Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Critical MLflow Flaw Lets Attackers Steal Cloud Credentials via Webhook Redirects

19 August 2026  |  dark6  |  Vulnerability

A critical server-side request forgery flaw in MLflow, tracked as CVE-2026-64849 with a 9.3 CVSS score, lets unauthenticated attackers abuse the platform's webhook-testing endpoint to reach cloud metadata...

>> read more

Fake CAPTCHA Prompts on Hacked WordPress Sites Fuel Global StopAndProtect Malware Botnet

19 August 2026  |  dark6  |  Malware

Researchers have uncovered a sprawling campaign, dubbed StopAndProtect, that has hijacked thousands of poorly maintained WordPress sites to serve as rotating command-and-control infrastructure. Fake CAPTCHA prompts trick visitors...

>> read more

Chinese APT Group Deploys Signed Kernel Rootkit to Hide ‘CoolClient’ Backdoor on Government Networks

18 August 2026  |  dark6  |  Malware

Researchers have exposed a HoneyMyte campaign that pairs the PlugX loader with a new backdoor called CoolClient, concealed by a digitally signed kernel rootkit driver. The malware has...

>> read more

Roundcube Patches Eleven Flaws, Including Remote Code Execution Reachable Through Spam-Learning Plugin

18 August 2026  |  dark6  |  Vulnerability

Roundcube 1.6.18 and 1.7.3 close eleven vulnerabilities, headlined by a remote code execution bug in the markasjunk plugin and two SSRF filter bypasses. No in-the-wild exploitation has been...

>> read more

Four Chained Flaws in Microsoft SCCM Let Any Domain User Seize Full Server Control

18 August 2026  |  dark6  |  Vulnerability

A newly disclosed exploit chain in Microsoft System Center Configuration Manager, tracked as CVE-2026-47301, lets a standard Active Directory user achieve remote code execution as SYSTEM on the...

>> read more

Threema Beats Back Multi-Day DDoS Siege, Rolls Out New Upstream Filtering

18 August 2026  |  dark6  |  Cybercrime

Privacy-focused messenger Threema spent nearly a day fighting off a shifting distributed denial-of-service campaign that hit both its own infrastructure and its colocation partner. No group has claimed...

>> read more

Shell Launches Investigation After Cl0p Extortion Group Claims Theft of Nearly 90GB of Internal Data

17 August 2026  |  dark6  |  Databreach

Energy giant Shell has activated its incident response process after the Cl0p extortion syndicate listed the company on its dark-web leak site, claiming to have stolen roughly 89GB...

>> read more

Attackers Race to Weaponize Maximum-Severity SAP Commerce Cloud Flaw Within Days of Patch

17 August 2026  |  dark6  |  Vulnerability

A maximum-severity remote code execution flaw in SAP Commerce Cloud is already being probed by attackers just days after a fix shipped, with honeypot sensors picking up automated...

>> read more