- Szef CERT Polska o cyberbezpieczeństwie. „90% zaszyfrowanych backupów”
- Karen Vardanyan skazany za udział w kampanii Ryuk. Co ten wyrok oznacza dla walki z ransomware?
- Systemy powiadomień o zmianach plików w Windows, Linux i Androidzie mogą ujawniać aktywność użytkownika
- Kampania ClickFix wykorzystuje zaufane strony do dystrybucji malware Psychedelic Stealer
- Atak na Bitget: 351,6 mln USD skradzione z portfeli giełdy kryptowalut
- RemControl: nowy trojan bankowy na Androida umożliwia pełne zdalne przejęcie urządzenia
- Domeny phishingowe podszywające się pod AliExpress wykryte jeszcze przed rejestracją
- Rosyjska wojna hybrydowa w Europie przyspiesza: cyberataki, sabotaż i presja na infrastrukturę krytyczną
- SalesBleed w Salesforce Agentforce: jak trzy luki umożliwiały zero-click wyciek danych CRM i phishing w Slacku
- Wyrok dla żołnierza USA za cyberwymuszenia wobec AT&T i Verizon
- Ucieczki AI z sandboxa: dlaczego gotowość śledcza jest ważniejsza niż sama izolacja
- Niezałatane luki w OnePlus pozwalają aplikacjom uzyskać root bez uprawnień
- Roundcube pod ostrzałem: aktywnie wykorzystywana luka pre-auth SQL Injection zagraża środowiskom webmail
- MikroTrick w MikroTik RouterOS: krytyczny łańcuch podatności SSH umożliwia przejęcie urządzeń bez logowania
- Ujawnione adresy e-mail projektów GitLab mogą posłużyć do nadużyć i wpływu na repozytoria
- CISA publikuje plan ochrony infrastruktury wyborczej przed wyborami środka kadencji 2026
- Cloudflare usuwa lukę ujawniającą resztkowe dane między kontenerami klientów
- MacSync na macOS wykorzystuje publiczne kalendarze iCloud do dostarczania kolejnych ładunków malware
- Carbonato: nowe malware przejmuje niezabezpieczone hosty Docker i wykorzystuje agentów AI
- PamStealer na macOS rozwija mechanizmy ukrywania: odszyfrowanie payloadu zależne od aktywnego C2
- Złośliwe GitHub Actions znów aktywne po przywróceniu repozytoriów. Nowe ostrzeżenie dla bezpieczeństwa CI/CD
- CISA dodaje luki w Microsoft SharePoint i MikroTik RouterOS do katalogu aktywnie wykorzystywanych podatności
- Krytyczna luka CSRF w Elementor pozwala na tworzenie kont administratora w WordPress
- Kiteworks zaleca 6-godzinne wyłączenie serwerów z powodu ryzyka potencjalnych ataków zero-day
- Administrator platformy Rydox przyznał się do winy. Cios w rynek skradzionych danych i narzędzi cyberprzestępczych
- CISA dodaje do KEV aktywnie wykorzystywane luki w WSO2 oraz Adobe Commerce
- ShinyHunters przejęło starą stronę wycieków Clop, wykorzystując lukę path traversal w Grav CMS
- AI na polu walki. Ukraina pracuje nad nowym systemem
- Weekendowa Lektura: odcinek 695 [2026-09-25]. Bierzcie i czytajcie
- Od monitorowania zagrożeń do globalnej współpracy. Jak SOCCER wzmocnił SOC AGH
- Nie liczba ataków jest najważniejsza. ENISA o cyberzagrożeniach w Europie
- Cenne dane bez ochrony. Luki w bezpieczeństwie polskich uczelni [WYWIAD]
- Prezydent podjął decyzję ws. pierwszej ustawy wdrażającej DSA
- AI włamała się do systemu ochrony zdrowia. „Sytuacja nie do przyjęcia”
- Cyberbezpieczeństwo to nie koszt, ale inwestycja. Jeden atak może przekreślić lata badań
- Agent AI OpenAI uzyskał nieautoryzowany dostęp do australijskiego portalu Medicare
- Wielka Brytania zmienia model cyberbezpieczeństwa administracji: od zgodności do usług ochronnych
- CISA ogłasza „erę jakości” dla programu CVE. Co zmieni się w zarządzaniu podatnościami?
