Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Zero-Day in Meta’s Muse AI Assistant Lets Local Malware Hijack Voice Commands and Steal Credentials

22 September 2026  |  dark6  |  Vulnerability

Researcher Patrick Wardle has disclosed an unpatched flaw in Meta's macOS AI agent Muse that lets unprivileged malware quietly redirect dictation traffic and harvest account credentials. The bug...

>> read more

Ireland Hits Google With a €403 Million Fine Over Years of Location-Data Practices

22 September 2026  |  dark6  |  Privacy

Ireland's Data Protection Commission has fined Google €403 million after finding that three of its location-related features failed to meet GDPR's requirements on lawfulness, fairness, transparency, and data...

>> read more

Popular npm Package With Nearly 2 Million Weekly Downloads Hid Malware That Talks to Attackers Through Ethereum

22 September 2026  |  dark6  |  Malware

Researchers at Checkmarx uncovered a supply-chain campaign hiding inside a widely used npm package that impersonates a legitimate data-structure library. Rather than infecting machines at install time, the...

>> read more

PAYLOAD Group Weaponizes Windows Group Policy to Take Down an Entire Domain Without Touching a Single File

22 September 2026  |  dark6  |  Ransomware

A ransomware crew calling itself PAYLOAD breached a Middle Eastern manufacturer's Windows domain and disrupted it enterprise-wide using nothing but malicious Group Policy Objects — no encryption, no...

>> read more

Agentic AI Forces Enterprises to Replace Standing Access With Task-Level Control

21 September 2026  |  dark6  |  AI

Rapid adoption of autonomous workplace agents is exposing the limits of broad, long-lived permissions designed for people and predictable software. Enterprises need short-lived credentials, task-specific authorization and clear...

>> read more

Cisco and Android Zero-Days Lead a Week of Identity and AI Security Failures

21 September 2026  |  dark6  |  Vulnerability

Active exploitation of Cisco ISE and Android modem flaws led a week crowded with critical vulnerabilities, agent hijacking research and identity-driven attacks. Defenders should prioritize exposed control planes,...

>> read more

Hugging Face Intrusion Shows Autonomous AI Can Break In—but Struggles to Stay Quiet

21 September 2026  |  dark6  |  AI

An AI security evaluation reportedly escaped its intended environment and spent days inside Hugging Face systems, leaving an unusually detailed record of autonomous offensive behavior. The case shows...

>> read more

CISA Orders Forensic Checks as Three Linux Kernel Flaws Face Active Exploitation

20 September 2026  |  dark6  |  Vulnerability

CISA has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog and ordered covered agencies to patch and investigate exposed systems. The flaws affect kernel TLS,...

>> read more