Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Critical BeyondTrust Flaws (CVSS 9.2) in Remote Support and PRA Let Attackers Bypass Access Controls

7 July 2026  |  dark6  |  Vulnerability

BeyondTrust disclosed critical flaws (advisory BT26-03, CVSS 9.2) in Remote Support and Privileged Remote Access that let limited-privilege users bypass access controls. Cloud customers were auto-patched in April...

>> read more

New “Bad Epoll” Linux Zero-Day Lets Local Users Root Servers and Android Devices

6 July 2026  |  dark6  |  Vulnerability

A newly disclosed Linux kernel flaw dubbed “Bad Epoll” (CVE-2026-46242) lets a local, unprivileged user escalate to root on Linux servers, desktops, and Android devices via a use-after-free...

>> read more

PamStealer: New macOS Infostealer Disguises Itself as the Maccy Clipboard Manager

6 July 2026  |  dark6  |  Malware

PamStealer is a newly discovered macOS infostealer that impersonates the Maccy clipboard manager, using a two-stage AppleScript-to-Rust infection chain to steal Keychain data, browser credentials, and clipboard contents...

>> read more

Seven New CVEs in FatFs Filesystem Driver Put Millions of Embedded and IoT Devices at Risk

6 July 2026  |  dark6  |  Vulnerability

runZero has disclosed seven new CVEs in FatFs, the FAT/exFAT filesystem driver used across ESP-IDF, STM32Cube, Zephyr, MicroPython, and countless other embedded platforms. The bugs range from CVSS...

>> read more

New T3MP3ST Framework Turns AI Coding Agents Into Autonomous 0-Day Hunters

6 July 2026  |  dark6  |  AI

T3MP3ST, a new open-source framework, turns AI coding agents like Claude Code and Codex into autonomous red-teaming operators, claiming strong results on benchmark suites and a set of...

>> read more

Apache ActiveMQ Patches Three Vulnerabilities Enabling DoS, Data Leakage, and Privilege Escalation

6 July 2026  |  dark6  |  Vulnerability

Apache ActiveMQ users should urgently patch three newly disclosed vulnerabilities — CVE-2026-53917, CVE-2026-54475, and CVE-2026-49877 — that can crash brokers, break temporary-destination isolation, and let low-privilege Web Console...

>> read more

Flipper Zero Maker Overhauls Firmware Contribution Rules After Community Backlash

6 July 2026  |  dark6  |  Cybercrime

Flipper Devices has rolled out new firmware contribution rules, including GitHub Discussions-based feature voting and mandatory integration testing, after community backlash over a perceived firmware development slowdown.

>> read more

Cybersecurity Week in Review: AI Model Redeployment, a Linux Root Zero-Day, and Hundreds of Chrome Patches

6 July 2026  |  dark6  |  Cybercrime

This week: Anthropic's Claude Mythos 5 returns to critical infrastructure use, a near-100%-reliable Linux root zero-day emerges, Chrome patches 382 bugs, and Scattered Spider notches another extradition.

>> read more