Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Cavern Manticore: Iranian-Linked APT Abuses SysAid RMM and DLL Sideloading to Deploy Modular C2 Framework

7 July 2026  |  dark6  |  Malware

A newly identified Iranian-linked group, Cavern Manticore, is abusing the SysAid RMM platform and DLL sideloading via WinDirStat to deploy a modular C2 framework against Israeli organizations. Check...

>> read more

Januscape: 16-Year-Old Linux KVM Flaw (CVE-2026-53359) Lets Malicious VMs Corrupt Host Kernel Memory

7 July 2026  |  dark6  |  Vulnerability

A 16-year-old flaw in Linux KVM, tracked as CVE-2026-53359 and dubbed Januscape, lets a malicious guest VM corrupt host kernel memory via a use-after-free in the shadow MMU's...

>> read more

Tenda Router Backdoor (CVE-2026-11405) Lets Attackers Skip Login and Seize Full Admin Control

7 July 2026  |  dark6  |  Vulnerability

A hardcoded authentication backdoor in Tenda FH1201, W15E, AC10, AC5, and AC6 routers (CVE-2026-11405) lets attackers log in as admin with any username. The undocumented flaw sits in...

>> read more

Critical BeyondTrust Flaws (CVSS 9.2) in Remote Support and PRA Let Attackers Bypass Access Controls

7 July 2026  |  dark6  |  Vulnerability

BeyondTrust disclosed critical flaws (advisory BT26-03, CVSS 9.2) in Remote Support and Privileged Remote Access that let limited-privilege users bypass access controls. Cloud customers were auto-patched in April...

>> read more

New “Bad Epoll” Linux Zero-Day Lets Local Users Root Servers and Android Devices

6 July 2026  |  dark6  |  Vulnerability

A newly disclosed Linux kernel flaw dubbed “Bad Epoll” (CVE-2026-46242) lets a local, unprivileged user escalate to root on Linux servers, desktops, and Android devices via a use-after-free...

>> read more

PamStealer: New macOS Infostealer Disguises Itself as the Maccy Clipboard Manager

6 July 2026  |  dark6  |  Malware

PamStealer is a newly discovered macOS infostealer that impersonates the Maccy clipboard manager, using a two-stage AppleScript-to-Rust infection chain to steal Keychain data, browser credentials, and clipboard contents...

>> read more

Seven New CVEs in FatFs Filesystem Driver Put Millions of Embedded and IoT Devices at Risk

6 July 2026  |  dark6  |  Vulnerability

runZero has disclosed seven new CVEs in FatFs, the FAT/exFAT filesystem driver used across ESP-IDF, STM32Cube, Zephyr, MicroPython, and countless other embedded platforms. The bugs range from CVSS...

>> read more

New T3MP3ST Framework Turns AI Coding Agents Into Autonomous 0-Day Hunters

6 July 2026  |  dark6  |  AI

T3MP3ST, a new open-source framework, turns AI coding agents like Claude Code and Codex into autonomous red-teaming operators, claiming strong results on benchmark suites and a set of...

>> read more