- Ktoś twierdzi, że ukradł dane 2 milionów pacjentów gabinetów stomatologicznych i nie jest to Fingerprint
- Wyciek / incydent bezpieczeństwa w FELG Software (oprogramowanie dla gabinetów dentystycznych). Atakujący twierdzą, że uzyskali dostęp do 2,4 miliona rekordów z danymi pacjentów.
- Unia wzmocni łączność służb. KE przedstawiła projekt
- Samochód jak smartfon. Dane kierowcy trafiają do zewnętrznych firm
- Nastolatek szykował atak terrorystyczny? Akcja policjantów
- Chat Control 2.0 bez porozumienia. Spór o skanowanie prywatnych wiadomości
- Co z „Cyber Piątką”? Ministerstwo ujawnia stan prac
- Chiński model AI potrafi tworzyć exploity. Anthropic ostrzega przed GLM-5.3
- Rosja uderza w ukraińskich żołnierzy. Kreml sięga po sztuczną inteligencję
- Nowy wariant Spectre v2. Czym jest Branch Target Reuse
- Administrator nie chciał przekazać wyjaśnień. Dostał karę od UODO
- Gry mobilne śledzą użytkowników na ogromną skalę
- Rozgrzewka przed Krakowem! 60 minut hackowania z sekurakiem na żywo (z ekstra bonusem!)
- Polska buduje trzy nowe centra danych. Ponad 1,5 mld zł na cyfrową odporność państwa
- Podatności w oprogramowaniu YunoHost-Apps sogo_yhn
- Gawkowski: powołaliśmy Centrum Walki z Dezinformacją
- Oszukiwali tych, którzy wcześniej stracili pieniądze. CBZC zatrzymało dwie osoby
- Spór sądowy Google z KE. Chodzi o Androida i wyszukiwarki
- Apple łata groźny zero-day. Luka w CoreGraphics była wykorzystywana w wyrafinowanych atakach
- System FBI zaatakowany przez cyberprzestępców. Efekt? Wyciek danych z systemu HR
- Krytyczna luka w Unsloth Studio: inspekcja modelu mogła prowadzić do zdalnego wykonania kodu
- Luki w AWS AgentCore SDK zwiększają ryzyko ataków na ekosystem agentów AI
- Infostealery coraz częściej przejmują konta AI i sesje użytkowników
- Krytyczna podatność w TDengine umożliwia zdalne wyłączenie serwerów OT i IoT jednym pakietem
- DARPA wykorzysta AI do testowania bezpieczeństwa wojskowych komunikatorów
- Naruszenie danych w Pentagonie: wyciek z DMDC objął blisko 3 mln osób
- Cloudflare uruchamia publiczne CA i przygotowuje Web PKI na erę postkwantową
- Carbonato: botnet z agentem AI atakuje źle zabezpieczone hosty Docker
- Bitget po ataku za 388 mln USD: luka w zewnętrznym narzędziu bezpieczeństwa jako wektor włamania
- NeedyMantis: malware do długotrwałego utrzymywania dostępu w przejętych sieciach
- RatHat na Androidzie wykorzystuje Gemini do selekcji ofiar o wyższej wartości
- Krytyczna luka w MCP Python SDK naraża poświadczenia OAuth na przejęcie
- OpenAI wstrzymuje użycie narzędzi po incydencie z agentem AI omijającym ograniczenia internetu
- Star Blizzard atakuje organizacje wspierające Ukrainę, wykorzystując fałszywe zaproszenia do instalacji backdoora
- 101 złośliwych pakietów npm potajemnie dodaje deweloperów do grup WhatsApp
- Wietnamczyk oskarżony o pranie 16 mln dolarów z oszustwa „pig butchering” na kryptowalutach
- Keio i Tokyo Metro ujawniają incydenty cyberbezpieczeństwa w japońskim transporcie
- Kradzież danych podatkowych we Francji po wykorzystaniu przejętych haseł pracowników
- Kiteworks usuwa krytyczną lukę po dziewięciogodzinnym, prewencyjnym wyłączeniu usług
- Autonomiczny agent AI wykorzystany w ataku na DIVD. Nowy etap zagrożeń w cyberbezpieczeństwie
- Apple usuwa zero-day w CoreGraphics wykorzystywany w ukierunkowanych atakach
- Times Car potwierdza wyciek danych 6,6 mln kont użytkowników
- Byli członkowie Sił Powietrznych USA skazani za ataki BEC i oszustwa phishingowe
- FBI zwiększa presję na ShinyHunters po zatrzymaniu domniemanego lidera
- Aktywne ataki na Citrix NetScaler: zero-day umożliwia web shelle i tunelowanie ruchu
- BTR: nowy wariant Spectre v2 umożliwia wyciek pamięci Linuksa mimo istniejących zabezpieczeń
- Złośliwe niestandardowe GPT w kampanii ClickFix. Jak atakujący wdrażają trojana RAT
- Signal rozszerza szyfrowane kopie zapasowe na iOS i komputery desktopowe
- 16-latek dostał się do 17 bilionów rekordów z baz danych Microsoftu.
