Secure Bulletin Navigating the cyber sea with knowledge
Home > Categoria > Vulnerability
Latest news

Unauthenticated Attackers Are Actively Exploiting a ServiceNow Sandbox-Escape Flaw

22 July 2026  |  dark6  |  Vulnerability

A critical ServiceNow vulnerability that lets unauthenticated attackers break out of the platform's scripting sandbox is now being exploited in the wild. ServiceNow has shipped patches, but self-hosted...

>> read more

New Windows ‘Bind Link’ Trick Lets Attackers Fool EDR, AMSI, and AppLocker Without Touching a File

21 July 2026  |  dark6  |  Vulnerability

Bitdefender researchers have detailed how Windows 'bind links' — a legitimate feature behind containers and Sandbox — can be abused by an attacker with local admin rights to...

>> read more

Decade-Old NGINX Bug Finally Exposed: A Single Regex Quirk Enables Remote Code Execution

20 July 2026  |  dark6  |  Vulnerability

A remote code execution flaw that has quietly lived inside nginx's script engine since 2011 has finally come to light, tracked as CVE-2026-42533. Researchers say a single malicious...

>> read more

wp2shell: The WordPress Core Bug That Lets Anyone Take Over 500 Million Sites Without Logging In

20 July 2026  |  dark6  |  Vulnerability

A newly disclosed WordPress Core vulnerability, nicknamed wp2shell, chains a REST API batch-route flaw into full unauthenticated remote code execution. No plugins, no login, and no special configuration...

>> read more

HollowByte: How 11 Bytes Can Quietly Starve an OpenSSL Server to Death

20 July 2026  |  dark6  |  Vulnerability

A newly disclosed OpenSSL weakness, dubbed HollowByte, lets an unauthenticated attacker trigger a slow, memory-fragmenting denial-of-service condition using a payload as small as 11 bytes. Because it was...

>> read more

This Week’s Threat Landscape: Patch Tuesday’s 570 Fixes, an Active Directory Zero-Day, and AI Tools Under Fire

20 July 2026  |  dark6  |  Vulnerability

A packed week in cybersecurity saw Microsoft ship roughly 570 patches including two actively exploited zero-days, a WordPress RCE bug threatening hundreds of millions of sites, and a...

>> read more

Citrix Patches Privilege Escalation Flaw That Hands Standard Users Full SYSTEM Control

19 July 2026  |  dark6  |  Vulnerability

Cloud Software Group has disclosed two vulnerabilities in Citrix Secure Access and Endpoint Analysis clients for Windows, including a high-severity flaw (CVSS 8.5) that lets a low-privileged local...

>> read more

Unpatched LegacyHive Bug Lets Standard Windows Users Hijack Admin Accounts

18 July 2026  |  dark6  |  Vulnerability

A newly disclosed Windows zero-day called LegacyHive abuses the User Profile Service to let a low-privileged user tamper with an administrator's registry hive, opening a path to persistence...

>> read more