- Fałszywe transakcje M&A nowym narzędziem oszustw BEC wymierzonych w duże firmy
- Breeze Comet atakuje systemy finansowe i infrastrukturę płatniczą – nowy model cyberprzestępczości
- Atak „machine-speed”: agenci AI skrócili operację ransomware z dwóch tygodni do 10 godzin
- Wyciek danych nabywców biletów The Town 2025 trafił do dark webu
- CVE-2026-59827 w Metabase: uwierzytelnione RCE przez deserializację obiektów Java w H2
- CVE-2025-57819 w FreePBX: krytyczne RCE przez nieuwierzytelnione SQL Injection w Endpoint Manager
- Outsider wraca po przejęciu infrastruktury: phishing kit znów aktywny z setkami nowych stron
- Likwidacja botnetu Sality: międzynarodowa operacja uderza w wieloletnią infrastrukturę cyberprzestępczą
- OpenLeash: warstwa kontroli bezpieczeństwa dla ryzykownych działań agentów AI
- Cisco ostrzega przed lukami w Secure Email i łata krytyczne podatności w IOS XR oraz Nexus 9000
- FalconFlank ujawnia lokalną eskalację uprawnień w CrowdStrike Falcon Sensor
- Wyciek danych 8,8 mln osób po odmowie zapłaty okupu przez Manchester Airports Group
- 153 mln skanów praw jazdy w dark webie. Możliwy wyciek z platformy weryfikacji tożsamości
- CISA rozszerza katalog KEV o siedem aktywnie wykorzystywanych podatności
- Google, Anthropic i OpenAI rozwijają cyber AI: nowe modele, większe możliwości i ostrzejsze zabezpieczenia
- Pegasus na iPhone’ach działaczy w Serbii: zero-click przez iMessage ponownie alarmuje o zagrożeniu spyware
- Shai-Hulud skanuje już 469 lokalizacji poświadczeń. Rosnące ryzyko dla łańcucha dostaw oprogramowania
- USA głównym celem globalnej kampanii phishingowej z użyciem narzędzi RMM
- Atakujący wykorzystują Node.js do dostarczania malware i omijania klasycznych mechanizmów detekcji
- BraZetsu: malware, które zamienia przejęte systemy Windows w produkt na cyberprzestępczym rynku
- Krytyczna luka w Cisco Nexus 9000 pozwala na zdalne przejęcie urządzeń bez uwierzytelnienia
- Krytyczna luka w All-in-One WP Migration naraża miliony stron WordPress na zdalne przejęcie
- CVE-2026-9586 w Sangoma Switchvox aktywnie wykorzystywana do przejmowania systemów VoIP
- Naruszenie bezpieczeństwa C-Track od Thomson Reuters mogło ujawnić numery SSN i dane z akt sądowych
- HPE usuwa krytyczną lukę RCE w ArubaOS-CX. Zagrożone przełączniki enterprise
- Kompromitacja rejestru Coder umożliwiła dystrybucję złośliwych modułów Terraform
- Krytyczna luka w Elementor Pro pozwala przejąć witryny WordPress
- Francuski szpital ukarany 500 tys. euro po wycieku danych 727 tys. osób
- Plex wzywa do natychmiastowej aktualizacji. Krytyczne poprawki bezpieczeństwa dla Plex Media Server i Plex Desktop
- Hasło pracownika w logu infostealera: jak ocenić ryzyko i skutecznie zareagować
- Awarie ChataGPT i Claude'a. Problemy z popularnymi usługami AI
- O wycieku z MyDr w Sejmie. „Dane nie zostały opublikowane”
- Organ nadzoru AI coraz bliżej. Sejm zmieni swój regulamin
- Świat nauki wspiera machinę wojenną Rosji. Ukraiński wywiad ujawnia listę nazwisk
- Podatność w oprogramowaniu OptimiDoc Server (On-Premise)
- Zełenski wypowiada wojnę fałszywym call center
- Ustawy o blokowaniu treści w Internecie z dwiema zmianami
- Służby rozbiły potężny botnet. Cyberprzestępcy wykorzystywali go ponad 20 lat
- Klientka banku straciła niemal 200 tys zł. Ostrzegamy przed nowym oszustwem
- TerminalFix – nowa odmiana ClickFix prowadzi do wieloetapowego ataku na systemy Windows
- ABW podzieliło się danymi. Liczba tych ataków w Polsce gwałtownie wzrosła
- Nutex Health potwierdza kradzież danych pacjentów i groźbę publikacji wycieku
