Defence24.pl…
- W związku z dzisiejszym uderzeniem rosyjskiego pocisku w miejscowości Tarnawa-Kolonia premier Donald Tusk zwołał posiedzenie sztabu kryzysowego. Szef rządu przekazał szczegóły działań organów i służb państwa podczas ostatniej nocy.
- W nocy z 29 na 30 lipca doszło do naruszenia przestrzeni powietrznej Polski przez rosyjski statek powietrzny, najprawdopodobniej rakietę manewrującą Ch-101. Pocisk upadł w rejonie około 85 km od polskiej granicy, pokonując ponad 100 km. Dlaczego nie został zestrzelony?
- Polska otrzymała od Ukrainy konkretną propozycję dotyczącą wymiany myśliwców MiG-29 na bezzałogowe systemy powietrzne. Jak poinformowała wiceminister obrony narodowej Magdalena Sobkowiak-Czarnecka, Kijów przedstawił już ofertę określającą, jakie typy dronów mogłyby zostać przekazane w zamian za polskie samoloty. Ostateczna decyzja w tej sprawie ma zapaść w ciągu najbliższych kilku tygodni.
- Pomimo faktu, że Laos należy do najbiedniejszych gospodarek regionu Azji Południowo-Wschodniej i państw Półwyspu Indochińskiego, pełni on istotną rolę w chińskiej geopolityce, będąc jednym z elementów wielkiego chińskiego projektu gospodarczo-politycznego znanego pod nazwą Inicjatywy Pasa i Szlaku. Laos to dobry przykład, jak Chiny budują wpływy gospodarcze. Analiza prof. dr hab. Piotra Ostaszewskiego, SGH, Ambasadora RP […]
- Podczas spotkania sztabu kryzysowego dokładną sekwencję wydarzeń oraz powziętych działań przedstawił Dowódca Operacyjny Rodzajów Sił Zbrojnych gen. dyw. Ireneusz Nowak.
- Michał Stela, Dominik Mikołajczyk i Mariusz Marszałkowski rozmawiają o incydencie, który miał miejsce dzisiejszego ranka w województwie lubelskim. Co spadło na terytorium Polski i jak zareagowało wojsko i służby? Zapraszamy do obejrzenia odcinka specjalnego.
- Firma Leonardo rozszerzyła i rozszerza swoja ofertę europejskich samolotów bojowych. Pierwszych klientów zdobył ubojowiony Master, trwa produkcja kolejnych wersji Eurofightera. Coraz bliżej jest także międzynarodowy samolot przyszłości GCAP. O tym rozwoju i możliwościach dla Polski z Tommaso Panim, Senior Vice President, Marketing & Sales, Leonardo Aeronautics Division, rozmawia Antoni Walkowski.
- Centrum Szkolenia Personelu Bezzałogowych Statków Powietrznych Lotniczej Akademii Wojskowej (LAW) uzyskało akredytację GRUPY WB. Uzyskanie certyfikatu oznacza, że dębliński ośrodek spełnia standardy producenta systemów bezzałogowych i ma kompetencje do prowadzenia specjalistycznych szkoleń.
- Armia USA przyznała koncernowi Lockheed Martin kontrakt wart do 58,6 mld USD na pociski Patriot – przekazał w środę Pentagon. Celem jest uzupełnienie zapasów, uszczuplonych przez konflikty w Ukrainie i Iranie – podała agencja Reutera.
- W nocy z 29 na 30 lipca, podczas zmasowanego rosyjskiego ataku rakietowego i dronowego na Ukrainę, doszło do naruszenia polskiej przestrzeni powietrznej przez niezidentyfikowany obiekt. Jak poinformowało Dowództwo Operacyjne Rodzajów Sił Zbrojnych, obiekt pojawił się nad terytorium Polski około godziny 3:40 i pozostawał w przestrzeni powietrznej przez około sześć minut, po czym zniknął z radarów.
