Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Next.js Ships Emergency Fixes for Nine Flaws, Including High-Severity SSRF and Auth Bypass Bugs

24 July 2026  |  dark6  |  Vulnerability

Vercel has patched nine security vulnerabilities in Next.js, the widely used React framework, covering server-side request forgery, a middleware authentication bypass, denial-of-service conditions, and data-exposure issues. Four of...

>> read more

Chaos Ransomware’s New msaRAT Tool Hijacks Chrome and Edge as a Stealth Command Channel

24 July 2026  |  dark6  |  Ransomware

Cisco Talos has identified msaRAT, a Rust-based tool tied to the Chaos ransomware group that quietly launches Chrome or Edge in headless mode and turns the browser into...

>> read more

Sloppy Server Configuration Unmasks JadeProx Espionage Campaign and Its TriBack Malware Loader

24 July 2026  |  dark6  |  Malware

Researchers at Group-IB stumbled onto an active espionage operation, now tracked as JadeProx, after its operators left a staging server's directory listing wide open. The exposed files revealed...

>> read more

Alleged 160-Million-Record Decathlon Customer Database Surfaces on Cybercrime Forum

24 July 2026  |  dark6  |  Databreach

A threat actor is advertising what they claim is a Decathlon customer database of roughly 160 million records on an underground forum, seeking cryptocurrency payment. Decathlon has not...

>> read more

ASUS Rushes Out Router Patch After Discovery of Unauthenticated Remote Command Execution Flaw

23 July 2026  |  dark6  |  Vulnerability

ASUS has issued firmware updates for a high-severity vulnerability, tracked as CVE-2026-13385, that could let remote attackers run arbitrary commands on widely deployed router models without authentication. Security...

>> read more

RefluXFS: A Nine-Year-Old Race Condition in Linux’s XFS Filesystem Opens a Silent Road to Root

23 July 2026  |  dark6  |  Vulnerability

Qualys researchers have disclosed RefluXFS (CVE-2026-64600), a race condition in the Linux kernel's XFS copy-on-write path that lets a local, unprivileged user seize root access while leaving no...

>> read more

HermeticReader: How a Bug in Adobe’s PDF Browser Extension Could Expose WhatsApp Chats to Any Website

23 July 2026  |  dark6  |  Privacy

Researchers at Guardio Labs disclosed a flaw in the Adobe Acrobat Chrome extension, installed on roughly 329 million browsers, that let a malicious website silently read a victim's...

>> read more

Iran’s Cyber Playbook Shifts From Loud Attacks to Patient, Long-Term Access

23 July 2026  |  dark6  |  Cybercrime

A new SentinelOne assessment finds Iran-linked hacking groups increasingly favor quiet, persistent access over destructive attacks, planting footholds in cloud accounts, IT suppliers, and industrial systems that could...

>> read more