Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

AI-Powered Pentest Uncovers Eight Security Holes in Popular NodeBB Forum Software

27 July 2026  |  dark6  |  Vulnerability

A whitebox penetration test assisted by AI tools found eight high-severity flaws in the NodeBB forum platform, including bugs that could let attackers read private messages, hijack admin...

>> read more

Claude AI’s Shared Chat Links Briefly Turned Up in Google Search, Exposing Private Conversations

27 July 2026  |  dark6  |  Privacy

Hundreds of Claude AI shared-chat links reportedly became publicly searchable on Google over the weekend, exposing legal advice, proprietary code, and personal conversations to anyone who searched for...

>> read more

OpenAI Patches ‘AgentForger’ Flaw That Let One Link Hijack ChatGPT Workspace Agents

27 July 2026  |  dark6  |  AI

Researchers at Zenity Labs found a critical ChatGPT Workspace Agents bug, dubbed AgentForger, that let a single phishing link silently build and publish a fully permissioned rogue AI...

>> read more

Inside the Pro-Iran Hacktivist Coalition Racing to Mobilize During the US-Iran Conflict

27 July 2026  |  dark6  |  Hacktivism

A new analysis maps the loosely coordinated network of pro-Iran hacktivist groups, state-aligned actors, and opportunistic allies that have ramped up disruptive cyber campaigns since US and Israeli...

>> read more

How a Crafted SVG File Could Have Handed Attackers SYSTEM Access on Microsoft’s Bing Servers

25 July 2026  |  dark6  |  Vulnerability

Three critical, now-patched vulnerabilities in Microsoft's infrastructure show how an everyday image upload feature in Bing Images became a path to remote code execution as NT AUTHORITY\SYSTEM. Researchers...

>> read more

Certighost Flaw Let Ordinary Users Impersonate Domain Controllers and Seize Active Directory

25 July 2026  |  dark6  |  Vulnerability

A newly patched Active Directory Certificate Services bug, dubbed Certighost, let any low-privileged domain user trick a certificate authority into treating a rogue machine as a real Domain...

>> read more

Cl0p Affiliates Are Breaching PTC Windchill Servers to Steal Product Blueprints Before Extortion

25 July 2026  |  dark6  |  Ransomware

Cl0p-linked attackers are chaining an unauthenticated information disclosure bug with a critical deserialization flaw in PTC Windchill and FlexPLM to steal engineering and product-design data from manufacturers, automakers,...

>> read more

Fake Claude Desktop Ads on Bing Are Delivering SectopRAT to Corporate Networks

25 July 2026  |  dark6  |  Malware

A campaign dubbed FakeAgent used paid Bing search ads and a malicious public Claude Artifact to trick corporate employees into installing a disguised remote access trojan. At least...

>> read more