Secure Bulletin Navigating the cyber sea with knowledge
Home > Categoria > Vulnerability
Latest news

Critical VMware Workstation and Fusion Bugs Let Attackers Break Out of the Virtual Machine

4 September 2026  |  dark6  |  Vulnerability

Broadcom has patched two vulnerabilities in VMware Workstation and Fusion that allow an attacker with access to a guest virtual machine to execute code on the underlying host,...

>> read more

GitSpawn Turns Booby-Trapped Repositories Into Silent Code Execution Across AI Coding Tools

3 September 2026  |  dark6  |  Vulnerability

GitSpawn weaknesses allow specially prepared project folders to execute local commands when AI coding agents perform routine Git checks. Several vendors have patched variants, but researchers say four...

>> read more

New WhatsApp Video Call Trick Bypasses Android Lock Screens to Expose Your Photos

3 September 2026  |  dark6  |  Vulnerability

A newly disclosed WhatsApp flaw lets anyone answer a video call on a locked Android phone and, through the in-call background editor, browse the device's entire photo gallery...

>> read more

High-Severity Cleo Harmony Bug Lets Attackers Forge Their Way to Admin Access

3 September 2026  |  dark6  |  Vulnerability

A high-severity flaw in Cleo Harmony's JWT refresh-token handling, tracked as CVE-2026-84115, lets remote attackers escalate privileges to admin level with a working exploit already public. Cleo has...

>> read more

Attackers Exploit Critical Langflow and Rails Flaws to Hunt Cloud Secrets

2 September 2026  |  dark6  |  Vulnerability

Attackers are actively exploiting critical flaws in Langflow and Ruby on Rails, with observed activity focused on credentials, application secrets and paths to remote code execution. Defenders should...

>> read more

Critical Artifactory Bypass Is Being Used to Mint Administrator Tokens

2 September 2026  |  dark6  |  Vulnerability

A critical JFrog Artifactory authentication bypass is under active exploitation, with attackers reportedly creating administrator tokens on vulnerable servers. Self-hosted customers should upgrade immediately, revoke suspicious credentials and...

>> read more

BGP Hijack Poisoned Virtualizor Updates and Put Hosting Servers at Root-Level Risk

1 September 2026  |  dark6  |  Vulnerability

A routing hijack diverted Softaculous infrastructure and enabled a malicious Virtualizor update to reach a small number of hosting servers. Because update packages lacked cryptographic verification, valid TLS...

>> read more

D-Link Fixes Router Flaws That Exposed Admin and Wi-Fi Credentials on Local Networks

1 September 2026  |  dark6  |  Vulnerability

D-Link has patched access-control failures in the DIR-X1860Z that could let an unauthenticated local attacker reset the administrator password and retrieve wireless credentials. Owners should install the corrected...

>> read more