Secure Bulletin Navigating the cyber sea with knowledge
Home
Latest news

Foxit’s Own Update Service Can Be Turned Into a SYSTEM-Level Backdoor on Windows

27 July 2026  |  dark6  |  Vulnerability

A privilege-escalation flaw in Foxit PDF Reader's updater, tracked as CVE-2026-57239, lets an attacker who already has a foothold on a Windows machine ride the update service all...

>> read more

Five-Year-Old Bugs in a JSON Parser Open a Code Execution Hole in Self-Managed GitLab

27 July 2026  |  dark6  |  Vulnerability

Researchers chained two long-dormant memory-safety bugs in Ruby's Oj JSON parser to achieve remote code execution on self-managed GitLab instances, using nothing more than an ordinary commit and...

>> read more

A Booby-Trapped Git Repository Can Quietly Leak Files Through Claude Code, Researchers Show

27 July 2026  |  dark6  |  AI

Security firm Tego AI says an ordinary-looking repository file can trick Anthropic's Claude Code into reading a file from outside the project and silently including it in its...

>> read more

JetBrains Patches a Wave of Critical Flaws Across IntelliJ IDEA and TeamCity

27 July 2026  |  dark6  |  Vulnerability

JetBrains has released fixes for a critical remote-code-execution flaw in IntelliJ IDEA and four high-severity vulnerabilities in TeamCity, including a critical RCE reachable through malicious Git repository configuration....

>> read more

AI-Powered Pentest Uncovers Eight Security Holes in Popular NodeBB Forum Software

27 July 2026  |  dark6  |  Vulnerability

A whitebox penetration test assisted by AI tools found eight high-severity flaws in the NodeBB forum platform, including bugs that could let attackers read private messages, hijack admin...

>> read more

Claude AI’s Shared Chat Links Briefly Turned Up in Google Search, Exposing Private Conversations

27 July 2026  |  dark6  |  Privacy

Hundreds of Claude AI shared-chat links reportedly became publicly searchable on Google over the weekend, exposing legal advice, proprietary code, and personal conversations to anyone who searched for...

>> read more

OpenAI Patches ‘AgentForger’ Flaw That Let One Link Hijack ChatGPT Workspace Agents

27 July 2026  |  dark6  |  AI

Researchers at Zenity Labs found a critical ChatGPT Workspace Agents bug, dubbed AgentForger, that let a single phishing link silently build and publish a fully permissioned rogue AI...

>> read more

Inside the Pro-Iran Hacktivist Coalition Racing to Mobilize During the US-Iran Conflict

27 July 2026  |  dark6  |  Hacktivism

A new analysis maps the loosely coordinated network of pro-Iran hacktivist groups, state-aligned actors, and opportunistic allies that have ramped up disruptive cyber campaigns since US and Israeli...

>> read more