Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Pwn2Own Berlin 2026 Day 2: Exchange, Windows 11, and AI Coding Tools Fall to Zero-Days — $908,750 in Total Prizes

18 May 2026  |  dark6  |  Vulnerability

Day Two of Pwn2Own Berlin 2026 saw 15 new zero-day exploits demonstrated against Microsoft Exchange (full RCE chain worth $200,000), Windows 11, Red Hat Linux, Cursor IDE, OpenAI...

>> read more

First Public macOS Kernel Exploit on Apple M5 Bypasses Hardware Memory Protection — Developed in Just Five Days With AI Assistance

18 May 2026  |  dark6  |  Vulnerability

Security researchers have developed the first known public macOS kernel exploit targeting Apple M5 hardware, bypassing Memory Integrity Enforcement (MIE) — a protection Apple spent five years building....

>> read more

Grafana Labs Security Breach: Hackers Steal GitHub Token, Download Private Codebase, and Demand Ransom

18 May 2026  |  dark6  |  Databreach

A threat actor infiltrated Grafana Labs GitHub environment using a stolen privileged token to download the company private codebase. The attacker then attempted to extort Grafana with a...

>> read more

JDownloader Official Website Hijacked to Deliver RAT Malware in Windows and Linux Installers

17 May 2026  |  dark6  |  Malware

Attackers compromised the official JDownloader website between May 6-7, 2026, replacing legitimate Windows and Linux installers with malicious versions containing a Python-based Remote Access Trojan. Users who downloaded...

>> read more

Android 16 ‘Tiny UDP Cannon’ Flaw Lets Malicious Apps Bypass VPN and Expose Your Real IP Address

17 May 2026  |  dark6  |  Privacy

A newly disclosed Android 16 design flaw dubbed 'Tiny UDP Cannon' allows any app with basic permissions to bypass VPN lockdown mode and reveal the device's real IP...

>> read more

CVE-2026-46333: ‘ssh-keysign-pwn’ Linux Kernel Flaw Exposes SSH Keys and Shadow Passwords — Public PoC Released

17 May 2026  |  dark6  |  Vulnerability

A critical Linux kernel race condition flaw (CVE-2026-46333), dubbed 'ssh-keysign-pwn,' allows local unprivileged attackers to steal SSH private keys and read hashed passwords from /etc/shadow. A public proof-of-concept...

>> read more

Google Project Zero Reveals Silent Zero-Click Exploit Chain Rooting Pixel 10 Devices

17 May 2026  |  dark6  |  Vulnerability

Google Project Zero has demonstrated a two-vulnerability chain that silently roots Google Pixel 10 devices without any user interaction, combining a Dolby media framework flaw with a newly...

>> read more

Inside The Gentlemen: The Fastest-Growing Ransomware-as-a-Service Operation of 2026 — 332 Victims, Leaked Playbook Exposed

16 May 2026  |  dark6  |  Ransomware

The Gentlemen, a ransomware-as-a-service operation that emerged in mid-2025, has claimed approximately 332 victims in the first five months of 2026 alone by targeting Fortinet and Cisco edge...

>> read more