Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Chrome’s Latest Patch Closes 12 Security Holes, Nine of Them Rated High Severity

22 July 2026  |  dark6  |  Vulnerability

Google has shipped a new Stable Chrome release fixing 12 vulnerabilities, nine of them high severity, touching core components like V8, ANGLE, and the GPU stack. Several of...

>> read more

Unauthenticated Attackers Are Actively Exploiting a ServiceNow Sandbox-Escape Flaw

22 July 2026  |  dark6  |  Vulnerability

A critical ServiceNow vulnerability that lets unauthenticated attackers break out of the platform's scripting sandbox is now being exploited in the wild. ServiceNow has shipped patches, but self-hosted...

>> read more

New Windows ‘Bind Link’ Trick Lets Attackers Fool EDR, AMSI, and AppLocker Without Touching a File

21 July 2026  |  dark6  |  Vulnerability

Bitdefender researchers have detailed how Windows 'bind links' — a legitimate feature behind containers and Sandbox — can be abused by an attacker with local admin rights to...

>> read more

HOLLOWGRAPH Malware Turns Microsoft 365 Calendars Into a Covert Spy Channel

21 July 2026  |  dark6  |  Malware

Group-IB has uncovered HOLLOWGRAPH, a stealthy malware component that hides its command-and-control traffic inside Microsoft 365 calendar invites dated decades in the future. The tool shows technical overlap...

>> read more

Gig Economy Platform Paidwork Leaks Banking and Personal Data of 23 Million Users

21 July 2026  |  dark6  |  Databreach

A data breach at gig-economy platform Paidwork has exposed banking details, payout histories, and personal information for more than 23 million users, with the stolen dataset publicly leaked...

>> read more

Qilin Ransomware Affiliates Exploit Palo Alto Firewall Bypass to Skip Straight Past Perimeter Defenses

21 July 2026  |  dark6  |  Ransomware

A critical PAN-OS authentication bypass, CVE-2026-0257, is being actively exploited by Qilin ransomware affiliates to gain direct VPN access to corporate networks. Arctic Wolf Labs traced multiple June...

>> read more

Decade-Old NGINX Bug Finally Exposed: A Single Regex Quirk Enables Remote Code Execution

20 July 2026  |  dark6  |  Vulnerability

A remote code execution flaw that has quietly lived inside nginx's script engine since 2011 has finally come to light, tracked as CVE-2026-42533. Researchers say a single malicious...

>> read more

wp2shell: The WordPress Core Bug That Lets Anyone Take Over 500 Million Sites Without Logging In

20 July 2026  |  dark6  |  Vulnerability

A newly disclosed WordPress Core vulnerability, nicknamed wp2shell, chains a REST API batch-route flaw into full unauthenticated remote code execution. No plugins, no login, and no special configuration...

>> read more