Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Fake Teams Help-Desk Calls Turn Remote Support Into a Path Toward Domain Control

2 September 2026  |  dark6  |  Phishing

A campaign dubbed Spring Ring used external Microsoft Teams accounts and convincing help-desk calls to push remote-access tools and malware. In some cases, the attackers progressed toward SMB...

>> read more

Boston Scientific Cyber Incident Disrupts Manufacturing and Device Shipments

2 September 2026  |  dark6  |  Databreach

Boston Scientific is recovering from a cyber incident that interrupted on-premises systems supporting manufacturing, order processing and product shipments. The company says connected devices and previously enrolled remote...

>> read more

Critical Artifactory Bypass Is Being Used to Mint Administrator Tokens

2 September 2026  |  dark6  |  Vulnerability

A critical JFrog Artifactory authentication bypass is under active exploitation, with attackers reportedly creating administrator tokens on vulnerable servers. Self-hosted customers should upgrade immediately, revoke suspicious credentials and...

>> read more

Attackers Exploit Critical Langflow and Rails Flaws to Hunt Cloud Secrets

2 September 2026  |  dark6  |  Vulnerability

Attackers are actively exploiting critical flaws in Langflow and Ruby on Rails, with observed activity focused on credentials, application secrets and paths to remote code execution. Defenders should...

>> read more

D-Link Fixes Router Flaws That Exposed Admin and Wi-Fi Credentials on Local Networks

1 September 2026  |  dark6  |  Vulnerability

D-Link has patched access-control failures in the DIR-X1860Z that could let an unauthenticated local attacker reset the administrator password and retrieve wireless credentials. Owners should install the corrected...

>> read more

BGP Hijack Poisoned Virtualizor Updates and Put Hosting Servers at Root-Level Risk

1 September 2026  |  dark6  |  Vulnerability

A routing hijack diverted Softaculous infrastructure and enabled a malicious Virtualizor update to reach a small number of hosting servers. Because update packages lacked cryptographic verification, valid TLS...

>> read more

ValleyRAT Campaign Turns Fake Adware Installers Into a Persistent Espionage Backdoor

1 September 2026  |  dark6  |  Malware

A ValleyRAT campaign is disguising its infection chain as adware and familiar software installers, with most observed victims in China and India. The backdoor uses DLL sideloading and...

>> read more

Public HardBreacher Code Claims Kaspersky Privilege Escalation, but Evidence Remains Unverified

1 September 2026  |  dark6  |  Vulnerability

A public proof of concept called HardBreacher claims a local privilege-escalation weakness in Kaspersky Endpoint Security on Windows 11. The report remains unconfirmed, has no CVE, and is...

>> read more