Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

CVE-2026-8178: Critical Amazon Redshift JDBC Driver Flaw Enables RCE via Malicious Connection URLs — Patch Now

16 May 2026  |  dark6  |  Vulnerability

A critical vulnerability (CVE-2026-8178) in the Amazon Redshift JDBC driver allows remote code execution through manipulated database connection URLs. The flaw exploits unsafe class loading in the com.amazon.redshift:redshift-jdbc42...

>> read more

TeamPCP Supply Chain Campaign Poisons Checkmarx KICS, Bitwarden CLI, and PyPI Packages to Steal Cloud Credentials at Scale

16 May 2026  |  dark6  |  Cybercrime

A financially motivated threat group tracked as TeamPCP has executed at least seven waves of sophisticated supply chain attacks since March 2026, poisoning trusted CI/CD tools including Checkmarx...

>> read more

CVE-2026-44338: PraisonAI Framework Actively Exploited Within Hours of Disclosure — No Auth Required

16 May 2026  |  dark6  |  Vulnerability

A critical authentication bypass flaw in PraisonAI's legacy API server (CVE-2026-44338) shipped with auth disabled by default, allowing unauthenticated attackers to hijack AI workflows and drain API quotas....

>> read more

84 TanStack npm Packages Poisoned in Sophisticated Supply-Chain Attack Stealing Cloud and CI Credentials

15 May 2026  |  dark6  |  Cybercrime

Attackers compromised 84 npm artifacts across 42 TanStack packages — including react-router with 12M+ weekly downloads — injecting a credential-stealing payload via chained GitHub Actions abuse. Organizations that...

>> read more

BitUnlocker: New Tool Breaks BitLocker on Patched Windows 11 Systems in Under 5 Minutes

15 May 2026  |  dark6  |  Vulnerability

A publicly released tool called BitUnlocker demonstrates a practical downgrade attack against BitLocker on fully-patched Windows 11 machines, exploiting a gap between CVE-2025-48804 patching and certificate revocation to...

>> read more

CVE-2026-26083: Critical Fortinet FortiSandbox Flaw Allows Unauthenticated Remote Code Execution — Patch Now

15 May 2026  |  dark6  |  Vulnerability

Fortinet has disclosed CVE-2026-26083, a critical (CVSS 9.1) missing-authorization vulnerability in FortiSandbox that lets unauthenticated attackers execute arbitrary code remotely across on-prem, cloud, and PaaS deployments. Enterprises should...

>> read more

CVE-2026-43898: Critical SandboxJS Escape (CVSS 10.0) Enables Full Host Takeover via npm

15 May 2026  |  dark6  |  Vulnerability

A maximum-severity (CVSS 10.0) vulnerability in the SandboxJS npm library allows attackers to completely escape the JavaScript sandbox and execute arbitrary code on the host system — no...

>> read more

ClickFix Evolves: Attackers Combine Social Engineering With Decade-Old PySoxy SOCKS5 Proxy for Persistent Access

14 May 2026  |  dark6  |  Malware

A new ClickFix campaign observed by ReliaQuest pairs the social engineering technique with PySoxy, a 10-year-old Python SOCKS5 proxy, creating a two-channel persistent access chain that continues operating...

>> read more