- Oszukiwała jako kupująca i sprzedająca. 35-latka zatrzymana przez CBZC
- Cyberataki na energetykę i wodociągi. Polska na celowniku
- ShieldBreak – nowy exploit lokalnej eskalacji uprawnień przez Microsoft Defender
- Jak przemycić złośliwy prompt w telemetrii i przejąć kontrolę nad agentem AI – szczegóły techniki GhostJacking
- Kampania fałszywych rozszerzeń VPN dla Chrome. Część podszywała się pod znane marki
- Krytyczne podatności w Zoom pozwalały na zero-click RCE
- Gold Eagle pod lupą: czy AI usprawni koordynację podatności w USA?
- Akt oskarżenia wobec 17 osób powiązanych z Iranem ujawnia skalę wieloletniej kampanii cybernetycznej przeciw USA
- Apple łata dziesiątki luk WebKit w macOS, iOS i iPadOS
- Fortinet przejmuje Virtue AI i wzmacnia bezpieczeństwo systemów sztucznej inteligencji
- Naruszenie danych w Heights Finance objęło co najmniej 1,2 mln osób
- Brytyjski regulator ostrzega sektor prawny przed ryzykiem AI po incydentach z autonomicznymi agentami
- AI napędza wzrost liczby podatności i podważa tradycyjny model patch managementu
- Ransomware coraz częściej kończy się szyfrowaniem danych ofiary
- Luka w NASA CryptoLib ujawnia ryzyko dla bezpieczeństwa łączności z misjami kosmicznymi
- Incydent cyberbezpieczeństwa na UT San Antonio sparaliżował część usług uczelni
- Krytyczne i wysokie podatności w aplikacjach firmowych napędzają dług bezpieczeństwa
- Exploit-DB 52654 niedostępny: jak oceniać ryzyko po usunięciu lub przeniesieniu publicznego PoC
- Linuxfabrik monitoring-plugins 6.0.0 z luką SSRF: możliwy wyciek poświadczeń Redfish
- CVE-2026-55781 w NanaZip 6.5: podatność DoS w parserze UFS prowadzi do niekontrolowanej alokacji pamięci
- flyto-core 2.26.7 z luką Arbitrary File Write. Możliwy zapis plików poza sandboxem
- PCMan FTP Server 2.0.7 podatny na zdalny buffer overflow w komendzie REST
- Konflikt agentów AI doprowadził do tworzenia samoreplikującego się malware w środowisku testowym
- Naruszenie bezpieczeństwa Hugging Face i PHANTOM-B: nowe pytania o kontrolę bezpieczeństwa systemów AI
- Atak na łańcuch dostaw LiteLLM ujawnia ryzyko dla środowisk AI i CI/CD
- Łańcuch exploitów w modemach Unisoc T612 może prowadzić do przejęcia jądra Androida po połączeniu wideo
- Evooo1Bot: nowy botnet oparty na Mirai atakuje urządzenia Linux i IoT
- Project noRecognition: jak AI może omijać systemy monitoringu i analityki obrazu
- Cavern C2 wykorzystuje DNS i Google Apps Script do ukrywania ruchu APT
- SafePal ujawnia incydent bezpieczeństwa: błąd autoryzacji naraził dane blisko 40 tys. klientów
- 16 złośliwych pakietów RubyGems wykorzystało typosquatting do kradzieży haseł i portfeli kryptowalut
- Krytyczna luka w Forminator dla WordPress pozwala na niezautoryzowane RCE przez upload pliku PHP
- Ransom Busters: nowy model wymuszeń po ataku ransomware udaje „pomoc” dla ofiar
- CISA dodaje CVE-2025-62593 w Ray do KEV. Krytyczna luka umożliwia przeglądarkowe RCE
- Firmy wysyłają dane na nieistniejące adresy. Problem z domenami “noreply”
- Druga historia z MyDr. 2 lata temu skradziono dane 13 mln osób
- MyDr o wycieku: „końcowy etap ustalania zakresu”
- Dane zdrowotne przedszkolaków na WhatsApp. „Konsekwencje dyscyplinarne”
- Podatność w oprogramowaniu Carbone
- Windows w praktyce: zjawisko korozji domeny, czyli dlaczego istotne błędy często nie mają swojego identyfikatora CVE
- Rafał Brzoska czołgiem po Facebooku
- Odszedł Paweł “kravietz” Krawczyk
- Brzoska odpowiada Mecie. „Nie ma słowa przepraszamy, nie odpuszczę"
- Podatność w Firefox JIT wykorzystana w łańcuchu browser-to-kernel
- Ghostjacking – atak odwracający zachowanie agenta AI
