Secure Bulletin Navigating the cyber sea with knowledge
Home > Categoria > Vulnerability
Latest news

JetBrains Patches a Wave of Critical Flaws Across IntelliJ IDEA and TeamCity

27 July 2026  |  dark6  |  Vulnerability

JetBrains has released fixes for a critical remote-code-execution flaw in IntelliJ IDEA and four high-severity vulnerabilities in TeamCity, including a critical RCE reachable through malicious Git repository configuration....

>> read more

AI-Powered Pentest Uncovers Eight Security Holes in Popular NodeBB Forum Software

27 July 2026  |  dark6  |  Vulnerability

A whitebox penetration test assisted by AI tools found eight high-severity flaws in the NodeBB forum platform, including bugs that could let attackers read private messages, hijack admin...

>> read more

How a Crafted SVG File Could Have Handed Attackers SYSTEM Access on Microsoft’s Bing Servers

25 July 2026  |  dark6  |  Vulnerability

Three critical, now-patched vulnerabilities in Microsoft's infrastructure show how an everyday image upload feature in Bing Images became a path to remote code execution as NT AUTHORITY\SYSTEM. Researchers...

>> read more

Certighost Flaw Let Ordinary Users Impersonate Domain Controllers and Seize Active Directory

25 July 2026  |  dark6  |  Vulnerability

A newly patched Active Directory Certificate Services bug, dubbed Certighost, let any low-privileged domain user trick a certificate authority into treating a rogue machine as a real Domain...

>> read more

Next.js Ships Emergency Fixes for Nine Flaws, Including High-Severity SSRF and Auth Bypass Bugs

24 July 2026  |  dark6  |  Vulnerability

Vercel has patched nine security vulnerabilities in Next.js, the widely used React framework, covering server-side request forgery, a middleware authentication bypass, denial-of-service conditions, and data-exposure issues. Four of...

>> read more

ASUS Rushes Out Router Patch After Discovery of Unauthenticated Remote Command Execution Flaw

23 July 2026  |  dark6  |  Vulnerability

ASUS has issued firmware updates for a high-severity vulnerability, tracked as CVE-2026-13385, that could let remote attackers run arbitrary commands on widely deployed router models without authentication. Security...

>> read more

RefluXFS: A Nine-Year-Old Race Condition in Linux’s XFS Filesystem Opens a Silent Road to Root

23 July 2026  |  dark6  |  Vulnerability

Qualys researchers have disclosed RefluXFS (CVE-2026-64600), a race condition in the Linux kernel's XFS copy-on-write path that lets a local, unprivileged user seize root access while leaving no...

>> read more

Chrome’s Latest Patch Closes 12 Security Holes, Nine of Them Rated High Severity

22 July 2026  |  dark6  |  Vulnerability

Google has shipped a new Stable Chrome release fixing 12 vulnerabilities, nine of them high severity, touching core components like V8, ANGLE, and the GPU stack. Several of...

>> read more