Defence24.pl…
- Prezydent Karol Nawrocki wziął udział w bankiecie wydanym przez prezydenta Stanów Zjednoczonych Donalda Trumpa – poinformował szef Biura Polityki Międzynarodowej Kancelarii Prezydenta Marcin Przydacz. Prezydenci rozmawiali m.in. o obecności wojsk USA w Polsce.
- W Stanach Zjednoczonych doszło do katastrofy myśliwca F/A-18 Hornet. Samolot należący do Korpusu Piechoty Morskiej USA rozbił się w pobliżu jeziora Rimrock.
- EURENCO oraz Polska Grupa Zbrojeniowa oficjalnie podpisały umowę dotyczącą przyszłego joint venture podczas wystawy Eurosatory 2026.
- W trakcie targów Eurosatory konsorcjum KNDS zaprezentowało zmodernizowany czołg podstawowy Leclerc.
- Belfast i Southampton w ogniu, Pakt Migracyjny dla Unii Europejskiej i antymigracyjne referendum w Szwajcarii. Co dzieje się w Europie?
- Żołnierze sił zbrojnych Litwy, Francji i Polski od 16 do 26 czerwca br. uczestniczyć będą w międzynarodowych ćwiczeniach „Dzielny Dzik 2026” w strategicznie kluczowym regionie Przesmyku Suwalskiego – poinformowała litewska armia oraz polskie Dowództwo Generalne Rodzajów Sił Zbrojnych.
- Z okazji Dnia Rosji, obchodzonego jak co roku 12 czerwca, prezydent Władimir Putin zwiększył etatową liczbę żołnierzy pełniących służbę w strukturach Ministerstwa Obrony.
- Na Syberii w obwodzie irkuckim rozbił się rosyjski bombowiec Tu-22M3. Według wstępnych informacji, załoga przeżyła katastrofę.
- PONAR Wadowice S.A. oraz amerykański koncern Moog Inc. podpisały Memorandum of Understanding, otwierając nowy rozdział współpracy technologicznej i przemysłowej w Polsce. Porozumienie ma na celu rozwój nowoczesnych rozwiązań dla sektora obronnego oraz wzmocnienie krajowych zdolności produkcyjnych i serwisowych.
- Koncern KNDS prezentuje w trakcie targów Eurosatory 2026 nowe propozycje w domenie ciężkich opancerzonych wozów bojowych.
- MiG-i-29 w zamian za ukraińskie technologie dronowe? Na temat potencjalnej polsko-ukraińskiej wymiany wypowiedział się wiceszef MON, Cezary Tomczyk.
- Rada Unii Europejskiej formalnie zatwierdziła w poniedziałek umowę z Kanadą, która umożliwia kanadyjskim firmom i produktom udział w zamówieniach publicznych realizowanych w ramach SAFE. Kanada stała się tym samym pierwszym państwem spoza Europy, które przystąpiło do tego programu obronnego.
- Polska umacnia swoją pozycję jako istotny gracz w europejskiej transformacji sektora bezpieczeństwa. Wzrost wydatków obronnych do poziomu 4,8 proc. PKB, dynamiczny rozwój technologii wojskowych oraz doświadczenie zdobyte w związku ze wsparciem Ukrainy sprawiają, że polskie firmy są coraz częściej postrzegane jako wiarygodni partnerzy strategiczni – także przez największe gospodarki Europy, w tym Francję. Kluczowym momentem […]
- Czy europejskie rakiety uderzą na Rosjan na Ukrainie, sterowane przez amerykański system AI? O zakończeniu ważnego etapu testów prowadzących do wdrożenia rozwiązania poinformowała firma Shield AI, w trakcie rozpoczynających się targów Eurosatory.
- „Polska do 2039 roku będzie chciała pozyskać dodatkowe dwie eskadry samolotów F-35” – potwierdził wiceminister obrony narodowej Cezary Tomczyk.
- Władze w Teheranie ogłosiły, że uroczystości pogrzebowe zabitego na początku wojny Najwyższego Przywódcy Iranu ajatollaha Alego Chameneiego odbędą się na początku lipca. Waszyngton wysyła coraz więcej sygnałów o możliwym pokoju.
