- Nie informowali o przetwarzaniu danych. Zapłacą 30 tysięcy złotych
- Głos włoskiej premier zastrzeżony. Krok przeciwko deepfake'om
- Cyberzagrożenia codziennością w pracy. Eurobarometr pokazuje skalę problemu
- Dołącz do drużyny Mega Sekurak Hacking Party!
- Scam w sieci. Meta zmienia zasady, oszustwa także na YouTube
- Luka CSRF w popularnym dodatku Elementor do WordPressa. Wystarczy kliknąć w link, aby zdobyć uprawnienia administratora
- Nowe narzędzie do alarmowania ludności. W grudniu prezentacja aplikacji SOiA
- LiteLLM podatne na przejęcie kont przez niezweryfikowane adresy e-mail w JWT
- Algorytm starzeje się szybciej niż procedura. Jak skrócić drogę od laboratorium do żołnierza
- Jak ograniczyć ważność sekretów aplikacji w Microsoft Entra ID
- Warlock nadal wykorzystuje luki SharePoint do ataków na infrastrukturę krytyczną
- Citrix łata aktywnie wykorzystywaną lukę zero-day w NetScaler SAML
- Zatrzymanie domniemanego członka ShinyHunters w Jordanii może wzmocnić śledztwa przeciwko grupie
- TA419 atakuje ekspertów polityki AI w USA przy użyciu phishingu AitM podszywającego się pod Microsoft
- Wyciek z serwisu wakacje PL. Wyciekły w szczególności dane paszportowe
- Trzeba zmilitaryzować język, którym mówimy o działaniach Rosji [OPINIA]
- CISA dodaje krytyczne luki Zammad do katalogu KEV po potwierdzeniu aktywnego wykorzystania
- Fałszywy instalator Zoom na macOS ukrywa backdoora CloudSyncD
- Krytyczne luki w Dell CSM pozwalają przejąć klastry Kubernetes i dostęp do storage
- Antino: backdoor w Rust wykorzystuje Outlook i OneDrive do ukrytej komunikacji C2
- Fortra łata krytyczne luki w BoKS. Zagrożone uwierzytelnianie, root i integracja z Active Directory
- Warlock wykorzystuje luki w SharePoint do wyłączania zabezpieczeń i wdrażania ransomware
- Naruszenie bezpieczeństwa na DTU mogło ujawnić dane nawet 200 tys. osób
- Zatrzymanie domniemanego członka ShinyHunters w Jordanii może wzmocnić działania FBI przeciwko grupie
- Naruszenie danych w Frontline Education ujawnia wrażliwe informacje pracowników okręgów szkolnych
- MI5 ostrzega uczelnie: chiński MSS miał finansować badania ponad 100 naukowców powiązanych z Wielką Brytanią
- Zażądali od gościa $1700 na Airbnb za to, że zalał wynajmowane mieszkanie. Na dowód wysłali fotkę… AI.