- FulcrumSec przyznaje się do naruszenia Manchester Airports Group. Możliwy wyciek danych klientów
- Incydenty bezpieczeństwa w METR ujawniają ryzyko kradzieży poświadczeń w środowiskach AI
- Silniejsze zabezpieczenia wypychają grupy ransomware w stronę rekrutacji insiderów
- Mirage Kitten atakuje programistów przez fałszywe testy rekrutacyjne. NodeRabbit i PollCat rozszerzają arsenał APT
- Niezałatane luki otworzyły drogę do naruszenia filipińskiej agencji jądrowej
- Kampania Spring Ring atakuje użytkowników Microsoft Teams. Vishing otwiera drogę do przejęcia środowisk firmowych
- Wzrost liczby podatności wykrywanych przez AI może być łatwiejszy do opanowania, niż obawiała się branża
- AI skraca czas ataku i daje cyberprzestępcom nową przewagę
NEWS
- French hospital fined €500,000 after breach exposes data of 727,000
- Nobody Is Saying Why OpenAI and Anthropic Had Outages Today
- Prediction Market Betting Is Getting People Banned and Arrested
- Large Enterprises Targeted in Fake Merger & Acquisition Scams
- Coder's registry infrastructure compromised to push malicious modules
- What We Missed: Did ShinyHunters 'Breach' ReliaQuest?
- HPE patches critical ArubaOS-CX remote code execution flaw
- ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories
- The story behind the intelligence
- Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
- BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
- Microsoft: KB5120998 mouse reset bug affects only non-English PCs
- OpenAI confirms ChatGPT is down ahead of 'Astra' model launch
- Anthropic confirms Claude is down, multiple models affected
- Critical Elementor Pro flaw exploited to take over WordPress sites
- Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
- AI 'Machine Speed' Cuts 2-Week Attack Down to 10 Hours
- Your Employee’s Password Appeared in an Infostealer Log. Now What?
- Microsoft says KB5120998 Windows update resets desktop settings
- 'Breeze Comet' Tears Into Brazilian & Global Financial Systems
- US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries
- Plex warns users to patch security vulnerabilities immediately
- Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
- Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means
- This Is Flock’s AI Search Tool for Cops
- Microsoft Teams, Outlook fail to launch on ARM-based Windows PCs
- Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone
- Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
- CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
- AI’s Vulnerability Surge May Be More Manageable Than First Feared
- Hackers exploit Sangoma Switchvox flaw to deploy reverse shells
- SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE
- AI Gives Cybercriminals a Dangerous Time Advantage
- WordPress backup plugin flaw exposes millions of sites to takeover attacks
- Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs
- Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users
- Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
- Hackers exploit critical JFrog Artifactory flaw to forge admin tokens
- Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
- Ransomware protection for MSPs: A 6-point checklist for faster recovery
INFLUENCERS
- Researching Employment Scams
- AI Agents Are Now Emailing Me with Their Security Concerns
- Wireless Routers as Motion Detectors
- FBI Probes Service Selling 153M+ Drivers Licenses
- Weekly Update 519: Breaches & Data Integrity
- What’s the Scam?
- Leaked Russian Cyber-Operations Training Materials
- Rewiring Democracy Series on The Renovator
- Is Someone Hacking DoD Refrigerators?