- W Camp Kościuszko w Poznaniu uhonorowany został sierżant sztabowy Michael H. Ollis, który został pośmiertnie odznaczony Medalem Honoru, najwyższym odznaczeniem wojskowym w USA, za uratowanie życia polskiego żołnierza.
- W obliczu zbliżającego się Szczytu NATO w Ankarze, Turcja chce pokazać, że nie jest już tylko dużym sojusznikiem wojskowym, ale także poważnym aktorem przemysłowo-obronnym. W wywiadzie z dr. Aleksandrem Olechem, prof. Haluk Görgün, Sekretarz ds. Przemysłu Obronnego Turcji, przekonuje, że tureckie firmy mogą wzmocnić NATO poprzez drony, obronę przeciwlotniczą, systemy morskie, cyberzdolności, rozwiązania dowodzenia i […]
- Sąd Rejonowy w Czernihowie skazał na karę dożywotniego pozbawienia wolności kursanta, który podczas szkolenia wojskowego zastrzelił dwóch instruktorów, żołnierzy Sił Zbrojnych Ukrainy oraz ranił trzeciego.
- Ambasador Szwecji w Polsce, Martina Quick, widzi duży potencjał pogłębiania współpracy obronnej z Polską niemal we wszystkich kluczowych obszarach — od zdolności dalekiego rażenia, przez program okrętów podwodnych ORKA, aż po wspólne zakupy uzbrojenia. W rozmowie z Defence24.pl podkreśla, że doświadczenia wojny na Ukrainie wyraźnie pokazują, jak ważne jest szybkie rozwijanie precyzyjnych środków rażenia o […]
TVN wiadomości…
Błąd RSS: Retrieved unsupported status code "403"
Wyborcza Kraj…
Wystąpił błąd, co prawdopodobnie oznacza, że kanał nie działa. Spróbuj ponownie później.
Wyborcza Świat…
Wystąpił błąd, co prawdopodobnie oznacza, że kanał nie działa. Spróbuj ponownie później.
The Hacker News…
- A single click on a trusted Microsoft link could have let an attacker pull emails, calendar details, and indexed files out of Microsoft 365 Copilot Enterprise Search. Researchers at Varonis Threat Labs chained three bugs into a one-click exfiltration path they call SearchLeak. Because the link pointed to a real microsoft.com domain, traditional anti-phishing and […]
- Stuff broke again. Not in a movie way. An old tool was left exposed. An abandoned package was abused. A deprecated feature was still running in prod. This week is the same lesson in a new form: phishing kits are easier to rent, AI names are useful bait, old login paths still fail, and forgotten […]
- Employee onboarding is a busy time for IT teams. New starters need devices, accounts, access permissions, and passwords, all delivered within a tight timeframe. That usually means sharing a temporary "first-day" password so employees can access systems for the first time. The issue is that these passwords don't always stay temporary. They may be sent […]
- Cybersecurity researchers have discovered a network of 152 Google Chrome extensions that act as new tab live wallpaper add-ons to distribute a potentially unwanted program (PUP) family. The cluster spans 38 separate Chrome Web Store publisher accounts and three brand backends: tabplugins[.]com, yowgames[.]com, and chromewallpaper[.]com. They have been collectively installed 105,000 times. The
- An attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, turning those files into a way to break into the sites. When a site administrator was logged in as the file loaded, the code created an admin account under the attacker's control and installed a hidden plugin that opened […]
- Cybersecurity researchers have disclosed details of fraudulent activity targeting users across the Middle East and North Africa by employing various fraudulent Facebook accounts impersonating politicians, public figures, and trusted organizations. "These accounts promoted fake offers, including free mobile internet packages, financial compensation, and government subsidy programs," Group-IB
- Palo Alto Networks has revealed that it has observed "active exploitation" of a recently disclosed PAN-OS vulnerability by an unknown threat actor to obtain unauthorized access to GlobalProtect portals. The vulnerability in question is CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software that could be exploited […]
- Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct unauthenticated file operations and even remote code execution. The vulnerability, tracked as CVE-2026-20253, is rated 9.8 on the CVSS scoring system. "In Splunk Enterprise versions below 10.2.4 and 10.0.7, an unauthenticated user could create or […]
