Secure Bulletin Navigating the cyber sea with knowledge
Home > Categoria > Vulnerability
Latest news

New Outlook Flaw Lets Attackers Run Malicious Code Through a Single Booby-Trapped Email Attachment

14 August 2026  |  dark6  |  Vulnerability

Microsoft has patched a high-severity remote code execution flaw in Outlook, tracked as CVE-2026-70329, that can be triggered when a victim opens a specially crafted Office file. The...

>> read more

Red Hat Patches Kubernetes Flaw That Let Developers Seize Full Cluster-Admin Rights

11 August 2026  |  dark6  |  Vulnerability

A critical privilege escalation vulnerability in Red Hat Advanced Cluster Management, tracked as CVE-2026-10090 and rated 9.9 in severity, allowed any user with basic namespace-level edit permissions to...

>> read more

CISA Flags Actively Exploited Progress LoadMaster Flaw Rated 9.6 in Severity

11 August 2026  |  dark6  |  Vulnerability

CISA has added an unauthenticated command injection vulnerability in Progress LoadMaster and ADC appliances, tracked as CVE-2026-8037, to its Known Exploited Vulnerabilities catalog after security researchers observed active...

>> read more

New “Pass-the-Passkey” Technique Shows How Windows 11 Logs Undermined Phishing-Resistant MFA

11 August 2026  |  dark6  |  Vulnerability

Security researchers at SpecterOps have detailed a family of attacks called Pass-the-Passkey that exploit how Windows 11 logged WebAuthn authentication data and how Microsoft Entra ID validated it,...

>> read more

Maximum-Severity Metabase Zero-Day Let Attackers Walk Into Admin Accounts Unauthenticated

10 August 2026  |  dark6  |  Vulnerability

A CVSS 10.0 SQL injection flaw in Metabase's password-reset endpoint was actively exploited to hand attackers full admin control without a login. Metabase Cloud was breached before a...

>> read more

Zapscape Flaw Lets a Rogue Cloud Virtual Machine Seize Root on Its Host Server

9 August 2026  |  dark6  |  Vulnerability

A Linux kernel vulnerability nicknamed Zapscape and tracked as CVE-2026-64561 allows a malicious KVM guest running nested virtualization to escape its virtual machine entirely and take root control...

>> read more

New WordPress Flaw Turns a Failed Login Attempt Into Full Server Takeover

9 August 2026  |  dark6  |  Vulnerability

A newly disclosed WordPress vulnerability, dubbed XSS2Shell and tracked as CVE-2026-64638, chains a decade-old parsing quirk in the login page into full remote code execution, putting an estimated...

>> read more

18-Year-Old Linux Kernel Bug Lets Attackers Seize Full Root and Break Out of Containers

9 August 2026  |  dark6  |  Vulnerability

A newly disclosed use-after-free vulnerability nicknamed SCTPhantom, tracked as CVE-2026-64564, traces back to Linux kernel code written in 2007 and lets a local attacker escalate to full root...

>> read more