- Nightmare Eclipse nie zwalnia. Kolejne exploity trafiają na GitHuba
- Irańscy hakerzy dostali rozkaz. Celem wrogowie reżimu
- CISA stawia na wszechstronnych ekspertów bezpieczeństwa infrastruktury krytycznej
- Program PIVOT zyskuje znaczenie w testach cyberbezpieczeństwa klasy enterprise
- Trzy grupy cyberzagrożeń atakują rosyjskie firmy: backdoory, ransomware i destrukcyjne wipery
- N0va phishkit atakuje firmy w USA i Europie, wykorzystując legalne procesy uwierzytelniania
- Luki zero-day w TP-Link Tapo C200: ryzyko podsłuchu i przejęcia kontroli nad kamerą
- Cyberoperacja przeciwko mediom i branży motoryzacyjnej w Korei Południowej. Atak na HAProxy ujawnia nowy kierunek działań APT
- Microsoft wydaje awaryjne poprawki po rekordowym Patch Tuesday i problemach z RDS oraz Hyper-V
- CISA i NIST publikują wytyczne dotyczące ochrony tokenów tożsamości w chmurze
- Chrome i Firefox łatają 115 podatności w nowych aktualizacjach przeglądarek
- Naruszenie danych w Premier Medical Group dotknęło ponad 280 tysięcy pacjentów
- Pierwszy zgłoszony wyciek danych z użyciem agentowego AI trafił do hiszpańskiego regulatora
- Aktywne próby wykorzystania krytycznej luki JWT w WSO2 API Manager. Administratorzy powinni działać natychmiast
- Radaris traci domeny po sporze o prywatność. Przełom w walce z brokerami danych
- CenterPoint Energy potwierdza naruszenie danych klientów po doniesieniach o wycieku 7,49 mln rekordów
- Wyciek danych Revolut może wynikać z przejęcia kont włoskiej administracji
- Przejęcie sesji asystenta AI i robak Shai-Hulud: kompromitacja około 100 repozytoriów
- Jedno rozszerzenie mogło przejąć asystentów AI w Chrome, Edge, Comet, Opera Neon i Claude
- BambooToken: malware wykorzystujący MQTT do ukrytej komunikacji C2
- CISA ostrzega przed aktywnie wykorzystywaną krytyczną luką w ConnectWise ScreenConnect
- Luka w Parallels Desktop pozwala lokalnie zdobyć uprawnienia root na macOS
- Krytyczne luki RCE w The Events Calendar zagrażają setkom tysięcy stron WordPress
- Krytyczna luka w WooCommerce Wholesale Lead Capture umożliwia wgrywanie web shelli PHP
- CVE-2026-87886: krytyczna luka we wtyczce Acronis Backup dla cPanel i WHM wykorzystywana w ukierunkowanych atakach
- Aktywne ataki na Issabel Framework. Krytyczna luka umożliwia zdalne wykonywanie poleceń
- Złośliwa aktualizacja Admin Menu Editor Pro otworzyła tylne furtki na co najmniej 1,5 tys. stron WordPress
- Google łata krytyczną lukę w modemie Pixel wykorzystywaną w ukierunkowanych atakach
- CISA dodaje krytyczną lukę Cisco Secure Email Gateway do katalogu KEV
- Chosen Brick: służby USA, Wielkiej Brytanii i Holandii ujawniają irańskie spyware wymierzone w dysydentów
- KREMLIN: malware bankowy przejmuje Chrome i Edge, kradnąc poświadczenia oraz tokeny sesyjne
- Narzędziownik AI 3.0 Revolutions. Zobacz, co przygotowaliśmy w nowej odsłonie kultowego szkolenia
- Poważna wpadka Revoluta: przekazał dane klientów oszustom. Poszkodowani mają być też Polacy
- Próba cyberataku na wodociągi w Lubelskiem. Celem panel administracyjny
- 760 mln zł z oszukańczych reklam? Tyle Meta mogła uzyskać w Polsce
- Schrony, cyberodporność, dual-use. Miliardy z KPO na bezpieczeństwo Polski
- UODO zmienia priorytety po cyberataku na MyDr
- Zhakowano Centralną Komisję Wyborczą Rosji. Skradziono dokumenty
- Dostałeś taki SMS z banku? To nowa sztuczka oszustów
- Podatności w routerach WNC T-Mobile 5G Box IDU
- Trzy na cztery z badanych uczelni bez dedykowanego zespołu cyberbezpieczeństwa. Jak chronić polską naukę?
- Poważna luka w oprogramowaniu Cisco. Konieczna aktualizacja
- CC4ES 2026: trzy dni o cyberbezpieczeństwie infrastruktury energetycznej
- Podrabiane leki za miliony. CBZC zatrzymało członków zorganizowanej grupy
- „Sterowanie dronem to jak używanie odkurzacza”. Rosyjski fejk uderza w ukraińskie kobiety
- Backdoor w większości tanich urządzeń Wi-Fi. Jak go odkryto?
