Defence24.pl…
- W obliczu narastającej eskalacji działań Rosji przeciwko Ukrainie, a także działań hybrydowych i sabotaży na terenie państw europejskich, nie słabnie pytanie o to, kiedy (i czy w ogóle) dojdzie do wojny NATO z Rosją. 12 września rosyjski Kommersant zacytował Putina, który wskazał sytuację będącą dla niego przekroczeniem „czerwonej linii”.
- Jak donosi „The Korean Times”, w sobotę 12 września, około godziny 5:20, Korea Północna wystrzeliła kilka rakiet balistycznych krótkiego zasięgu w kierunku Morza Japońskiego. To kolejna prowokacja Pjongjangu w okresie ostatnich dwóch miesięcy. Seul zdecydowanie potępił ruch komunistycznego reżimu, uznając start rakiet za naruszenie rezolucji Rady Bezpieczeństwa ONZ.
- W sobotę, 12 września, CNN potwierdziło obecność ukraińskich wojsk w Afryce – są między innymi w Mali, Sudanie czy w Libii. Część z nich to instruktorzy szkolący tuareskich rebeliantów z Frontu Wyzwolenia Azawadu (FLA) – inni dronami morskimi uderzają we „flotę cieni”. Celem Ukrainy są prorosyjskie reżimy i rosyjskie statki.
- W niedzielę, 13 września, w godzinach popołudniowych, na Litwie poderwano myśliwce, a mieszkańców Wilna i Trok poinformowano o zagrożeniu. Wszystko to z powodu niezidentyfikowanego obiektu latającego, który pojawił się na radarze. Myślano, że to dron – okazało się, że ptaki.
- Ukraiński bezzałogowy kuter Sargan-3000 zniszczył ogniem karabinowym rosyjski morski pojazd bezzałogowy. To pierwszy odnotowany przypadek bezpośredniej walki dwóch morskich dronów.
- Noc z 12 na 13 września upłynęła niespokojnie nie tylko dla Ukrainy, atakowanej rosyjskimi dronami, ale i dla Polski. Do naruszenia polskiej przestrzeni nie doszło, ale jeden z dronów uderzył w ciężarówkę ok. kilometr od granicy. Polskie myśliwce patrolowały teren.
- W niedzielę w pociąg relacji Kijów–Warszawa przed granicą z Polską uderzył dron. PKP Intercity poinformowało, że wśród pasażerów nie ma obywateli Polski.
- Rosyjskie wojska uderzyły w zakład należący do polskiej spółki Cersanit SA w obwodzie żytomierskim. Obiekt wytwarza płytki ceramiczne i armaturę sanitarną.
- Ubiegłoroczna premiera nowego bezzałogowego systemu wieżowego od Huty Stalowa Wola, nazwanego ZSMU 30/40, była pewną sugestią toku myślenia jego twórców. Zestawiono ją z Wielozadaniowym Pojazdem Taktycznym 4×4 Waran, przeznaczonym m.in. do wypełniania roli pojazdu rozpoznania i dowodzenia dla artylerii. W tym roku ten sam moduł uzbrojenia zademonstrowano w zabudowie na platformie UMPG, znanej doskonale z […]
- Ponad 450 dronów oraz czterech dronów-rakiet Banderol użyły siły rosyjskie w atakach na Ukrainę w nocy z soboty na niedzielę – przekazały ukraińskie Siły Powietrzne. Wśród atakowanych regionów znalazły się obwody w zachodniej części kraju.
- Przejęcie przez jemeńskich Hutich kontroli nad całym wschodnim wybrzeżem Morza Czerwonego, a także strategicznymi wyspami Zuqar oraz Mayyun (Piram), a w rezultacie nad Bab al-Mandab, będzie miało konsekwencje zarówno regionalne, jak i globalne. Pokazuje to również potencjał zapomnianych konfliktów oraz ograniczenia supremacji technologicznej w wojnie asymetrycznej. To również bardzo dobra wiadomość dla Iranu w kontekście […]
- Zakończyło się operowanie wojskowego lotnictwa w polskiej przestrzeni powietrznej, związane z uderzeniami bezzałogowych statków powietrznych Rosji na cele w zachodniej części Ukrainy – podało przed godziną 10 Dowództwo Operacyjne Rodzajów Sił Zbrojnych.
- W Lubaniu trwa kolejny etap specjalistycznego szkolenia żołnierzy Wojsk Obrony Terytorialnej. Centrum Szkolenia Wojsk Obrony Terytorialnej wspólnie z Ośrodkiem Szkoleń Specjalistycznych Straży Granicznej prowadzi kolejny etap kursu taktyki i technik interwencji z użyciem środków przymusu bezpośredniego. Tym razem szkolenie ma szczególne znaczenie, ponieważ jego uczestnicy przygotowują się do roli instruktorów.
- Podczas targów MSPO 2026 spółka WZE S.A. zaprezentowała swoje produkty, między innymi w zakresie nawigacji i obserwacji dookrężnej. Równolegle podpisano umowy dotyczące produkcji na potrzeby kolejnych partii zestawów Patriot, w ramach rozwoju kompetencji WZE.
