Latest news

CVE-2026-39987: Critical Marimo Python Notebook RCE Exploited Within 10 Hours of Disclosure
Vulnerability

CVE-2026-39987: Critical Marimo Python Notebook RCE Exploited Within 10 Hours of Disclosure

11 April 2026 dark6

A pre-authentication remote code execution flaw (CVSS 9.3) in the Marimo Python notebook framework was weaponized by attackers within just...
Windows Zero-Day “BlueHammer” Exploit Code Released — SYSTEM Privileges at Risk
Vulnerability

Windows Zero-Day “BlueHammer” Exploit Code Released — SYSTEM Privileges at Risk

10 April 2026 dark6

Exploit code has been publicly released for BlueHammer, a Windows zero-day privilege escalation vulnerability that allows attackers to gain full...
Critical Fortinet FortiClient EMS Zero-Day CVE-2026-35616 Actively Exploited — Patch Now
Vulnerability

Critical Fortinet FortiClient EMS Zero-Day CVE-2026-35616 Actively Exploited — Patch Now

10 April 2026 dark6

A critical zero-day in Fortinet FortiClient EMS (CVE-2026-35616, CVSS 9.8) is being actively exploited in the wild. CISA has added...
CVSS 10.0: Critical Flowise AI Vulnerability Is Being Actively Exploited — 15,000+ Instances Still Exposed
AI

CVSS 10.0: Critical Flowise AI Vulnerability Is Being Actively Exploited — 15,000+ Instances Still Exposed

9 April 2026 dark6

A maximum-severity RCE vulnerability (CVE-2025-59528, CVSS 10.0) in the popular Flowise AI agent builder is under active attack. Over 15,000...
Chrome’s Fourth Zero-Day of 2026: CISA Orders Federal Agencies to Patch CVE-2026-5281 by April 15
Vulnerability

Chrome’s Fourth Zero-Day of 2026: CISA Orders Federal Agencies to Patch CVE-2026-5281 by April 15

9 April 2026 dark6

Google has patched CVE-2026-5281, a use-after-free zero-day in Chrome’s WebGPU engine already exploited in the wild. It’s the fourth Chrome...
Unpatched Adobe Reader Zero-Day Has Been Silently Exploiting Users Since December
Vulnerability

Unpatched Adobe Reader Zero-Day Has Been Silently Exploiting Users Since December

9 April 2026 dark6

A highly sophisticated zero-day exploit targeting Adobe Reader has been active since December 2025, requiring just a single click to...
GitLab Releases Critical Security Patch for Multiple High-Severity Vulnerabilities
Vulnerability

GitLab Releases Critical Security Patch for Multiple High-Severity Vulnerabilities

11 December 2025 dark6

Security researchers have uncovered vulnerabilities in GitLab’s Community Edition and Enterprise Edition platforms, prompting the company to release critical security...
A Critical Patch for Vulnerable Next.js: New Scanner Unveils Hidden Attacks
Vulnerability

A Critical Patch for Vulnerable Next.js: New Scanner Unveils Hidden Attacks

4 December 2025 dark6

With the rise of Serverless functions, static site generators like Next.js have become ubiquitous in web development, streamlining functionality and...
A Silent Vulnerability Exposed: How Hackers Used Hidden Commands to Steal Sensitive Data
Vulnerability

A Silent Vulnerability Exposed: How Hackers Used Hidden Commands to Steal Sensitive Data

3 December 2025 dark6

Microsoft’s seemingly “unremarkable” November 2025 Patch Tuesday update actually contained a major security fix. But even the most meticulous patching...
Chrome 143: A Patch Day For Deep Dive Cybersecurity Professionals
Vulnerability

Chrome 143: A Patch Day For Deep Dive Cybersecurity Professionals

3 December 2025 dark6

Google has just released Chrome 143, ushering in a new era of browser security with 13 addressed vulnerabilities. This release...
Android’s December Patch: Zero-Day Vulnerabilities and Their Impact
Vulnerability

Android’s December Patch: Zero-Day Vulnerabilities and Their Impact

2 December 2025 dark6

The latest security bulletin from Google has brought forth a grim reality for Android users: multiple zero-day vulnerabilities are actively...
A Critical Design Flaws in Microsoft Azure API Management Threatens Organizations
Vulnerability

A Critical Design Flaws in Microsoft Azure API Management Threatens Organizations

1 December 2025 dark6

Microsoft’s Azure API Management (APIM) Developer Portal, a platform commonly used for managing and securing APIs, is vulnerable to a...