Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Iran’s Cyber Playbook Shifts From Loud Attacks to Patient, Long-Term Access

23 July 2026  |  dark6  |  Cybercrime

A new SentinelOne assessment finds Iran-linked hacking groups increasingly favor quiet, persistent access over destructive attacks, planting footholds in cloud accounts, IT suppliers, and industrial systems that could...

>> read more

Fake Game Downloads Are Quietly Installing Amatera Stealer Through a Disguised RenPy Loader

22 July 2026  |  dark6  |  Malware

A malware campaign is hiding behind fake games, cracks, and mods to install Amatera Stealer, a multi-stage infostealer that harvests browser credentials, messaging data, and cryptocurrency wallets. The...

>> read more

PhantomEnigma: How a Malware Crew Turned Brazilian Government Sites Into Trusted Malware Hubs

22 July 2026  |  dark6  |  Malware

A campaign tracked as PhantomEnigma has compromised more than 20 official Brazilian government websites, using them to host and deliver malware that passes email authentication checks and slips...

>> read more

Chrome’s Latest Patch Closes 12 Security Holes, Nine of Them Rated High Severity

22 July 2026  |  dark6  |  Vulnerability

Google has shipped a new Stable Chrome release fixing 12 vulnerabilities, nine of them high severity, touching core components like V8, ANGLE, and the GPU stack. Several of...

>> read more

Unauthenticated Attackers Are Actively Exploiting a ServiceNow Sandbox-Escape Flaw

22 July 2026  |  dark6  |  Vulnerability

A critical ServiceNow vulnerability that lets unauthenticated attackers break out of the platform's scripting sandbox is now being exploited in the wild. ServiceNow has shipped patches, but self-hosted...

>> read more

New Windows ‘Bind Link’ Trick Lets Attackers Fool EDR, AMSI, and AppLocker Without Touching a File

21 July 2026  |  dark6  |  Vulnerability

Bitdefender researchers have detailed how Windows 'bind links' — a legitimate feature behind containers and Sandbox — can be abused by an attacker with local admin rights to...

>> read more

HOLLOWGRAPH Malware Turns Microsoft 365 Calendars Into a Covert Spy Channel

21 July 2026  |  dark6  |  Malware

Group-IB has uncovered HOLLOWGRAPH, a stealthy malware component that hides its command-and-control traffic inside Microsoft 365 calendar invites dated decades in the future. The tool shows technical overlap...

>> read more

Gig Economy Platform Paidwork Leaks Banking and Personal Data of 23 Million Users

21 July 2026  |  dark6  |  Databreach

A data breach at gig-economy platform Paidwork has exposed banking details, payout histories, and personal information for more than 23 million users, with the stolen dataset publicly leaked...

>> read more