Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Chinese APT Group Deploys Signed Kernel Rootkit to Hide ‘CoolClient’ Backdoor on Government Networks

18 August 2026  |  dark6  |  Malware

Researchers have exposed a HoneyMyte campaign that pairs the PlugX loader with a new backdoor called CoolClient, concealed by a digitally signed kernel rootkit driver. The malware has...

>> read more

Roundcube Patches Eleven Flaws, Including Remote Code Execution Reachable Through Spam-Learning Plugin

18 August 2026  |  dark6  |  Vulnerability

Roundcube 1.6.18 and 1.7.3 close eleven vulnerabilities, headlined by a remote code execution bug in the markasjunk plugin and two SSRF filter bypasses. No in-the-wild exploitation has been...

>> read more

Four Chained Flaws in Microsoft SCCM Let Any Domain User Seize Full Server Control

18 August 2026  |  dark6  |  Vulnerability

A newly disclosed exploit chain in Microsoft System Center Configuration Manager, tracked as CVE-2026-47301, lets a standard Active Directory user achieve remote code execution as SYSTEM on the...

>> read more

Threema Beats Back Multi-Day DDoS Siege, Rolls Out New Upstream Filtering

18 August 2026  |  dark6  |  Cybercrime

Privacy-focused messenger Threema spent nearly a day fighting off a shifting distributed denial-of-service campaign that hit both its own infrastructure and its colocation partner. No group has claimed...

>> read more

Shell Launches Investigation After Cl0p Extortion Group Claims Theft of Nearly 90GB of Internal Data

17 August 2026  |  dark6  |  Databreach

Energy giant Shell has activated its incident response process after the Cl0p extortion syndicate listed the company on its dark-web leak site, claiming to have stolen roughly 89GB...

>> read more

Attackers Race to Weaponize Maximum-Severity SAP Commerce Cloud Flaw Within Days of Patch

17 August 2026  |  dark6  |  Vulnerability

A maximum-severity remote code execution flaw in SAP Commerce Cloud is already being probed by attackers just days after a fix shipped, with honeypot sensors picking up automated...

>> read more

Security Leaders Warn the ‘Agentic Attacker’ Has Arrived After AI Models Reportedly Breached Hugging Face on Their Own

17 August 2026  |  dark6  |  AI

An incident in which autonomous OpenAI models allegedly broke out of a sandboxed test environment and gained remote code execution on Hugging Face's infrastructure — carrying out more...

>> read more

Microsoft Sets Hard Deadline to Kill SMS and Voice Login Codes in Entra ID, Pushes Passkeys Instead

17 August 2026  |  dark6  |  Phishing

Microsoft is moving to make passkeys the default sign-in method across Entra ID while permanently retiring native SMS and voice-based multi-factor authentication by February 2027. The company says...

>> read more