Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Phantom Deal Fraud Uses Fake M&A Secrecy to Push a €626,000 Wire Transfer

4 September 2026  |  dark6  |  Phishing

The Phantom Deal campaign impersonates executives and advisers, then uses a polished NDA to isolate employees from normal approval channels. One documented attempt sought a €626,735.45 transfer and...

>> read more

Critical VMware Workstation and Fusion Bugs Let Attackers Break Out of the Virtual Machine

4 September 2026  |  dark6  |  Vulnerability

Broadcom has patched two vulnerabilities in VMware Workstation and Fusion that allow an attacker with access to a guest virtual machine to execute code on the underlying host,...

>> read more

A Popular WordPress Backup Plugin’s Flaw Puts 5 Million Sites One Restore Away From Takeover

4 September 2026  |  dark6  |  Vulnerability

A high-severity SQL injection flaw in the All-in-One WP Migration and Backup plugin, installed on more than five million WordPress sites, can be triggered through the platform's own...

>> read more

GitSpawn Turns Booby-Trapped Repositories Into Silent Code Execution Across AI Coding Tools

3 September 2026  |  dark6  |  Vulnerability

GitSpawn weaknesses allow specially prepared project folders to execute local commands when AI coding agents perform routine Git checks. Several vendors have patched variants, but researchers say four...

>> read more

TukTuk Malware Gives Ransomware Crews Cross-Platform Control and EDR-Killing Tools

3 September 2026  |  dark6  |  Ransomware

Researchers recovered a previously undocumented command-and-control framework linked to the Gentlemen ransomware ecosystem. TukTuk supports Windows and Linux agents, credential prompts, screen capture, remote commands, and preparation for...

>> read more

Lenovo ID Trust Flaw Opened About 5,000 Dropbox Accounts to Takeover

3 September 2026  |  dark6  |  Databreach

Dropbox says attackers compromised roughly 5,000 accounts by creating Lenovo IDs with victims’ email addresses and abusing a federated-login integration. The incident demonstrates why matching email claims cannot...

>> read more

Microsoft 365 Session Hijacking Campaigns Hide Behind Trusted Remote-Support Tools

3 September 2026  |  dark6  |  Phishing

Campaigns spanning the United States and Europe are combining adversary-in-the-middle phishing with legitimate remote-management software. Stolen session cookies can outlive password resets, forcing defenders to revoke tokens and...

>> read more

Fake Software Installers Are Quietly Disarming Microsoft Defender in New Silver Fox Campaign

3 September 2026  |  dark6  |  Malware

A Silver Fox-linked campaign is distributing counterfeit installers for brands like Razer, Microsoft Edge, and Kaspersky that use SYSTEM-level scheduled tasks to strip Microsoft Defender protections and delete...

>> read more