- Szpital jako podmiot kluczowy KSC. Ten sam przepis, inne konsekwencje [OPINIA]
- Wakacje.pl zhackowane – pozyskano dane paszportowe Polaków
- Rosyjscy dziennikarze z bogatej dzielnicy Berlina. Putinowska propaganda w trasie po Europie
- Incydenty Kiteworks i Citrix pokazują, jak trudna jest reakcja na luki zero-day
- Krytyczna luka RCE w SConnect zagraża sektorowi bankowemu i administracji
- Złośliwe implanty Linuksa podszywają się pod azjatyckie systemy bezpieczeństwa poczty
- Dwa zero-daye w Zammad wykorzystane w ataku na holenderski DIVD
- Ekstradycja domniemanego irańskiego hakera do USA. Rzadki precedens w sprawach cyberoperacji państwowych
- Fałszywy instalator Zoom na macOS dostarcza backdoora CloudSyncD
- Antino: backdoor w Rust ukrywa komunikację C2 w Outlooku i OneDrive
- Operation KillSwitch: służby rozbiły ransomware KillSec i przejęły 110 TB skradzionych danych
- OpenAI rozstaje się z trzema badaczami bezpieczeństwa po incydencie z danymi wrażliwymi
- Android 17 ogranicza nadużycia usług dostępności dzięki Advanced Protection
- Agenci AI testowali SQL injection wobec serwisów rządowych USA i Kanady
- AI przyspiesza cyberataki. Microsoft wskazuje tożsamość i dane jako klucz do obrony
- Przejęcie oficjalnego konta Microsoft na X do promocji oszustwa kryptowalutowego
- Krytyczne luki w Dell CSM mogą umożliwić przejęcie klastrów Kubernetes i dostęp administracyjny bez logowania
- Krytyczna luka zero-day w FortiMail aktywnie wykorzystywana. CVE-2026-104286 pozwala na niezautoryzowany zapis plików
- Warlock ransomware atakuje przez luki w SharePoint. Sektor wodny i telekomunikacyjny na celowniku
- USA nakłada sankcje na członków Tren de Aragua za kampanię ATM jackpotting
- Ślepy punkt EDR: jak ataki w przeglądarce omijają telemetrię endpointów
- Naruszenie danych we Frontline Education uderzyło w pracowników okręgów szkolnych
- GitLab usuwa krytyczną lukę CVE-2026-90970 w AI Gateway dla środowisk self-hosted
NEWS
- Rejetto HFS servers now actively scanned for critical RCE flaw
- IQVIA fined $7.8 million for failing to properly anonymize health data
- Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes
- Chinese Hackers Impersonate US Officials for AI Cyber Espionage
- Denmark population registry data breach affects 8.8 million people
- New Dell System Update flaw lets hackers gain root privileges
- South Korea probes bank breaches amid suspected AI-powered attacks
- ⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
- tenfold CE: Our free Identity Governance tool just got 2 new features
- Alleged dev of Ploutus ATM malware appears in US court after arrest
- Need for Speed: AI-Driven Attacks Are Changing Security Strategies
- The Credential Layer Is Expanding Faster Than Security Teams Can See It
- Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2
- Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access
- OpenAI will show visual ads in ChatGPT while you generate images
- Microsoft: Windows KB5124010 update crashes some games and apps
- Google halts open-source bug bounty program amid AI spam surge
- Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
- A week in security (September 28 – October 4)
- New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
- Citrix patches NetScaler SAML zero-day exploited in attacks
- Anthropic asks Claude users to share voice data for AI model training
- ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members
- China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
- Google Gemini could soon get full access to your Mac’s files, apps and the web
- ShinyHunters hacker reportedly detained in Jordan, aiding FBI
- MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics
- Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
- Danish university DTU breach exposes data of up to 200,000 people
- Muse Creates Detailed Profiles of All Your Friends and Family
- The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations
- RemoteThreat Bets Security Teams Need to Test What Happens After Defenses Fail
- ICE Has Been Dumping Protester Photos Into a Palantir Database
- Frontline Education breach exposes school district employee data
- Warlock ransomware breach SharePoint in water, telecom operator attacks
- GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
- Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
- Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes
- Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response
- SWIFT Banking & Government Middleware Enables RCE
INFLUENCERS
- Another Historic Cipher Falls to AI
- Weekly Update 524: Live From Copenhagen
- Friday Squid Blogging: EU is Trying to Fight Unregulated Squid Fishing
- Unidentified Flock Cameras in Florida
- How American Political Campaigns Are Using AI—and What They’re Spending on the Tools
- Connected Cars Are a Surveillance Platform
- I Want Better Reporting on AI Genie Behavior
- Using Device Linking to Eavesdrop on WhatsApp and Signal
TOOLS
- Jackalope
- pyrasp
- CyberStrikeAI v1.7.21
- htmlpurifier
- Deep-Live-Cam — Updated!
- presentations
- llm-security
- Corporate_Masks
- Response Overview and Colonel Clustered – Grouping Burp Responses by Content
- Kramer
- donut-decryptor
- osmedeus v5.1.2
- enumerate-iam
- pyvex
- veneficus-implant-public
- xss-cheatsheet-data
- strix — Updated!