- Nielegalne treści mają być blokowane. Prezeska Panoptykonu: „to dobry kompromis”
- Grupa APT28 po raz kolejny atakuje cele w Europie. Zamiast skomplikowanego malware i wyszukanych eksploitów stosują makra, przeglądarkę Edge i webhooki jako serwer C2
- Tylko 0,5% firm odzyskuje działanie zgodnie z celem po ataku ransomware
- Fałszywie zatrudnieni pracownicy uzyskują dostęp do systemów przed wykryciem
NEWS
- Anthropic wants Claude to analyze your bank account and financial data
- AI Security Spending Jumps as Fear Outpaces Proof of Value
- Windows 11 KB5124008 update breaks domain trust for some users
- Iranian hackers use CHOSEN BRICK Windows malware to spy on targets
- Malware bypasses browser checks to force install Chrome, Edge extensions
- Fighting Your Dragons Through Tough Tech Times
- Spain's data agency gets first report of AI-powered data breach
- BragJack Attack Can Turn a Browser's Agentic AI Against It
- Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
- Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
- One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude
- The true cost of a ransomware attack, with and without BCDR
- Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
- Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix
- Microsoft says Copilot buttons still missing in classic Outlook
- Webinar: What happens in the first hours of a Google Workspace breach
- N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
- Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
- Threat Intelligence Alone Won't Close the Exploitation Gap
- Critical ScreenConnect flaw now actively exploited in attacks
- Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
- Hackers Got Inside a Flock Camera. Its Data Shows How the System Really Works
- Securing the unpatchable in an age of AI-driven vulnerabilities
- Windows Server 2022 reaches end of mainstream support next month
- Google fixes actively exploited Android zero-day on Pixel devices
- Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
- Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
- Cyber Op Targets South Korean Media & Automotive Sectors
- Acronis warns of actively exploited flaw in its cPanel backup plugin
- Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
- Microsoft Issues Emergency Fixes After Massive Patch Tuesday
- Black Hat USA 2026 | The 'Breaking' News: The OpenAI–Hugging Face Incident
- KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
- VectraRAT Can Hack Windows Enterprises for $250 per Month
- CenterPoint Energy confirms customer data stolen in cyberattack
- Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
- BambooToken Malware Uses MQTT to Control Windows and Linux Systems
- BambooToken malware controls Windows and Linux systems via MQTT
- Hackers target WordPress sites via third-party WooCommerce plugin
- What Zero-Day Response Should Be in the Post-Mythos Era
INFLUENCERS
- Data Broker Radaris Loses Domains in Privacy Fight
- Fake CAPTCHA Scams
- 25 Years of Mass Surveillance Is Enough
- On the NSA’s Supercomputer from the 1960s
- Upcoming Speaking Engagements
- Using AI for Weapons Development
- Microsoft’s Patching
- Friday Squid Blogging: Rotting Squid on a Beached California Boat
- Weekly Update 521: Breach Perception v. Reality
- My Talk at DEF CON
- Cliff Stoll’s DEF CON Talk
- AIs Compress Exploit Timeline
TOOLS
- ipaforge
- terminalphone — Updated!
- netbox v4.7.1
- mini-diarium v0.7.3
- privacybadger v2026.9.15
- douglas-042-HQ
- easywall v2.20.1
- polaris v10.2.3
- codejail v4.1.1
- SindriKit v2.0.0
- wazuh v4.10.5
- dalfox v3.2.3
- sonar v0.9.1
- augustus v0.14.30
- Responsible-Alliance-Protocol
- whitelist-bypass
- ResetSpy
- limeyard
- Aresius
- XXStrike
MALWARE
- ISC Stormcast For Thursday, September 17th, 2026 https://isc.sans.edu/podcastdetail/10098, (Thu, Sep 17th)
- Canada: Nipigon hospital hit by ransomware attack
- Apple security advisory (AV26-930)
- ISC BIND security advisory (AV26-931)
- Oracle Corporation security advisory (AV26-929)
- Scans Targeting Hospitality Applications, (Wed, Sep 16th)
- HPE security advisory (AV26-928)
- AI agents are getting better at cybersecurity. That cuts both ways
- Data Broker Radaris Loses Domains in Privacy Fight
- [Control Systems] Phoenix Contact security advisory (AV26-927)
- Google security advisory (AV26-926)
- Approaching stealers devs: a brief interview with Remus
- Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH
- 일본인을 노린 악성코드 분석-仮送り状 9907344-FIN0002026.bz2
- What’s New in GravityZone September 2026 (v 6.77)
- CrowdStrike Accelerates Real-Time Data Classification with On-Device AI
- CVE-2026-27540 WooCommerce Flaw Exploited
- CVE-2026-76461: Cisco Email Gateway Flaw Exploited
- The OSINT Framework Every Agency Needs: A Four-Pillar Model for Law Enforcement and Intelligence Agencies
- Falso “Bonus Vacanze” dell’Agenzia delle Entrate ruba dati personali
ARTICLES
- Salesforce’s massive outage exposes the hidden risks of cloud dependencies
- LinkedIn fights for the right to tell customers when the feds want their data
- Big Tech’s AI safety rift signals disruption and disparity for enterprises
- Nextcloud adds desktop app for Euro-Office productivity suite
- AWS bets that AI agents need an inbox, not another chat window
- Cybersecurity Innovation Takes Centre Stage in International Cyber Expo Awards Shortlist
- Could blame culture be cybersecurity’s next Achilles heel?
- Apple just gave every iPhone photo a digital alibi
- Here’s why Microsoft supports open-source Chinese AI
- 5 efficiency-enhancing Chrome extensions worth trying on Android
- Oracle forecasts 33% increase in restructuring costs as new round of layoffs hits
- Tech layoffs: A 2026 timeline
- Apple to OpenAI: If you have nothing to hide, you have nothing to fear
- CFO on the Spot: Five minutes with Niall McCallum, CFO of LRQA
- Europe’s railways enter a platform battle
- Kura Appoints Acumen Cyber to Deliver 24/7 Cyber Defence
- CFO on the Spot: Five minutes with Philip Watson, CFO of Payscale
- Pacing the frontier: security industry reacts to AI slowdown and kill switch debate
- Tech CEOs used to fear their boards. No more
- Microsoft’s AI Code of Conduct aims to curb AI behavior