- Wg relacji wyciekło właśnie 6TB danych z Fakturowni…
NEWS
- Microsoft says threat actors are ahead in the early AI race
- Give yourself room to be human
- Experience What It’s Like to Travel in the Occupied West Bank
- Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers
- ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories
- WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory
- Police dismantle KillSec ransomware gang allegedly led by 16-year-old
- Shadow AI explained: The work shortcut that could leak your company’s secrets
- The Day-One Hole in Zero Trust Architecture
- Kiteworks patches max severity code injection vulnerability
- Warlock Ransomware Hits Large Spanish, Portuguese Orgs
- How Financial Services Companies Can Modernize Their Software Supply Chain
- Microsoft enables Windows settings backup by default for orgs
- Malwarebytes earns another Top Product award in independent testing
- Pentagon breach exposes Social Security numbers and military records of millions
- OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates
- CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
- The Fine Art of Frustrating the Adversary
- Hackers stole Pentagon personnel records of over 3 million people
- The Secrets of the US Spyware King
- Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version
- Metamask discloses security incident affecting its infrastructure
- Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
- Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
- MetaMask Security Incident Prompts Exit of Affected Ethereum Validators
- Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs
- Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure
- Trump, Tech Giants Strike Voluntary AI Safety Accord
- Russian state hackers use new RedFlick technique to push malware
- DIVD says Zammad zero-days enabled AI-driven network breach
- As AI Reshapes the SOC Career Ladder, Satisfaction Rises for 91%, but Entry Gets Harder for Nearly Half
- Over 543,000 valid credentials exposed in public GitHub repositories
- Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
- Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
- CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS
- Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
- Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net
- Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
- Cisco warns of new SD-WAN zero-day exploited in attacks
- AI's Third Wave: Coworkers Break the Security Model That Worked for Agents
INFLUENCERS
- Connected Cars Are a Surveillance Platform
- I Want Better Reporting on AI Genie Behavior
- Using Device Linking to Eavesdrop on WhatsApp and Signal
- Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
- New Attack Against RSA
- Weekly Update 523: Live From a Norwegian Fjord
- U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
- Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee
- On Anthropic’s AI Misuse Report
EXPLOITS
- [webapps] Food-Ordering 1.0 - LFI
- [webapps] WordPress 7.0.2 - Path Travesal
- [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write
- [remote] Teltonika_RutOS 00.07.06.21 - command injection
- [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities
- [webapps] InvoicePlane 1.7.1 - RCE
- [webapps] Krayin CRM 2.2.4 - IDOR
- [webapps] SuiteCRM 8.10.1 - Authenticated SSRF
- [remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE
MALWARE
- Give yourself room to be human
- Kiteworks security advisory (AV26-988)
- Teenagers suspected of leading KillSec ransom group arrested during international operation
- Fortra security advisory (AV26-987)
- MISP security advisory (AV26-986)
- N8n security advisory (AV26-985)
- Google security advisory (AV26-984)
- [Control systems] CODESYS security advisory (AV26-983)
- Fake xStocks, Pendle, and other sites bait crypto users with rewards votes
- ‘A treasure trove of information:’ Cybersecurity specialist says sensitive McMinnville records exposed online
- CrowdStrike Expands Federal SOC Modernization Through CISA-Funded SIEMaaS
- Ransomware Data Theft Surged 275% in 2026: Schools, Hospitals, and Government Agencies Had Some of the Largest Claims
- The 6 Best VPN for Streaming Compared: Key Features + Pricing
- HPE security advisory (AV26-982)
- [일본 애니메이션]転生貴族の異世界冒険録(전생귀족의 이세계 모험록~자중할 줄 모르는 신들의 사도~)
- WatchGuard security advisory (AV26-981)
- Threat Intelligence Snapshot: Week 40, 2026
- From Access to Exfiltration: What Defenders Need to Know
- OpenSSL security advisory (AV26-980)
- Backdoors in the Dungeon – TURN & MQTT Abused by DragonForce
ARTICLES
- Memory squeeze set to tighten through 2028, Micron says
- RMM abuse behind 45% of endpoint incidents as Huntress publishes inaugural Tragic Quadrant
- CFO on the Spot: Five minutes with Tom Coward, CFO of Cytora
- ServiceNow launches standalone AI service desk to provide support in Teams, Slack, and email
- Will ‘move fast, ship quicker’ kill the Apple brand?
- CFO on the Spot: Five minutes with Aziz Megji, CFO of Asana
- Huntress and ALSO partner to put managed security in reach of more European MSPs
- OpenAI takes on Microsoft and Google with office productivity push
- Attacker signs up as a member to plant webshells on parks and recreation platform, hunts for card data
- Trump’s answer to AI’s image problem: Industry self-regulation and a new name
- Apple issues urgent iOS patch as it navigates the spyware arms race
- CyberASAP Celebrates 10th Anniversary with Special Event Exploring Future of UK Cyber Security Innovation
- Continuous Penetration Testing: Why Annual Pen Tests Are a Compliance Checkbox, Not a Security Strategy
- AI Is Making Software Cheaper to Attack. Defenders Need to Change the Price
- How much does the average UK SME spend on cybersecurity each year?
- How Is AI Improving These 3 Tech Sectors?
- Your guide to Google Messages’ new hidden gestures
- Meta’s next big AI bet is enterprise; its biggest hurdle may be trust
- Anthropic revelations suggest a much stronger AI negotiating stance for enterprise CIOs
- Inside the factory where companies build AI they own