Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

NodeStealer Adds Keylogging and Screenshots to Its Account-Theft Arsenal

5 September 2026  |  dark6  |  Spyware

A new NodeStealer variant adds continuous keylogging, clipboard monitoring and screenshots to its browser and Facebook data theft. Financial services were the most affected sector in recent activity...

>> read more

Toy Ghouls Hide New Windows Backdoors Behind MQTT and Matrix Traffic

5 September 2026  |  dark6  |  Malware

The Toy Ghouls group has deployed two custom Windows backdoors that use MQTT and Matrix-based services for command traffic. The malware adds durable remote control to compromises previously...

>> read more

AI-Orchestrated Intrusions Hit Asian Government and Political Networks

5 September 2026  |  dark6  |  AI

Attackers used an AI-orchestration framework alongside conventional exploits, stolen credentials and custom malware in a campaign spanning Asian government, political and education targets. The case shows how agentic...

>> read more

Leaked AWS Administrator Key Fuels Costly LLMjacking Through Bedrock and Marketplace

4 September 2026  |  dark6  |  Cybercrime

A leaked AWS IAM key with administrator privileges allowed an attacker to create a new identity, activate premium AI models and bill inference usage to the victim. The...

>> read more

Rogue ScreenConnect Clients Turn Remote Support Sessions Into a Worm-Like Infection Chain

4 September 2026  |  dark6  |  Malware

Attackers are abusing unauthorized ScreenConnect installations to push staged malware into newly connected Windows systems. The campaign begins with social engineering, then uses trusted remote-support functions for persistence,...

>> read more

Inside ‘The Gentlemen’: The Ransomware Operation That Can Take Down a Network Before Lunch

4 September 2026  |  dark6  |  Ransomware

A ransomware-as-a-service operation dubbed 'The Gentlemen' by researchers is compromising networks and detonating encryption in as little as 24 hours, methodically disabling backups and security tooling before attackers...

>> read more

Attackers Are Already Probing a Critical Flaw in Sangoma’s Switchvox VoIP Platform

4 September 2026  |  dark6  |  Vulnerability

A critical, unauthenticated SQL injection flaw in Sangoma Switchvox is being actively probed in the wild just weeks after a patch became available. With thousands of phone systems...

>> read more

QR-Code Phishing Reaches Record Levels as Attackers Shift Credential Theft to Phones

4 September 2026  |  dark6  |  Phishing

ESET says QR-code phishing accounted for about 11% of detected phishing email in the first half of 2026, with roughly 100,000 detections per month. By moving victims from...

>> read more