- LazZzy_Dump
- jscd
- advisories
VULNERABILITIES
- CVE-2026-90970:
- CVE-2026-5782:
- CVE-2026-39717:
- CVE-2026-39439:
- CVE-2026-39600:
- CVE-2026-39444:
- CVE-2026-104638:
- CVE-2026-39601:
- CVE-2026-32585:
- CVE-2026-32584:
- CVE-2026-104637:
- CVE-2026-104625:
- CVE-2026-104026:
- CVE-2026-94422:
- CVE-2026-85215:
- CVE-2026-93875:
- CVE-2026-104721:
- CVE-2026-19652:
- CVE-2026-104613:
- CVE-2026-104614:
EXPLOITS
- [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities
- [webapps] InvoicePlane 1.7.1 - RCE
- [webapps] Krayin CRM 2.2.4 - IDOR
- [webapps] SuiteCRM 8.10.1 - Authenticated SSRF
- [remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE
- [webapps] Food-Ordering 1.0 - LFI
- [webapps] WordPress 7.0.2 - Path Travesal
- [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write
- [remote] Teltonika_RutOS 00.07.06.21 - command injection
MALWARE
- Microsoft security advisory (AV26-1001)
- New in Falcon Cloud Security: Third-Party App Insights and AI-Enhanced Remediation
- HPE security advisory (AV26-1000)
- Pwn2Own Ireland 2026 - The Full Schedule
- [Control systems] GeoVision security advisory (AV26-998)
- Progress security advisory (AV26-999)
- Falcon Data Security for SaaS Secures Sensitive Data in Microsoft 365
- Cyber Morocco: a quick and dirty experiment about artificial intelligence for cyber intelligence
- Google pauses open source bug bounty program after rise in AI submissions
- Gta 6가 공식적으로 m(성인용) 등급 호주와 뉴질랜드에서는 성적인 장면이 명시
- Pentagon personnel breach — undetected for months — renews cyber standard scrutiny
- Nueva EPS, Colombia’s largest regional healthcare promoting entity has allegedly been hacked
- Proposed anti-Flock bills could spell trouble for license plate readers
- 5th October – Threat Intelligence Report
- IBM security advisory (AV26-997)
- Swarm Datasheet | Picus
- Ransomware group threatens to leak customer data from top insurance companies in South Africa
- Daiwa Securities says info on 110,000 clients may have been leaked in vendor incident
- Hackers Breached Propulsion System of U.S.-Bound Oil Tanker
- MFA Passed. The Attacker Still Got In
ARTICLES
- The foundations for future CX success
- The building blocks of anticipatory customer experiences
- CFO on the Spot: Five minutes with John McCauley, CFO of Vanta
- Q&A With Oliver Simonnet at CultureAI: AI Security In 2026: Most Organisations Deploy AI And Hope For The Best
- Prime Big Deal Days: scammers stock up early as Amazon impersonation attacks nearly triple
- Denmark’s CPR breach exposes 8.8 million people as experts warn over trusted third-party access
- Cybersecurity Awareness Month “cannot be the strategy”: why awareness must become a year-round capability
- A familiar face is no longer proof: rethinking social engineering defence for the deepfake era
- Tech execs are getting wise about ROI from AI
- Apple locks down Full Disk Access, and AI agents are the reason
- Ship fast, verify independently: keeping application security in step with AI-written code
- Shadow AI and the permissions problem: what to check before handing AI the keys
- Trump’s Super Intelligence edict supercharges .si domain registrations
- Cybersecurity Awareness Month: AI agents are users too, and they need governing like it
- Malicious Email Could Hijack AI Agent and Access Connected Accounts
- How Meta stumbled onto a winning AI strategy
- Facing the music: Apple, Samsung, and memory cost inflation
- US FTC will investigate Anthropic and OpenAI
- AI could boost software engineer productivity by 32.6%
- Microsoft adds support for Linux containers in WSL