Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

28,000 Public .git Folders Left AWS Keys, Stripe Tokens, and HR Files Wide Open, Researchers Find

27 August 2026  |  dark6  |  Databreach

A large-scale internet scan uncovered 28,000 publicly accessible .git directories exposing hundreds of live cloud and payment credentials, along with sensitive employee records — a reminder that scrubbing...

>> read more

Google Ships Chrome 152 With Fixes for 327 Flaws, Including 10 Critical Use-After-Free Bugs

27 August 2026  |  dark6  |  Vulnerability

Chrome 152 lands with 327 security fixes, ten of them rated critical and mostly tied to use-after-free memory bugs across components like ANGLE, Aura, and Chromecast. None are...

>> read more

Mirage2FA Phishing Kit Hijacks Microsoft 365 Sessions at 3,500+ Organizations, Sidestepping MFA Entirely

27 August 2026  |  dark6  |  Phishing

A phishing-as-a-service kit called Mirage2FA has compromised thousands of Microsoft 365 accounts by stealing live session cookies through an adversary-in-the-middle proxy, letting attackers walk past passwords and MFA...

>> read more

Iran-Linked Tortoiseshell Expands Espionage With TWOSTROKE Backdoor and Reverse SSH Tunnels

27 August 2026  |  dark6  |  Spyware

Researchers have linked new Windows malware and reverse SSH infrastructure to the Iran-associated Tortoiseshell threat group. The tools masquerade as a legitimate Windows library and support covert tunneling,...

>> read more

One Malicious Webpage Can Hijack Your AI Coding Agent Through an NVIDIA NemoClaw Flaw

27 August 2026  |  dark6  |  AI

A critical flaw in NVIDIA's NemoClaw tooling exposes a local AI inference server to the open network, letting a single malicious website hijack an AI agent via DNS...

>> read more

OpenSSL Updates Close Heap Corruption and Remote Crash Weaknesses

26 August 2026  |  dark6  |  Vulnerability

OpenSSL has released patched builds for a broad set of vulnerabilities affecting CMS, CMP, DTLS, QUIC and cryptographic operations. Several weaknesses are remotely triggerable, making dependency discovery and...

>> read more

Core Werewolf Deploys Custom CoreRAT Against Russian Defense Targets

26 August 2026  |  dark6  |  Malware

The Core Werewolf threat group is using a newly documented Windows remote access trojan in campaigns aimed at Russian public-sector and defense organizations. Telegram lures and forged official...

>> read more

Actively Exploited SharePoint Flaw Combines With RCE for Server Takeover

26 August 2026  |  dark6  |  Vulnerability

Two on-premises SharePoint vulnerabilities can be chained to bypass authentication and execute code on vulnerable servers. With the authentication flaw already listed as exploited, administrators should patch exposed...

>> read more