Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

FortiWeb CVE-2025-64446 PoC: a critical weapon now widely available

16 November 2025  |  dark6  |  Vulnerability

The cybersecurity landscape has shifted once again, driven by the public release of a proof-of-concept exploit targeting the critical vulnerability CVE-2025-64446 within FortiWeb devices. This disclosure, originating from...

>> read more

SmartApeSG: the persistent evolution of a ClickFix-based RAT campaign

14 November 2025  |  dark6  |  Malware

The SmartApeSG campaign, previously identified by aliases like ZPHP and HANEY MANEY, continues to demonstrate a remarkable capacity for adaptation, moving beyond initial tactics of deceptive browser update...

>> read more

NVIDIA NeMo Framework: a critical cascade of vulnerabilities

14 November 2025  |  dark6  |  Vulnerability

The NVIDIA NeMo Framework, a cornerstone of conversational AI development, has recently revealed a significant and frankly concerning weakness. The disclosure, detailed in a critical security update, centers...

>> read more

New Bridgestone cyberattack: summary

4 September 2025  |  dark6  |  Databreach

Bridgestone Americas (BSA) is the North American division of Bridgestone, the world’s largest tire manufacturer by production volume. Attack Details Actions Taken Background

>> read more

Silk Road’s Ross Ulbricht receives $31 Million in Bitcoin from AlphaBay-linked source after release

6 June 2025  |  securebulletin.com  |  Cybercrime

The libertarian and crypto communities recently celebrated the release of Ross Ulbricht, the infamous founder of the Silk Road darknet marketplace. But the festivities took an unexpected turn...

>> read more

Critical Roundcube vulnerability (CVE-2025-49113): exploit sold in Darknet as “Email Armageddon” looms

6 June 2025  |  securebulletin.com  |  Vulnerability

A decade-old Remote Code Execution (RCE) flaw in Roundcube, the widely used open-source email client, has escalated into a global cybersecurity emergency. Designated CVE-2025-49113 with a near-maximum CVSS...

>> read more

Meta and Yandex Android apps exploit Localhost to track users

4 June 2025  |  securebulletin.com  |  Privacy

A recent investigation has uncovered that native Android apps from Meta (including Facebook and Instagram) and Yandex have been covertly tracking billions of users by exploiting localhost communications—a...

>> read more

Sophos exposes massive GitHub campaign distributing backdoored malware

4 June 2025  |  securebulletin.com  |  Malware

A sophisticated malware campaign targeting hackers, gamers, and cybersecurity researchers has been uncovered on GitHub, leveraging fake exploits, game cheats, and open-source tools to distribute backdoors. The operation,...

>> read more