- Prezydent składa drugi projekt ustawy o kryptoaktywach. „Próba kompromisu”
- Polska i Korea Południowa zacieśniają współpracę. W centrum wojskowa AI
- AI przyspiesza cyberataki. Uczelnie muszą bronić się razem
- FalconFlank. Gdy EDR sam staje się narzędziem do eskalacji uprawnień
- Rhysida atakuje administrację Berlina: wyciek danych i presja podwójnego wymuszenia
- Pozwy zbiorowe po cyberataku na MGM Resorts: skutki naruszenia danych i lekcje dla organizacji
- JSCeal: malware ukryty w bytekodzie V8 atakuje użytkowników kryptowalut
- NCSC ostrzega przed shadow AI: nieautoryzowane narzędzia AI zwiększają ryzyko wycieku danych i nadużyć uprawnień
- Dlaczego sandboxy dla agentów AI zawodzą testy bezpieczeństwa
- Nightmare Eclipse publikuje trzy exploity zero-day wymierzone w CrowdStrike, Nvidię i Avast
- Nowy linuksowy zestaw szpiegowski powiązany z Koreą Północną ukrywa backdoor w HAProxy
- Agenci OpenAI przejęli zewnętrzną wiki. Nowy sygnał ostrzegawczy dla bezpieczeństwa agentów AI
- Dlaczego jedna checklista bezpieczeństwa chmury nie działa w środowiskach wielochmurowych
- Telerik UI for ASP.NET AJAX: łańcuch padding oracle prowadzi do nieuwierzytelnionego RCE
- Dane 32,8 mln użytkowników Condé Nast wystawione na sprzedaż po wycieku powiązanym z WIRED
- Krytyczna luka RCE w N-able N-central. Czwarty hotfix w pięć tygodni wymaga natychmiastowej aktualizacji
- Ataki na routery MikroTik RouterOS: aktywnie wykorzystywany łańcuch luk umożliwia przejęcie urządzeń
- Naruszenie danych Trezor objęło już 81 tys. klientów. Rosną skutki incydentu w łańcuchu dostaw
- Ataki na Microsoft 365: fałszywy help desk i kradzież tokenów sesyjnych omijają klasyczne MFA
- ConnectWise ostrzega przed nową luką w ScreenConnect bez dostępnej poprawki
- Złośliwe klienty ScreenConnect rozprzestrzeniają czteroetapowy łańcuch VBScript na nowe hosty
- StyleSmuggler: zero-day w Magento i Adobe Commerce wykorzystywany do instalacji tylnej furtki w Linuxie
- BigBear 2.0 omija MFA w Microsoft 365. Nowa fala phishing-as-a-service uderza w firmy
- PEEP zamienia Chrome i Edge w tylne furtki po przejęciu stacji roboczej
- Mathspace ujawnia naruszenie danych ponad 1 mln osób po przejęciu systemu Metabase
- Sztuczna inteligencja zniszczy demokrację?
- Tajne dokumenty Bundeswehry trafiły do sieci. Cyberprzestępcy spełnili groźby
- Atak na sieć przychodni w Warszawie. Możliwy wyciek danych
- Poważne luki w systemie operacyjnym. CERT Polska alarmuje
- Wyciek danych nauczycieli. Faktury do badań medycznych w sieci
- Z pamiętnika admina #4
- Kryzys cyfrowego zaufania staje się problemem biznesu. Przed nami Sprint Cyber Forum 2026
- Kraje G7 biją na alarm. Komputery kwantowe wstrząsną kluczowym obszarem
- Pusty, bezludny i sztuczny. Znaczenie człowieka w cyfrowym świecie
- Service Principal zablokowany, ale token nadal żyje. Jak CAE odcina dostęp w Microsoft Entra ID?