- Hiding Prompt Injection in Legal Filing
- Friday Squid Blogging: Truckload of Squid Spills in Rhode Island
- AI Doesn’t Mean the End of Mathematics—at Least Not Yet
TOOLS
- amavis v2.15.0
- sonar v0.4.1
- fence v0.1.67
- bramble v1.24.0-chromium
- skill-scanner v2.0.14
- MasterHttpRelayVPN-RUST v1.9.37
- agent-vault v0.39.3
- SDK
- codex-security npm-v0.1.25
- pentest-ai v1.4.0
- jsc_deobfuscator
- javascript-obfuscator
- View8
- Windows-Kernel-Exploitation
- root-s24-e1s
- pocindex
- lure v0.7.1
- Rocket.Chat v8.8.0
- burpFakeIP
- honeypot-auditor
EXPLOITS
- [webapps] Metabase 0.61.0 - Authenticated Remote Code Execution
- [webapps] FreePBX 17.0.2 - Remote Code Execution (RCE)
- [hardware] Fullhan FH8626V100 - Multiple Vulnerabilities
- [webapps] Langflow 1.10.0 - RCE
- [webapps] Ghost_CMS 6.19.0 - Remote Code Execution
- [webapps] PodcastGenerator 3.2.9 - Stored XSS
- [webapps] Marimo 0.20.4 - RCE
- [webapps] Bludit CMS 3.20.0 - Reflected Cross-Site Scripting
- [dos] EVerest 2025.9.0 - DoS
- [webapps] Payload CMS 3.72.0 - Blind SQL Injection
- [webapps] miniOrange 5.4.3 - Unauthenticated Auth Bypass
- [webapps] Grav CMS 2.0.7 - RCE
- [webapps] Bludit CMS - Stored XSS
- [webapps] Wolf CMS 0.8.3.1 - RCE v
- [webapps] EasyAppointments 1.5.1 - Blind SQL Injection
- [webapps] Langflow 1.8.4 - Path Traversal to Remote Code Execution
- [webapps] Linksys E1200_2.0.04 - Unauthenticated OS Command Injection
- [webapps] CubeCart 6.7.4 - Cross-Site Scripting
- [webapps] CubeCart 6.7.4 - Stored XSS
- [webapps] CubeCart 6.7.4 - SQL
MALWARE
- Kim Sooki again? This time, it was disguised as a request for seafood ingredients
- Attack Cases in Korea Involving the Installation of Radmin and UltraVNC
- ISC Stormcast For Friday, September 4th, 2026 https://isc.sans.edu/podcastdetail/10082, (Fri, Sep 4th)
- Storm Ransomware Targets SITES Medical
- Settra Ransomware Strikes Dutch Firm Buroboot
- Panzer Ransomware Hits Dinas Komunikasi dan Informatika
- Vexy Ransomware Strikes Brazilian Adhesive Producer Engefitas
- Storm Ransomware Targets Petrocare Construction
- Storm Ransomware Targets Star Aviation, Inc
- Storm Ransomware Strikes GSAC Auto Financing
- Settra Ransomware Attack Targets Hansler Smith Limited
- Settra Ransomware Strikes Teletek Structures Inc
- Settra Ransomware Attack on MedEvolve
- Settra Ransomware Attack on DiaSorin S.p.A
- Qilin Ransomware Targets Complete Packaging Solutions
- CNIL: Health data breach: €500,000 fine imposed on the Loire Private Hospital
- Two “Nephrology Associates” suffered cyberattacks. Only one of them has disclosed it
- The New School Safety Perimeter: Where Cybersecurity Meets Physical Security
- Microsoft Exchange Vulnerability CVE-2026-62911: What Administrators Should Do and How Zscaler Can Help
- SUSE Linux security advisory (AV26-882)
ARTICLES
- ChatGPT, Claude, and Grok all went down at once; enterprises need a backup plan
- Word and Outlook will stop trying to guess what you’re going to type
- Serious vulnerability threatens tens of thousands of Exchange servers
- Banking on AI resilience
- Why is Apple so quiet about what it offers the enterprise?
- Adobe’s Slack integration brings AI content creation to workplace chats
- Hijacked ScreenConnect Installs Are Spreading Malware Like a Worm, Huntress Warns
- A look inside Apple’s relationships with Intel and TSMC
- KnowBe4 Names Kurt Mills as Channel Chief to Lead Next Phase of Partner-Led Growth
- New ‘Knight Office’ Phishing Kit Steals Microsoft 365 Logins Without Touching a Password
- Black Duck brings AI-powered vulnerability scanning into Claude with new Signal integration
- Fake Software Update Installs a Real Crypto Wallet – Rigged So It Can Never Open
- Hackers Abuse Legitimate IT Management Tool to Sneak Into Business Networks
- The ultimate Chrome keyboard shortcut upgrade
- Anthropic makes changes to stop AI agents running amok again
- Citrix buys company that containerizes Windows desktop apps independently of the OS
- Older workers are more bullish on AI than younger ones
- Forescout Research Tests Whether AI Can Create PLC Attacks
- The Hunt-to-Detection Gap: Choosing an AI Threat Hunting Solution in 2026
- Filigran Adds AI-Powered Attack Chaining to OpenAEV for Autonomous Pentesting