- Weekendowa Lektura: odcinek 689 [2026-08-14]. Bierzcie i czytajcie
- Weekendowa Lektura: odcinek 689 [2026-08-14]. Bierzcie i czytajcie
- Ukraińska policja zamknęła 94 oszukańcze call center
- Historyczna kradzież danych – weryfikacja najpóźniej za tydzień
- Koniec testów. Rządowy komunikator zostaje w Poczcie Polskiej
- Polska wraca do strefy Starlink Roam. SpaceX wycofuje się z decyzji
- Dokumenty z rekrutacji w sieci. Uczelnia, żłobek i nie tylko
- ICO upomina ACRO po incydencie bezpieczeństwa. Ostrzeżenie dla ochrony danych i odporności operacyjnej
- Krytyczne luki w belgijskim systemie eID: od kradzieży tożsamości po zdalne wykonanie kodu
- CISA rozszerza katalog KEV o luki w Metabase, Windows i Cisco Secure Firewall
- Ujawniony klucz AWS naraził dane ponad 1500 organizacji charytatywnych w Wielkiej Brytanii
- Narzędzia hakerskie oparte na AI trafiają na podziemne fora i obniżają próg wejścia do cyberataków
- WordPress 7.0.4 usuwa groźną lukę RCE związaną z Imagick i Ghostscript
- Ataki na SharePoint po publikacji PoC: CVE-2026-55040 napędza falę prób obejścia uwierzytelniania
- Cyberatak na CEVA Logistics zakłócił pracę magazynów i wysyłek w Europie
- Storm-1175 porzuca Medusę i wdraża StormEncryptor w błyskawicznych kampaniach ransomware
- Autonomiczny atak AI na Tajwan: chińscy hakerzy wykorzystali agentów AI przeciw sieciom rządowym
- ShieldBreak: nowy zero-day w Windows umożliwia eskalację uprawnień do SYSTEM
- Fortinet łata krytyczne luki uwierzytelniania w FortiWeb i FortiManager
- Lazarus wykorzystuje lukę zero-day w Windows do eskalacji uprawnień i instalacji backdoora
- WhatsApp wdraża Scam Alert: lokalne ostrzeżenia przed oszustwami w komunikatorze
- Ataki „City-Forum” na Salesforce i ServiceNow: jak błędnie udostępnione portale prowadzą do kradzieży danych
- Krytyczna luka w Adobe Commerce i Magento umożliwia przejęcie kont klientów bez logowania
- SpyNote i WindRelay na Androidzie: nowy schemat wyłudzeń kredytów i danych kart płatniczych
- Slopsquatting i AI: nowe zagrożenie dla bezpieczeństwa łańcucha dostaw open source
- Biały Dom otwiera drogę do kontrolowanych operacji „hack back” z udziałem sektora prywatnego
- Naruszenie danych klientów Trezor po ataku na partnera logistycznego ShipMonk
- Setki fałszywych rozszerzeń VPN dla Chrome przekierowywały ruch przez kontrolowane proxy
- Microsoft łata LegacyHive: zero-day w Windows umożliwiał lokalną eskalację uprawnień
- Ukraina zamyka 94 fałszywe call center. Służby ujawniają przemysłową skalę oszustw finansowych
- Krytyczna luka RCE w VMware vCenter wykorzystywana do utrzymywania dostępu przez reverse SSH
- Atak Akira w Safe Mode: wyłączenie EDR, kradzież danych i nieudane szyfrowanie
- Jewelbug: chiński aktor APT łączy cyberwywiad z kradzieżą kryptowalut
- Włamanie do bazy danych użytkowników systemu alarmowania OSP
- Dowódca DKWOC z awansem. Wyższy stopień też dla jego zastępcy
- Poczekajmy kilka dni z wchodzeniem na „Bezpieczne Dane”
- Polska najbardziej atakowana w UE. Rząd i wojsko łączą siły
- Przejęte konta, oszustwa, szantaż. Zatrzymano setki osób
- Agent AI miał zapisać go na siłownię. I zapisał, kasując rezerwacje innych osób.
