Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

UniBLEed Flaws Put Unitree G1 Humanoid Robots at Risk of Root Takeover

29 August 2026  |  dark6  |  Vulnerability

Researchers demonstrated a multi-stage attack that can give a nearby adversary root-level control of Unitree G1 humanoid robots. The UniBLEed chain combines unauthenticated Bluetooth writes, a cloud authorization...

>> read more

Cyber Incident Halts Small UK Power Plant for Four Days as Attribution Remains Unclear

29 August 2026  |  dark6  |  Cybercrime

A cyber incident reportedly stopped a small British peaking power plant for roughly four days without disrupting customers or the wider grid. Officials confirmed the event, while key...

>> read more

Emergency PaperCut Fix Targets Actively Exploited Flaw Affecting Every Supported Release

28 August 2026  |  dark6  |  Vulnerability

PaperCut has issued emergency builds after confirming real-world attacks against PaperCut NG and MF servers. Administrators should isolate internet-facing application servers, install the appropriate update and investigate for...

>> read more

Houston Healthcare Company Nutex Health Confirms Data Breach and Exfiltration

28 August 2026  |  dark6  |  Databreach

Nutex Health, a Houston-based healthcare operator, has disclosed in an SEC filing that an unknown third party accessed its network and exfiltrated data, potentially including patient and employee...

>> read more

Critical Veeam ONE Flaw Lets Unauthenticated Attackers Steal Backup Credentials (CVSS 9.3)

28 August 2026  |  dark6  |  Vulnerability

A newly disclosed flaw in Veeam ONE, tracked as CVE-2026-65641 with a CVSS score of 9.3, lets a remote attacker with no credentials trick the monitoring service into...

>> read more

Critical cPanel Domain-Parking Flaw Lets Basic Users Seize Root Control

28 August 2026  |  dark6  |  Vulnerability

CVE-2026-65643 allows a low-privileged cPanel user with domain-parking rights to create arbitrary files and ultimately execute code as root. Hosting providers should verify patched builds immediately and restrict...

>> read more

Old Microsoft SQL Server RCE Returns in Active Attacks, Triggering CISA Forensic Mandate

28 August 2026  |  dark6  |  Vulnerability

CISA says attackers are exploiting CVE-2019-1068, a Microsoft SQL Server remote-code execution flaw, and has ordered both remediation and forensic triage. Database owners should patch exposed systems, review...

>> read more

CISA Orders Rapid Action as Citrix NetScaler Flaw Is Exploited in the Wild

28 August 2026  |  dark6  |  Vulnerability

CISA has placed CVE-2026-8452 in its Known Exploited Vulnerabilities catalog following confirmed attacks against Citrix NetScaler products. The memory-safety flaw can disrupt critical gateway services, and organizations should...

>> read more