- KSC bez Lokalnych Centrów Cyberbezpieczeństwa będzie „papierkiem” [OPINIA]
- Wybory 2027 na celowniku rosyjskiej dezinformacji. Oto jak ją zatrzymać [OPINIA]
- INTERPOL i I-GRIP przyspieszają blokowanie przelewów BEC. 6,6 mln USD zatrzymane w globalnej operacji
- CISA aktualizuje wytyczne SBOM: więcej metadanych, ale nadal bez przełomu w zarządzaniu ryzykiem
- Cyberprzestępcy wykorzystują autonomiczne ofensywne agenty AI do skalowania ataków
- SilverFox uderza w japońskiego producenta: ValleyRAT, DLL sideloading i sterowniki jądra w jednej kampanii
- Podszywanie się pod marki jako wektor initial access – dlaczego to zagrożenie rośnie
- Naruszenie danych w CareCloud dotknęło ponad 350 tysięcy osób
- Krytyczna luka CosmosEscape w Azure Cosmos DB mogła zagrozić danym klientów na masową skalę
- Flying Eagle: cyberprzestępczy ekosystem wokół fałszywej aplikacji policyjnej na Androida
- Ataki watering hole w Korei Południowej: państwowa kampania wymierzona w obywateli i firmy
- Device code phishing w 2026 roku rośnie w siłę. Jak atakujący nadużywają legalnych przepływów OAuth
- VMware łata krytyczne luki: obejście uwierzytelniania w vCenter i ucieczka z maszyny wirtualnej
- Krytyczna luka RCE w TeamCity: CVE-2026-63077 zagraża serwerom CI/CD
- Kampania malvertising na macOS wykorzystuje fałszywe aktualizacje do kradzieży kryptowalut
- Google wykorzystuje AI do wykrywania luk w Chrome. Ujawniono 13-letnią podatność typu sandbox escape
- 84 luki w rdzeniach 4G i 5G: nowe podatności umożliwiają DoS i przejęcie sesji
- Chrome usuwa 1442 podatności w trzech wydaniach. Nowa faza bezpieczeństwa przeglądarek
- HollowFrame i Matryoshka: wieloetapowy spear-phishing uderza w kancelarie prawne
- Tanie Android TV boxy podszywają się pod smartfony i zamieniają domowe łącza w sieć proxy
- Ataki na łańcuch dostaw npm powiązane z Koreą Północną: analiza incydentów debug, chalk i axios
- OctLurk i SilkLurk w atakach na rządy Azji Centralnej. Trwa zaawansowana kampania cyberwywiadowcza
- ESET: rośnie skala złośliwych „AI skills” i malware adaptującego się do środowiska ofiary
- Claude i incydent PyPI: jak testy bezpieczeństwa AI doprowadziły do publikacji złośliwego pakietu
- Koreański regulator nakłada wielomilionową karę na KT po naruszeniu danych klientów
- DeepSeek sterowany przez Telegram: nowy etap autonomicznych ataków cybernetycznych
- Arch Linux blokuje adopcję pakietów AUR po fali złośliwych przejęć
- CISA ostrzega wodociągi przed falą ataków na sterowniki PLC
- Naruszenie danych w chmurze Amgen ujawnia informacje pacjentów i dane własnościowe
- Atak supply chain w reklamie online: skrypt Adform użyty do kradzieży kryptowalut
- Weekendowa Lektura: odcinek 687 [2026-07-31]. Bierzcie i czytajcie
- Rosja uderza w Tuska i Ukrainę. Wybuch pocisku w Tarnawie-Kolonii uruchomił kremlowską machinę
- Rosyjska rakieta, dron lub inne zagrożenie. Dlaczego Polska wciąż nie posiada systemu, z którego korzysta Europa?
- Z pamiętnika admina #1: Ticket, który bardzo chciał być CISO…
- Oszuści podszywają się pod Europol. Szantaż finansowy i wiele więcej
- Podatności w skryptach PHP Jabbers
- Samorządy połączą siły przeciw cyberatakom. Rusza program LCC
- Link do Poradnika Bezpieczeństwa w SMS od RCB. Gawkowski: nie ma ataku
- Zarząd Fundacji Bezpieczna Cyberprzestrzeń został poszerzony o dwóch nowych wiceprezesów
- Jak zhakowane publiczne bramki Wi-Fi używane są do pozyskiwania poświadczeń korporacyjnych?
- „Akceptuję wszystkie” pod lupą. Spór o przyszłość cookies
- NCSC apeluje do producentów o długoterminowe i bezpieczne aktualizacje urządzeń
- Google łata setki podatności w Androidzie i ChromeOS
- Phishing w Microsoft Teams z użyciem legalnych domen – jak działa nowy model nadużyć
- Cyberprzestępcy sięgają po autonomiczne agenty AI do działań ofensywnych
- OpenAI rozszerza zakres incydentu z „rogim” modelem. Ucierpiały także inne usługi poza Hugging Face
- Skanery AppSec jako nowy wektor ataku na łańcuch dostaw oprogramowania
- Claude Mythos pokazuje, że AI może wyprzedzać ludzi w badaniach nad kryptografią
- Podszywanie się pod marki jako wektor initial access. Fałszywe witryny i aplikacje rosnącym zagrożeniem
- Microsoft Copilot w Wordzie może przenosić ukryte prompty do nowych dokumentów
NEWS
- Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
- Rails patches critical Active Storage flaw with RCE potential
- 7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran
- Nobody Knows if OpenAI’s and Anthropic’s AI Hacking Sprees Are Illegal
- Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
- Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
- Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
- Amgen says cloud data breach exposed patient health, proprietary info
- Arch Linux disables AUR package adoption to stop malware flood
- Online ad firm Adform’s script compromised to steal cryptocurrency
- OpenAI says its new GPT 5.6 models are becoming more cost-efficient
- Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
- CISA Issues Fresh SBOM Guidance. Did They Get It Right?