- W najbliższych tygodniach Iran ma otrzymać pierwszą partię spośród 400 chińskich przenośnych przeciwlotniczych zestawów rakietowych – przekazała w środę agencja Reutera. Uzbrojenia tego używa się do niszczenia samolotów, śmigłowców i dronów, poruszających się na małej wysokości. Transakcja warta jest 60-70 mln dolarów.
- Prezydent Ukrainy Wołodymyr Zełenski zwrócił się do prezydenta USA Donalda Trumpa z prośbą o przekazanie Ukrainie specjalnego „zimowego pakietu” pocisków przechwytujących do systemów obrony powietrznej Patriot. Celem jest wzmocnienie ochrony infrastruktury energetycznej przed spodziewanymi rosyjskimi atakami w okresie jesienno-zimowym.
- Ukraińskie Siły Powietrzne poinformowały o utracie kontaktu z myśliwcem F-16 podczas wykonywania misji bojowej na jednym z odcinków frontu. Pilot zdołał bezpiecznie się katapultować i przeżył incydent. Trwa wyjaśnianie przyczyn zdarzenia.
- Co najmniej sześć osób zginęło, a około 30 zostało rannych w rosyjskich atakach rakietowych na Lwów i okolice Krzywego Rogu – podały w czwartek ukraińskie władze. Wśród ofiar są dzieci. We Lwowie trwa akcja ratunkowa, ponieważ pod gruzami mogą znajdować się ludzie.
- Codzienny przegląd mediów sektora bezpieczeństwa i obronności.
- Około godz. 3.40 w polskiej przestrzeni powietrznej wykryto niezidentyfikowany obiekt. W rejon skierowano myśliwiec F-16, jednak obiekt zanikł, a jego prawdopodobne miejsce upadku wskazano na terenie niezabudowanym w pobliżu miejscowości Tarnawa-Kolonia.
- Sojusz Północnoatlantycki przeprowadził ćwiczenia, które miały na celu sprawdzenie przerzutu wojsk i sprzętu z Niemiec na Litwę. Ważnym punktem manewrów była Polska, a szczególnie Przesmyk Suwalski.
- W odpowiedzi na stałą presję ze strony Chińskiej Republiki Ludowej, Tajwan kontynuuje dynamiczną modernizację i rozbudowę własnego potencjału obronnego, stawiając na suwerenność technologiczną. W ramach programu „Iron Cavalry Project” tamtejsze siły zbrojne otrzymają niebawem nowoczesne wozy rozpoznawcze.
- Czy włoski czołg średni/lekki, bazujący na lokalnej odmianie bojowego wozu piechoty KF41 Lynx, otrzyma mocniejsze uzbrojenie główne?
- Istnieje ryzyko, że Białoruś ponownie uruchomi przekaźniki znajdujące się w pobliżu granicy z Ukrainą i używane do kierowania rosyjskimi dronami; zwiększyłoby to zagrożenie dla Lwowa i zachodniej części naszego kraju – powiedział doradca prezydenta Ukrainy Serhij Bezkrestnow, cytowany przez ukraińską agencję Unian.
TVN wiadomości…
Błąd RSS: Retrieved unsupported status code "403"
Wyborcza Kraj…
Wystąpił błąd, co prawdopodobnie oznacza, że kanał nie działa. Spróbuj ponownie później.
Wyborcza Świat…
Wystąpił błąd, co prawdopodobnie oznacza, że kanał nie działa. Spróbuj ponownie później.
