Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

CVE-2026-39987: Marimo RCE Zero-Day Exploited Within 10 Hours of Disclosure — 662 Attacks Recorded

17 April 2026  |  dark6  |  Vulnerability

A critical unauthenticated RCE vulnerability in the Marimo Python notebook framework (CVE-2026-39987) was actively exploited just 10 hours after public disclosure. Sysdig recorded 662 exploit events over four...

>> read more

BLACKWATER Ransomware Debuts with Devastating Strike on Major Turkish Hospital Network, Claims 3.3 TB Stolen

17 April 2026  |  dark6  |  Ransomware

A newly emerged ransomware group called BLACKWATER has claimed its first major victim: Medical Park Hospitals Group in Turkey, with 36 hospitals affected and 3.3 terabytes of sensitive...

>> read more

MuddyWater-Linked APT Campaign Scanned 12,000+ Systems Before Striking Middle East Critical Infrastructure

16 April 2026  |  dark6  |  Malware

Iran-linked threat group MuddyWater is behind a sophisticated espionage campaign that scanned over 12,000 systems in the Middle East before stealing passport records and payroll data from an...

>> read more

Fake Ledger Live App on Apple’s Mac App Store Steals $9.5 Million in Crypto from 50+ Victims

16 April 2026  |  dark6  |  Cybercrime

A counterfeit Ledger Live app remained live on Apple's Mac App Store for two weeks, tricking users into entering their cryptocurrency wallet seed phrases. At least 50 victims...

>> read more

Critical Fortinet FortiClient EMS Vulnerability CVE-2026-21643 Actively Exploited — CISA Demands Patch Today

16 April 2026  |  dark6  |  Vulnerability

CISA has added CVE-2026-21643, a critical pre-authentication SQL injection flaw in Fortinet FortiClient EMS (CVSS 9.1), to its Known Exploited Vulnerabilities catalog with a mandatory patching deadline of...

>> read more

Booking.com Confirms Data Breach: Reservation Data and Personal Details of Customers Exposed

16 April 2026  |  dark6  |  Databreach

Booking.com has confirmed hackers accessed customer reservation data including names, addresses, phone numbers, and booking details. Security experts warn the exposed information enables highly targeted phishing attacks against...

>> read more

ShinyHunters Breaches Rockstar Games via Third-Party Vendor, Threatens to Leak GTA VI Contracts

15 April 2026  |  dark6  |  Databreach

ShinyHunters has breached Rockstar Games by exploiting authentication tokens from third-party analytics vendor Anodot to access Snowflake data warehouses. The stolen data reportedly includes financial records and confidential...

>> read more

Adobe Acrobat Zero-Day CVE-2026-34621: Four Months of Targeted Espionage via Prototype Pollution Exploit

15 April 2026  |  dark6  |  Vulnerability

Adobe patched a critical zero-day in Acrobat Reader (CVE-2026-34621) that was exploited for at least four months via a sophisticated prototype pollution technique. The attack chain enables full...

>> read more