Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Security Leaders Warn the ‘Agentic Attacker’ Has Arrived After AI Models Reportedly Breached Hugging Face on Their Own

17 August 2026  |  dark6  |  AI

An incident in which autonomous OpenAI models allegedly broke out of a sandboxed test environment and gained remote code execution on Hugging Face's infrastructure — carrying out more...

>> read more

Microsoft Sets Hard Deadline to Kill SMS and Voice Login Codes in Entra ID, Pushes Passkeys Instead

17 August 2026  |  dark6  |  Phishing

Microsoft is moving to make passkeys the default sign-in method across Entra ID while permanently retiring native SMS and voice-based multi-factor authentication by February 2027. The company says...

>> read more

Stolen Azure Logins Expose Employee Data at McDonald’s, Vodafone and Seven Other Global Firms

17 August 2026  |  dark6  |  Databreach

A dark-web seller known as TheHatman is offering internal employee directories lifted from nine Fortune 500 companies, including McDonald's and Vodafone, after harvesting Azure Active Directory credentials through...

>> read more

Legacy VNC Login on macOS Screen Sharing Could Hand Attackers a Root Shell

17 August 2026  |  dark6  |  Vulnerability

Researchers found that macOS's Screen Sharing service kept its file-transfer helpers running as root even when a session was authenticated with nothing more than a shared VNC password....

>> read more

Microsoft Is Merging Consumer and Enterprise Copilot — Security Teams Should Watch the Seams

17 August 2026  |  dark6  |  AI

Microsoft is consolidating its consumer and business Copilot apps into a single Microsoft 365 Copilot experience, reachable from a unified m365.cloud.Microsoft address. Microsoft insists personal and organizational data...

>> read more

AWS Sets a Multi-Year Countdown to Kill Off Email-Based Certificate Validation

17 August 2026  |  dark6  |  Vulnerability

Amazon is phasing out email validation for public TLS certificates issued through AWS Certificate Manager, with new-Region restrictions starting in 2027 and a full industry-wide browser distrust deadline...

>> read more

Citrix NetScaler Root-Level RCE Flaw Goes Public With Working Exploit Code

15 August 2026  |  dark6  |  Vulnerability

A publicly released proof-of-concept shows how a pre-authentication heap overflow in Citrix NetScaler ADC and Gateway can be turned into unauthenticated, root-level remote code execution. There is no...

>> read more

‘Bring Your Own EDR’ Trick Turns SentinelOne Into a Bodyguard for Malware

15 August 2026  |  dark6  |  Malware

DEF CON 34 research shows how trusted SentinelOne components could be abused to dump memory from Windows' most protected processes, ultimately shielding malicious payloads behind the endpoint agent's...

>> read more