- New writing lives at notes.dawidbalut.com
- Automatyczna AI poza kontrolą? Największym problemem może być człowiek
- Pentagon wybiera matematykę. Wyścig o bezpieczeństwo w erze komputerów kwantowych
- x47.c: nowy botnet Windows wykorzystuje API modeli AI do utrzymania infekcji i drenażu kredytów
- Ucieczki agentów AI z sandboxa: dlaczego gotowość śledcza jest ważniejsza niż sama izolacja
- Baza Exploit.in ujawnia korzenie współczesnego ekosystemu ransomware
- Wyrok za wymuszenia wobec AT&T i Verizon. Jak kradzież metadanych telekomunikacyjnych stała się narzędziem presji
- Bitget potwierdza kradzież 351,6 mln USD. Podejrzenia wobec hakerów powiązanych z Koreą Północną
- Krytyczna luka CSRF w Elementor umożliwia przejęcie witryny WordPress po kliknięciu linku
- OpenAI ujawnia niepożądane działania modeli wobec witryn rządowych USA
- CISA ostrzega przed aktywnie wykorzystywanymi lukami w SharePoint, WSO2 i Adobe Commerce
- CISA dodaje krytyczną lukę WordPress CVE-2026-87902 do katalogu KEV. Trwa aktywne wykorzystywanie podatności
- Lunex Stealer wykorzystuje podatny sterownik AMD do osłabienia EDR i kradzieży danych
- Zero Trust dla agentów AI zaczyna się od pełnej widoczności środowiska
- ShinyHunters przejęło stronę wycieków Clop przez lukę path traversal w Grav CMS
- GitHub Actions ponownie aktywne z ładunkiem Mini Shai-Hulud. Ryzyko supply chain nadal zagraża CI/CD
- ShinyHunters omija reguły WAF i ponownie atakuje Oracle PeopleSoft
- Kiteworks zaleca prewencyjne wyłączenie systemów po otrzymaniu ostrzeżenia o możliwym cyberataku
- OpenAI potwierdza incydent: agenci AI publikowali obrazy użytkowników w zewnętrznych serwisach
- Szef CERT Polska o cyberbezpieczeństwie. „90% zaszyfrowanych backupów”
- Karen Vardanyan skazany za udział w kampanii Ryuk. Co ten wyrok oznacza dla walki z ransomware?
- Systemy powiadomień o zmianach plików w Windows, Linux i Androidzie mogą ujawniać aktywność użytkownika
- Kampania ClickFix wykorzystuje zaufane strony do dystrybucji malware Psychedelic Stealer
- Atak na Bitget: 351,6 mln USD skradzione z portfeli giełdy kryptowalut
- Domeny phishingowe podszywające się pod AliExpress wykryte jeszcze przed rejestracją
- RemControl: nowy trojan bankowy na Androida umożliwia pełne zdalne przejęcie urządzenia
- SalesBleed w Salesforce Agentforce: jak trzy luki umożliwiały zero-click wyciek danych CRM i phishing w Slacku
- Rosyjska wojna hybrydowa w Europie przyspiesza: cyberataki, sabotaż i presja na infrastrukturę krytyczną
- Wyrok dla żołnierza USA za cyberwymuszenia wobec AT&T i Verizon
- Ucieczki AI z sandboxa: dlaczego gotowość śledcza jest ważniejsza niż sama izolacja
- Niezałatane luki w OnePlus pozwalają aplikacjom uzyskać root bez uprawnień
- Roundcube pod ostrzałem: aktywnie wykorzystywana luka pre-auth SQL Injection zagraża środowiskom webmail
- MikroTrick w MikroTik RouterOS: krytyczny łańcuch podatności SSH umożliwia przejęcie urządzeń bez logowania
- Ujawnione adresy e-mail projektów GitLab mogą posłużyć do nadużyć i wpływu na repozytoria
- CISA publikuje plan ochrony infrastruktury wyborczej przed wyborami środka kadencji 2026
- Cloudflare usuwa lukę ujawniającą resztkowe dane między kontenerami klientów
- MacSync na macOS wykorzystuje publiczne kalendarze iCloud do dostarczania kolejnych ładunków malware
- Carbonato: nowe malware przejmuje niezabezpieczone hosty Docker i wykorzystuje agentów AI
- PamStealer na macOS rozwija mechanizmy ukrywania: odszyfrowanie payloadu zależne od aktywnego C2
- Złośliwe GitHub Actions znów aktywne po przywróceniu repozytoriów. Nowe ostrzeżenie dla bezpieczeństwa CI/CD
- CISA dodaje luki w Microsoft SharePoint i MikroTik RouterOS do katalogu aktywnie wykorzystywanych podatności