- Cyberbezpieczeństwo w centrum technologicznej transformacji. Cyber Security Expo Poland 2026 już we wrześniu
- USA wykorzystają prywatne firmy w zagranicznych cyberoperacjach
- Wyciek danych Polaków to żyła złota dla obcych służb. Właśnie zyskały potężną broń
- Złośliwa karta SIM może przejąć modem. Niebezpieczna funkcja RUN AT w urządzeniach IoT
- Największy wyciek danych osobowych w historii Polski i co możemy z nim zrobić
- Chińscy hakerzy użyli agentów AI do autonomicznego ataku na infrastrukturę rządową Tajwanu
- Cyberprzestępcy wykorzystują AI do wyszukiwania nowych ścieżek wejścia do sieci firmowych
- Intel i AMD łatają ponad 80 luk bezpieczeństwa w procesorach, firmware i narzędziach AI
- Ivanti Endpoint Manager łata krytyczne luki: zdalne ataki, wyciek poświadczeń i ryzyko dla S3
- ICS Patch Tuesday w OT: krytyczne poprawki od Siemens, Schneider Electric i Phoenix Contact
- City-Forum: ukryte ataki na Salesforce i ServiceNow z użyciem niestandardowych narzędzi
NEWS
- Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
- The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI
- What Boards Need to Know About Tech Risk
- Max severity SAP Commerce Cloud flaw now targeted in attacks
- Cyera's Oasis Security Buy is All About AI Agent Control
- Shell investigates 'potential incident' after Clop data theft claims
- RingCentral data breach exposed info of 1.6 million accounts
- Data analyst sent to prison for stealing data, extorting employer
- Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks
- Ukraine shuts down 94 fraudulent call centers, seize millions in cash
- Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt
- Global Threat Campaign Hits Critical VMware vCenter Flaw
- Hackers breach govt webmail while running parallel crypto fraud
- Curiouser and Curiouser
- Microsoft patches LegacyHive Windows zero-day vulnerability
- AI 'watermark removers' flood the web. Almost none can prove they work.
- Critical VMware vCenter RCE flaw exploited for reverse SSH access
- Trezor discloses data breach affecting nearly 14,000 customers
- Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion
- White House taps security firms for offensive hack-back operations
- WhatsApp rolls out new feature that flags potential scam messages
- Dissecting the JWR phishing framework
- 'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft
- Parents take on Meta, TikTok, Google, and Snap in 3,000 youth safety lawsuits
- CBP Workers Allegedly Used Government Databases to Spy on Exes, Crushes, and Colleagues
- Belgium's eID Authentication Opens Citizen Accounts to RCE
- Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
- "City-Forum" data-theft attacks target Salesforce, ServiceNow portals
- Android malware combo takes out loans and relays victims' credit cards
- Long-running Data Theft Campaign Targeting Salesforce, ServiceNow
- Hackers exploit critical Adobe Commerce flaw to hijack customer accounts
- Hundreds of fake Chrome VPN extensions route traffic through a proxy
- Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
- Walmart's "Trusted Agent" Approach to Purple Teaming
- Plug and Pwn attack uses fake USB devices for Windows SYSTEM access
- Lazarus hackers exploited Windows zero-day to target defense firms
- FBI: Hackers target online accounts to steal nude photos
- 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One
- The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In
- Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition
INFLUENCERS
- Upcoming Speaking Engagements
- Who’s Tracking You? Use This New Service to Find Out
- If the Markets Reject OpenAI and Anthropic, the US Should Nationalize Them
