- Unia inwestuje w scale-upy. 5 mld euro na ekspansję technologicznych firm
- Jak zbudować system ostrzegania, który nie zawiedzie? Poradnik dla decydentów
- Hotelowe Wi-Fi na celowniku rosyjskich hakerów
- Wycieki danych medycznych Polaków. Rzecznik Praw Pacjenta pilnie apeluje do szpitali
- Włosi wydzielą „wojskową domenę cyber”. Poważne zmiany w armii i wielomilionowe inwestycje
- Polska walczy o historyczną inwestycję w AI. Mocni konkurenci w przetargu UE
- Programisto, pentesterze – na chwilę wraca nasz kurs XSS – do poniedziałku 30% taniej!
- Ostrzeżenie przed Chinami i Rosją. Japonia zapowiada historyczne zmiany w armii
- Wnioski po dziesiątkach ataków na wodociągi w Minnesocie
- Koniec „samowolki”. Surowe limity i kontrola portfeli kryptoaktywów w RPA
- Naruszenie danych w CareCloud: wyciek informacji medycznych i finansowych 345 tys. osób
- Domniemany wyciek danych Żabki: Jira, GitLab i klucze API w centrum ryzyka
- Ruby on Rails łata krytyczną lukę w Active Storage. Zagrożone aplikacje przetwarzające obrazy
- KT ukarane grzywną 39 mln USD po naruszeniu danych klientów
- Chińsko-powiązana grupa UAT-7810 rozwija sieć ORB z użyciem malware’u LONGLEASH
- Anthropic: to luki w izolacji środowiska, a nie model Claude, doprowadziły do incydentów bezpieczeństwa
- HollowFrame i fałszywa python39.dll: nowy łańcuch infekcji oparty na DLL sideloading
- Koalicja OT wzywa do reform po atakach na infrastrukturę wodną w USA
- SAGA pomaga ustalić źródło filmów generowanych przez AI
- Naruszenie bezpieczeństwa w Brinks Home: wyciek danych po publikacji plików przez ShinyHunters
- DeepSeek w ofensywie: jak AI przyspiesza rekonesans i próby cyberataków
- Atak ransomware na River Bank: firma twierdzi, że skradzione dane zostały usunięte przez sprawców
- Cyberataki na sektor wodno-kanalizacyjny w USA objęły co najmniej siedem stanów
- Rosyjska grupa APT wykorzystuje bramy publicznych sieci Wi‑Fi do kradzieży poświadczeń
- Cyberatak na rejestr beneficjentów rzeczywistych w Liechtensteinie. Dane 31 tys. osób mogły zostać ujawnione
- Ataki na Google Password Manager mogą zagrozić kontom chronionym passkeys
- Thermo Fisher łata lukę CVE-2026-17583 umożliwiającą niemal niewykrywalną manipulację plikami DNA
- Błąd RNG w portfelach COLDCARD mógł umożliwić kradzież bitcoinów o wartości 88,6 mln USD
- Krytyczne luki w Hugging Face Diffusers mogą prowadzić do zdalnego wykonania kodu podczas ładowania modeli
- 18 złośliwych pakietów npm uderza w użytkowników narzędzi Alibaba i dostarcza wieloplatformowego RAT-a
- Chiński aktor zagrożeń wykorzystuje wyciekły DarkSword do wdrażania GHOSTBLADE na iPhone’ach
- N-able potwierdza przejęcia serwerów N-central po niepełnej poprawce luki uwierzytelniania
- INC Ransomware dominuje ataki na SonicWall SMA 1000 po wykorzystaniu łańcucha dwóch luk zero-day
- Fałszywy launcher Xeno dla Robloxa rozprzestrzenia infostealera i trojana RAT
- Wyciek danych ponad 100 tys. funkcjonariuszy i pracowników brytyjskiej policji po ataku na PNLD
- DOUBLECUP i ClickFix: malware ukrywane w obrazach z cache przeglądarki
- BTMOB RAT: jak mobilny trojan na Androida przekształcił się w rozproszony ekosystem cyberprzestępczych usług
- Potencjalny wyciek danych z Żabki
- Żabka zhackowana. Co wyciekło?
- Dziwne znaki, spacje i stylometria – polska klawiatura na Linuksie
- Żabka zhakowana. Poważny incydent: wyciekły dane
- Atak hakerski na sieć polskich placówek zdrowotnych. Wydano komunikat
- Krzywda za ekranem. Dlaczego przemoc w sieci jest tak samo groźna?
- Groźny atak na szyfrowany komunikator Gajim przez lukę w KDE Plasma
- Myśleli, że ratują ukochane. Wpadli w pułapkę rosyjskich służb
- Co świadczy o odporności algorytmu Argon2 na ataki z wykorzystaniem GPU? Analiza standardu
- Złośliwe rozszerzenie do Chrome wykrada prompty z ChatGPT, Claude, Copilota i wielu innych serwisów AI
- Platforma HackerOne wprowadza obowiązkową weryfikację tożsamości w programach Bug Bounty
- 270 mln zł na cyberbezpieczeństwo samorządów. Jak zbudować LCC?