- Administrator platformy Rydox przyznał się do winy. Cios w rynek skradzionych danych i narzędzi cyberprzestępczych
- Krytyczna luka CSRF w Elementor pozwala na tworzenie kont administratora w WordPress
- Kiteworks zaleca 6-godzinne wyłączenie serwerów z powodu ryzyka potencjalnych ataków zero-day
- CISA dodaje do KEV aktywnie wykorzystywane luki w WSO2 oraz Adobe Commerce
- ShinyHunters przejęło starą stronę wycieków Clop, wykorzystując lukę path traversal w Grav CMS
- AI na polu walki. Ukraina pracuje nad nowym systemem
- Weekendowa Lektura: odcinek 695 [2026-09-25]. Bierzcie i czytajcie
- Od monitorowania zagrożeń do globalnej współpracy. Jak SOCCER wzmocnił SOC AGH
- Nie liczba ataków jest najważniejsza. ENISA o cyberzagrożeniach w Europie
NEWS
- Citrix admins warned to shut down NetScalers over 2 exploited zero-days
- Cloudflare fixes Containers cross-tenant flaw exposing customer data
- Anthropic turns Claude into an AI marketplace with 2,000+ plugins and connectors
- Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
- ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
- Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
- Claude Opus 5.5 uses 95% fewer em dashes, but its answers are getting longer
- Microsoft pauses KB5002907 update after Office license deactivations
- GitHub Actions re-enabled with Mini Shai-Hulud payload still active
- OpenAI's AI agents accidentally uploaded user-provided images to third-party sites
- Old-School Credit Card Scams Are Far From Dead
- Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
- Zero Trust for AI Agents Starts With Fixing Zero Visibility
- Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
- SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
- Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack
- Kiteworks urges 6-hour server shutdown over potential zero-day attacks
- ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw
- How the CISO CFO Relationship is a Key to Cybersecurity Success
- AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment
- Elementor WordPress flaw lets attackers create admin accounts
- What We Missed: Google Gemini Joins the AI Escape Party
- CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks
- Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions
- OpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex
- With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance
- Stopping IT Worker Scams Requires Revamped HR Process
- Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware
- PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
- Microsoft plans to deprecate Windows Deployment Services
- Rydox marketplace admin pleads guilty, faces 22 years in prison
- The SOC Doesn't Need to Start Over with Every Alert
- Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise
- Microsoft: Recent Windows updates cause desktop loading issues
- Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
- That shipping rebate offer may come with a monthly charge
- Hackers steal $351.6 million in Bitget crypto exchange hack
- Russia's Hybrid Cyber-Physical War in Europe Heats Up
- Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data
- WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
INFLUENCERS
- U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
- Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee
- On Anthropic’s AI Misuse Report
- Malicious npm Packages That Evade Defenses
- AI-Assisted Malware Analysis Tips
- Research on Models Engaging in Genie-Like Behavior
- Weekly Update 522: Live From Oslo with Scott Helme
- GPT-6 Astra Breaks an Old Enigma Message
- My Favorite Findings From the AI Security Decisions Report
- Reverse-Engineering Flock Cameras
- Brooklyn History: The Mystery of Club 338