- Separating AI’s Technological Problems from Its Capitalism Problems
- Prompt Injections for Defense
- Weekly Update 516: Live From Vietnam
- Microsoft Plugs Nearly 400 Security Holes
- AI Genie in the Wild
- AI for Military Support
- Python Now Has a Post-Quantum Encryption Library
- Friday Squid Blogging: Arctic Bobtail Squid Video
EXPLOITS
- [remote] PraisonAI praisonaiagents 1.6.77 - Remote Code Execution
- [webapps] Ray 2.56.0 - Directory Traversal & Local File Inclusion
- [remote] mcp-server-kubernetes 3.8.x - Argument Injection
- [webapps] Planyo_Online_Reservation_System 3.0 - Arbitrary File Read via SSRF
- [dos] LuCI DHCPv6 - Lease Hostname Stored Cross-Site Scripting
- [webapps] Blocksy Companion 2.1.46 - RCE
- [webapps] Apache Gravitino 1.2.1 - SSRF
- [webapps] Joomla 2.9.99.4 - Unauthenticated Remote Code Execution
- [webapps] CorgetGpsDget 2_3.2 - OS Command Injection
- [local] Microsoft Edge 150.0.4078.48 - RCE
- [webapps] OrkesConductor 3.30.2 - Unauthenticated Remote Code Execution
MALWARE
- France investigates tax authority breach after hacker claims 600,000 victims
- 일본인 을 대상으로 이메일 통한 정보 탈취 악성코드(AgentTesla)-20260804-000581.js
- Sintesi riepilogativa delle campagne malevole nella settimana del 8 – 14 agosto
- Ransomware Threats in the Americas H1 2026: Dissecting the Regional Attack Patterns and Dominant Actors
- Zimbra security advisory (AV26-816)
- Apple now uses iPhone alerts for targets of mercenary spyware
- Arctic Wolf Celebrates 2026 CRN Annual Report Card (ARC) Award Wins
- NHS admits data breach by sending patient data via pagers
- WhatsApp is testing a new warning for scam messages
- I Built an Azure Detection Engineering Lab with Microsoft Sentinel
- Who’s Tracking You? Use This New Service to Find Out
- Russia Targets Businesses and Officials Behind Europe’s Ukraine Defense Supply Chain
- APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
- AI Search Scams: Can You Still Trust the Answer Box?
- ISC Stormcast For Friday, August 14th, 2026 https://isc.sans.edu/podcastdetail/10052, (Fri, Aug 14th)
- Clop Ransomware Strikes AOL.COM
- Majinahanashi Strikes French Audio Retailer SON-VIDEO
- Emperador Ransomware Attack Targets City Government of Baguio
- Qilin Strikes United Association Local Union 345
- Aurora Ransomware Group Strikes Austrian Jewelry Brand FREYWILLE
ARTICLES
- The 80% Problem: Why AI resilience is more important than ever
- The first domino of AI disruption: How frontier models are revolutionising software security
- OpenAI loses its AI ethics lead
- Meta gives up control of Chinese AI startup Manus after eight months
- Microsoft brings Copilot apps together ahead of ‘super app’ overhaul
- Keeper Security Issues Cyber Guidance for Education IT Teams
- Apple cracks China with Alibaba for iPhone AI
- How to replace Edge as the default browser in Windows — and why you shouldn’t
- Trump Signs Memorandum Allowing Private Firms to Launch Offensive Cyber Operations Against Foreign Threat Actors
- Meet Huntress at International Cyber Expo 2026
- DeepSeek raises some V4 prices by more than 10x as AI demand strains capacity
- How Apple is leaving money on the table
- Adobe now lets Workfront users assign tasks to AI agents
- Scammers Exploit Shopify’s Own Notification System in New ‘Fake Refund’ Scam
- It took $58 to break Microsoft’s SCCM, but a patch made it harder
- Akira Ransomware Affiliate Rebooted Into Safe Mode to Dodge EDR and Broke Its Own Attack
- Is AI entering the SOC at the right stage?
- Forescout Launches Rapid Insight Assessment to Uncover Hidden Cyber Risks
- UK Cyber Attacks Jump 26% Year-on-Year as Ransomware Activity Doubles Globally
- OpenAI: Latest news and insights