Secure Bulletin Navigating the cyber sea with knowledge
Home > Categoria > Vulnerability
Latest news

Public HardBreacher Code Claims Kaspersky Privilege Escalation, but Evidence Remains Unverified

1 September 2026  |  dark6  |  Vulnerability

A public proof of concept called HardBreacher claims a local privilege-escalation weakness in Kaspersky Endpoint Security on Windows 11. The report remains unconfirmed, has no CVE, and is...

>> read more

AI Gateways Under Fire: Attackers Chain LiteLLM and MCP Flaws for Remote Code Execution

31 August 2026  |  dark6  |  Vulnerability

A 90-day honeypot study shows attackers systematically probing AI proxies, MCP servers, and agent frameworks like LangChain and Langflow, chaining authentication bypass and command-injection bugs into remote code...

>> read more

Critical ServiceNow AI Flaws Expose Enterprise Data and Code Execution Paths

29 August 2026  |  dark6  |  Vulnerability

ServiceNow has patched three critical AI-platform vulnerabilities and a high-severity Now Platform sandbox escape. Self-hosted customers should urgently verify fixed releases and investigate signs of unauthorized code execution...

>> read more

UniBLEed Flaws Put Unitree G1 Humanoid Robots at Risk of Root Takeover

29 August 2026  |  dark6  |  Vulnerability

Researchers demonstrated a multi-stage attack that can give a nearby adversary root-level control of Unitree G1 humanoid robots. The UniBLEed chain combines unauthenticated Bluetooth writes, a cloud authorization...

>> read more

Emergency PaperCut Fix Targets Actively Exploited Flaw Affecting Every Supported Release

28 August 2026  |  dark6  |  Vulnerability

PaperCut has issued emergency builds after confirming real-world attacks against PaperCut NG and MF servers. Administrators should isolate internet-facing application servers, install the appropriate update and investigate for...

>> read more

Critical Veeam ONE Flaw Lets Unauthenticated Attackers Steal Backup Credentials (CVSS 9.3)

28 August 2026  |  dark6  |  Vulnerability

A newly disclosed flaw in Veeam ONE, tracked as CVE-2026-65641 with a CVSS score of 9.3, lets a remote attacker with no credentials trick the monitoring service into...

>> read more

CISA Orders Rapid Action as Citrix NetScaler Flaw Is Exploited in the Wild

28 August 2026  |  dark6  |  Vulnerability

CISA has placed CVE-2026-8452 in its Known Exploited Vulnerabilities catalog following confirmed attacks against Citrix NetScaler products. The memory-safety flaw can disrupt critical gateway services, and organizations should...

>> read more

Old Microsoft SQL Server RCE Returns in Active Attacks, Triggering CISA Forensic Mandate

28 August 2026  |  dark6  |  Vulnerability

CISA says attackers are exploiting CVE-2019-1068, a Microsoft SQL Server remote-code execution flaw, and has ordered both remediation and forensic triage. Database owners should patch exposed systems, review...

>> read more