# Secure Bulletin: Navigating the cyber sea with knowledge Generated by Yoast SEO v28.2, this is an llms.txt file, meant for consumption by LLMs. ## Pages - [Posts](https://securebulletin.com/posts/) - [Home](https://securebulletin.com/homepage/) - [Pin Posts](https://securebulletin.com/be-pin-posts-2/) - [Privacy Policy](https://securebulletin.com/privacy-policy/) - [Contact Us](https://securebulletin.com/contact-us/) ## Posts - [Red Hat Patches Kubernetes Flaw That Let Developers Seize Full Cluster\-Admin Rights](https://securebulletin.com/red-hat-patches-kubernetes-flaw-that-let-developers-seize-full-cluster-admin-rights/): A critical privilege escalation vulnerability in Red Hat Advanced Cluster Management, tracked as CVE\-2026\-10090 and rated 9\.9 in severity, allowed any user with basic namespace\-level edit permissions to escalate to full cluster\-admin access across an entire fleet of managed Kubernetes clusters\. The bug directly undermines ACM's documented multi\-tenant security model\. - [CISA Flags Actively Exploited Progress LoadMaster Flaw Rated 9\.6 in Severity](https://securebulletin.com/cisa-flags-actively-exploited-progress-loadmaster-flaw-rated-9-6-in-severity/): CISA has added an unauthenticated command injection vulnerability in Progress LoadMaster and ADC appliances, tracked as CVE\-2026\-8037, to its Known Exploited Vulnerabilities catalog after security researchers observed active scanning and exploitation attempts\. Federal civilian agencies were given until August 10, 2026 to patch the near\-maximum\-severity flaw\. - [New "Pass\-the\-Passkey" Technique Shows How Windows 11 Logs Undermined Phishing\-Resistant MFA](https://securebulletin.com/new-pass-the-passkey-technique-shows-how-windows-11-logs-undermined-phishing-resistant-mfa/): Security researchers at SpecterOps have detailed a family of attacks called Pass\-the\-Passkey that exploit how Windows 11 logged WebAuthn authentication data and how Microsoft Entra ID validated it, letting attackers replay captured assertions to impersonate privileged cloud accounts without ever touching a private key\. Microsoft patched the core issue, tracked as CVE\-2026\-34348, in its July 2026 update\. - [Gunra Ransomware Gang Turns Fortinet VPN Bugs Into a Backdoor Around MFA](https://securebulletin.com/gunra-ransomware-gang-turns-fortinet-vpn-bugs-into-a-backdoor-around-mfa/): A joint advisory from the FBI, CISA, NSA, and South Korean authorities warns that the Gunra ransomware operation is exploiting known Fortinet VPN flaws to sidestep multi\-factor authentication and steal enterprise data before encrypting networks\. The group, now allegedly rebranding as "Golden Community," has grown into a full ransomware\-as\-a\-service operation built on leaked Conti code\. - [Hackers Are Turning Plain CSS Into Keyloggers Hidden Inside Everyday Emails](https://securebulletin.com/hackers-are-turning-plain-css-into-keyloggers-hidden-inside-everyday-emails/): Security researcher Gareth Heyes has demonstrated that ordinary CSS styling code, not JavaScript or malware, can be weaponized to hijack webmail interfaces and capture passwords keystroke by keystroke\. The technique, dubbed 'CSS bomb,' has already been proven against Gmail, Outlook, Yahoo Mail, and other major providers\. ## Categories - [Vulnerability](https://securebulletin.com/category/vulnerability/) - [Malware](https://securebulletin.com/category/malware/) - [Ransomware](https://securebulletin.com/category/ransomware/) - [Databreach](https://securebulletin.com/category/databreach/) - [Cybercrime](https://securebulletin.com/category/cybercrime/) ## Tags - [cybersecurity](https://securebulletin.com/tag/cybersecurity/) - [malware](https://securebulletin.com/tag/malware/) - [vulnerability](https://securebulletin.com/tag/vulnerability/) - [ransomware](https://securebulletin.com/tag/ransomware/) - [data breach](https://securebulletin.com/tag/data-breach/) ## Optional - [Sitemap index](https://securebulletin.com/sitemap_index.xml)