Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

BREEZE COMET Hackers Use AI-Written Tools to Speed-Run Brazilian Bank Fraud

3 September 2026  |  dark6  |  Cybercrime

Google Cloud researchers detail how the financially motivated BREEZE COMET group has spent two years infiltrating Brazilian banks and retailers, combining social engineering and rogue hardware with generative-AI-assisted...

>> read more

High-Severity Cleo Harmony Bug Lets Attackers Forge Their Way to Admin Access

3 September 2026  |  dark6  |  Vulnerability

A high-severity flaw in Cleo Harmony's JWT refresh-token handling, tracked as CVE-2026-84115, lets remote attackers escalate privileges to admin level with a working exploit already public. Cleo has...

>> read more

New WhatsApp Video Call Trick Bypasses Android Lock Screens to Expose Your Photos

3 September 2026  |  dark6  |  Vulnerability

A newly disclosed WhatsApp flaw lets anyone answer a video call on a locked Android phone and, through the in-call background editor, browse the device's entire photo gallery...

>> read more

Fake Teams Help-Desk Calls Turn Remote Support Into a Path Toward Domain Control

2 September 2026  |  dark6  |  Phishing

A campaign dubbed Spring Ring used external Microsoft Teams accounts and convincing help-desk calls to push remote-access tools and malware. In some cases, the attackers progressed toward SMB...

>> read more

Boston Scientific Cyber Incident Disrupts Manufacturing and Device Shipments

2 September 2026  |  dark6  |  Databreach

Boston Scientific is recovering from a cyber incident that interrupted on-premises systems supporting manufacturing, order processing and product shipments. The company says connected devices and previously enrolled remote...

>> read more

Critical Artifactory Bypass Is Being Used to Mint Administrator Tokens

2 September 2026  |  dark6  |  Vulnerability

A critical JFrog Artifactory authentication bypass is under active exploitation, with attackers reportedly creating administrator tokens on vulnerable servers. Self-hosted customers should upgrade immediately, revoke suspicious credentials and...

>> read more

Attackers Exploit Critical Langflow and Rails Flaws to Hunt Cloud Secrets

2 September 2026  |  dark6  |  Vulnerability

Attackers are actively exploiting critical flaws in Langflow and Ruby on Rails, with observed activity focused on credentials, application secrets and paths to remote code execution. Defenders should...

>> read more

D-Link Fixes Router Flaws That Exposed Admin and Wi-Fi Credentials on Local Networks

1 September 2026  |  dark6  |  Vulnerability

D-Link has patched access-control failures in the DIR-X1860Z that could let an unauthenticated local attacker reset the administrator password and retrieve wireless credentials. Owners should install the corrected...

>> read more