Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

DuneSlide: Critical Zero-Click RCE Bugs in Cursor IDE Put Fortune 500 Developer Machines at Risk

2 July 2026  |  dark6  |  Vulnerability

Two critical zero-click RCE vulnerabilities (CVE-2026-50548, CVE-2026-50549) in Cursor IDE, dubbed DuneSlide, allow attackers to escape the AI coding agent sandbox via prompt injection with no user interaction...

>> read more

Apple’s Unpatched ‘Hide My Email’ Flaw Has Exposed User Identities for Over a Year

2 July 2026  |  dark6  |  Privacy

An unpatched vulnerability in Apple's Hide My Email feature can expose users' real email addresses behind their iCloud+ anonymization aliases, researcher Tyler Murphy and 404 Media have confirmed....

>> read more

Four New CVEs in Fluentd Expose Millions of Cloud and Kubernetes Logging Pipelines to RCE and Data Leaks

2 July 2026  |  dark6  |  Vulnerability

Four new CVEs in the widely deployed Fluentd log collector — including a critical RCE vulnerability (CVE-2026-44024) exploitable via crafted log entries — put cloud and Kubernetes logging...

>> read more

81 Million Login Attempts: Massive Password Spray Campaign Bypasses MFA to Compromise Azure and Microsoft 365 Accounts

2 July 2026  |  dark6  |  Cybercrime

A massive automated campaign made 81 million login attempts against Microsoft 365 and Azure CLI accounts between June 12 and June 26, 2026, successfully compromising 78 accounts across...

>> read more

PoC Published for CVE-2026-24294: NTLM Reflection Bypass Grants SYSTEM Access on Windows Server 2025

1 July 2026  |  dark6  |  Vulnerability

Synacktiv has released a working PoC for CVE-2026-24294, a new NTLM reflection bypass that grants SYSTEM-level access on Windows Server 2025 by abusing the SMB-over-custom-port feature. Microsoft patched...

>> read more

Critical wolfSSL Vulnerabilities Expose Billions of Servers and IoT Devices to Certificate Forgery and RCE

1 July 2026  |  dark6  |  Vulnerability

Multiple newly disclosed vulnerabilities in the wolfSSL embedded TLS library — including certificate trust bypasses, heap overflows, and post-quantum cryptography weaknesses — put billions of servers, IoT devices,...

>> read more

SEO-Poisoned Bing Search Delivers BumbleBee Loader and Akira Ransomware to Enterprise Network

1 July 2026  |  dark6  |  Ransomware

An IT administrator searching Bing for ManageEngine OpManager was redirected to a trojanized installer, triggering a 44-hour intrusion that ended with Akira ransomware deployed network-wide and 75GB of...

>> read more

CVE-2026-8037: Critical Pre-Auth RCE in Progress Kemp LoadMaster Puts Enterprise Networks at Risk

1 July 2026  |  dark6  |  Vulnerability

A CVSS 9.8 pre-authentication remote code execution vulnerability (CVE-2026-8037) in Progress Kemp LoadMaster allows unauthenticated attackers to run arbitrary commands on enterprise network edge appliances. Patched versions are...

>> read more