- Poważne luki w WordPressie. Możliwość wystąpienia incydentu krytycznego
- Aktualizacja listy OWASP Top 10 dla LLM 2026. Agent AI dostał ręce, klucze i dostęp do firmowych systemów
- Turecki sąd nakazuje X zablokować konto rywala Erdoğana. Platforma składa odwołanie
- Gawkowski: MSWiA powinno wdrażać system ostrzegania. Ekspert wskazuje metody
- Białe plamy nadal na mapie Polski. NIK krytycznie o rozbudowie sieci
- Luka w Google ADK. Agenci AI wpadli we własną pułapkę
- CosmosEscape. Krytyczna podatność w Azure Cosmos DB mogła otworzyć dostęp do każdej bazy danych
- Presja ataków i nowego prawa. Twój biznes potrzebuje prawdziwego SOC-a, a nie jego atrapy
- Chmura i SaaS coraz częściej na celowniku cyberprzestępców
- AI odpowiada już za ponad połowę złośliwych i spamowych e-maili
- Naruszenie bezpieczeństwa PNLD: wyciek danych kontaktowych brytyjskiej policji i partnerów publicznych
- Device code phishing i vishing gwałtownie rosną w 2026 roku
- SAGA: nowe narzędzie do identyfikacji źródła filmów generowanych przez AI
- Anthropic: luki w środowisku testowym, a nie model Claude, doprowadziły do realnych incydentów
- Fałszywe głosowanie na WhatsApp umożliwia przejęcie konta użytkownika
- Cisco Talos: atakujący rozdzielają zadania, by skuteczniej unikać wykrycia
- Atak na szwajcarską agencję federalną przez luki w SharePoint. Około 200 kont zostało przejętych
- Luka w AI notetakerze tl;dv mogła ujawnić rządowe i korporacyjne wideorozmowy
- INC Ransomware zwiększa presję na ofiary po wykorzystaniu luk zero-day w SonicWall SMA 1000
- Wyciek 31 tys. rekordów z rejestru beneficjentów rzeczywistych w Liechtensteinie
- AI wzmacnia spearphishing i podnosi koszty cyberataków
- AI przyspiesza eksploatację podatności i ataki na łańcuch dostaw
- Krytyczna luka w cPanel pozwala wykonywać polecenia SQL z uprawnieniami roota bazy danych
- SAFE: branża technologiczna proponuje wspólny system raportowania incydentów bezpieczeństwa agentów AI
- Atak agent-to-agent w Gemini ADK ujawnił sekrety i otworzył drogę do manipulacji pull requestami
- Wieloletnia luka w BMC naraża centra danych na przejęcie przez ataki offline
- Masowy atak na npm: robak powiązany z Keyv zatruł setki pakietów i uderzył w łańcuch dostaw
- Google usuwa trzy workflowy ADK po wykryciu łańcucha ataku z prompt injection
- 18 złośliwych pakietów npm atakuje użytkowników narzędzi Alibaba i dostarcza wieloplatformowego RAT-a
- Fałszywe aktualizacje Adobe i Zoom instalują ScreenConnect i dają atakującym trwały dostęp
- Asystenci AI w poczcie e-mail mogą ułatwiać przejęcia kont i oszustwa finansowe
- CISA dodaje aktywnie wykorzystywaną lukę w N-able N-central do katalogu KEV
- Ataki Pass-ta-key ujawniają słaby punkt zsynchronizowanych passkeys po przejęciu stacji roboczej
- DOUBLECUP wykorzystuje ClickFix i steganografię w PNG do dostarczania CountLoader oraz DeviceManager RAT
- Greatness PhaaS rozwija phishing device code i omija MFA, przechwytując tokeny dostępu
- Fałszywy launcher Xeno dla Roblox rozprzestrzenia infostealera i RAT
- ChainDrop: masowy atak na łańcuch dostaw npm infekuje setki pakietów
- Ataki przez hotelowe Wi‑Fi wymierzone w Microsoft 365: jak działa kampania z użyciem malware CornFlake i ChocoShell
- Unia inwestuje w scale-upy. 5 mld euro na ekspansję technologicznych firm
- Jak zbudować system ostrzegania, który nie zawiedzie? Poradnik dla decydentów
- Hotelowe Wi-Fi na celowniku rosyjskich hakerów
- Wycieki danych medycznych Polaków. Rzecznik Praw Pacjenta pilnie apeluje do szpitali
- Włosi wydzielą „wojskową domenę cyber”. Poważne zmiany w armii i wielomilionowe inwestycje
- Polska walczy o historyczną inwestycję w AI. Mocni konkurenci w przetargu UE
- Programisto, pentesterze – na chwilę wraca nasz kurs XSS – do poniedziałku 30% taniej!
