Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Seven New CVEs in FatFs Filesystem Driver Put Millions of Embedded and IoT Devices at Risk

6 July 2026  |  dark6  |  Vulnerability

runZero has disclosed seven new CVEs in FatFs, the FAT/exFAT filesystem driver used across ESP-IDF, STM32Cube, Zephyr, MicroPython, and countless other embedded platforms. The bugs range from CVSS...

>> read more

New T3MP3ST Framework Turns AI Coding Agents Into Autonomous 0-Day Hunters

6 July 2026  |  dark6  |  AI

T3MP3ST, a new open-source framework, turns AI coding agents like Claude Code and Codex into autonomous red-teaming operators, claiming strong results on benchmark suites and a set of...

>> read more

Apache ActiveMQ Patches Three Vulnerabilities Enabling DoS, Data Leakage, and Privilege Escalation

6 July 2026  |  dark6  |  Vulnerability

Apache ActiveMQ users should urgently patch three newly disclosed vulnerabilities — CVE-2026-53917, CVE-2026-54475, and CVE-2026-49877 — that can crash brokers, break temporary-destination isolation, and let low-privilege Web Console...

>> read more

Flipper Zero Maker Overhauls Firmware Contribution Rules After Community Backlash

6 July 2026  |  dark6  |  Cybercrime

Flipper Devices has rolled out new firmware contribution rules, including GitHub Discussions-based feature voting and mandatory integration testing, after community backlash over a perceived firmware development slowdown.

>> read more

Cybersecurity Week in Review: AI Model Redeployment, a Linux Root Zero-Day, and Hundreds of Chrome Patches

6 July 2026  |  dark6  |  Cybercrime

This week: Anthropic's Claude Mythos 5 returns to critical infrastructure use, a near-100%-reliable Linux root zero-day emerges, Chrome patches 382 bugs, and Scattered Spider notches another extradition.

>> read more

Microsoft Ships KB5095189 Cumulative Update to Patch the Windows 11 Setup Experience

6 July 2026  |  dark6  |  Vulnerability

Microsoft's KB5095189 update patches the Windows 11 setup experience for versions 24H2 and 25H2. It carries no CVE, but enterprises relying on Autopilot-style provisioning should confirm devices aren't...

>> read more

Researcher Chains a Guardrail Bypass With a Path Traversal Flaw to Access System Files in ChatGPT

4 July 2026  |  dark6  |  Vulnerability

A proof-of-concept disclosed by researcher zer0dac combined social engineering against ChatGPT's own safety logic with a path traversal bug to retrieve restricted system files through the platform's file...

>> read more

Ousaban Banking Trojan Resurfaces With Steganographic PDF Lures Targeting Spain and Portugal

4 July 2026  |  dark6  |  Malware

Fortinet's FortiGuard Labs has documented a fresh wave of the Ousaban banking trojan hitting Windows users in Spain and Portugal through fake corrupted PDFs and a spoofed tax...

>> read more