Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Six Ways to Break Flowise: New RCE Chain Puts AI Workflow Servers at Risk

5 August 2026  |  dark6  |  Vulnerability

Security researchers at Elttam disclosed six separate remote code execution flaws in the Flowise AI workflow platform, spanning CSV processing, sandboxed JavaScript, and database configuration. Several of the...

>> read more

DarkSword Exploit Kit Quietly Expands to 180 Sites, Turning iPhones Into Data-Theft Targets

5 August 2026  |  dark6  |  Spyware

A leaked iOS exploit chain known as DarkSword has grown into a sprawling, fast-changing network of malicious infrastructure, with researchers at Censys tracking 27 hosts and 180 web...

>> read more

Arch Linux Freezes AUR Package Adoptions After Attackers Exploit Abandoned Projects

4 August 2026  |  dark6  |  Cybercrime

Arch Linux has temporarily disabled the ability to adopt orphaned AUR packages after security teams spotted a wave of hostile takeovers followed by malicious code injected through routine-looking...

>> read more

How One Poisoned Tracking Script Turned a Major Ad Platform Into a Crypto-Theft Pipeline

4 August 2026  |  dark6  |  Malware

Researchers say attackers hijacked a widely deployed JavaScript file from ad-tech company Adform, turning routine website analytics into a silent clipboard hijacker that swaps copied crypto wallet addresses...

>> read more

ShinyHunters Strikes Again: Brinks Home Confirms Breach Tied to Salesforce Systems

4 August 2026  |  dark6  |  Databreach

Brinks Home has confirmed attackers broke into systems connected to its Salesforce environment after the ShinyHunters extortion crew claimed to have stolen nearly five million records. The company...

>> read more

865,000 ‘No-Logs’ VPN Users Exposed After SplitVPN Breach Reveals Hidden Connection Records

4 August 2026  |  dark6  |  Databreach

A breach at Russian VPN provider SplitVPN, formerly NotVPN, has exposed the records of roughly 865,000 users despite the service's long-standing 'no logs' promise. The leaked database reportedly...

>> read more

FBI and Allied Governments Warn Companies Are Unknowingly Hiring North Korean Operatives

4 August 2026  |  dark6  |  Cybercrime

A joint advisory from the U.S. State Department, FBI, and partner nations including Japan, the UK, Germany, Canada, and South Korea warns that North Korean IT workers are...

>> read more

The Gentlemen Ransomware Uses a Malicious Kernel Driver to Blind Security Tools Before Striking

4 August 2026  |  dark6  |  Ransomware

A ransomware operation dubbed The Gentlemen is using a custom kernel-level driver to silently kill nearly 180 security processes before it starts encrypting files. Researchers say the driver...

>> read more