Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > cve
#cve

Chrome’s Fourth Zero-Day of 2026: CISA Orders Federal Agencies to Patch CVE-2026-5281 by April 15

9 April 2026  |  dark6  |  Vulnerability

Google has patched CVE-2026-5281, a use-after-free zero-day in Chrome’s WebGPU engine already exploited in the wild. It’s the fourth Chrome zero-day of 2026. CISA has mandated federal agencies...

>> read more

A Silent Vulnerability Exposed: How Hackers Used Hidden Commands to Steal Sensitive Data

3 December 2025  |  dark6  |  Vulnerability

Microsoft’s seemingly “unremarkable” November 2025 Patch Tuesday update actually contained a major security fix. But even the most meticulous patching process can sometimes be outmaneuvered by cunning threat...

>> read more

FortiWeb CVE-2025-64446 PoC: a critical weapon now widely available

16 November 2025  |  dark6  |  Vulnerability

The cybersecurity landscape has shifted once again, driven by the public release of a proof-of-concept exploit targeting the critical vulnerability CVE-2025-64446 within FortiWeb devices. This disclosure, originating from...

>> read more

NVIDIA NeMo Framework: a critical cascade of vulnerabilities

14 November 2025  |  dark6  |  Vulnerability

The NVIDIA NeMo Framework, a cornerstone of conversational AI development, has recently revealed a significant and frankly concerning weakness. The disclosure, detailed in a critical security update, centers...

>> read more

Critical Roundcube vulnerability (CVE-2025-49113): exploit sold in Darknet as “Email Armageddon” looms

6 June 2025  |  securebulletin.com  |  Vulnerability

A decade-old Remote Code Execution (RCE) flaw in Roundcube, the widely used open-source email client, has escalated into a global cybersecurity emergency. Designated CVE-2025-49113 with a near-maximum CVSS...

>> read more

China-Linked APTs exploit critical SAP NetWeaver vulnerability to breach over 580 systems globally

13 May 2025  |  securebulletin.com  |  Cybercrime

In a significant escalation of cyber-espionage activities, multiple China-affiliated advanced persistent threat (APT) groups have been found actively exploiting a recently disclosed critical vulnerability in SAP NetWeaver, identified...

>> read more

MITRE Signals Critical Risk to CVE Program as Federal Funding Expires

15 April 2025  |  securebulletin.com  |  Vulnerability

The cybersecurity world faces a significant challenge as the Common Vulnerabilities and Exposures (CVE) program, a cornerstone of global vulnerability management, risks disruption due to expiring federal funding....

>> read more

The Ballista Botnet: a new IoT threat with italian roots

11 March 2025  |  securebulletin.com  |  Malware

Cato Networks has uncovered a sophisticated IoT botnet, dubbed Ballista, targeting TP-Link Archer routers by exploiting a two-year-old vulnerability (CVE-2023-1389). This threat, linked to an Italian threat actor,...

>> read more