...

>> read more

Roundcube Patches a Dozen Flaws, Including a Zero-Click Webmail XSS and an IPv6-Based SSRF Bypass

8 September 2026  |  dark6  |  Vulnerability

The Roundcube team has shipped versions 1.6.19 and 1.7.4 to close twelve security holes, headlined by a stored cross-site scripting bug that fires the moment a crafted email...

>> read more

Google Rushes Emergency Chrome Patch as Attackers Exploit V8 Zero-Day

5 September 2026  |  dark6  |  Vulnerability

Google has pushed an emergency Chrome update after confirming that a type confusion flaw in the V8 engine, tracked as CVE-2026-85046, is being actively exploited in the wild....

>> read more

TP-Link Patches Archer AX55 Flaws Enabling Code Execution and Password Theft

5 September 2026  |  dark6  |  Vulnerability

TP-Link has fixed two Archer AX55 v4 vulnerabilities affecting EasyMesh and web login security. A local attacker could crash or potentially take over the router, while captured HTTP...

>> read more

Attackers Are Already Probing a Critical Flaw in Sangoma’s Switchvox VoIP Platform

4 September 2026  |  dark6  |  Vulnerability

A critical, unauthenticated SQL injection flaw in Sangoma Switchvox is being actively probed in the wild just weeks after a patch became available. With thousands of phone systems...

>> read more

A Popular WordPress Backup Plugin’s Flaw Puts 5 Million Sites One Restore Away From Takeover

4 September 2026  |  dark6  |  Vulnerability

A high-severity SQL injection flaw in the All-in-One WP Migration and Backup plugin, installed on more than five million WordPress sites, can be triggered through the platform's own...

>> read more