- Anthropic said on Friday it will "abruptly disable" its most advanced artificial intelligence (AI) models, Claude Fable 5 and Mythos 5, for all users after the U.S. government ordered it to suspend access to the models for foreign nationals, whether inside or outside the U.S., citing national security concerns. The AI company said it received […]
- Attackers took over more than 400 packages in the Arch User Repository (AUR) this week and rewrote their build scripts to install a credential stealer on any machine that built them. The malware is a Rust binary built to harvest developer secrets. When it lands with root, it can also load an eBPF rootkit to […]
- Google on Friday said it's pursuing legal action against a Chinese cybercrime network, accusing it of using its Gemini artificial intelligence (AI) agent to send phishing text messages targeting Americans. The network is said to be behind the development and management of a phishing-as-a-service (PhaaS) software kit called Outsider, per the tech giant. "The operation […]
- Instead of hiding on the laptops and servers defenders watch most closely, a China-nexus group spent close to a decade hidden inside the Linux login system itself. Sygnia, which tracks the group as Velvet Ant, says it backdoored the PAM and OpenSSH components that decide who is allowed to sign in, planting its access where […]
- Cybersecurity researchers have described what they say is a new class of attack that can trick artificial intelligence (AI) coding agents into running arbitrary code on developer machines. Called Agentjacking by Tenet Security, the attack can be triggered by means of a fake error report crafted using Sentry, an open-source error-tracking and performance-monitoring platform. "The […]
- For most of the past decade, managed detection and response was the answer to a real problem. Security teams couldn't staff around the clock, couldn't hire enough analysts, and needed someone else to handle the alert queue. MDR stepped in. It worked well enough. Until now. The threat landscape has changed faster than the MDR […]
- Cybersecurity researchers have disclosed details of three now-patched security flaws impacting LangGraph, including a critical vulnerability chain that could result in remote code execution. LangGraph is an open-source framework created by LangChain to build complex, stateful, and multi-agent artificial intelligence (AI) agentic applications. "An SQL injection in LangGraph's function could
- An INTERPOL-led operation last month resulted in the disruption of Sniper Dz, a decade-long phishing-as-a-service (PhaaS) platform, Group-IB said Thursday. The effort, codenamed Operation Ramz, took place between October 2025 and February 2026, and saw authorities from 13 countries in the Middle East and North Africa (MENA) region making 201 arrests. Included among them was […]
- Authorities in Europe have disrupted AudiA6, a cryptocurrency laundering service used by ransomware gangs and cybercriminal networks. Europol, in a statement issued Thursday, said the dismantling of AudiA6 cut off a "key financial pipeline used to wash hundreds of millions in illicit profits." The service is estimated to have been used to launder more than […]
- The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to keep it private. The campaign hit universities hardest. Google's Mandiant attributes it to the group it tracks as UNC6240, and dates the activity between May 27 and June 9. Oracle did not publish […]
- Two security teams have shown, in separate research published this week, that OpenClaw, the popular self-hosted AI agent, can be driven to run attacker-controlled code or hand over sensitive data through ordinary-looking inputs. Imperva buried instructions inside shared contacts, vCards, and location pins that the agent executed without the victim ever seeing them. Varonis built […]
- Security researcher Chaotic Eclipse (aka Nightmare-Eclipse and MSNightmare) has released a new Windows BitLocker bypass dubbed GreatXML, a day after they published an exploit for Microsoft Defender. "This was an accidental discovery, it took a total of 4 hours to find this," the researcher said in a post on Blogger. "If you ever attempted to […]
SANS Internet Storm Center…
- I like it when a fellow handler posts a diary entry about images with malicious content. Last one is Xavier: "The Evil MSI Background is Back!".
