- Żabka zhakowana. Poważny incydent: wyciekły dane
- Atak hakerski na sieć polskich placówek zdrowotnych. Wydano komunikat
- Krzywda za ekranem. Dlaczego przemoc w sieci jest tak samo groźna?
- Groźny atak na szyfrowany komunikator Gajim przez lukę w KDE Plasma
- Myśleli, że ratują ukochane. Wpadli w pułapkę rosyjskich służb
- Co świadczy o odporności algorytmu Argon2 na ataki z wykorzystaniem GPU? Analiza standardu
- Złośliwe rozszerzenie do Chrome wykrada prompty z ChatGPT, Claude, Copilota i wielu innych serwisów AI
- Platforma HackerOne wprowadza obowiązkową weryfikację tożsamości w programach Bug Bounty
- 270 mln zł na cyberbezpieczeństwo samorządów. Jak zbudować LCC?
- „Potwierdź, że nie jesteś robotem”. Uwaga na fałszywe CAPTCHA
- Fala przejęć kont na WhatsAppie. Znane polskie nazwiska wśród ofiar
- Dlaczego LDAP ma ponad 30 lat, a nadal nie odchodzi na emeryturę?
- Luka w generatorze losowości Coldcard mogła ułatwić kradzież Bitcoinów
- CISA ostrzega wodociągi: odłączcie sterowniki PLC od Internetu po atakach w Minnesocie
- Chrome może domyślnie blokować rozszerzenia przejmujące kartę „Nowa karta”
- Naruszenie danych w CareCloud ujawnia informacje medyczne i finansowe 345 tys. osób
- Jesteśmy zgubieni? Czyli o porażce Alertu RCB i polskiego systemu ostrzegania ludności
- Dezinformacja dla maszyn. Kto zaprogramuje odpowiedź, ten zdefiniuje rzeczywistość
- Domowy przegląd smartfona. Co wyczyścić, usunąć i sprawdzić
- OctLurk i SilkLurk uderzają w rządy Azji Centralnej. Nowa kampania cyberszpiegowska budzi obawy
- DeepSeek i Hermes Agent automatyzują ataki na podatne serwery
- Przejęte hotelowe Wi‑Fi rozsyła fałszywe aktualizacje i malware szpiegowskie
- CISA aktualizuje wytyczne SBOM: więcej danych, większa przejrzystość i nadal pytania o realną redukcję ryzyka
- Korea Południowa ostrzega przed państwowo wspieranymi atakami watering hole
- Krytyczna wada Coldcard powiązana z kradzieżą 70 mln USD w bitcoinie
- Arch Linux czasowo wyłącza adopcję pakietów AUR po fali złośliwych przejęć
- Naruszenie danych w chmurze u Amgen: wyciek informacji medycznych pacjentów i danych proprietary
- Krytyczna luka w Ruby on Rails Active Storage może prowadzić do odczytu plików i zdalnego wykonania kodu
- Krytyczna luka CVSS 10.0 w Adobe Campaign Classic. Możliwe zdalne wykonanie kodu bez interakcji użytkownika
- Zatruty skrypt Adform podmieniał adresy portfeli kryptowalut na stronach klientów
- KSC bez Lokalnych Centrów Cyberbezpieczeństwa będzie „papierkiem” [OPINIA]
- Wybory 2027 na celowniku rosyjskiej dezinformacji. Oto jak ją zatrzymać [OPINIA]
- INTERPOL i I-GRIP przyspieszają blokowanie przelewów BEC. 6,6 mln USD zatrzymane w globalnej operacji
- CISA aktualizuje wytyczne SBOM: więcej metadanych, ale nadal bez przełomu w zarządzaniu ryzykiem
- Cyberprzestępcy wykorzystują autonomiczne ofensywne agenty AI do skalowania ataków
- SilverFox uderza w japońskiego producenta: ValleyRAT, DLL sideloading i sterowniki jądra w jednej kampanii
- Podszywanie się pod marki jako wektor initial access – dlaczego to zagrożenie rośnie
- Naruszenie danych w CareCloud dotknęło ponad 350 tysięcy osób
- Krytyczna luka CosmosEscape w Azure Cosmos DB mogła zagrozić danym klientów na masową skalę
- Flying Eagle: cyberprzestępczy ekosystem wokół fałszywej aplikacji policyjnej na Androida
- Ataki watering hole w Korei Południowej: państwowa kampania wymierzona w obywateli i firmy
- Device code phishing w 2026 roku rośnie w siłę. Jak atakujący nadużywają legalnych przepływów OAuth
- VMware łata krytyczne luki: obejście uwierzytelniania w vCenter i ucieczka z maszyny wirtualnej
- Krytyczna luka RCE w TeamCity: CVE-2026-63077 zagraża serwerom CI/CD
- Kampania malvertising na macOS wykorzystuje fałszywe aktualizacje do kradzieży kryptowalut
- 84 luki w rdzeniach 4G i 5G: nowe podatności umożliwiają DoS i przejęcie sesji
- Google wykorzystuje AI do wykrywania luk w Chrome. Ujawniono 13-letnią podatność typu sandbox escape
- Chrome usuwa 1442 podatności w trzech wydaniach. Nowa faza bezpieczeństwa przeglądarek
- HollowFrame i Matryoshka: wieloetapowy spear-phishing uderza w kancelarie prawne
- Tanie Android TV boxy podszywają się pod smartfony i zamieniają domowe łącza w sieć proxy
NEWS
- Fake Roblox Xeno script launcher pushes infostealer, RAT malware
- 18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
- N-able warns of N-central auth bypass flaw exploited in attacks
- Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
- INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
- [Webinar] Tales from the Frontlines: An exclusive briefing on Q2 incidents
- Chinese Actor Weaponizes DeepSeek AI Agent to Attack Security Firm
- ExfilSquad hackers leak info of over 100,000 UK police officers, staff
- Inside the Underground Business of BTMOB RAT
- ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
- Is There Really a Fix for CISO Fatigue?
