- Brzoska odpowiada Mecie. „Nie ma słowa przepraszamy, nie odpuszczę"
- Podatność w Firefox JIT wykorzystana w łańcuchu browser-to-kernel
- Ghostjacking – atak odwracający zachowanie agenta AI
- ETSI proponuje 17 nowych specyfikacji cyberbezpieczeństwa dla produktów cyfrowych
- Infostealery napędzają masową kradzież danych uwierzytelniających
- Krytyczna luka w Payment Gateway Pix for WooCommerce do 1.5.0 umożliwia zdalne wykonanie kodu
- Krytyczna luka RCE w D-Link DNS-340L i innych NAS-ach: CVE-2024-10914 bez poprawek dla urządzeń legacy
- Luka SQL Injection w QSM zagroziła ponad 40 tys. stron WordPress
- Krytyczna luka RCE w ipTIME A3004T: usługa EAD może umożliwiać pełne przejęcie routera
- Krytyczna luka w Forminator dla WordPressa: nieuwierzytelnione usuwanie plików może prowadzić do przejęcia witryny
- Podatność SSRF w flyto_core do 2.26.7: DNS rebinding pozwala ominąć walidację URL
- Exploit-DB 52645 niedostępny: jak ocenić ryzyko, gdy rekord exploita zwraca błąd 404
- Probo do wersji 0.222.2 z luką cross-tenant IDOR. Ryzyko ujawnienia danych między organizacjami
- Duplicati 2.2.0.3: wyciek klucza JWT umożliwia przejęcie uprawnień administratora
- Cavern C2 ukrywa komunikację w DNS i Google Apps Script, utrudniając wykrycie operacji APT
- Atak na łańcuch dostaw LiteLLM ujawnia poświadczenia i uderza w sektor technologiczny, finansowy oraz ochronę zdrowia
- phpSysInfo 3.4.5: obejście listy dozwolonych adresów IP prowadzi do ujawnienia informacji systemowych
- Naruszenie bezpieczeństwa w Baylor Genetics: wyciek danych pacjentów i pracowników po cyberataku
- Krytyczny łańcuch exploitów w modemach Unisoc umożliwia przejęcie jądra Androida przez VoLTE
- Akira ransomware wykorzystuje tryb awaryjny Windows do obchodzenia EDR
- Krytyczna luka w macOS Screen Sharing aktywnie wykorzystywana w atakach
- Ukryte prompty AI w pismach procesowych doprowadziły do sankcji sądowych
- Evooo1Bot atakuje urządzenia brzegowe z Linuksem i zamienia je w proxy SOCKS5
- Aktor powiązany z Chinami wykorzystuje lukę VMware vCenter i wdraża ransomware pochodne od Babuk
- Krytyczna luka w SAP Commerce Cloud wykorzystana trzy dni po ujawnieniu
- Mustang Panda rozwija CoolClient o rootkit jądra Windows
- Jak serwery MCP mogą ujawniać sekrety przedsiębiorstwa i zwiększać ryzyko cyberataków
- Luka w GitHub Actions w repozytorium Snowflake umożliwiała command injection przez spreparowane zgłoszenia
- Agenci Claude w konflikcie celów wdrażali samoreplikujące się malware
- Naruszenie danych SafePal objęło 39 798 klientów. Źródłem wycieku była luka w śledzeniu zamówień
- Krytyczna luka w GitLab GraphQL pozwala na niezautoryzowane usuwanie publicznych projektów
- Naruszenie danych francuskiej administracji podatkowej objęło 678 tys. osób
- Ataki DDoS zakłóciły działanie komunikatora Threema. Co wiadomo o incydencie?
