- Fakturownia.pl zhackowana – wykradziono faktury i dane kontrahentów
- Fakturownia.pl ofiarą „Fingerprinta”. Wicepremier potwierdza atak
- Rosyjskie oprogramowanie w amerykańskich i europejskich służbach
- Wyciek danych z Pentagonu. Ponad 3 mln osób dotkniętych incydentem
- Nowe włamanie "Fingerprinta" - ofiarą firma Fakturownia.pl
- 17 powodów, aby ogarnąć NIS2 z sekurakiem! 😉
- Nowa jednostka NASK wesprze ofiary cyberataków
- Podatność w oprogramowaniu Quick.Cart
- Podatność w oprogramowaniu MyPresta Google Merchant Center Feed
- Negocjacje ws. Chat Control 2.0. „Najbardziej drakońska wersja”
- Podatność w oprogramowaniu Ghostscript
- Podatność w oprogramowaniu Das U-Boot
- Nowe uprawnienia dla polskich służb. Chodzi o ruch telekomunikacyjny
- Atak na FBI oznaką wewnętrznej wojny ShinyHunters?
- Poper Blocker w Chrome Web Store: popularne rozszerzenie jako potencjalne narzędzie spyware
- MCP tworzy poważne luki w nadzorze bezpieczeństwa AI
- CVE-2026-42542 w TDengine: pojedynczy pakiet może zdalnie wyłączyć serwery OT i IoT
- Google ostrzega przed nową kampanią ShinyHunters wymierzoną w Oracle PeopleSoft
- Krytyczna luka w Kiteworks Advanced Forms: producent zalecił prewencyjne wyłączenie serwerów
- Roundcube pod ostrzałem: aktywnie wykorzystywana luka SQL Injection CVE-2026-48842 zagraża serwerom webmail
- Były żołnierz USA skazany za cyberwymuszenia wobec firm technologicznych i telekomunikacyjnych
- Ujawnienie danych blisko 400 tys. beneficjentów programu zdrowotnego w Waszyngtonie
- Carbonato atakuje niezabezpieczone hosty Docker i wdraża agenta Hermes AI sterowanego przez Telegram
- NeedyMantis: malware utrzymujące długotrwały dostęp do przejętych sieci
- Apple łata krytyczną lukę CoreGraphics wykorzystywaną w ukierunkowanych atakach
- Bitget po ataku za 388 mln dolarów: luka w narzędziu bezpieczeństwa firmy trzeciej źródłem incydentu
- Skradzione loginy do narzędzi AI w ponad 80 tys. organizacji. Shadow AI i LLMjacking zwiększają ryzyko
- CISA ostrzega przed globalnym wykorzystywaniem dwóch krytycznych luk w Citrix NetScaler
- RatHat wykorzystuje Gemini do selekcji cenniejszych ofiar w kampaniach malware na Androida
- Times Car potwierdza wyciek danych 6,6 mln kont użytkowników po nieautoryzowanym dostępie
- Ponad 16 tysięcy źle skonfigurowanych baz Supabase ujawniało dane osobowe, hasła i tokeny
- Holenderska policja zatrzymała podejrzanego w śledztwie przeciwko ShinyHunters
- Keio potwierdza atak ransomware, który zakłócił systemy biznesowe
- Ataki JADEPUFFER w Azure: skompromitowane service principals posłużyły do destrukcyjnego usuwania zasobów
- Używasz Windowsa lub Androida? Pozornie niegroźne mechanizmy pomagają Cię śledzić
- Jak wdrożyć NIS2 i nie utonąć w procedurach? Praktyczny przewodnik odpowiada na wyzwania UKSC
- Złe wieści dla twórców Claude'a. Sąd poparł Pentagon. Padł mocny argument
- Fałszywe reklamy Google atakują użytkowników Ledgera. Cyberprzestępcy kradli frazy odzyskiwania portfeli
- Cyberprzestępcy serwują malware na zhakowanych stronach. Szczegóły kampanii Psychedelic Stealer
- Atak na Centrum Medyczne Enel-Med. Możliwy wyciek danych pacjentów
- Gdzie przestępcy kupują dostęp do twojej firmy
- Wyciek danych Polaków z Medyc. Firma komentuje
- Jak chronić kluczowe systemy państwa? Eksperci i liderzy rynku łączą siły na Cyber24 DAYS
- Sprawcy ataku na FBI: nie atakujemy ludzi, tylko firmy
- Podatności w oprogramowaniu Dayforce Payroll
- Podatności w routerach Kaon AR2140
- Z pamiętnika admina #5
- Kamery nagrywały sąsiadów. UODO ukarało ich właściciela
- Podatności w urządzeniach F&F Filipowski mH-DEVELOPER
- Cyberatak na Enel-Med. Wyciekły dane pacjentów
NEWS
- OpenAI Gets Sued Over the Hugging Face Hack
- Hackers exploit Citrix NetScaler zero-day to deploy web shells
- Former US Air Force members sent to prison over BEC attacks
- French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks
- Windows 11 2026 Update released, here's everything you need to know
- Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor
- New Spectre v2 attack variant leaks Linux root password hash in minutes
- Cloudflare Announces Public Certificate Authority for the Post-Quantum Web
- New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses
- Automated AI agent used to breach cybersecurity nonprofit DIVD
- 'NeedyMantis' Provides Long-Term Access to Compromised Networks
- Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers
- Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown
- Catch threats before they escalate with real-time Identity Telemetry
- 101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent
- Vietnamese man charged in $16 million 'pig butchering' crypto scam
- Update your iPhone, iPad, or Mac: Flaw could run attackers’ code
- Securing the keys to the kingdom: Announcing Executive Threat Detection
- Kiteworks patches critical flaw, brings customer systems online
- Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation
- Apple patches CoreGraphics zero-day flaw exploited in attacks
- Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
- OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions
- OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot
- Nvidia Launches AI Agent Safety Platform to Prevent Rogue Activities
- One Packet Can Crash OT Servers in Industrial Sectors
- Japan's Keio confirms ransomware attack disrupted business systems
- Times Car confirms data breach affecting 6.6 million user accounts
- Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts
- Dutch police confirm arrest in ShinyHunters hacking investigation
- Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
- Misconfigured Supabase apps expose data in over 16,000 databases
- AI Agents Are Privileged Users; Who Is Auditing Their Access?
- Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
- IAM for AI agents: A Practical Enterprise Framework
- Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M
- RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims
- Chrome Store Hosts 'Poper Blocker' Spyware Downloaded by Millions
- JadePuffer agentic AI attacks target Azure, destroy cloud resources
- JadePuffer AI Actor Compromises Azure Tenant in Destructive Cloud Attack
INFLUENCERS
- Using Device Linking to Eavesdrop on WhatsApp and Signal
- Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
- New Attack Against RSA
- Weekly Update 523: Live From a Norwegian Fjord
- U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
- Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee
- On Anthropic’s AI Misuse Report
- Malicious npm Packages That Evade Defenses
- AI-Assisted Malware Analysis Tips
- Research on Models Engaging in Genie-Like Behavior
- Weekly Update 522: Live From Oslo with Scott Helme
MALWARE
- Cyberattacks to be insured like accidents: Ministry of Finance discusses new rules for critical infrastructure
- Mozilla security advisory (AV26-976)
- Shocker: suspected ShinyHunters member charged with attempted incitement to commit two murders
- What Is a Brute Force Attack? Types, Risks and Prevention
- Quarterly WordPress Threat Intelligence Report – Q2 2026
- FBI warns ShinyHunters members to come forward after alleged leader’s arrest
- Copy, Paste, Compromised: How ClickFix Attacks Work and How CrowdStrike Stops Them
- SUSE Linux security advisory (AV26-974)
- FreePBX security advisory (AV26-973)
- A Practical Guide to Symantec PAM Secondary Sites
- Third-party(.)com ClickFix(클릭픽스) 공격 분석 개발 문서 속 예시 도메인 위험
- 9 Venmo Scams to Watch for and How to Avoid Them
- Social Engineering in the Age of Synthetic Media
- CVE-2026-85706: Critical GitLab Unauthenticated Arbitrary File Read Vulnerability (CVSS 10.0)
- WatchGuard security advisory (AV26-972)
- Scans for Wordfence Protected Websites, (Tue, Sep 29th)
- Meta’s Muse sent a Facebook Marketplace buyer to a seller’s home
- Russian pizza restaurant chain confirms cyberattack: Hackers claim 68 million users exposed
- FBI Hackers Say They Won’t Publish Massive Trove of FBI Employee Data
- Know What's Actually Happening to Your Suppliers, Not Just When Their Names Show Up in Threat Data
CYBERWARFARE
- Russia strikes at heart of Ukraine’s digital economy with attacks on ISPs and datacentres
- Russia could attack a Nato country within months, Danish intelligence says
- How the ‘poisonous tide’ of disinformation stokes division and sows despair
- The Guardian view on Russian disinformation: a foreign threat that relies on UK complicity | Editorial
- PM’s new anti-disinformation unit won’t target ‘domestic politcal dissent’, defence secretary says – UK politics live
- New UK agency will tackle ‘information warfare’ from likes of Russia, Burnham says
ARTICLES
- Why AI won’t fix your cybersecurity problem
- Meta’s ex launches agent rival to Meta’s Muse
- CFO on the Spot: Five minutes with Mark Holt, CFO of Trustonic
- Apple wasn’t late to AI, it was the adult in the room
- Is Microsoft truly serious about confronting AI’s dangers?
- Proton brings Microsoft 365 to Easy Switch for Business as security leaders weigh US ‘kill switch’ risk
- Attackers weaponise ChatGPT Custom GPTs to deliver RAT via eight-stage ClickFix chain
- Stop using ‘tech debt’ to refer to anything old
- CFO on the Spot: Five minutes with Matthias Steinberg, COO and CFO of MindBridge
- New Guide from Filigran Highlights the Many Routes Women Take into Cyber Threat Intelligence
- Try Google Drive Projects for fast, focused AI analysis
- Apple’s long, lonely game in the AR race
- James Moore, Q&A: AI Security And Governance: Why Most Organisations Are Flying Blind
- Cybersecurity leadership acceptance of frameworks and standards with UTAUT2
- CFO on the Spot: Five minutes with Samantha Greenberg, CFO of AlphaSense
- AI tools help hacker break in for $25 per target
- OpenAI wants you to use AI — but not to train its AI
- Microsoft’s new Copilot ‘super app’ unifies chat, code, agents
- Adobe’s next platform for Creative Cloud? Your AI assistant
- Google is set to launch a small AI data center into space