- Ostrzeżenie przed Chinami i Rosją. Japonia zapowiada historyczne zmiany w armii
- Wnioski po dziesiątkach ataków na wodociągi w Minnesocie
- Koniec „samowolki”. Surowe limity i kontrola portfeli kryptoaktywów w RPA
- Domniemany wyciek danych Żabki: Jira, GitLab i klucze API w centrum ryzyka
- Ruby on Rails łata krytyczną lukę w Active Storage. Zagrożone aplikacje przetwarzające obrazy
NEWS
- The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop
- 15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning
- Flaws in Google APK for Python Unlock Agent-to-Agent Attack
- COLDCARD security audit phishing attack installs remote access tool
- DHS Is Hiring Bounty Hunters to Find and Photograph Deported People’s Homes Abroad
- Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery
- CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws
- Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt
- Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
- Google Blogger locks hundreds of blogs in malware false positive
- Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
- How AI-powered phishing killed blocklists for good
- Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses
- New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch
- Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk
- Google’s synchronized passkeys can be stolen in ‘Pass‑ta‑key’ attacks
- Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup
- Leaked n8n API Tokens Exposed Live Instances to Credential Theft
- Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
- Junk Cleaner clears the clutter from your Android
- Angola's Largest Telco Breached Hours Before IPO
- Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself
- CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
- QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
- OpenAI, Anthropic AI agents targeted real people and systems in cyber tests
- OK, Well, Rogue AI Agents Are Hacking Again
- TP-Link patches Omada ZTP flaws allowing hackers to breach networks
- Phishing service spoofs RingCentral to steal Microsoft 365 accounts
- Apple battles it out again with the UK over encrypted iCloud access
- New XCSSET variant targets macOS devs via compromised Xcode projects
- 77 Open VSX extensions found harvesting developer info
- Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook
- Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
- Landmark Deal Would Officially Add Laser Weapons to US Army Arsenal
- Massive ChainDrop npm supply-chain attack infects hundreds of packages
- Varonis Agent IBAC keeps AI agents within their intended boundaries
- Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
- Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
- AI Notetaker Lets Hackers Spy on Government, Corporate Video Calls
- Travelers targeted when logging into hotel Wi-Fi networks
INFLUENCERS
- Vulnerabilities in Car Anti-Theft Device
- Iran Cyberattacks Against Minnesota Water Systems
- Some Claude Chats Are Searchable on Google
- More on the OpenAI Agent’s Attack on Hugging Face
- The OpenAI Hack Shows the Genie Is Out of the Bottle
- Welcoming the Nepalese Government to Have I Been Pwned
- Weekly Update 515
- Five Questions to Answer Before Buying an AI Security Product
- Friday Squid Blogging: Squid Helps Discover New Marine Species
- Anthropic’s Opus 5 Is Better at Resisting Prompt Injection
- Facial Recognition at Madison Square Garden
- Read This Before You Buy That TV Streaming Stick
- American Being Prosecuted for Wiping His Phone Before Handing It Over to Border Officials
- Should You Use AI for a Task? Here’s a Simple Way to Decide
- A Field Guide to the AI Security Market
MALWARE
- Zbtlink security advisory (AV26-779)
- Hype vs. Reality: What the Hugging Face Incident Means for AI Safety
- Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)
- Hugging Face AI breach is ‘most consequential hack’ since Morris Worm, former NSA cyber chief says
- Mini Shai-Hulud npm Attack: More Than 2,200 Components Impacted
- From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide
- 은행 명세서부터 진단서까지 구글 지메일 ai 스캔 기능 끄는 방법
- From Stolen Credentials to Full Breach: The 72-Hour Timeline
- Arctic Wolf Named a Winner in CRN’s 2026 Tech Innovator Awards
- AU: Updoc patients notified of security breach where personal information may have been stolen
- Changes in the Channel: Leadership Moves and Shakeups July 20 – July 24
- Phishing ai danni di ARERA utilizza il tema “bonus sociale idrico”
- When Trusted Sites Turn
- Cybersecurity startup Silent Push appoints CRO with partner-first strategy
- Endpoint Security and Network Monitoring News for the Week of June 26th: Expel, Secure Code Warrior, Hack the Box, and More
- The WordPress Chain Massacre
- Hewlett Packard Enterprise (HPE) security advisory (AV26-778)
- Defense at Machine Speed: How Arctic Wolf Built an Agentic SOC on AWS
- How Bitsight Helps Financial Institutions Align With Bank Negara Malaysia’s RMiT Policy Document
- Google’s synchronized passkeys can be stolen in ‘Pass‑ta‑key’ attacks
ARTICLES
- Microsoft moves to limit AI use by its employees
- Apple’s memory crisis is a big red flag for tech
- Salt Security Launches Industry-First AWS WAF Managed Ruleset for AI Agents and API Protection
- Hackers Smuggle Post-Exploitation Toolkit Into Oracle Database Via Classic SQL Injection Flaw
- 6 things you should know about Google’s new selfie sign-in system
- TP-Link Zero-Touch Provisioning Flaws Could Expose Enterprise Networks, Warns Forescout
- ‘Apple is one of the greatest companies of all time,’ says OpenAI
- AI agents get better at IT ops, but only with humans in the loop
- Fake Bank of America Phishing Emails Found Delivering Disguised ScreenConnect RAT via UAC Bypass
- When AI Agents Meet Real Infrastructure: Hype, Human Error or a Genuine New Threat?
- Surviving AI: Navigating workload creep, AI slop, and the new tech career playbook
- Anthropic’s AI models accidentally hacked three companies
- Sourcing smarter, not harder: meet the AI agent built to transform sourcing
- Check Point Named a Visionary Leader in 2026 Frost Radar for Enterprise Risk Mitigation and Management Platforms
- Huntress Makes RMM-Blocking Feature Free for All Customers as Attacks Surge 277%
- AI pentesting tools are generating more findings than security teams can validate, new survey finds
- Apple and the invisible wolf: AI slop drowns real security threats
- Alibaba takes aim at OpenAI and Anthropic with Qwen3.8-Max launch
- Greg Soros Shares How Podcasters Build Lasting Authority Through Thought Leadership
- How AI is killing smartphone apps in China