- Tysiące projektów z poufnymi danymi jest “nieświadomie” udostępnianych przez użytkowników narzędzi AI
- Blokowanie treści w sieci. Będą zmiany ws. ochrony dzieci
- UKNF: sektor finansowy musi być gotowy na zaawansowaną AI
- AI kontra AI. Microsoft pokazuje nową strategię cyberobrony
- Podatności w oprogramowaniu MWDB Core
- Ponad 30 systemów wodociągowych w USA celami cyberataków
- Podatność w oprogramowaniu Quick.CMS
- Poznaj 10 kieszonkowych narzędzi prawdziwego hackera! Bez ściemy i lukru
- Prawdziwy incydent z malware na macOS: wnioski z fałszywego instalatora i fałszywego procesu rekrutacyjnego
- Podatność w oprogramowaniu Streamsoft Business Intelligence
- Włamanie na Hugging Face. Agent AI wykorzystał inne platformy
- Podatność w oprogramowaniu diff-so-fancy
- Każdy mógł być pracownikiem stacji benzynowej MOL dzięki błędom w apce. Firma zignorowała zgłoszenie
- Podatności w oprogramowaniu GNU Bison
- 66 kilogramów narkotyków przejęte. Akcja CBZC na Podkarpaciu
- Incydent w Zegrzu. Dostęp wymagał specjalistycznej wiedzy
- AI pomaga stworzyć exploit dla jądra Linuksa. CVE-2026-53264 umożliwia przejęcie uprawnień root
- Agentic browsers cofają bezpieczeństwo WWW o 20 lat. Nowa klasa ryzyk dla firm i użytkowników
- Dlaczego reset hasła nie wystarcza już do zatrzymania atakujących
- Atak szpiegowski na tajskie Ministerstwo Finansów z użyciem agenta AI Hermes
- Operacja Cronos i upadek LockBit: jak rozbicie zaufania afiliantów osłabiło imperium ransomware
- Ucieczka agentów AI z sandboxa pokazuje, że klasyczne zasady bezpieczeństwa wciąż są kluczowe
- Niekontrolowany rozrost tożsamości nie-ludzkich otwiera nową ścieżkę ataku w chmurze
- Luki w Hugging Face Diffusers pozwalały ominąć trust_remote_code i uruchomić zdalny kod
- Skoordynowany cyberatak na systemy wodociągowe w Minnesocie ujawnia słabości OT w infrastrukturze krytycznej
- Apple łata dziesiątki podatności w iOS i ponad 150 luk w macOS Tahoe
- Cruciferra: nowy model Crypter-as-a-Service wzmacnia globalne kampanie malware
- MedusaHVNC: trojan wykorzystujący ukryte pulpity Windows do przejmowania sesji przeglądarki
- CVE-2026-53264: lokalna eskalacja uprawnień w Linuksie przez błąd use-after-free w net/sched
- Google wprowadza nowy system nazewnictwa grup zagrożeń
- NVIDIA uruchamia Open Secure AI Alliance. Otwarty ekosystem bezpieczeństwa dla agentów AI
- Nimbus Manticore rozwija cyberarsenał: NightLedger i tunele WebSocket wzmacniają operacje wywiadowcze
- Claude wspiera kryptanalizę: nowy atak na HAWK-256 i szybszy atak na 7-rundowy AES
- Krytyczna luka pre-auth RCE w vBulletin z publicznym exploitem. Zagrożone wersje 5.x i 6.x
- Dysphoria: botnet IoT ukrywa C2 w blockchainie i wykorzystuje zainfekowane przekaźniki
- Krytyczna luka w OpenWrt DHCPv6 umożliwia zdalne wykonanie kodu jako root
- Certighost w AD CS: nowe PoC pokazuje drogę do przejęcia domeny Windows
- Krytyczna luka w JetBrains TeamCity pozwala na zdalne wykonanie kodu bez uwierzytelnienia
- FastJson pod ostrzałem: aktywne ataki wykorzystują zero-day RCE w środowiskach Spring Boot
- Apple pozwane po kradzieży 1,8 mln USD w Bitcoinie przez fałszywą aplikację Sparrow Wallet
- Tengu: nowy botnet Mirai dla Linuksa wykorzystuje watchdog sprzętowy do utrudniania usuwania infekcji
- Krytyczna luka zero-day w Arista VeloCloud Orchestrator umożliwia zdalne przejęcie bez logowania
- Naruszenie danych w MCBS dotknęło 1,26 mln osób. Wyciek ujawnia ryzyko dla całego sektora ochrony zdrowia
- Jak skutecznie zabezpieczyć SSO przed nowoczesnymi atakami na poświadczenia
- 24 650 publicznie dostępnych interfejsów BMC ujawnia hashe IPMI przed logowaniem
- Atak DNS hijacking na CubePilot zakłócił usługi producenta oprogramowania dla dronów
- Gość zainfekował pytanie egzaminacyjne ukrytą instrukcją dla AI…
- Wydał ~100 zł na subskrypcję GPT 5.6 (Sol). Ten znalazł mu exploita wartego ~2000000zł
- Polskie ośrodki pomocy społecznej na celowniku cyberprzestępców
- Brytyjska posłanka pozywa xAI. „Grok od początku umożliwiał cyfrowe rozbieranie”
NEWS
- Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
- Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare
- Who's Liable When AI Agents Escape? Hugging Face Breach Raises Hard Questions
- Hugging Face Hack Lessons for Cyber Defenders
- When AppSec Scanners Become a Supply Chain Attack Vector
- Buying TikTok views or followers? Here’s what you’re really getting
- OpenAI agent used exposed credentials at 4 services in Hugging Face breach
- Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
- Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
- AI robocalls: Why caller ID is still lying to you
- Hackers target over 30 Minnesota water utilities in coordinated OT attack
- Patch-Resistant 'RufRoot' Flaw Can Unleash Malicious AI Agent Swarms
- OpenAI explains how its AI agent breached Hugging Face
- Your AI Agents Are Guessing at Scale: Permissions Decide the Damage
- Windows 11 KB5101684 update released with 42 changes and fixes
- Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline
- Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments
- Mythos Asks the Right Question. It Doesn't Answer It.
- Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
- 73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack
- These near-mint ASUS Chromebook refurbs are only $145
- Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity
- We found 120 fake Walmart stores trying to steal your credit card
- ICE’s New Detention Center Contracts Declare State Laws ‘Shall Not Apply’
- Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
- New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands
- Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates
- OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach
- Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js
- OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face
- A Typo Landed an Innocent Gamer in Prison for 18 Months
- Ghost Credentials Expose Cloud Systems to Hidden Identity Risks
- CubePilot drone software dev hit by DNS hijacking to intercept traffic
- Flaw From 2004 Exposes Data Centers to Server Takeover
- OpenAI models used Artifactory zero-days to escape to the internet
- When AI Agents Escape Sandboxes, Old Security Rules Apply
- Stronger AI Safety Requires Peeking Inside the 'Black Box'
- Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack
- CISA shares advice on isolating vital systems during cyberattacks
- vBulletin fixes critical pre-auth RCE flaw with public exploit
INFLUENCERS
- Measuring the Tendency of AI Agents to Go Rogue
- Long-Lived Vulnerability in Microsoft Secure Boot
- Measuring LLMs’ Ability to Perform Cryptanalysis
- Axon Is Another License Plate Surveillance Company
- Cyber Company Profiles: Consistent AI Analysis of Security Vendors
- Cognyte Sells a Mobile Cell Surveillance Van
- Weekly Update 514: This Week in Data Breaches
- What 239 Products Reveal About the Shape of AI Security
- Friday Squid Blogging: Illex Squid Catch in the Falklands
- Why AI Needs a “Genie Coefficient”
- End-to-End Encryption and “Going Dark”
MALWARE
- Amazon uncovers broad North Korean hacking campaign against open-source software
- Malware development trick 61: Module stomping. Simple C example
- UKCT Report: "One Network, Two Systems: The Research Security Risks of UK/China University Cyber Partnerships"
- Buying TikTok views or followers? Here’s what you’re really getting
- Better security starts with better questions
- WP2Shell WordPress Exploit Technical Analysis and Real Attack Data
- AI robocalls: Why caller ID is still lying to you
- 삼성전자 브로드컴 2030년까지 2천억 달러 이상 규모의 ai 칩 파트너십 체결
- Inside Astaroth's New Spambot Component
- Adobe security advisory (AV26-756)
- Some notes about Anthropic’s new results
- Report As You Go: Maintaining Good Documentation for SOC Analysts
- CMMC Phase II Is Paused: Why Defense Contractors Cannot Afford to Stop Preparing
- Vulnerabilities in MWDB Core software
- Coordinated Cyberattacks Hit Dozens of Minnesota Water Utilities, Raising Questions of Link to T-Mobile Outage
- What is Geospatial Intelligence? A Complete Guide to GEOINT
- Vulnerability in Streamsoft Business Intelligence software
- The ECB’s AI cybersecurity action plan: Why speed, visibility, and evidence matter
- Protected: Beyond R57: Uncovering the Identities Behind a Threat Actor Network
- We found 120 fake Walmart stores trying to steal your credit card
ARTICLES
- OpenAI’s runaway AI agent also compromised a cloud platform customer
- Apple preps for a wearable AI revolution
- Building Trustworthy Agentic AI: How Security Concerns Have Changed in 2026
- Huntress Flags Widespread Credential Stuffing Campaign Hitting SonicWall Devices
- Managing cyber-physical risk in smart buildings
- Securing What Matters: Why Cyber Resilience Needs Prioritisation
- Q&A: Nvidia genAI chief explains why open models matter in AI
- AI has become Apple’s latest bug detective
- Synsira Launches Kind Local Pro with 100% On-Device AI
- Anthropic rejects open-weight AI bans, calls for China chip controls and safety tests
- Microsoft’s Nadella calls out Big AI for hypocrisy — but what about his own company?
- How to respond when AI-generated hallucinations smear your brand
- Microsoft, Samsung expand presence in Europe’s sovereign AI market with Mistral deals
- Hackers are compromising hotel Wi-Fi gateways to hijack Microsoft 365 accounts
- Samsung’s entry into AI-powered glasses forces CISOs to again consider corporate risk
- Hugging Face CEO wants transparency after OpenAI’s AI incident
- The best thing about Apple’s smart glasses: what Cupertino rejects
- The AI leadership manifesto
- Legacy enterprise architecture will stall your AI gains
- Scaling AI with the human edge