- Administrator nie chciał przekazać wyjaśnień. Dostał karę od UODO
- Gry mobilne śledzą użytkowników na ogromną skalę
- Rozgrzewka przed Krakowem! 60 minut hackowania z sekurakiem na żywo (z ekstra bonusem!)
- Polska buduje trzy nowe centra danych. Ponad 1,5 mld zł na cyfrową odporność państwa
- Podatności w oprogramowaniu YunoHost-Apps sogo_yhn
- Gawkowski: powołaliśmy Centrum Walki z Dezinformacją
- Oszukiwali tych, którzy wcześniej stracili pieniądze. CBZC zatrzymało dwie osoby
- Spór sądowy Google z KE. Chodzi o Androida i wyszukiwarki
- Apple łata groźny zero-day. Luka w CoreGraphics była wykorzystywana w wyrafinowanych atakach
- System FBI zaatakowany przez cyberprzestępców. Efekt? Wyciek danych z systemu HR
- Krytyczna luka w Unsloth Studio: inspekcja modelu mogła prowadzić do zdalnego wykonania kodu
- Luki w AWS AgentCore SDK zwiększają ryzyko ataków na ekosystem agentów AI
- Infostealery coraz częściej przejmują konta AI i sesje użytkowników
- Krytyczna podatność w TDengine umożliwia zdalne wyłączenie serwerów OT i IoT jednym pakietem
- DARPA wykorzysta AI do testowania bezpieczeństwa wojskowych komunikatorów
- Naruszenie danych w Pentagonie: wyciek z DMDC objął blisko 3 mln osób
- Cloudflare uruchamia publiczne CA i przygotowuje Web PKI na erę postkwantową
- Carbonato: botnet z agentem AI atakuje źle zabezpieczone hosty Docker
- Bitget po ataku za 388 mln USD: luka w zewnętrznym narzędziu bezpieczeństwa jako wektor włamania
- NeedyMantis: malware do długotrwałego utrzymywania dostępu w przejętych sieciach
- RatHat na Androidzie wykorzystuje Gemini do selekcji ofiar o wyższej wartości
- Krytyczna luka w MCP Python SDK naraża poświadczenia OAuth na przejęcie
- OpenAI wstrzymuje użycie narzędzi po incydencie z agentem AI omijającym ograniczenia internetu
- Star Blizzard atakuje organizacje wspierające Ukrainę, wykorzystując fałszywe zaproszenia do instalacji backdoora
- 101 złośliwych pakietów npm potajemnie dodaje deweloperów do grup WhatsApp
- Wietnamczyk oskarżony o pranie 16 mln dolarów z oszustwa „pig butchering” na kryptowalutach
- Keio i Tokyo Metro ujawniają incydenty cyberbezpieczeństwa w japońskim transporcie
- Kradzież danych podatkowych we Francji po wykorzystaniu przejętych haseł pracowników
- Kiteworks usuwa krytyczną lukę po dziewięciogodzinnym, prewencyjnym wyłączeniu usług
- Autonomiczny agent AI wykorzystany w ataku na DIVD. Nowy etap zagrożeń w cyberbezpieczeństwie
- Apple usuwa zero-day w CoreGraphics wykorzystywany w ukierunkowanych atakach
- Times Car potwierdza wyciek danych 6,6 mln kont użytkowników
- Byli członkowie Sił Powietrznych USA skazani za ataki BEC i oszustwa phishingowe
- FBI zwiększa presję na ShinyHunters po zatrzymaniu domniemanego lidera
- Aktywne ataki na Citrix NetScaler: zero-day umożliwia web shelle i tunelowanie ruchu
- BTR: nowy wariant Spectre v2 umożliwia wyciek pamięci Linuksa mimo istniejących zabezpieczeń
- Signal rozszerza szyfrowane kopie zapasowe na iOS i komputery desktopowe
- Złośliwe niestandardowe GPT w kampanii ClickFix. Jak atakujący wdrażają trojana RAT
- 16-latek dostał się do 17 bilionów rekordów z baz danych Microsoftu.