- Francuski CERT opublikował raport z aktywności grupy Turla – rosyjskiego APT powiązanego z FSB
- PixelSmash, czyli podatność, która może zaatakować zewsząd
- Samopropagujący się atak na Microsoft Word – prompt injection w Copilot
- Z pamiętnika admina #2
- Brzoska kontra Meta. Gawkowski: żądam realnych działań
- Francuski urząd skarbowy zaatakowany. Setki tysięcy poszkodowanych
- Włamanie do radia i fałszywe strony. Fake newsy o polskim zajęciu czeskich ziem
- Zamawiał obcym jedzenie za tysiące złotych. Zatrzymało go CBZC
- Prokuratura szybciej sięgnie po e-maile i dane z komunikatorów
- Podatność w oprogramowaniu OutSystems Service Center
- Kolejny kraj wyrzuca smartfony ze szkół. Polskę też to czeka
- Brzoska grzmi ws. scamu na Facebooku. „Jesteście marionetkami”
- Jak odpowiedzi AI będą znakowane w sposób niewidzialny dla ludzi?
- Wdrożenia AI w firmie. Ważne ostrzeżenia UODO
- Co zrobić po wycieku danych? Osobowych. Medycznych. Wszystkich.
- Cyberatak na Instytut Pileckiego. Publikowano rosyjską propagandę
- Kto i do czego powinien mieć dostęp? Od IDM do Identity Governance
NEWS
- Microsoft confirms outage affecting search in Microsoft 365 apps
- SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers
- Microsoft starts removing WMIC tool used by cybercriminals
- CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
- Video Call Exploit Chains Two Flaws in Unisoc Modems
- Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
- 'Turf War' Between Claude Agents Leads to Self-Replicating Malware
- Hacker claims 3.6 million Azure account records stolen from major companies
- Adam Shostack Talks Hugging Face & PHANTOM-B
- Pokémon Center data breach exposes customer info, cancels some orders
- Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection
- Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
- Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
- Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS
- Microsoft confirms GitHub is down worldwide
- Certighost and the Privilege Hiding in Your Certificate Authority
- ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
- Windows Server 2022 reaches end of mainstream support in 60 days
- How MCP Servers Can Expose Enterprise Secrets
- Philips and GE investigating Clop ransomware data theft claims
- Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access
- French tax authority data breach affects 678,000 individuals
- Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies
- Microsoft working on Defender patch for ShieldBreak zero-day
- Why Facebook’s war on ad blockers could help scammers
- Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware
- A week in security (August 10 – August 16)
- SafePal data breach impacts 39,798 customers, stolen info for sale
- Anthropic confirms Claude is down in major outage affecting multiple services
- Large-scale DDoS attacks disrupted Threema secure messaging service
- New AmnesiaStealer macOS malware hijacks browser sessions via remote control
- New Evooo1Bot Linux botnet turns routers into traffic relay nodes
- SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch
- Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner
- How Anthropic plans to watermark Claude's AI-generated text
- New York City Lawmakers Push to ‘Ban the Scan’ at MSG
- Mission-Driven Security: Inside a Global Bank's Defense
- Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware
- Hackers arrested over €30M bank fraud exploiting service provider flaw
- Amid AI-Driven Bug Tsunami, NIST Looks to…AI
INFLUENCERS
- Weekly Update 517: Cyber Ransoms
- Hacking Public Wi-Fi DNS to Steal Credentials
- Friday Squid Blogging: Searching for the Colossal Squid
- Upcoming Speaking Engagements
- Who’s Tracking You? Use This New Service to Find Out
- If the Markets Reject OpenAI and Anthropic, the US Should Nationalize Them
- Separating AI’s Technological Problems from Its Capitalism Problems
- Prompt Injections for Defense