The Hacker News…
- The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors. The activity, which began on July 22, 2026, involves […]
- The Federal Communications Commission (FCC) added foreign-produced mobile robots and networked power inverters to its Covered List on July 28. The move generally prevents new models from receiving the equipment authorization required for import, marketing, or sale in the US. Previously authorized models can still be sold, and devices people already own are unaffected. Federal […]
- Amazon has tied the September 2025 hijack of the npm packages debug and chalk to North Korea. For ten months, the incident sat in the public record as crypto theft: a maintainer phished through a lookalike npm domain and a wallet-draining script pushed into at least 18 packages carrying more than 2 billion weekly downloads […]
- The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation. The vulnerability, assigned CVE-2026-20316 (CVSS score: 5.3), could permit an unauthenticated, remote attacker to log
- Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials,
- Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3. It has been codenamed RufRoot by Noma Security's
- Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity. The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), which has been described as an authentication bypass in VMware vCenter. "A malicious actor with network […]
- A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response. Braham, Plymouth, South St. Paul and Maple Plain have publicly described a plant outage, communications failures or affected automated controls. Braham's water plant went offline, and the city asked residents to […]
- Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years. According to Russian cybersecurity vendor F6, the threat actors have set up clone websites of Russian companies across fertilizer manufacturers, petrochemical companies
- AI is compressing exploit timelines. The real question isn't whether your vulnerability management playbook needs to change, it's which part of it you've been getting wrong all along. The conversation happening in security circles right now goes something like this: Mythos is here. Exploit timelines are collapsing. Does the vulnerability management playbook need to change? […]
- Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process. Mozilla rated it High and fixed it in the Firefox 151.0.3 update. "No settings or additional […]
- Most organizations have incident response plans, security tools, and technical teams in place. Yet new research suggests that many still lack the coordination, visibility, and executive alignment needed to withstand a serious cyberattack. According to The State of Incident Response Readiness 2026, based on a survey of 600 senior IT security decision makers conducted by […]
- The Federal Security Service of the Russian Federation (FSB) on Wednesday said it charged Telegram founder Pavel Durov for allegedly facilitating terrorist activities and for failing to remove prohibited information in violation of Russian law. The principal security agency said the instant messaging platform "failed to remove numerous channels, chats, and bots on the platform […]
- Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass in the SmartConsole login process that
- OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face's production environment also hacked multiple third-party accounts and services as part of the attack. The latest disclosure shows that the security incident, which stemmed from an internal security test, was more extensive in scope […]
- Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account. Tracked as CVE-2026-60004 (CVSS score: 9.8), the flaw affects Gitea versions 1.17 and later before 1.27.1 […]
- Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent researcher NetAskari traced matching control panels and certificates to 170 internet servers. They linked the framework to a fake "公安一网通办" Public Security service application targeting Android users in China. The kit supports payment-password
- Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family. The list of affected packages is as follows – @joyfill/[email protected] @joyfill/[email protected] The two packages "contain an import-time JavaScript implant that resolves encrypted code
- Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128. The HAWK attack exploits a previously unused symmetry in the lattice behind the signature scheme. Anthropic's released implementation gives an expected end-to-end runtime of about three hours and 42 minutes […]
- A new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its main process. If that happens, Tengu's other persistence mechanisms get another chance to relaunch it. Nozomi Networks Labs observed the dropper reaching its honeypots through Telnet credential brute force. Tengu supports 25 distributed […]
SANS Internet Storm Center…
- (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
- [This is a Guest Diary by Adam Cann, an ISC intern as part of the SANS.edu BACS program]
- I am a bit late with this summary, but this week Apple released updates to all its operating systems and Safari. The Safari update, as usual, targets macOS prior to macOS 26. macOS updates covered the two older versions (14 and 15), while other operating system patches only covered the current 26 versions.
- (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
- For a long time, AutoIT[1] has been pretty common in the malware ecosystem. Threat actors still use it because it's easy to write and powerful. Indeed, it can perform all the required actions to inject a payload into a remote process as you'll see below.
- ISC Stormcast For Tuesday, July 28th, 2026 https://isc.sans.edu/podcastdetail/10026, (Tue, Jul 28th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
- Spring Boot exposes the endpoint "/actuator/heapdump" to collect debug information. By default, the endpoint will return a file heapdump.hprof, which includes a binary heapdump that can be used to analyze the current state of the application. Non-Java readers may be familiar with a similar concept, core dumps, which are produced by binaries to expose a […]
- (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
- ESAFENET's CDG showed up in our data before. The company focused on secure document management and data leakage prevention solutions. The "CDG" stands for "Content Data Guard", and the product appears to be mostly targeting the Chinese market [1]. Sadly, like so many security products, it suffers from basic security vulnerabilities like SQL Injection, XSS, […]
- (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Cybersecurity Avast…
- A call saying someone you love has been arrested and needs money ASAP can feel so real that you act before you think. Learn how bail bond scams work and what to watch for to help protect you and your family from falling for the scheme.