- Jak złośliwy CSS może przełamywać zabezpieczenia webmaila
- Claude Code jako narzędzie w rękach cyberprzestępców. Analiza przypadków użycia agentów AI w realnych atakach
- Luki PaperCut wykorzystywane w atakach na szkoły w USA i Europie
- Agenci AI wykorzystali niemiecką wiki do koordynacji oszustw. Incydent ujawnia nowe ryzyko bezpieczeństwa
- OpenAI przeznacza 1 mld dolarów na wsparcie cyberobrony wodociągów i infrastruktury krytycznej
- Niewidzialne znaki Unicode w phishingu: nowa metoda omijania filtrów pocztowych
- REVSTEALER rozszerza atak: powiązane moduły wyłączają Windows Update i Defender, a następnie uruchamiają koparkę
- MikroTik RouterOS pod aktywnym ostrzałem: kampania MikroTrick wykorzystuje luki SSH i zostawia ślad „-2” w logach
- Krytyczne luki w MikroTiku, umożliwiające przejęcie urządzenia przez SSH. Łatajcie się pilnie.
- Rosja rozwija niebezpieczną siatkę w Grecji. Uderza w czułe punkty społeczeństwa
- Wyciek danych Manchester Airports Group objął 8,8 mln osób. Incydent ujawnia ryzyko ekspozycji danych pasażerów
- CISA dodaje aktywnie wykorzystywaną lukę Google Chromium V8 do katalogu KEV
- Naruszenie JetBrains Cadence po luce w TeamCity. Wyciek poświadczeń AWS i ryzyko dla kodu źródłowego
- Ponad 5,4 tys. zhakowanych stron rozprowadza ClickFix z ładunkami ukrytymi w blockchainie
- Broadcom łata krytyczne luki VM-escape w VMware Workstation i Fusion
NEWS
- 220 million traveler records exposed in Vietnam-linked APIS leak
- Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing
- PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
- Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
- Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
- BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
- ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
- Mathspace discloses data breach affecting over 1 million people
- Trezor data breach impact now reaches 81,000 customers
- Your Cloud Security Checklist Doesn't Work the Way You Think It Does
- Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
- Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released
- ChatGPT can now connect to your personal apps to mimic writing style
- Hackers exploit new MikroTik RouterOS flaws to hijack routers
- ConnectWise warns of new ScreenConnect flaw without patch
- N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw
- JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
- A week in security (August 31 – September 6)
- N-able patches max severity N-central flaw amid ongoing attacks
- ChatGPT Astra is now rolling out to $20 Plus subscription
- Attackers conceal phishing lures using invisible Unicode characters
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
- Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
- Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
- Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
- OpenAI admits it didn't disclose rogue AI wiki hijacking incident
- OpenAI Agents Hacked Another Website
- Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel
- Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
- [Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
- [Virtual Event] Building a Secure AI Strategy for the Enterprise
- IDScan sued over alleged data breach affecting 153 million drivers
- Companies Have Six Months to Prepare for Automated Attacks
- Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
- Critical Citrix NetScaler auth bypass now leveraged in attacks
- PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution
- New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
INFLUENCERS
- Automobile Camouflage to Hide from Flock Cameras
- Weekly Update 520: The Unscripted Edition
- Friday Squid Blogging: Squid on a Stick at the New York State Fair
- Using a VM to Contain an AI Agent
- Security Vulnerability in a Voting System
- AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks
- Researching Employment Scams
- AI Agents Are Now Emailing Me with Their Security Concerns
- Wireless Routers as Motion Detectors
- FBI Probes Service Selling 153M+ Drivers Licenses
- Weekly Update 519: Breaches & Data Integrity
- What’s the Scam?
- Leaked Russian Cyber-Operations Training Materials
- Rewiring Democracy Series on The Renovator
TOOLS
- Watcher v3.5.3
- DNSlivery
- CyberStrikeAI
- wraith
- DarkTortilla-RAT-Telegram-Exfiltration-Payload-Extraction-Analysis
- syswarden
- mvt v2026.9.7
- log-horizon v0.9.0
- raptor v3.1.0
- NETworkManager v2026.9.7.0
- r2frida v6.2.2
- yj_nearbyglasses v1.0.10
- radare2 v6.2.2
- Setup IPsec VPN — Updated!