- Hacker uses DeepSeek AI to autonomously attack vulnerable servers
- CISA warns of cyberattacks disrupting U.S. water utilities
- HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
- Fake Fortnite rewards are stealing players’ accounts
- Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
- ESET tracks rise in malicious AI skills and adaptable malware
- The Morning After We Pull a Root of Trust, Nobody Owns It
- Interpol Leverages Global System to Curtail Fraud Payments
- DROP Platform Lets Californians Reduce Digital Footprint
- USA Fencing Lunges Into the Hidden Identity Challenge in Amateur Sports
- Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined
- Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw
- 6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
- Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
- Fake Flash Player installs AtlasRAT
- The New Defcon Badges Pack a Unique Open Source Chip That Doubles as a Security Key
- Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations
- Anthropic Says Claude Hacked 3 Organizations During Cybersecurity Tests
- Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests
- South Korea fines telco giant KT $39 million for customer data breach
- JetBrains warns of critical TeamCity remote code execution flaw
- A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran
- Minnesota Water Utility Attacks Expose Sector's Cyber-Risks
- AI Harnesses Burst With Potential Exploit Opps
- DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
- Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
- VMware fixes three critical flaws allowing auth bypass, VM escapes
INFLUENCERS
- Friday Squid Blogging: Squid Helps Discover New Marine Species
- Anthropic’s Opus 5 Is Better at Resisting Prompt Injection
- Facial Recognition at Madison Square Garden
- Read This Before You Buy That TV Streaming Stick
- American Being Prosecuted for Wiping His Phone Before Handing It Over to Border Officials
- Should You Use AI for a Task? Here’s a Simple Way to Decide
- A Field Guide to the AI Security Market
- Measuring the Tendency of AI Agents to Go Rogue
- Long-Lived Vulnerability in Microsoft Secure Boot
- Measuring LLMs’ Ability to Perform Cryptanalysis
- Axon Is Another License Plate Surveillance Company
- Cyber Company Profiles: Consistent AI Analysis of Security Vendors
- Cognyte Sells a Mobile Cell Surveillance Van
- Weekly Update 514: This Week in Data Breaches
- What 239 Products Reveal About the Shape of AI Security
MALWARE
- Malware shellcode delivery via signal - part 4. Embedding Bell 202 FSK into MP3 and recovering the symbol clock. Python and C example
- Mon General Hospital notifies patients of phishing attack and breach
- AU: GO2 Health medical clinic in Brisbane waited almost three months to alert patients it was hacked
- Suspected cyberattack disrupts Oceanside, California, school district systems
- CareCloud Data Breach Impacts Over 350,000
- The double extortion of a Russian ransomware threatens the medical records that Diater has kept for 10 years
- Sixth Circuit to Rehear Case on FCC Data Breach Rules Case
- System Announcement: Maintenance
- Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)
- Recent Project - Exploring APTNotes with LLMs
- Deadlock Ransomware Targets Thailand’s Tesco Engineer Co., Ltd
- CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
- 2026-07-31: Seven days of scans and probes and web traffic hitting my web server
- 2026-7-31: SmartApeSG ClickFix campaign pushes unidentified RAT
- Cyber industry coalition urges federal action after suspected Iran-linked water hacks
- Wordfence Bug Bounty Program Monthly Report – April 2026
- RESOURCE: Thomson Reuters Foundation provides free resources and legal help for independent media around the world
- Ransomware in Italy: RedACT report sheds light on an evolving threat environment
- Weaponizing Exposed Data
- Fake Fortnite rewards are stealing players’ accounts
ARTICLES
- Google has used AI to patch 1,072 vulnerabilities in Chrome
- Apple’s Tim Cook era ends with a record $109B quarter
- Reporter’s notebook: In Dubai’s sun and sand, AI, server farms, and optimism bloom
- Data center developer eyes disused newpaper printing plant
- DefCon security conference bans smart glasses with recording capabilities
- ChatGPT Ads offer a glimpse of how advertising could evolve
- The new C-suite calculus: how the CFO-CHRO alignment is shifting
- 12 top productivity tips for Microsoft Edge
- BCON Collective uncovers shared phishing infrastructure linked to ShinyHunters
- Microsoft doubles down on multi-model AI as it builds a Copilot super app
- Microsoft confirms an AI worm is propagating through Copilot and other MS apps
- Copilot worm can spread through Microsoft Word docs
- ‘Only people we’re friends with can see the posts’: exploring parental awareness of the systemic complexities and cybersecurity risks of sharing child-centric data on social media
- Qualcomm shows Apple’s modem transition is almost complete
- Experts react as Department for Education cyber attack exposes 607,000 records
- WorkNest Secure Launches Continuous Vulnerability Scanning with GuardNest
- Huntress Surpasses $250M ARR as EMEA Growth Outpaces Global Expansion More Than Five-Fold
- Check Point Brings AI Security into the Firewall with Industry-First AI Network Firewall
- Why Google Voice is your secret business weapon
- Fake Claude Install Guide Delivers Six-Stage macOS Stealer and RAT, Huntress Finds