Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

PoC Exploit Leaked for Unpatched Windows Privilege Escalation Zero-Day ‘BlueHammer’

13 April 2026  |  dark6  |  Vulnerability

A disgruntled researcher has published a working exploit for BlueHammer, an unpatched Windows local privilege escalation zero-day that abuses Windows Defender's update mechanism. Fully patched Windows 10, 11,...

>> read more

Adobe Patches Actively Exploited Acrobat Reader Zero-Day CVE-2026-34621 — Exploited Since December 2025

13 April 2026  |  dark6  |  Vulnerability

Adobe has issued an emergency patch for CVE-2026-34621 (CVSS 8.6), a prototype pollution zero-day in Acrobat Reader actively exploited since December 2025. Attackers can achieve code execution by...

>> read more

CISA Warning: Iranian-Affiliated Hackers Targeting US Critical Infrastructure PLCs to Cause Disruption

12 April 2026  |  dark6  |  Cybercrime

CISA has issued an urgent advisory (AA26-097A) warning that Iranian-affiliated APT actors have been actively targeting internet-exposed Programmable Logic Controllers across U.S. critical infrastructure since at least March...

>> read more

Russia’s APT28 Deploys New PRISMEX Malware in Espionage Campaign Targeting Ukraine and NATO Allies

12 April 2026  |  dark6  |  Malware

Russia-linked APT28 (Fancy Bear) has launched a new spear-phishing espionage campaign deploying PRISMEX, a previously undocumented malware suite combining steganography, COM hijacking, and cloud-based C2 infrastructure. Targets span...

>> read more

APT Iran Claims 375TB Breach of Lockheed Martin — F-35 Blueprints and Source Code Allegedly Stolen

12 April 2026  |  dark6  |  Hacktivism

Pro-Iranian hacktivist group APT Iran claims to have stolen 375 terabytes of data from Lockheed Martin, including alleged F-35 blueprints and internal source code. The group is demanding...

>> read more

Google Patches Actively Exploited Chrome Zero-Day CVE-2026-5281 — Update Now

12 April 2026  |  dark6  |  Vulnerability

Google has confirmed that CVE-2026-5281, a high-severity use-after-free vulnerability in Chrome's Dawn WebGPU implementation, is being actively exploited in the wild. CISA has added the flaw to its...

>> read more

Payload Ransomware Group Hits Egyptian Oil Giant WASCO in Double-Extortion Attack

11 April 2026  |  dark6  |  Ransomware

The Payload ransomware group has claimed a cyberattack against El Wastani Petroleum Company (WASCO), a major Egyptian oil and gas operator, using a double-extortion model that threatens to...

>> read more

CVE-2026-39987: Critical Marimo Python Notebook RCE Exploited Within 10 Hours of Disclosure

11 April 2026  |  dark6  |  Vulnerability

A pre-authentication remote code execution flaw (CVSS 9.3) in the Marimo Python notebook framework was weaponized by attackers within just 10 hours of public disclosure. The vulnerability allows...

>> read more