- Weekly Update 516: Live From Vietnam
- Microsoft Plugs Nearly 400 Security Holes
- AI Genie in the Wild
- AI for Military Support
VULNERABILITIES
- CVE-2026-71567 — CVSS 7.7
- CVE-2026-73851
- CVE-2026-71566 — CVSS 9.3
- CVE-2026-16047 — CVSS 4.3
- CVE-2026-16046 — CVSS 4.3
- CVE-2026-16049 — CVSS 4.3
- CVE-2026-16048 — CVSS 6.3
- CVE-2026-10527 — CVSS 6.3
- CVE-2026-16045 — CVSS 4.3
- CVE-2026-16044 — CVSS 5.4
- CVE-2026-13202
- CVE-2026-15754 — CVSS 4.2
- CVE-2026-59909 — CVSS 7.1
- CVE-2026-56686 — CVSS 7.8
- CVE-2026-59911 — CVSS 5.5
- CVE-2026-56685 — CVSS 7.3
- CVE-2026-59910 — CVSS 7.8
- CVE-2026-56090 — CVSS 7.3
- CVE-2026-56089 — CVSS 3.3
- CVE-2026-19693 — CVSS 8.1
EXPLOITS
- [webapps] WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload
- [dos] Nmap 7.99 - Extension Header Integer Underflow
- [dos] NanaZip 6.5 - DoS
- [remote] D-Link DNS_340L - OS Command Injection
- [webapps] flyto_core 2.26.7 - Server-Side Request Forgery
- [webapps] Duplicati 2.2.0.3 - JWT Signing Key Leak
- [remote] ipTIME A3004T - Remote Code Execution
- [webapps] Joomla JCE_2.9.15 - Remote Code Execution
- [webapps] Probo 0.222.2 - IDOR
- [webapps] webpack_devserver 5.2.5 - CSRF
- [remote] phpSysInfo 3.4.5 - IP Allowlist Bypass
MALWARE
- Compromised Credentials | What They Are, How They’re Stolen, and How to Detect Them Before Attackers Do
- Vulnerability in Carbone software
- ISC Stormcast For Tuesday, August 18th, 2026 https://isc.sans.edu/podcastdetail/10056, (Tue, Aug 18th)
- Apple Patches iOS and macOS, (Mon, Aug 17th)
- Trendbericht KI und Cybersicherheit 2026
- The EU CRA Clock is Ticking:Are You Compliant?
- 235 GB of PHI and internal documents dumped; Chaos claims it comes from Healthcare Highways
- Progress security advisory (AV26-824)
- 600,000 WordPress Sites Affected by Arbitrary File Upload Vulnerability in Forminator Forms WordPress Plugin
- Arctic Wolf Lösungen – Übersicht
- Apple security advisory (AV26-823)
- 애플 불법 스파이웨어 공격에 대한 새로운 위협 알림 기능 도입
- Teaching AI to Reason Through Detection Triage
- Apple Screen Sharing Security, (Mon, Aug 17th)
- C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
- ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw
- Microsoft Edge security advisory (AV26-822)
- Compromising the Developer: How Modern Dependency Culture Reshaped the Supply Chain Threat Landscape
- 17th August – Threat Intelligence Report
- Israel’s largest crypto broker Bits of Gold hit by data breach affecting 200,000 customers
ARTICLES
- GitHub restores services after nearly 8-hour outage disrupts Actions, APIs, PRs and Copilot
- ‘Data-driven, human-led’: Inside Revolut’s strategy for global hypergrowth
- AI inference is getting cheaper, but your agents are getting more expensive
- OpenAI president’s blog pushing agentic AI most notable for what it did not say
- US confounds Apple’s memory supply challenge
- Moburst Launches Answerburst, a Purpose-Built AEO Practice for the AI Search Era
- Exchange CU1 delayed further as Microsoft races to verify AI-found flaws
- Enterprise AI’s second act: from automation to augmentation
- August’s Patch Tuesday is a monster: 751 fixes, with an exploited Windows flaw
- The 80% Problem: Why AI resilience is more important than ever
- The first domino of AI disruption: How frontier models are revolutionising software security
- OpenAI loses its AI ethics lead
- Meta gives up control of Chinese AI startup Manus after eight months
- Microsoft brings Copilot apps together ahead of ‘super app’ overhaul
- Keeper Security Issues Cyber Guidance for Education IT Teams
- Apple cracks China with Alibaba for iPhone AI
- How to replace Edge as the default browser in Windows — and why you shouldn’t
- Trump Signs Memorandum Allowing Private Firms to Launch Offensive Cyber Operations Against Foreign Threat Actors
- Meet Huntress at International Cyber Expo 2026
- DeepSeek raises some V4 prices by more than 10x as AI demand strains capacity