Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Operation Saffron: International Authorities Dismantle ‘First VPN’ Criminal Network Linked to Global Ransomware Attacks

22 May 2026  |  dark6  |  Cybercrime

A coordinated international law enforcement operation led by France, the Netherlands, Europol, and Eurojust has dismantled First VPN — a criminal VPN service explicitly marketed to cybercriminals and...

>> read more

WantToCry Ransomware Encrypts Files Remotely Over SMB — No Malware Required

22 May 2026  |  dark6  |  Ransomware

A ransomware operation called WantToCry is exploiting exposed SMB file-sharing services to encrypt business data without ever installing malware on victim machines. SophosLabs researchers warn that over 1.5...

>> read more

Dark Web Brokers Flood Forums With Recycled Breach Data Disguised as Fresh Corporate Leaks

22 May 2026  |  dark6  |  Cybercrime

Cybercriminals operating in Chinese-language dark web ecosystems are repackaging data from old breaches and selling it as fresh corporate intelligence, according to new research from Group-IB. The scam...

>> read more

DevilNFC: New Android Malware Traps Victims in Kiosk Mode During NFC Card Relay Attacks

21 May 2026  |  dark6  |  Malware

DevilNFC is a new Android malware that combines NFC relay attacks with Android Kiosk Mode to trap victims inside a fake banking screen while stealing card PINs in...

>> read more

Void Botnet Weaponizes Ethereum Smart Contracts for Seizure-Proof Command-and-Control Infrastructure

21 May 2026  |  dark6  |  Malware

The Void Botnet uses Ethereum smart contracts as a seizure-resistant C2 channel, making traditional law enforcement takedowns impossible. Sold on Russian-language forums since March 2026 for $600, the...

>> read more

Gremlin Stealer Evolves: New Variant Hides C2 URLs in Encrypted Resources and Adds Discord Token Theft

21 May 2026  |  dark6  |  Malware

A newly analyzed Gremlin stealer variant hides C2 URLs inside XOR-encrypted .NET resource sections, making it invisible to static scanners. The malware now targets Discord tokens and adds...

>> read more

Claude Code’s Five-Month Network Sandbox Bypass Silently Exposed Developer Credentials and Source Code

21 May 2026  |  dark6  |  Vulnerability

Anthropic's Claude Code harbored a critical SOCKS5 null-byte injection sandbox bypass for over five months, allowing attackers to silently exfiltrate developer credentials, source code, and API keys. The...

>> read more

Kimsuky APT Runs Four Simultaneous Spear-Phishing Campaigns Targeting Recruiters, Crypto Users, and Defense Officials

20 May 2026  |  dark6  |  Phishing

North Korea's Kimsuky threat group has been operating four parallel spear-phishing campaigns targeting corporate recruiters, cryptocurrency developers, defense sector officials, and graduate school staff. The campaigns use LNK...

>> read more