- Saab podpisał nową umowę na wsparcie techniczne pięciu polskich ośrodków szkolenia bojowego. Kontrakt zapewni ciągłość serwisu systemów laserowej symulacji pola walki do końca 2028 roku i stanowi kontynuację współpracy, którą firma prowadzi na rzecz Sił Zbrojnych RP od 2023 r.
- Mimo niesprzyjających sondaży Donald Trump chce być twarzą decydującej fazy kampanii przed listopadowymi wyborami parlamentarnymi, aby zmobilizować swój elektorat. Na rozpoczynającej się w środę, dwudniowej konwencji Partii Republikańskiej w Dallas w Teksasie prezydent wystąpi dwukrotnie.
- W sobotę, 12 września, na polskim niebie miały miejsce dwa zdarzenia godne odnotowania. Dwie amerykańskie maszyny – tankowiec i transporter – wylądowały w Powidzu z przyczyn nieznanych. Dwa inne samoloty – amerykański „superszpieg” Bombardier ARTEMIS II i brytyjski RC-135W Rivet Joint – wykonywały misję rozpoznawczą nad Morzem Czarnym.
- W sobotę, 12 września, Wołodymyr Zełenski powiedział, że jest gotowy na spotkanie z prezydentem Rosji, Władimirem Putinem. Miałoby ono mieć miejsce w trakcie grudniowego szczytu G20 w Miami. Kreml odpowiedział błyskawicznie: „Zaproszenie jest aktualne”.
- 24 września w Waszyngtonie miało dojść do ważnego spotkania prezydenta USA, Donalda Trumpa, z jego chińskim odpowiednikiem – Xi Jinpingiem. Japońska agencja prasowa Kyodo donosi jednak, że do spotkania może wcale nie dojść. Powodem jest amerykańska sprzedaż broni dla Tajwanu, której ostro sprzeciwiają się Chiny.
- Władze Litwy są w trakcie procedury zmieniającej jeden z przepisów konstytucji. Chodzi o art. 137, który na chwilę obecną nie pozwala Litwinom na rozmieszczenie broni jądrowej na swoim terytorium. Wkrótce ma się to zmienić, ale sytuacja ta nie podoba się Rosji. Wczoraj Litwie groził Pieskow – dziś grozi Miedwiediew.
TVN wiadomości…
Błąd RSS: Retrieved unsupported status code "403"
Wyborcza Kraj…
Wystąpił błąd, co prawdopodobnie oznacza, że kanał nie działa. Spróbuj ponownie później.
Wyborcza Świat…
Wystąpił błąd, co prawdopodobnie oznacza, że kanał nie działa. Spróbuj ponownie później.
The Hacker News…
- Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. The first campaign, per the tech giant, involved sending over a million scam emails between August 3 and 5, 2026, by masquerading as […]
- The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. Details of the vulnerabilities are as follows – CVE-2026-42016 (CVSS score: 8.1) – An incorrect authorization
- Over the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in the stream: alerts that were triggered by AI tools and agents. Not attacks against AI, but the ordinary, everyday footprint of an organization using it, from developers running coding agents and […]
- The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated […]
- GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server […]
- Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax. Knowledge distillation by itself is a legitimate training method. It refers to a machine learning technique where a large, powerful AI model assumes the role of […]
- Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026. The threat actors, which the artificial intelligence (AI) company has branded Generative Threat Groups (GTGs), span state-sponsored groups, financially motivated criminals, commercial
- Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve. The operation has been attributed to a cyber espionage group it calls GTG-20006 (where "GTG" stands for Generative Threat Group), which aligns with broader reporting […]
- Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path to compromise. A critical vulnerability may look alarming on a scanner report, but if it sits behind strong segmentation, identity controls, and other defenses that […]
- Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz said in a report. Wiz saw the attacks between August 15 and September 8. JFrog had fixed both flaws before then, so only servers that had […]
- A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital said in research published Thursday. The attack started with a crafted link and ended with the attacker able to do anything […]
- PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download. "These are Regular Maintenance Releases (MR) […]
- Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass
- A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right […]
- Bad actors are misusing Google Play's Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. Early Access apps are apps that haven't been released on the official Android app marketplace. The main idea behind the program is for developers to solicit user feedback for new applications […]
- Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only "under specific conditions" that it has not described. One flaw affects Check Point's Security Gateways, its firewall appliances. The other affects those […]
- A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports from Blackpoint Cyber and GreyNoise, the activity originates from "45.142.193[.]132," an IP address that has been […]
- The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm Group-IB said in a report published on September 9. A work profile is a separate space that Android typically reserves for employer apps, and what's inside it […]
- The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The vulnerabilities are listed below – CVE-2026-20079 (CVSS score: 10.0) – An authentication
- Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM's own setup guide. LiteLLM is an open-source AI gateway, the software a company puts between its applications and the model providers it pays for. That key is the gateway's administrator credential. Anyone who holds it […]
SANS Internet Storm Center…
- (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
- I identified an attacker using a semi-autonomous coding agent to run an offensive operation: finding poorly secured LLM resale gateways, acquiring API access through ordinary web flaws and account farming, validating the resulting inference capacity, and aggregating it behind a single gateway of their own.