- FOMO in the SOC: Where AI Platforms like Claude Actually Fit
- Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
- ICE Collected Nearly 1 Million People’s DNA Last Year—Including Young Children
- PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web
- Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable
- A week in security (July 27 – August 2)
- N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
- Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
- OpenAI teases Astra, its next major AI model, after it solves 10 long-standing math problems
- COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft
- Google Chrome may soon block New Tab hijacker extensions by default
- 8 Best Password Managers (2026), Tested and Reviewed
- Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
- Rails patches critical Active Storage flaw with RCE potential
- 7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran
- Nobody Knows if OpenAI’s and Anthropic’s AI Hacking Sprees Are Illegal
- Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
- Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
- Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
- Amgen says cloud data breach exposed patient health, proprietary info
- Arch Linux disables AUR package adoption to stop malware flood
- Online ad firm Adform’s script compromised to steal cryptocurrency
- OpenAI says its new GPT 5.6 models are becoming more cost-efficient
- Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
- CISA Issues Fresh SBOM Guidance. Did They Get It Right?
- Hacker uses DeepSeek AI to autonomously attack vulnerable servers
- CISA warns of cyberattacks disrupting U.S. water utilities
- HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
- Fake Fortnite rewards are stealing players’ accounts
INFLUENCERS
- More on the OpenAI Agent’s Attack on Hugging Face
- The OpenAI Hack Shows the Genie Is Out of the Bottle
- Welcoming the Nepalese Government to Have I Been Pwned
- Weekly Update 515
- Five Questions to Answer Before Buying an AI Security Product
- Friday Squid Blogging: Squid Helps Discover New Marine Species
- Anthropic’s Opus 5 Is Better at Resisting Prompt Injection
- Facial Recognition at Madison Square Garden
- Read This Before You Buy That TV Streaming Stick
- American Being Prosecuted for Wiping His Phone Before Handing It Over to Border Officials
- Should You Use AI for a Task? Here’s a Simple Way to Decide
- A Field Guide to the AI Security Market
- Measuring the Tendency of AI Agents to Go Rogue
- Long-Lived Vulnerability in Microsoft Secure Boot
- Measuring LLMs’ Ability to Perform Cryptanalysis
- Axon Is Another License Plate Surveillance Company
- Cyber Company Profiles: Consistent AI Analysis of Security Vendors
MALWARE
- Targeted Attack on Government Entities in the Middle East | Part 2
- Cyber Conflict Briefing Q2 2026
- Amgen Breach: What Our January Warning Tells Defenders
- [Webinar] Tales from the Frontlines: An exclusive briefing on Q2 incidents
- LLMjacking is a New Cyber Threat
- 3rd August – Threat Intelligence Report
- Lawmakers propose giving 2015 OPM breach victims identity protection for life
- Cyberattack hits Liechtenstein, with 31,000 records stolen
- UK: Details of 100,000 police staff leaked on the dark web after hack
- Arctic Wolf Launches Comprehensive Cyber Resilience Offering to Help Organizations with Enhanced Coverage for Cybersecurity Incidents
- Arctic Wolf’s Aurora Agentic SOC Sets a New Standard for Scale, Value, Trust, and Speed in the Age of AI
- Phishing a tema SPID in corso
- You Can’t Buy Your Way Out of Downtime
- Scale, Trust, and Value: How the Aurora Agentic SOC Delivers for Customers
- What Is the DPDP Act 2025? Key Rules, Compliance Requirements, and Business Impact
- What Is a Phishing Link? How to Spot, Check, and Recover From One
- Analysis of a Phishing Email Attack Case by the Larva-24009 Threat Actor
- Octagon: Technical Analysis of a Fake Bahrain Civil Defense Application
- CrowdStrike 2026 Threat Hunting Report: Exploitation Window Closes as AI Use Accelerates
- Minnesota Water Systems Attacks: Internet-Exposed PLCs Under Attack
ARTICLES
- Anthropic’s AI models accidentally hacked three companies
- Sourcing smarter, not harder: meet the AI agent built to transform sourcing
- Check Point Named a Visionary Leader in 2026 Frost Radar for Enterprise Risk Mitigation and Management Platforms
- Huntress Makes RMM-Blocking Feature Free for All Customers as Attacks Surge 277%
- AI pentesting tools are generating more findings than security teams can validate, new survey finds
- Apple and the invisible wolf: AI slop drowns real security threats
- Alibaba takes aim at OpenAI and Anthropic with Qwen3.8-Max launch
- Greg Soros Shares How Podcasters Build Lasting Authority Through Thought Leadership
- How AI is killing smartphone apps in China
- Critical N-able N-central Vulnerability Under Active Exploitation as Hotfix Lands
- Google has used AI to patch 1,072 vulnerabilities in Chrome
- Apple’s Tim Cook era ends with a record $109B quarter
- Reporter’s notebook: In Dubai’s sun and sand, AI, server farms, and optimism bloom
- Data center developer eyes disused newpaper printing plant
- DefCon security conference bans smart glasses with recording capabilities
- ChatGPT Ads offer a glimpse of how advertising could evolve
- The new C-suite calculus: how the CFO-CHRO alignment is shifting
- 12 top productivity tips for Microsoft Edge
- BCON Collective uncovers shared phishing infrastructure linked to ShinyHunters
- Microsoft doubles down on multi-model AI as it builds a Copilot super app