- Włamanie do bazy danych użytkowników systemu alarmowania OSP
- Dowódca DKWOC z awansem. Wyższy stopień też dla jego zastępcy
- Poczekajmy kilka dni z wchodzeniem na „Bezpieczne Dane”
- Polska najbardziej atakowana w UE. Rząd i wojsko łączą siły
- Przejęte konta, oszustwa, szantaż. Zatrzymano setki osób
- Agent AI miał zapisać go na siłownię. I zapisał, kasując rezerwacje innych osób.
- Cyberbezpieczeństwo w centrum technologicznej transformacji. Cyber Security Expo Poland 2026 już we wrześniu
- USA wykorzystają prywatne firmy w zagranicznych cyberoperacjach
- Wyciek danych Polaków to żyła złota dla obcych służb. Właśnie zyskały potężną broń
- Złośliwa karta SIM może przejąć modem. Niebezpieczna funkcja RUN AT w urządzeniach IoT
- Największy wyciek danych osobowych w historii Polski i co możemy z nim zrobić
- Chińscy hakerzy użyli agentów AI do autonomicznego ataku na infrastrukturę rządową Tajwanu
- Cyberprzestępcy wykorzystują AI do wyszukiwania nowych ścieżek wejścia do sieci firmowych
- Intel i AMD łatają ponad 80 luk bezpieczeństwa w procesorach, firmware i narzędziach AI
- Ivanti Endpoint Manager łata krytyczne luki: zdalne ataki, wyciek poświadczeń i ryzyko dla S3
- ICS Patch Tuesday w OT: krytyczne poprawki od Siemens, Schneider Electric i Phoenix Contact
- City-Forum: ukryte ataki na Salesforce i ServiceNow z użyciem niestandardowych narzędzi
- Luki w adnotacjach Zoom mogły umożliwić przejęcie klienta uczestnika spotkania
- Cyberatak na Ceva Logistics zakłócił operacje magazynowe w Europie
- Aktywne wykorzystanie luki w VMware vCenter umożliwia trwały zdalny dostęp do środowisk firmowych
- Kimwolf v7: botnet Android maskuje ataki DDoS jako legalny ruch HTTP/2
- Krytyczna luka w SAP Commerce Cloud: CVE-2026-58231 umożliwia zdalne wykonanie kodu bez logowania
- Atak supply chain na LiteLLM naraził tysiące organizacji i setki tysięcy pipeline’ów CI/CD
- DeadLock ransomware wykorzystuje blockchain, by utrudnić przejęcie infrastruktury
- Delta bada incydent z fałszywą siecią Wi‑Fi i atakiem deautoryzacji na pokładzie samolotu
- Fałszywe rozmowy rekrutacyjne jako wektor ataku: UAC-0145 wykorzystuje spreparowany VPN
- Adobe łata krytyczne luki CVSS 10.0 w ColdFusion i Campaign Classic
- Microsoft łata 398 podatności, w tym aktywnie wykorzystywany zero-day w sterowniku Windows
- ShieldBreak: nowy zero-day w Microsoft Defender umożliwia eskalację uprawnień do SYSTEM
- Ujawniona słabość API modeli AI pozwalała odzyskiwać ukryte ślady rozumowania i sekrety
- Złośliwe wersje LiteLLM mogły narazić tysiące organizacji na wyciek sekretów
- Cisco ASA i FTD pod ostrzałem: aktywnie wykorzystywana podatność DoS w usługach zdalnego dostępu
- Krytyczna luka w Adobe Commerce i Magento umożliwia przejęcie kont klientów
- Signal wzmacnia ochronę przed atakami man-in-the-middle dzięki Automatic Key Verification
- Fałszywi pracownicy zdalni jako nowy wektor ataku na firmy
- FBI ostrzega przed przejęciami kont w celu kradzieży intymnych materiałów
- Lazarus wykorzystuje zero-day w Windows do eskalacji do SYSTEM i wdrażania backdoora
- SpyNote i WindRelay na Androidzie: malware wyłudza kredyty i relayuje karty przez NFC
- Plug and Pwn: fałszywe urządzenia USB mogą dać uprawnienia SYSTEM w Windows
- Setki fałszywych rozszerzeń VPN dla Chrome przechwytywały ruch przez serwer proxy
- Nowy exploit na Microsoft SharePoint wykorzystywany w realnych atakach
- Chiński robot w Porcie Wojennym wywołał kontrowersje. Flotylla wyjaśnia
- 19 milionów Polaków, tysiące placówek. Co zrobić po wycieku danych?
- Po historycznym wycieku MyDr może grozić historyczna kara
- Bezprecedensowy wyciek danych milionów Polaków. Potwierdzenie z rządu
- Przejmowali firmowe maile i podmieniali numery kont. Straty przekroczyły 4 mln zł
- Gdy zabezpieczenia pomagają spamerom: Jak przejąć reputację domeny bez łamania kryptografii?