- (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
- [This is a Guest Diary by Aaron Ng, an ISC intern as part of the SANS.edu BACS program]
- (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
- About a week ago, Proxmox published an advisory revealing a vulnerability in older versions of Proxmox VE, its flagship Virtual Environment product. The vulnerability only affects version 7, which has not been supported for a couple of years now.
- (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
- This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. Two vulnerabilities are listed as exploited in the wild, while none were publicly disclosed before Patch Tuesday. Notable fixes […]
- (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
- Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication bypass and is already being exploited. At this point, assume compromise. Attackers have been adding new accounts to affected devices to maintain access after a patch is installed.
Cybersecurity Avast…
- A call saying someone you love has been arrested and needs money ASAP can feel so real that you act before you think. Learn how bail bond scams work and what to watch for to help protect you and your family from falling for the scheme.
- Latest news We launched a new Avast One experience in 2026. Discover what’s new, see how it compares to the previous version, and learn how it makes your digital life simpler and more secure. In the ever-evolving landscape of the digital world, safeguarding your online presence has become more a necessity than a choice. […]
- If you've ever mentioned something in passing and then seen an ad for it shortly after, you're not imagining things. Learn how ads can sometimes follow you from real life to your screen, and how secure browsers with built-in ad blockers can help you take back control of what you see online.
- Spring break scams are out to ruin your vacation, but they don't have to. With a little awareness and Avast Free Antivirus protecting your devices, you can hit the beach without handing criminals an opening.
- You just sold a stack of old books for $100 on Facebook Marketplace. The buyer seemed eager, messaged instantly, and offered to pay extra. Sounds too good to be true? It probably is. Learn how to spot fake buyers before you lose both your money and your stuff.
- Scammers are using deepfake technology to replicate your child's voice in a kidnapping hoax, catfish with AI-generated video dates, and impersonate executives to steal millions. Learn how to spot deepfake fraud, and use Avast Deepfake Guard to help verify what's real before it's too late.
- Adoption fraud can blindside even the most prepared families, especially when emotions run high. Understanding common adoption scams and how to stay safe can help you move forward with more peace of mind.
- Facebook may feel like a safe place to connect, but scammers are increasingly using its ads, posts, and messages to deceive users. Here’s how cybercriminals are turning your feed into a gateway for fraud and what you can do to stay protected.
- If someone is blackmailing you with private photos or threats, do not pay. We know it's scary, but you don't need to comply. Learn how to handle sextortion threats, and discover how Avast can help secure your privacy.
- How a simple “I found your photo” message can quietly take over your account
Cybersecurity Kaspersky…
Błąd RSS: WP HTTP Error: cURL error 52: Empty reply from server
We Live Security…
- LLM-based code scanners won’t help attackers build a nuclear weapon, but that refusal could work in their favor
- AI scams are now hyper-realistic. But there’s one simple way to see through them.
- Don’t panic if you spot an illegally created image or video of you online – there are ways to request its removal
- Details about the Hugging Face hack, critical infrastructure under attack, a spoofed in-flight Wi-Fi network, and more of this month's cybersecurity news
- It’s getting cheaper and easier for cybercriminals to research potential victims. Here’s what’s still in your control.
- Quishing has become a popular alternative to traditional phishing. Here’s how businesses can close the gap.
- And will today’s surge in AI-driven vulnerability discovery eventually make tomorrow’s software safer?
- The incident involving OpenAI models shows that autonomous hacks make human oversight more important, not less
- AI took center stage, but the clearest lesson was less about what AI can do than about who is accountable when something goes wrong
- AI tutors can offer useful support, but their quality and safeguards vary widely. Here’s what parents should check before handing one to a child.
- OpenAI models going rogue, the first documented agentic ransomware operation, and an emergent AI-driven supply chain threat made for a packed July roundup
- The screenshot may look convincing, but it doesn’t necessarily prove that the payment, booking or conversation is genuine
- ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities
- A view of the H1 2026 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts.
- AI is changing cybercrime, but SMB cyber readiness still largely depends on closing the familiar gaps
- Three-day patching deadlines, exposed fuel-tank systems, scams costing billions of dollars, and social media bans for children all gave Tony plenty to unpack in June 2026
- Your inbox is an identity system all of its own: whoever owns it may own a lot more
- Your business may be small, but its attack surface is anything but. Readiness is the first step to resilience.
- ESET Research analyzes Gamaredon’s new toolset and the group’s growing reliance on legitimate online services to hide its C&C infrastructure and exfiltrate stolen data
- ESET researchers assisted in the global disruption of the Amadey botnet and Stealc infostealer, providing technical analysis, infrastructure tracking, and affiliate-level insights