Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Vercel Confirms KVM Zero-Day Behind Claimed Guest-to-Host Root Escape

5 October 2026  |  dark6  |  Vulnerability

Vercel has confirmed a KVM zero-day reported through its Sandbox bounty program after a researcher claimed a full guest-to-host escape. Technical details, affected versions and remediation guidance remain...

>> read more

Debian’s Massive 1,313-CVE Kernel Update: What Administrators Actually Need to Know

5 October 2026  |  dark6  |  Vulnerability

Debian's DSA-6528-1 advisory bundles fixes for 1,313 CVEs into a single kernel update for Trixie, addressing privilege escalation, denial-of-service, and information-leak risks. The headline number is less alarming...

>> read more

Root-Level cPanel/WHM Flaw Puts Every Hosted Account on a Server at Risk

5 October 2026  |  dark6  |  Vulnerability

cPanel has patched a critical flaw (CVE-2026-93698) in the Multilang adminbin component that allows arbitrary command execution as root, alongside two stored XSS bugs in WHM's SSL Hosts...

>> read more

Leaked Control Panel Exposes 50,000 Stolen Credentials Harvested From WordPress Backups

5 October 2026  |  dark6  |  Databreach

Researchers at LevelBlue uncovered TIKTOUK, a credential-harvesting toolkit that scans for exposed WordPress backups, configuration files, and JavaScript secrets. A leaked operator panel contained roughly 50,000 real credentials...

>> read more

Inside the Supply Chain Playbook Turning Trusted Software Updates Into Credential Thieves

5 October 2026  |  dark6  |  Cybercrime

A new ReversingLabs report ties together the S1ngularity, Shai-Hulud, and TeamPCP/Trivy supply chain incidents, showing how stolen maintainer tokens and compromised CI pipelines let attackers push credential-stealing code...

>> read more

Red Hat Satellite Authorization Flaw Can Expose Root Passwords and Enable Code Execution

5 October 2026  |  dark6  |  Vulnerability

Red Hat has patched a CVSS 9.1 authorization flaw in Satellite's Foreman component that lets low-privileged users view protected host data, potentially including root passwords. Unsafe Safemode configurations...

>> read more

Attackers Abuse SQL Server as a Covert Command and Exfiltration Channel

5 October 2026  |  dark6  |  Cybercrime

Investigators found attackers using Microsoft SQL Server functionality to execute Windows commands and return stolen files through query output. An exposed staging server also leaked the intruders' toolkit...

>> read more

Dell Storage Module Flaws Expose Kubernetes Environments to Admin Takeover

5 October 2026  |  dark6  |  Vulnerability

Dell has fixed multiple critical flaws in its Container Storage Modules, including two CVSS 10 vulnerabilities reachable without authentication. Attacks could expose array credentials, bypass tenant controls and...

>> read more