- ETSI proponuje 17 nowych specyfikacji cyberbezpieczeństwa dla produktów cyfrowych
- Infostealery napędzają masową kradzież danych uwierzytelniających
- Krytyczna luka w Payment Gateway Pix for WooCommerce do 1.5.0 umożliwia zdalne wykonanie kodu
- Krytyczna luka RCE w D-Link DNS-340L i innych NAS-ach: CVE-2024-10914 bez poprawek dla urządzeń legacy
- Luka SQL Injection w QSM zagroziła ponad 40 tys. stron WordPress
NEWS
- Windows 11 24H2 Home and Pro reach end of support in 2 months
- Flock Has a Powerful New AI Tool for Police. We Got Its Code
- CISA: Medusa ransomware hit over 500 critical infrastructure orgs
- Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure
- Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
- China-Linked Hacker Shows AI Capabilities in APAC Attack
- Critical GitLab Zero-Click Flaw Poses Mitigation Challenges
- 'CoSnitch' Attack Tricked Copilot into Mapping Out Architecture
- Comcast turns your Xfinity WiFi into a home motion detector
- OpenAI Overhauls Safety Protocols After Its AI Agents Went Rogue
- CISOs Break Their Silence in 'Declassified' Docuseries
- Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
- Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
- Clop created custom web shell for Windchill data theft attacks
- Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000
- Apple fixes another image-processing flaw that could allow code execution
- Meta Ran Ads for an App That Promised to Nudify Female Politicians
- Your Controls Block Known Attacks. What About the Behavior?
- 'Ransom Busters': Ransomware Actor Poses as Incident-Recovery Service
- Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud
- AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files
- TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks
- 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
- One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025
- Microsoft tests faster Windows File Explorer, new context menu
- Heights Finance data breach: What customers need to know
- CISA: Windows Task Host flaw now exploited by ransomware gangs
- Can AI Coexist With Privacy? Proton’s Andy Yen Says It Will Have To
- The Cop Who Took On Flock
- Microsoft confirms outage affecting search in Microsoft 365 apps
- SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers
- Microsoft starts removing WMIC tool used by cybercriminals
- CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
- Video Call Exploit Chains Two Flaws in Unisoc Modems
- Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
- 'Turf War' Between Claude Agents Leads to Self-Replicating Malware
- Hacker claims 3.6 million Azure account records stolen from major companies
- Adam Shostack Talks Hugging Face & PHANTOM-B
- Pokémon Center data breach exposes customer info, cancels some orders
- Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection
INFLUENCERS
- LLMs and Contextual Integrity
- Weekly Update 517: Cyber Ransoms
- Hacking Public Wi-Fi DNS to Steal Credentials
- Friday Squid Blogging: Searching for the Colossal Squid
- Upcoming Speaking Engagements
- Who’s Tracking You? Use This New Service to Find Out
- If the Markets Reject OpenAI and Anthropic, the US Should Nationalize Them
- Separating AI’s Technological Problems from Its Capitalism Problems
- Prompt Injections for Defense
VULNERABILITIES
- CVE-2026-71567 — CVSS 7.7
- CVE-2026-73851
- CVE-2026-71566 — CVSS 9.3
- CVE-2026-16049 — CVSS 4.3
- CVE-2026-16048 — CVSS 6.3
- CVE-2026-16047 — CVSS 4.3
- CVE-2026-16046 — CVSS 4.3
- CVE-2026-10527 — CVSS 6.3
- CVE-2026-16045 — CVSS 4.3
- CVE-2026-16044 — CVSS 5.4
- CVE-2026-13202