- „Potwierdź, że nie jesteś robotem”. Uwaga na fałszywe CAPTCHA
NEWS
- New XCSSET variant targets macOS devs via compromised Xcode projects
- 77 Open VSX extensions found harvesting developer info
- Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook
- Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
- Landmark Deal Would Officially Add Laser Weapons to US Army Arsenal
- Massive ChainDrop npm supply-chain attack infects hundreds of packages
- Varonis Agent IBAC keeps AI agents within their intended boundaries
- Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
- Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
- AI Notetaker Lets Hackers Spy on Government, Corporate Video Calls
- Travelers targeted when logging into hotel Wi-Fi networks
- Online backlash ends in Google rolling back Google Earth AI tool after a day
- When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted
- Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent
- New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
- “Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI
- DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT
- CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
- Device Code Phishing Up 1,500% in 2026; Vishing Doubles
- WhatsApp account takeover scam asks you to “vote for my friend”
- Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
- New Pass-ta-key attacks let malware hijack Google-synced passkeys
- “Adult TikTok” searches lead to scams
- Attackers Exploit N-able Patch Bypass Flaw on RMM Servers
- The AI Act kicks into action, forces companies to be clear about AI chatbots
- Californians can tell data brokers to DROP their information
- New Tool Traces AI Videos Back to Their Source
- Anthropic: AI Attacks Result of Security Gaps, Not Model Issues
- New DOUBLECUP ClickFix service hides malware in browser cache images
- Fake Roblox Xeno script launcher pushes infostealer, RAT malware
- 18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
- N-able warns of N-central auth bypass flaw exploited in attacks
- Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
- INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
- [Webinar] Tales from the Frontlines: An exclusive briefing on Q2 incidents
- Chinese Actor Weaponizes DeepSeek AI Agent to Attack Security Firm
- ExfilSquad hackers leak info of over 100,000 UK police officers, staff
- Inside the Underground Business of BTMOB RAT
- ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
- Is There Really a Fix for CISO Fatigue?
INFLUENCERS
- Iran Cyberattacks Against Minnesota Water Systems
- Some Claude Chats Are Searchable on Google
- More on the OpenAI Agent’s Attack on Hugging Face
- The OpenAI Hack Shows the Genie Is Out of the Bottle
- Welcoming the Nepalese Government to Have I Been Pwned
- Weekly Update 515
- Five Questions to Answer Before Buying an AI Security Product
- Friday Squid Blogging: Squid Helps Discover New Marine Species
- Anthropic’s Opus 5 Is Better at Resisting Prompt Injection
- Facial Recognition at Madison Square Garden
- Read This Before You Buy That TV Streaming Stick
- American Being Prosecuted for Wiping His Phone Before Handing It Over to Border Officials
- Should You Use AI for a Task? Here’s a Simple Way to Decide
- A Field Guide to the AI Security Market
- Measuring the Tendency of AI Agents to Go Rogue
- Long-Lived Vulnerability in Microsoft Secure Boot
- Measuring LLMs’ Ability to Perform Cryptanalysis
MALWARE
- 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET
- MISP security advisory (AV26-775)
- Rapidly Rising Risk: AI in the Shadows
- Chinese telecom firms kept footholds in US networks despite federal crackdowns, House probe finds
- 5 Reasons Developers Still Download Malicious Packages
- Sage Water Resources says Utah saltwater disposal controller intrusion bypassed pump safeguards
- Things You Won’t Want to Miss at Black Hat USA 2026
- Checkpoint security advisory (AV26-774)
- Florida Man Sentenced for Conspiracy to Commit Wire Fraud
- Tenable, Inc. security advisory (AV26-773)
- WebPros security advisory (AV26-772)
- Dell security advisory (AV26-771)
- IBM security advisory (AV26-770)
- The Insider’s Guide to Evaluating Endpoint Security Solutions
- Silent Push 6.0 adds AI workflows and unified cyber platform
- APT29 호텔 Wi-Fi 공격을 통해 맞춤형 악성 소프트웨어를 사용하여 Microsoft 365 계정 공격
- Ongoing Threats of Swatting and Indicators for Community Members
- N-able security advisory (AV26-769)
- Arctic Wolf Introduces Cyber AI Readiness Accelerator, Enables Partners to Deliver Exposure Management and Resilience
- Querying ONYPHE from Python in 2026: pyonyphe 3.0
ARTICLES
- ‘Apple is one of the greatest companies of all time,’ says OpenAI
- AI agents get better at IT ops, but only with humans in the loop
- Fake Bank of America Phishing Emails Found Delivering Disguised ScreenConnect RAT via UAC Bypass
- When AI Agents Meet Real Infrastructure: Hype, Human Error or a Genuine New Threat?
- Surviving AI: Navigating workload creep, AI slop, and the new tech career playbook
- Anthropic’s AI models accidentally hacked three companies
- Sourcing smarter, not harder: meet the AI agent built to transform sourcing
- Check Point Named a Visionary Leader in 2026 Frost Radar for Enterprise Risk Mitigation and Management Platforms
- Huntress Makes RMM-Blocking Feature Free for All Customers as Attacks Surge 277%
- AI pentesting tools are generating more findings than security teams can validate, new survey finds
- Apple and the invisible wolf: AI slop drowns real security threats
- Alibaba takes aim at OpenAI and Anthropic with Qwen3.8-Max launch
- Greg Soros Shares How Podcasters Build Lasting Authority Through Thought Leadership
- How AI is killing smartphone apps in China
- Critical N-able N-central Vulnerability Under Active Exploitation as Hotfix Lands
- Google has used AI to patch 1,072 vulnerabilities in Chrome
- Apple’s Tim Cook era ends with a record $109B quarter
- Reporter’s notebook: In Dubai’s sun and sand, AI, server farms, and optimism bloom
- Data center developer eyes disused newpaper printing plant
- DefCon security conference bans smart glasses with recording capabilities