- BrowserBox v18.8.0
- godirb
- MemoryModulePP
- edrEvasionWorkshop
- android-kernel-exploitation
- mythic_ornn
EXPLOITS
- [webapps] Metabase 0.61.0 - Authenticated Remote Code Execution
- [webapps] FreePBX 17.0.2 - Remote Code Execution (RCE)
- [hardware] Fullhan FH8626V100 - Multiple Vulnerabilities
- [webapps] Langflow 1.10.0 - RCE
- [webapps] Ghost_CMS 6.19.0 - Remote Code Execution
- [webapps] PodcastGenerator 3.2.9 - Stored XSS
- [webapps] Marimo 0.20.4 - RCE
- [webapps] Bludit CMS 3.20.0 - Reflected Cross-Site Scripting
- [dos] EVerest 2025.9.0 - DoS
MALWARE
- Drug trafficking investigation leads to some of the world’s biggest underground bankers
- Shai-Hulud in the Wild: What Security and Incident Response Teams Need to Know
- CYBER HUNTER PROJECT Book — What You Will Find Inside
- A 2026 Gartner® Peer Insights™ Customers’ Choice for Adversarial Exposure Validation
- How Can I Detect Fake Domains and Apps Impersonating My Brand
- What Is Privacy Protection and Why Is It Important for Businesses?
- What Tools Can Monitor the Dark Web for Leaked Company Credentials
- StressingLLMs OpenCode Benchmark Results
- ISC Stormcast For Tuesday, September 8th, 2026 https://isc.sans.edu/podcastdetail/10084, (Tue, Sep 8th)
- MA: Springfield Public Schools will be closed Tuesday after a cyber incident
- Chameleon Ultra: Guide to RFID Reading, Emulation and Testing
- When Clients Ask About Quantum, Will Their Lawyers Be Ready?
- Loyalty points fraud is funding hacker holidays (Lock and Code S07E18)
- Hackers drain $320M in Bitcoin from Liquid Network, claim they’re the good guys
- 7th September – Threat Intelligence Report
- [일본 애니메이션]お気楽領主の楽しい領地防衛~生産系魔術で名もなき村を最強の城塞都市に~(2026)
- E-Commerce Access, Vedicline Data, Langflow RCE, ASUS Claim, and Energy Shell Access
- Bring Licensed Threat Intelligence into Every Conversation with SOCRadar and ChatGPT
- StyleSmuggler: Unpatched Magento and Adobe Commerce Zero-Day Exploited
- LG TV flaws could let attackers listen in, even in standby mode
ARTICLES
- Sam Altman calls GPT-6 Astra rollout ‘messy’ as enterprise users wait for access
- The UK’s Cyber Community Comes North as CyberFest returns for 2026
- Check Point Brings OpenAI’s Daybreak Models Into Its Security Platform to Speed Up Threat Validation and Remediation
- 16 Gmail power moves for more efficient inbox management
- How to automate your Gmail inbox — without AI
- AI is finding vulnerabilities faster. Who is funding the people expected to fix them?
- Q&A: Viasat Tests Satellite Resilience With AI as Cyber Expert Warns an Attack Could ‘Hurt an Entire Country’
- The Human Connection Paradox: Why AI Makes People Matter More
- Nvidia-Hugging Face deal could require an enterprise AI rethink
- Macs don’t just do AI, they’re replacing the cloud for it
- Nvidia lets you build your own AI clusters locally with PAIR software
- Bidding war for defunct Spirit Airlines’ employee data will not die
- KnowBe4 to Put AI Trust to the Test at Leeds Digital Festival
- Compliance teams have gone continuous, but their evidence-gathering hasn’t caught up
- Protecting Against Zero-Click Attacks
- Adobe replaces CEO with customer experience leader
- Gmail labels: Your secret weapon against inbox chaos
- OpenAI launches GPT-6 Astra, its first model to cross a critical cybersecurity threshold
- ChatGPT, Claude, and Grok all went down at once; enterprises need a backup plan
- Word and Outlook will stop trying to guess what you’re going to type