Latest news

A Critical Patch for Vulnerable Next.js: New Scanner Unveils Hidden Attacks
Vulnerability

A Critical Patch for Vulnerable Next.js: New Scanner Unveils Hidden Attacks

4 December 2025 dark6

With the rise of Serverless functions, static site generators like Next.js have become ubiquitous in web development, streamlining functionality and...
A Silent Vulnerability Exposed: How Hackers Used Hidden Commands to Steal Sensitive Data
Vulnerability

A Silent Vulnerability Exposed: How Hackers Used Hidden Commands to Steal Sensitive Data

3 December 2025 dark6

Microsoft’s seemingly “unremarkable” November 2025 Patch Tuesday update actually contained a major security fix. But even the most meticulous patching...
HashJack: weaponizing trust in AI browser assistants
AI

HashJack: weaponizing trust in AI browser assistants

26 November 2025 dark6

A vulnerability in the way AI browser assistants handle URL fragments opens doors for malicious attacks. For years, we’ve seen...
A Critical Security Flaws in HashiCorp’s Provider
Vulnerability

A Critical Security Flaws in HashiCorp’s Provider

25 November 2025 dark6

HashiCorp’s Vault Terraform provider, a cornerstone of secure secrets management for organizations worldwide, has been found with a critical security...
Wireshark 4.6.1: critical security update addresses major vulnerabilities
Vulnerability

Wireshark 4.6.1: critical security update addresses major vulnerabilities

24 November 2025 dark6

A recent update from the Wireshark Foundation addresses critical vulnerabilities impacting the widely used network protocol analyzer, potentially exposing users...
Chrome: a rapid-response Zero-Day exploits type confusion vulnerabilities
Vulnerability

Chrome: a rapid-response Zero-Day exploits type confusion vulnerabilities

18 November 2025 dark6

Google’s Chrome browser has found itself squarely in the crosshairs. A critical, previously unknown vulnerability – a zero-day – is...
NVIDIA NeMo Framework: a critical cascade of vulnerabilities
Vulnerability

NVIDIA NeMo Framework: a critical cascade of vulnerabilities

14 November 2025 dark6

The NVIDIA NeMo Framework, a cornerstone of conversational AI development, has recently revealed a significant and frankly concerning weakness. The...
China-Linked APTs exploit critical SAP NetWeaver vulnerability to breach over 580 systems globally
Cybercrime

China-Linked APTs exploit critical SAP NetWeaver vulnerability to breach over 580 systems globally

13 May 2025 securebulletin.com

In a significant escalation of cyber-espionage activities, multiple China-affiliated advanced persistent threat (APT) groups have been found actively exploiting a...
MITRE Signals Critical Risk to CVE Program as Federal Funding Expires
Vulnerability

MITRE Signals Critical Risk to CVE Program as Federal Funding Expires

15 April 2025 securebulletin.com

The cybersecurity world faces a significant challenge as the Common Vulnerabilities and Exposures (CVE) program, a cornerstone of global vulnerability...
Malicious NPM packages targeting PayPal users: a recap analysis
Malware

Malicious NPM packages targeting PayPal users: a recap analysis

12 April 2025 securebulletin.com

FortiGuard Labs recently uncovered a series of malicious NPM packages designed to steal sensitive information from compromised systems. These packages,...
Surge in Palo Alto Networks scanner activity
Vulnerability

Surge in Palo Alto Networks scanner activity

1 April 2025 securebulletin.com

GreyNoise has detected a significant surge in login scanning activity aimed at Palo Alto Networks PAN-OS GlobalProtect portals. In the...
Critical Remote Code Execution vulnerability discovered in GiveWP WordPress Plugin (CVE-2025-0912)
Vulnerability

Critical Remote Code Execution vulnerability discovered in GiveWP WordPress Plugin (CVE-2025-0912)

5 March 2025 securebulletin.com

A critical security vulnerability, identified as CVE-2025-0912, has been discovered in the GiveWP WordPress donation plugin. This flaw potentially exposes...