- Ransomware 2026 – wnioski z raportu Sophos
- Gawkowski: SpaceX musi przywrócić Polskę do Europy
- Incydent w MyDr. Gawkowski: zwołałem Połączone Centrum Operacyjne Cyberbezpieczeństwa
NEWS
- Trezor discloses data breach affecting nearly 14,000 customers
- Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion
- White House taps security firms for offensive hack-back operations
- WhatsApp rolls out new feature that flags potential scam messages
- Dissecting the JWR phishing framework
- 'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft
- Parents take on Meta, TikTok, Google, and Snap in 3,000 youth safety lawsuits
- CBP Workers Allegedly Used Government Databases to Spy on Exes, Crushes, and Colleagues
- Belgium's eID Authentication Opens Citizen Accounts to RCE
- Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
- "City-Forum" data-theft attacks target Salesforce, ServiceNow portals
- Android malware combo takes out loans and relays victims' credit cards
- Long-running Data Theft Campaign Targeting Salesforce, ServiceNow
- Hackers exploit critical Adobe Commerce flaw to hijack customer accounts
- Hundreds of fake Chrome VPN extensions route traffic through a proxy
- Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
- Walmart's "Trusted Agent" Approach to Purple Teaming
- Plug and Pwn attack uses fake USB devices for Windows SYSTEM access
- Lazarus hackers exploited Windows zero-day to target defense firms
- FBI: Hackers target online accounts to steal nude photos
- 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One
- The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In
- Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition
- Walmart Leaders Transform Security Operations Without Going Bananas
- Hackers leverage new Microsoft SharePoint exploit in attacks
- This Coin-Sized Device Can Hack a Boeing 737
- OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning
- Enterprise Defenses Recovered at the Edge and Collapsed Inside
- Signal adds new security feature to thwart man-in-the-middle attacks
- Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws
- New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges
- ‘The Worst I’ve Ever Seen’: Cargo Thefts Have Turned Violent in Pursuit of AI Hardware
- Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
- Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
- SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
- ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access
- Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS
- Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities
- DeadLock ransomware uses blockchain to resist infrastructure takedown
INFLUENCERS
- Separating AI’s Technological Problems from Its Capitalism Problems
- Prompt Injections for Defense
- Weekly Update 516: Live From Vietnam
- Microsoft Plugs Nearly 400 Security Holes
- AI Genie in the Wild
- AI for Military Support
- Python Now Has a Post-Quantum Encryption Library
- Friday Squid Blogging: Arctic Bobtail Squid Video
- ICE Is Buying Access to Credit Card Records
- Canadian Man Pleads Guilty in Snowflake Extortions
EXPLOITS
- [webapps] Ray 2.56.0 - Directory Traversal & Local File Inclusion
- [remote] mcp-server-kubernetes 3.8.x - Argument Injection
- [webapps] Planyo_Online_Reservation_System 3.0 - Arbitrary File Read via SSRF
- [dos] LuCI DHCPv6 - Lease Hostname Stored Cross-Site Scripting
- [webapps] Blocksy Companion 2.1.46 - RCE
- [webapps] Apache Gravitino 1.2.1 - SSRF
- [remote] PraisonAI praisonaiagents 1.6.77 - Remote Code Execution
- [webapps] Joomla 2.9.99.4 - Unauthenticated Remote Code Execution
- [webapps] CorgetGpsDget 2_3.2 - OS Command Injection
- [local] Microsoft Edge 150.0.4078.48 - RCE
- [webapps] OrkesConductor 3.30.2 - Unauthenticated Remote Code Execution
MALWARE
- WebPros security advisory (AV26-815)
- How Packers Work: UPX & Executable Obfuscation | Packing & Obfuscation Lesson 01
- Quincy Valley Medical Center notifies patients of Aesto breach
- In a first, US will allow some private firms to carry out cyberattacks
- 윈도우 10 kb5120249,윈도우 11 kb5121003 보안업데이트
- Malware Crypting Services and the Threat Actors Who Sell Them
- GitLab security advisory (AV26-814)
- The Model Is the Malware | What Four Agentic Intrusions Tell Defenders
- The State of Ransomware Q2 2026
- Threat Intelligence Snapshot: Week 33, 2026
- New Android malware lets criminals use your bank card in real time
- Dissecting the JWR phishing framework
- Phishing Protection | The Complete Guide to Stopping Phishing Attacks in 2026
- Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side
- July 2026 Cyber Attacks Statistics
- July 2026 Cyber Attacks Statistics Infographic
- Armored Likho expands its cyber-espionage toolkit
- When SQL Server Becomes the Initial Launcher: A Deep Dive into Weaxor Ransomware Execution
- 2026-08-12: SmartApeSG ClicFix leads to two RATs
- ISC Stormcast For Thursday, August 13th, 2026 https://isc.sans.edu/podcastdetail/10050, (Thu, Aug 13th)
ARTICLES
- Scammers Exploit Shopify’s Own Notification System in New ‘Fake Refund’ Scam
- It took $58 to break Microsoft’s SCCM, but a patch made it harder
- Akira Ransomware Affiliate Rebooted Into Safe Mode to Dodge EDR and Broke Its Own Attack
- Is AI entering the SOC at the right stage?
- Forescout Launches Rapid Insight Assessment to Uncover Hidden Cyber Risks
- UK Cyber Attacks Jump 26% Year-on-Year as Ransomware Activity Doubles Globally
- OpenAI: Latest news and insights
- Pixel 11 envy? Here’s how to unlock its best new feature on any Android device
- Atlassian’s Chief People Officer on how to fix enterprise AI’s ROI problem
- Lovable bolsters its AI software creation capacity, touts $400M funding round
- Researcher creates workaround for Microsoft Defender security patch
- Researcher bypasses Microsoft Defender security patch, seizing control
- Lovable raises another $400M, confirms new $13.3B valuation
- IT infrastructure shortages are real and lasting. Here’s how to cope
- Vega Introduces Detection Skills, The New Open Standard for AI Reasoning in Agentic Cyber Defense
- Apple’s response to RAM-ageddon? Lease, downgrade, refurbish, repair
- AI policies work better when employees help write them
- Anthropic to watermark AI-generated content
- Q&A: Ransomware is now a ‘fully fledged industry’, says cybercrime journalist Geoff White
- Apple’s price hikes are a warning to IT