Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

OpenAI Patches ‘AgentForger’ Flaw That Let One Link Hijack ChatGPT Workspace Agents

27 July 2026  |  dark6  |  AI

Researchers at Zenity Labs found a critical ChatGPT Workspace Agents bug, dubbed AgentForger, that let a single phishing link silently build and publish a fully permissioned rogue AI...

>> read more

Inside the Pro-Iran Hacktivist Coalition Racing to Mobilize During the US-Iran Conflict

27 July 2026  |  dark6  |  Hacktivism

A new analysis maps the loosely coordinated network of pro-Iran hacktivist groups, state-aligned actors, and opportunistic allies that have ramped up disruptive cyber campaigns since US and Israeli...

>> read more

How a Crafted SVG File Could Have Handed Attackers SYSTEM Access on Microsoft’s Bing Servers

25 July 2026  |  dark6  |  Vulnerability

Three critical, now-patched vulnerabilities in Microsoft's infrastructure show how an everyday image upload feature in Bing Images became a path to remote code execution as NT AUTHORITY\SYSTEM. Researchers...

>> read more

Certighost Flaw Let Ordinary Users Impersonate Domain Controllers and Seize Active Directory

25 July 2026  |  dark6  |  Vulnerability

A newly patched Active Directory Certificate Services bug, dubbed Certighost, let any low-privileged domain user trick a certificate authority into treating a rogue machine as a real Domain...

>> read more

Cl0p Affiliates Are Breaching PTC Windchill Servers to Steal Product Blueprints Before Extortion

25 July 2026  |  dark6  |  Ransomware

Cl0p-linked attackers are chaining an unauthenticated information disclosure bug with a critical deserialization flaw in PTC Windchill and FlexPLM to steal engineering and product-design data from manufacturers, automakers,...

>> read more

Fake Claude Desktop Ads on Bing Are Delivering SectopRAT to Corporate Networks

25 July 2026  |  dark6  |  Malware

A campaign dubbed FakeAgent used paid Bing search ads and a malicious public Claude Artifact to trick corporate employees into installing a disguised remote access trojan. At least...

>> read more

Next.js Ships Emergency Fixes for Nine Flaws, Including High-Severity SSRF and Auth Bypass Bugs

24 July 2026  |  dark6  |  Vulnerability

Vercel has patched nine security vulnerabilities in Next.js, the widely used React framework, covering server-side request forgery, a middleware authentication bypass, denial-of-service conditions, and data-exposure issues. Four of...

>> read more

Chaos Ransomware’s New msaRAT Tool Hijacks Chrome and Edge as a Stealth Command Channel

24 July 2026  |  dark6  |  Ransomware

Cisco Talos has identified msaRAT, a Rust-based tool tied to the Chaos ransomware group that quietly launches Chrome or Edge in headless mode and turns the browser into...

>> read more