- Latest news We launched a new Avast One experience in 2026. Discover what’s new, see how it compares to the previous version, and learn how it makes your digital life simpler and more secure. In the ever-evolving landscape of the digital world, safeguarding your online presence has become more a necessity than a choice. […]
- If you've ever mentioned something in passing and then seen an ad for it shortly after, you're not imagining things. Learn how ads can sometimes follow you from real life to your screen, and how secure browsers with built-in ad blockers can help you take back control of what you see online.
- Spring break scams are out to ruin your vacation, but they don't have to. With a little awareness and Avast Free Antivirus protecting your devices, you can hit the beach without handing criminals an opening.
- You just sold a stack of old books for $100 on Facebook Marketplace. The buyer seemed eager, messaged instantly, and offered to pay extra. Sounds too good to be true? It probably is. Learn how to spot fake buyers before you lose both your money and your stuff.
- Scammers are using deepfake technology to replicate your child's voice in a kidnapping hoax, catfish with AI-generated video dates, and impersonate executives to steal millions. Learn how to spot deepfake fraud, and use Avast Deepfake Guard to help verify what's real before it's too late.
- Adoption fraud can blindside even the most prepared families, especially when emotions run high. Understanding common adoption scams and how to stay safe can help you move forward with more peace of mind.
- Facebook may feel like a safe place to connect, but scammers are increasingly using its ads, posts, and messages to deceive users. Here’s how cybercriminals are turning your feed into a gateway for fraud and what you can do to stay protected.
- If someone is blackmailing you with private photos or threats, do not pay. We know it's scary, but you don't need to comply. Learn how to handle sextortion threats, and discover how Avast can help secure your privacy.
- How a simple “I found your photo” message can quietly take over your account
Cybersecurity Kaspersky…
Błąd RSS: WP HTTP Error: cURL error 52: Empty reply from server
We Live Security…
- ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities
- A view of the H1 2026 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts.
- AI is changing cybercrime, but SMB cyber readiness still largely depends on closing the familiar gaps
- Three-day patching deadlines, exposed fuel-tank systems, scams costing billions of dollars, and social media bans for children all gave Tony plenty to unpack in June 2026
- Your inbox is an identity system all of its own: whoever owns it may own a lot more
- Your business may be small, but its attack surface is anything but. Readiness is the first step to resilience.
- ESET Research analyzes Gamaredon’s new toolset and the group’s growing reliance on legitimate online services to hide its C&C infrastructure and exfiltrate stolen data
- ESET researchers assisted in the global disruption of the Amadey botnet and Stealc infostealer, providing technical analysis, infrastructure tracking, and affiliate-level insights
- ESET Research shares the results of a months-long investigation into the suite of EDR killers maintained by the RaaS gang Gentlemen
- Many manufacturing plants depend on OT systems that stay in service for many years. That long run can hide significant cybersecurity risks.
- ESET researchers have discovered SprySOCKS for Windows, FishMonger’s backdoor weaponizing a kernel driver for advanced stealthiness
- A phishing kit subverting Microsoft’s legitimate authentication flow lets attackers break into accounts without stealing passwords or creating fake login pages
- A shift in operational pattern of the infamous Vietnam-aligned APT group
- A company that's expecting a cyberattack but hasn’t actively prepared for it risks making the hardest decisions at the worst possible moment
- Every organisation gets audited. The question is who does the auditing.
- Your child’s first data breach may happen before they’ve even opened a bank account. Here’s how to keep their digital life safe.
- In this roundup, Tony looks at attacks against Polish water treatment facilities, how AI-directed attacks failed in Mexico, and what Google believes is the first AI-generated zero-day exploit
- An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2025 and Q1 2026
- Using chatbots for medical advice could elicit hallucinations and even expose you to security and privacy risks. Here’s what’s at stake and how to stay safe.
- The malware pairs remote access capabilities with ready-made campaign tools, lowering the barrier for full device compromise