Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

FSB Claims Foreign Spyware Found on Russian Officials’ Phones in Targeted Espionage Campaign

3 June 2026  |  dark6  |  Spyware

Russia's FSB announced the disruption of a foreign intelligence campaign implanting advanced spyware on senior officials' mobile phones, enabling silent surveillance, communication interception, and data exfiltration consistent with...

>> read more

1-Click GitHub Token Theft: VSCode Webview Flaw Exposes OAuth Tokens for All Private Repositories

3 June 2026  |  dark6  |  Vulnerability

A critical VSCode webview vulnerability lets attackers steal GitHub OAuth tokens with a single click, granting full access to all private repositories. Researcher Ammar Askar published a complete...

>> read more

Critical Supply Chain Attack: 31 Red Hat Cloud Services npm Packages Backdoored to Steal Cloud and Dev Credentials

2 June 2026  |  dark6  |  Cybercrime

A sophisticated supply chain attack dubbed "Miasma: The Spreading Blight" has backdoored over 30 official @redhat-cloud-services npm packages, deploying credential-stealing malware that targets AWS, Azure, GCP secrets, GitHub...

>> read more

SmartApeSG Campaign Exploits ClickFix Fake Verification Pages to Deliver NetSupport RAT

2 June 2026  |  dark6  |  Malware

The SmartApeSG campaign is using ClickFix scripts disguised as fake browser verification pages to deploy a two-stage infection chain, culminating in a persistent NetSupport Manager RAT installation on...

>> read more

Attackers Exploit Docker and Kubernetes Misconfigurations to Escape Containers and Seize Host Control

2 June 2026  |  dark6  |  Vulnerability

Security researchers have documented a wave of attacks exploiting Docker and Kubernetes misconfigurations to break out of containers and take full control of host systems, including supply chain...

>> read more

OverlayPhantom Android Banking Trojan Targets 180+ Apps Across 10 Countries

2 June 2026  |  dark6  |  Malware

A dangerous new Android banking trojan called OverlayPhantom has been targeting users in ten countries, abusing Android's Accessibility Service to steal banking and cryptocurrency credentials from over 180...

>> read more

Hackers Are Calling You on Microsoft Teams Pretending to Be IT Support — How to Detect and Stop the Attack

1 June 2026  |  dark6  |  Phishing

Threat actors are systematically abusing Microsoft Teams' external collaboration features to impersonate IT helpdesk staff, convincing employees to grant remote access and install malware. Black Basta ransomware affiliates...

>> read more

Massive Supply Chain Attack: Poisoned VS Code Extension and “Megalodon” Campaign Steal Credentials from Millions of Developers

1 June 2026  |  dark6  |  Cybercrime

Two coordinated supply chain attacks poisoned the Nx Console VS Code extension (2.2M installs) and backdoored 5,561 GitHub repositories simultaneously, stealing cloud credentials and 3,800 internal GitHub source...

>> read more