Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

ServiceNow Confirms Unauthorized Access Vulnerability Exposing Enterprise Customer Data

11 June 2026  |  dark6  |  Vulnerability

ServiceNow has confirmed a security vulnerability allowing unauthorized actors to query customer instance tables without proper authentication, potentially exposing sensitive enterprise data. The platform, used by thousands of...

>> read more

Operation TaxShadow: Fileless Malware Campaign Uses Fake Tax Emails to Evade Detection on Windows

11 June 2026  |  dark6  |  Phishing

A sophisticated phishing campaign called Operation TaxShadow is targeting Windows users with fake government tax notifications that deliver multi-stage fileless malware. The payload runs entirely in memory using...

>> read more

Critical npm Supply Chain Attack: Malicious ‘dbmux’ Package Gives Hackers Full System Control

11 June 2026  |  dark6  |  Malware

A malicious npm package named dbmux was discovered containing malware that gives attackers complete control over any developer system that installed it. Part of a coordinated wave of...

>> read more

Windows CTFMON Zero-Day CVE-2026-45586 Lets Low-Privilege Users Escalate to SYSTEM

11 June 2026  |  dark6  |  Vulnerability

A publicly disclosed zero-day in the Windows Collaborative Translation Framework (CTFMON) allows attackers with standard user privileges to escalate to SYSTEM. Tracked as CVE-2026-45586, the flaw affects all...

>> read more

UNC3753 (Luna Moth) Escalates Campaign Against US Law Firms: Vishing, RMM Tools, and Now Physical Intrusion

10 June 2026  |  dark6  |  Cybercrime

Google Cloud Mandiant has documented a sustained UNC3753 (Luna Moth) campaign targeting US law firms from January–May 2026. The group uses vishing calls and RMM tools to exfiltrate...

>> read more

SAP June 2026 Patch Day: Four Critical Flaws Including CVSS 9.9 SAML Bypass in NetWeaver ABAP

10 June 2026  |  dark6  |  Vulnerability

SAP's June 2026 Security Patch Day addressed 15 security notes including four critical vulnerabilities. The most severe — CVE-2026-44748 (CVSS 9.9) — is an XML Signature Wrapping flaw...

>> read more

Meet Pink: The New Extortion Group Using Vishing and Microsoft 365 Tools to Drain Enterprise Cloud Storage

10 June 2026  |  dark6  |  Cybercrime

A new extortion group called Pink (CL-CRI-1147) has emerged, targeting enterprise organizations through voice phishing to steal Microsoft 365 credentials and cloud files. With ties to the Com...

>> read more

Google Chrome 149 Patches 429 Vulnerabilities Including 22 Critical — Update Immediately

10 June 2026  |  dark6  |  Vulnerability

Google has released Chrome 149.0.7827.53 with 429 security fixes, including 22 rated critical. The patch covers use-after-free and memory corruption bugs across ANGLE, GPU, Network, Password Manager, and...

>> read more