- Wg relacji wyciekło właśnie 6TB danych z Fakturowni…
- Fakturownia.pl zhackowana – wykradziono faktury i dane kontrahentów
- Fakturownia.pl ofiarą „Fingerprinta”. Wicepremier potwierdza atak
- Rosyjskie oprogramowanie w amerykańskich i europejskich służbach
- Wyciek danych z Pentagonu. Ponad 3 mln osób dotkniętych incydentem
- Nowe włamanie "Fingerprinta" - ofiarą firma Fakturownia.pl
- 17 powodów, aby ogarnąć NIS2 z sekurakiem! 😉
- Nowa jednostka NASK wesprze ofiary cyberataków
- Podatność w oprogramowaniu Quick.Cart
- Podatność w oprogramowaniu MyPresta Google Merchant Center Feed
- Negocjacje ws. Chat Control 2.0. „Najbardziej drakońska wersja”
NEWS
- Russian state hackers use new RedFlick technique to push malware
- DIVD says Zammad zero-days enabled AI-driven network breach
- As AI Reshapes the SOC Career Ladder, Satisfaction Rises for 91%, but Entry Gets Harder for Nearly Half
- Over 543,000 valid credentials exposed in public GitHub repositories
- Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
- Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
- CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS
- Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
- Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net
- Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
- Cisco warns of new SD-WAN zero-day exploited in attacks
- AI's Third Wave: Coworkers Break the Security Model That Worked for Agents
- Microsoft to block Entra ID script injection attacks starting October
- TeamViewer urges users to patch severe flaws “as soon as possible”
- Know Your Enemy: Browser-Based Attack Techniques in 2026
- AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub
- Bitget hacked via zero-day in third-party security products
- US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access
- China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor
- How Israeli Checkpoints Choke Palestinian Life in the Occupied West Bank
- Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT
- OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted
- South Africa Seeks Help After Cyberattack Targets Air Traffic Control
- Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution
- Microsoft is rolling out Linux container support to WSL
- Apple Zero-Day Vulnerability Weaponized in Targeted Attacks
- Signal adds encypted local backup support to iOS, desktop apps
- Unsloth Studio Flaw Turns Routine Model Inspection Into Code Execution
- Custom ChatGPTs push ClickFix attacks to deploy RAT malware
- FBI tells ShinyHunters members to turn themselves in after recent arrest
- OpenAI Gets Sued Over the Hugging Face Hack
- Hackers exploit Citrix NetScaler zero-day to deploy web shells
- Former US Air Force members sent to prison over BEC attacks
- French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks
- Windows 11 2026 Update released, here's everything you need to know
- Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor
- New Spectre v2 attack variant leaks Linux root password hash in minutes
- Cloudflare Announces Public Certificate Authority for the Post-Quantum Web
- New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses
- Automated AI agent used to breach cybersecurity nonprofit DIVD
INFLUENCERS
- I Want Better Reporting on AI Genie Behavior
- Using Device Linking to Eavesdrop on WhatsApp and Signal
- Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
- New Attack Against RSA
- Weekly Update 523: Live From a Norwegian Fjord
- U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
- Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee
- On Anthropic’s AI Misuse Report
- Malicious npm Packages That Evade Defenses
- AI-Assisted Malware Analysis Tips
MALWARE
- Is sandboxing sufficient to contain rogue agents?
- Actively Exploited NetScaler Vulnerabilities
- Building Scalable Real-Time Live Streaming Systems
- Radford experiencing outage after potential data incident
- Renewed CISA support comes too late for midterm prep, some election officials say
- Recorded Future Debuts Autonomous Defense, Built for Machine-Speed Threats
- The Pit Wall Principle: How Human Judgment and AI Speed Run the Modern SOC
- Hackers steal protective order and foster care records from Arizona courts
- Why a global financial company replaced three data sources with one
- 개발자 자격증명 을 노린 Shai-Hulud 악성코드-_index.js
- 2CLoader: A New Malware Loader Delivering Vidar and Remus
- AI Threat Realities Prompt Proactive Security Readiness
- My impressions of BruCon 0x12
- Copilot has the largest AI attack surface of any tool we tracked
- New Slips version v1.1.24 is here!
- Your car’s app could be telling Big Tech who you are and where you go
- EU law enforcement chiefs gather to discuss new challenges in EU security
- Phishing Response Protocol: 3 Essential SOC Steps Powered by ANY.RUN’s Latest Product Updates
- August 2026 Threat Trend Report on APT Attacks (South Korea)
- Cybersecurity Month: 4 essential security habits
ARTICLES
- OpenAI takes on Microsoft and Google with office productivity push
- Attacker signs up as a member to plant webshells on parks and recreation platform, hunts for card data
- Trump’s answer to AI’s image problem: Industry self-regulation and a new name
- Apple issues urgent iOS patch as it navigates the spyware arms race
- CyberASAP Celebrates 10th Anniversary with Special Event Exploring Future of UK Cyber Security Innovation
- Continuous Penetration Testing: Why Annual Pen Tests Are a Compliance Checkbox, Not a Security Strategy
- AI Is Making Software Cheaper to Attack. Defenders Need to Change the Price
- How much does the average UK SME spend on cybersecurity each year?
- How Is AI Improving These 3 Tech Sectors?
- Your guide to Google Messages’ new hidden gestures
- Meta’s next big AI bet is enterprise; its biggest hurdle may be trust
- Anthropic revelations suggest a much stronger AI negotiating stance for enterprise CIOs
- Inside the factory where companies build AI they own
- AI is only as reliable as its evidence
- CFO on the Spot: Five minutes with Chris Kehoe, CFO of Theorem
- Why AI won’t fix your cybersecurity problem
- Meta’s ex launches agent rival to Meta’s Muse
- CFO on the Spot: Five minutes with Mark Holt, CFO of Trustonic
- Apple wasn’t late to AI, it was the adult in the room
- Is Microsoft truly serious about confronting AI’s dangers?