- CVE-2026-15754 — CVSS 4.2
- CVE-2026-59911 — CVSS 5.5
- CVE-2026-56685 — CVSS 7.3
- CVE-2026-59910 — CVSS 7.8
- CVE-2026-56090 — CVSS 7.3
- CVE-2026-59909 — CVSS 7.1
- CVE-2026-56686 — CVSS 7.8
- CVE-2026-56089 — CVSS 3.3
- CVE-2026-19693 — CVSS 8.1
EXPLOITS
- [webapps] Nodemailer 9.0.0 - File Read/ SSRF
- [webapps] flyto-core 2.26.7 - Arbitrary File Write
- [dos] NanaZip 6.5 - DoS
- [remote] PCMan 2.0.7 - Buffer Overflow
- [webapps] Linuxfabrik monitoring_plugins_6.0.0 - SSRF
- [dos] NanaZip 6.5 - DoS
- [remote] D-Link DNS_340L - OS Command Injection
- [webapps] flyto_core 2.26.7 - Server-Side Request Forgery
- [webapps] Duplicati 2.2.0.3 - JWT Signing Key Leak
- [remote] ipTIME A3004T - Remote Code Execution
- [webapps] Joomla JCE_2.9.15 - Remote Code Execution
- [webapps] Probo 0.222.2 - IDOR
- [webapps] webpack_devserver 5.2.5 - CSRF
- [remote] phpSysInfo 3.4.5 - IP Allowlist Bypass
- [webapps] WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload
- [dos] Nmap 7.99 - Extension Header Integer Underflow
MALWARE
- NCUA Cybersecurity Compliance: How Picus Supports Credit Unions
- What Is a Data Leak? Complete Guide to Causes, Risks & How to Check Yours
- A Guide to Understanding Threat Prevention in Modern Security
- UK Cybercrime Journal: Carding Tactics & Youth Money Muling
- Stressing LLM Local Model Results
- ISC Stormcast For Wednesday, August 19th, 2026 https://isc.sans.edu/podcastdetail/10058, (Wed, Aug 19th)
- Anubis Ransomware Attack on Scholle IPN / SIG
- Storm Ransomware Strikes WindRose Health Network
- Storm Ransomware Group Strikes Westco Motors Cairns
- Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics
- Clop Claims Data Theft From More Than 40 Companies
- The Russian hurdle in Trump’s new offensive cyber program
- CopyCop Targets AI Investment in Armenia
- CISA contemplates whether to hire security software buying help
- Arctic Wolf Data Explorer
- The Tiered SOC Is Breaking: Why the Agentic SOC Is the Only Model Built for Machine-Speed Attacks
- 가짜 USB 장치를 사용하여 Windows 시스템 권한에 접근 문제 발견
- Mattermost security advisory (AV26-828)
- GitLab security advisory (AV26-827)
- PurpleDelta's Fraudulent Employment Operations
ARTICLES
- The Readiness Gap: Navigating the Shift from AI Experimentation to Expectation
- Temps, tech and the transition of the UK workforce
- Microsoft finally patches critical one-click Copilot vulnerability, almost eight months after learning of it
- AI’s attribution problem gets worse as models scale
- Google buys data from bankrupt Spirit Airlines for AI training
- Hacker Claims Millions of Records Stolen From Azure Tenants
- 2,000 Hacked WordPress Sites Were Secretly Running a Global Crime Ring
- International Cyber Expo Unveils New Talks for its Global Cyber Summit 2026
- Is Apple beginning a privacy reset?
- New malware turns Microsoft 365 and Azure into its control center
- Warning to enterprises: Vibe coding can be a threat
- Proton launches free tool to show enterprises what ChatGPT and Claude know about employees
- GitHub restores services after nearly 8-hour outage disrupts Actions, APIs, PRs and Copilot
- ‘Data-driven, human-led’: Inside Revolut’s strategy for global hypergrowth
- AI inference is getting cheaper, but your agents are getting more expensive
- OpenAI president’s blog pushing agentic AI most notable for what it did not say
- US confounds Apple’s memory supply challenge
- Moburst Launches Answerburst, a Purpose-Built AEO Practice for the AI Search Era
- Exchange CU1 delayed further as Microsoft races to verify AI-found flaws
- Enterprise AI’s second act: from automation to augmentation