Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Critical cPanel Domain-Parking Flaw Lets Basic Users Seize Root Control

28 August 2026  |  dark6  |  Vulnerability

CVE-2026-65643 allows a low-privileged cPanel user with domain-parking rights to create arbitrary files and ultimately execute code as root. Hosting providers should verify patched builds immediately and restrict...

>> read more

Old Microsoft SQL Server RCE Returns in Active Attacks, Triggering CISA Forensic Mandate

28 August 2026  |  dark6  |  Vulnerability

CISA says attackers are exploiting CVE-2019-1068, a Microsoft SQL Server remote-code execution flaw, and has ordered both remediation and forensic triage. Database owners should patch exposed systems, review...

>> read more

CISA Orders Rapid Action as Citrix NetScaler Flaw Is Exploited in the Wild

28 August 2026  |  dark6  |  Vulnerability

CISA has placed CVE-2026-8452 in its Known Exploited Vulnerabilities catalog following confirmed attacks against Citrix NetScaler products. The memory-safety flaw can disrupt critical gateway services, and organizations should...

>> read more

Ransomware Affiliate Used AI Coding Tool Cursor to Plan Attacks on 20+ Companies Across 9 Countries

28 August 2026  |  dark6  |  Ransomware

An exposed staging server has given researchers an unusually detailed look at how a Russian-speaking Aurora ransomware affiliate used the AI coding assistant Cursor to help plan and...

>> read more

FBI Dismantles Chinese State-Sponsored Botnet That Powered a Global Hacking Platform

28 August 2026  |  dark6  |  Cybercrime

The FBI and Department of Justice have seized the domains behind QScan and QTRouter, a pair of linked platforms that a Chinese state-sponsored group allegedly used to hijack...

>> read more

Critical Next.js Flaws Put Windows Servers and AVIF Image Processing at Risk of RCE

27 August 2026  |  dark6  |  Vulnerability

Two critical Next.js vulnerabilities may enable unauthenticated remote code execution through Windows path handling and AVIF image processing. Vercel fixed both issues in Next.js 15.5.24 and 16.3.3, with...

>> read more

Ubiquiti Fixes 21 Critical UniFi Flaws Across Routers, Cameras and Access Systems

27 August 2026  |  dark6  |  Vulnerability

Ubiquiti has patched 21 critical vulnerabilities across a broad range of UniFi products, including flaws rated a maximum 10.0. The bugs enable outcomes including authentication bypass, command injection...

>> read more

CISA Flags Actively Exploited Gitea Flaw That Turns Repository Access Into Server Code Execution

27 August 2026  |  dark6  |  Vulnerability

CISA has added CVE-2026-60004 to its Known Exploited Vulnerabilities catalog after confirming attacks against Gitea servers. The flaw can let a repository writer plant a malicious Git hook...

>> read more