TOOLS
- house_of_apple_2
- EmbedXPL-Forge
- TrueVerdict
- binary-cartography
- CnaEmulator
- RC4Decryption
- polychrome-rs
- SOCMIntelligence
- reverse-engineering-browser
- Purple-Team-Automation
- wordpress-cve-scanner
- Prompt-Injection-in-the-Wild
- XXERipper
- SpectralCovert
- file-notification-attacks
- T-Backdoor
- aegis-audio-defense
- WordList
- libprocesshider
- unwaf
MALWARE
- AL26-024 - Critical vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway – CVE-2026-88771 and CVE-2026-88772
- Wireshark 4.6.9 Released, (Sun, Sep 27th)
- 우크라이나 를 노리는 북한 해킹 단체 Konni 악성코드-CV OlesiaTsvientukh SocialResearcher Sociologist Qualitativelnk
- Introducing ADE-Skills — Adversarial Detection Engineering Knowledge Base
- Personal information of over 23,500 Simba customers leaked in data breach
- UK: Ten NHS staff removed over Noah Woods data breach
- OpenAI’s Systems Meddled With U.S. Government Sites
- Poland reports a second medical data cyberattack in recent weeks
- Pentagon data breach of military personnel raises national security concerns
- Labcorp to overhaul data security practices, pay $2.3 million fine for cybersecurity failings
- Some Supabase customers are publicly exposing reams of people’s data to the web
- DragonForce Compromises WinFashion Technologies in Ransomware Attack
- Incransom Targets Moroccan Pharma Leader Pharma5
- Using Threat Intelligence to Stop Ransomware Attacks
- OpenAI says its advanced models may have gone after government websites
- U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
- Threat Actors Use Google Ads To Target Ledger Users
- Zimbra security advisory (AV26-964)
- Unmasking a Nova Ransomware Operator: Following Reused Contact Methods to a Real-World Identity
- Wordfence Bug Bounty Program Monthly Report – June 2026
CYBERWARFARE
- Russia strikes at heart of Ukraine’s digital economy with attacks on ISPs and datacentres
- Russia could attack a Nato country within months, Danish intelligence says
- How the ‘poisonous tide’ of disinformation stokes division and sows despair
- The Guardian view on Russian disinformation: a foreign threat that relies on UK complicity | Editorial
- PM’s new anti-disinformation unit won’t target ‘domestic politcal dissent’, defence secretary says – UK politics live
- New UK agency will tackle ‘information warfare’ from likes of Russia, Burnham says
ARTICLES
- CFO on the Spot: Five minutes with Samantha Greenberg, CFO of AlphaSense
- AI tools help hacker break in for $25 per target
- OpenAI wants you to use AI — but not to train its AI
- Microsoft’s new Copilot ‘super app’ unifies chat, code, agents
- Adobe’s next platform for Creative Cloud? Your AI assistant
- Google is set to launch a small AI data center into space
- iOS 27: Why you should learn to love Impersonation Risk Detection
- Meta floats project to lay first petabit submarine fiberoptic cable
- Attackers build “silent” cryptominer on victim’s machine and give themselves away
- Google plans Gemini 4 release before year-end
- Around the corner: Agentic AI PCs that cut token costs
- The companies racing to build frontier AI are now racing to govern it
- Private regulation of cyber proliferation: from norm entrepreneurship to a quasi-export control regime
- WordPress patches a critical severity security vulnerability
- CFO on the Spot: Five minutes with Enrique Patrickson, CFO of Hexagon
- CFO on the Spot: Five minutes with Steve McCue, CFO of Pragmatic Semiconductor
- CFO on the Spot: Five minutes with Chris Wilmot, CFO of Medius
- Microsoft integrates SOC capabilities with Defender for enterprises
- Jamf in the age of agentic IT: An interview with CEO Beth Tschida
- CFO on the Spot: Five minutes with Marta Garcia, CFO of Multiverse Computing