- Secrets sprawl w erze agentów AI: dlaczego to problem tożsamości, a nie tylko wycieków sekretów
- Corp MDM atakuje logistykę: nowe spyware na Androida przechwytuje SMS-y i przekierowuje połączenia
- Nowa grupa ransomware grozi zniszczeniem kopii zapasowych, zwiększając presję na ofiary
- TeamFiltration atakuje Microsoft 365: domyślne hasła umożliwiły przejęcie kont usługowych
- Process parameter poisoning: nowa technika omijania EDR w atakach process injection
- Trzy cyberzagrożenia, które zdefiniowały lato 2026
- Krytyczna luka zero-day w F5 BIG-IP APM umożliwia zdalne wykonanie kodu
- Salesbleed: podatności w Salesforce Agentforce umożliwiają phishing przez Slack
- SectopRAT wraca i ukrywa się w legalnej aplikacji. Nowa kampania utrudnia wykrycie RAT-a
- CLOSEDQUORUM: malware dla Windows wykorzystuje głosowanie modeli AI do wyboru działań operacyjnych
- Wiz wykorzystuje AI do wykrywania luk w infrastrukturze krytycznej
- MikroTrick w MikroTik RouterOS: krytyczny łańcuch błędów SSH umożliwiał pełne przejęcie routera
NEWS
- ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
- Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
- Claude Opus 5.5 uses 95% fewer em dashes, but its answers are getting longer
- Microsoft pauses KB5002907 update after Office license deactivations
- GitHub Actions re-enabled with Mini Shai-Hulud payload still active
- OpenAI's AI agents accidentally uploaded user-provided images to third-party sites
- Old-School Credit Card Scams Are Far From Dead
- Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
- Zero Trust for AI Agents Starts With Fixing Zero Visibility
- Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
- SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
- Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack
- Kiteworks urges 6-hour server shutdown over potential zero-day attacks
- ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw
- AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment
- Elementor WordPress flaw lets attackers create admin accounts
- What We Missed: Google Gemini Joins the AI Escape Party
- CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks
- Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions
- OpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex
- With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance
- Stopping IT Worker Scams Requires Revamped HR Process
- Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware
- PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
- Microsoft plans to deprecate Windows Deployment Services
- Rydox marketplace admin pleads guilty, faces 22 years in prison
- The SOC Doesn't Need to Start Over with Every Alert
- Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise
- Microsoft: Recent Windows updates cause desktop loading issues
- Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
- That shipping rebate offer may come with a monthly charge
- Hackers steal $351.6 million in Bitget crypto exchange hack
- Russia's Hybrid Cyber-Physical War in Europe Heats Up
- Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data
- WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
- 'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing
- MacSync malware uses public iCloud calendars to deliver new payloads
- SectopRAT Returns, Hiding Inside a Legitimate Application
- New Carbonato malware uses AI agents to hijack exposed Docker hosts
- Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
INFLUENCERS
- U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
- Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee
- On Anthropic’s AI Misuse Report
- Malicious npm Packages That Evade Defenses
- AI-Assisted Malware Analysis Tips
- Research on Models Engaging in Genie-Like Behavior
- Weekly Update 522: Live From Oslo with Scott Helme
- GPT-6 Astra Breaks an Old Enigma Message
- My Favorite Findings From the AI Security Decisions Report
- Reverse-Engineering Flock Cameras
- Brooklyn History: The Mystery of Club 338
MALWARE
- Poland reports a second medical data cyberattack in recent weeks
- Pentagon data breach of military personnel raises national security concerns
- Labcorp to overhaul data security practices, pay $2.3 million fine for cybersecurity failings
- Some Supabase customers are publicly exposing reams of people’s data to the web
- DragonForce Compromises WinFashion Technologies in Ransomware Attack
- Incransom Targets Moroccan Pharma Leader Pharma5
- Using Threat Intelligence to Stop Ransomware Attacks
- OpenAI says its advanced models may have gone after government websites
- U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
- Threat Actors Use Google Ads To Target Ledger Users
- Zimbra security advisory (AV26-964)
- Unmasking a Nova Ransomware Operator: Following Reused Contact Methods to a Real-World Identity
- Wordfence Bug Bounty Program Monthly Report – June 2026
- How the Aurora Agentic SOC Is Building the Next Generation of SOC Analysts
- Threat Research Roundup: September 2026
- Storm-3168: Agentic-driven cloud attacks using compromised service principals
- Sintesi riepilogativa delle campagne malevole nella settimana del 19 – 25 settembre
- Kothamine malware uses Tailscale’s tailcat to evade network detection
- LinkedIn adds new checks for fake profiles and work histories
- ServiceNow security advisory (AV26-963)
CYBERWARFARE
- Russia strikes at heart of Ukraine’s digital economy with attacks on ISPs and datacentres
- Russia could attack a Nato country within months, Danish intelligence says
- How the ‘poisonous tide’ of disinformation stokes division and sows despair
- The Guardian view on Russian disinformation: a foreign threat that relies on UK complicity | Editorial
- PM’s new anti-disinformation unit won’t target ‘domestic politcal dissent’, defence secretary says – UK politics live
- New UK agency will tackle ‘information warfare’ from likes of Russia, Burnham says
ARTICLES
- CFO on the Spot: Five minutes with Samantha Greenberg, CFO of AlphaSense
- AI tools help hacker break in for $25 per target
- OpenAI wants you to use AI — but not to train its AI
- Microsoft’s new Copilot ‘super app’ unifies chat, code, agents
- Adobe’s next platform for Creative Cloud? Your AI assistant
- Google is set to launch a small AI data center into space
- iOS 27: Why you should learn to love Impersonation Risk Detection
- Meta floats project to lay first petabit submarine fiberoptic cable
- Attackers build “silent” cryptominer on victim’s machine and give themselves away
- Google plans Gemini 4 release before year-end
- Around the corner: Agentic AI PCs that cut token costs
- The companies racing to build frontier AI are now racing to govern it
- Private regulation of cyber proliferation: from norm entrepreneurship to a quasi-export control regime
- WordPress patches a critical severity security vulnerability
- CFO on the Spot: Five minutes with Enrique Patrickson, CFO of Hexagon
- CFO on the Spot: Five minutes with Steve McCue, CFO of Pragmatic Semiconductor
- CFO on the Spot: Five minutes with Chris Wilmot, CFO of Medius
- Microsoft integrates SOC capabilities with Defender for enterprises
- Jamf in the age of agentic IT: An interview with CEO Beth Tschida
- CFO on the Spot: Five minutes with Marta Garcia, CFO of Multiverse Computing