- (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
- (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
- ISC Stormcast For Thursday, June 11th, 2026 https://isc.sans.edu/podcastdetail/9968, (Thu, Jun 11th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
- Back in 2023, I wrote a diary[1] discussing how commonly X-Frame-Options and CSP headers containing the frame-ancestors directive were used on 1 million most popular domains on the internet (based on the Tranco list[2]), and how they were set. Given that three years have passed since then, I thought it might be interesting to repeat […]
- (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
- Microsoft today released patches for 204 vulnerabilities. 38 of these vulnerabilities are considered critical, and three have been disclosed before today. Six of the vulnerabilities affect Microsoft cloud solutions and do not require any user action. In addition, Microsoft incorporated 360 different vulnerabilities affecting Chromium into its Edge browser.
- (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
- This diary continues the Internet Storm Center's tracking of the TeamPCP supply chain campaign, first documented in the SANS white paper When the Security Scanner Became the Weapon and most recently in the handler diary Activity Through 2026-05-24. Since that update, the story moved into two new places: the United States government, which formally caught […]
- (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Cybersecurity Avast…
- A call saying someone you love has been arrested and needs money ASAP can feel so real that you act before you think. Learn how bail bond scams work and what to watch for to help protect you and your family from falling for the scheme.
- Latest news We launched a new Avast One experience in 2026. Discover what’s new, see how it compares to the previous version, and learn how it makes your digital life simpler and more secure. In the ever-evolving landscape of the digital world, safeguarding your online presence has become more a necessity than a choice. […]
- If you've ever mentioned something in passing and then seen an ad for it shortly after, you're not imagining things. Learn how ads can sometimes follow you from real life to your screen, and how secure browsers with built-in ad blockers can help you take back control of what you see online.
- Spring break scams are out to ruin your vacation, but they don't have to. With a little awareness and Avast Free Antivirus protecting your devices, you can hit the beach without handing criminals an opening.
- You just sold a stack of old books for $100 on Facebook Marketplace. The buyer seemed eager, messaged instantly, and offered to pay extra. Sounds too good to be true? It probably is. Learn how to spot fake buyers before you lose both your money and your stuff.
- Scammers are using deepfake technology to replicate your child's voice in a kidnapping hoax, catfish with AI-generated video dates, and impersonate executives to steal millions. Learn how to spot deepfake fraud, and use Avast Deepfake Guard to help verify what's real before it's too late.
- Adoption fraud can blindside even the most prepared families, especially when emotions run high. Understanding common adoption scams and how to stay safe can help you move forward with more peace of mind.
- Facebook may feel like a safe place to connect, but scammers are increasingly using its ads, posts, and messages to deceive users. Here’s how cybercriminals are turning your feed into a gateway for fraud and what you can do to stay protected.
- If someone is blackmailing you with private photos or threats, do not pay. We know it's scary, but you don't need to comply. Learn how to handle sextortion threats, and discover how Avast can help secure your privacy.
- How a simple “I found your photo” message can quietly take over your account
Cybersecurity Kaspersky…
- The FROST technique: using an SSD in a roundabout way to leak private information.
- How to shut down unauthorized AI tools and block user access across a corporate network.
- Cybercriminals are spreading the Argamal remote access Trojan through hentai games. This article covers how this RAT works, its dangers, and how to protect both your devices and data.
- Breaking down Elon Musk’s XChat: how its end-to-end encryption works, why experts have slammed its PIN system, and how the new service stacks up against Signal, WhatsApp, and Telegram.
- How Kaspersky Automotive Secure Gateway (KASG) ensures vehicle security and why SIEM integration is essential.
- Kaspersky experts have investigated the security of public Wi-Fi access points in Mexico City, Guadalajara, and Monterrey.
- Kaspersky experts are studying the full end-to-end reality of messaging-based scams to understand the extent of the losses, how quickly harm occurs, how they impact trust, and what remains after an interaction ends. They also shared statistics and advice on how to avoid falling victim to scam schemes.
- We analyze how fake IPTV apps gain control of Android devices, abuse screen access features, and steal credentials, cash, and crypto assets.
- Threat actors are exploiting legitimate Google AppSheet addresses for phishing campaigns, sending emails on behalf of major companies to steal user credentials.
- Kaspersky experts have discovered an unpatchable vulnerability in popular Qualcomm chips used in smartphones, cars, smart devices, industrial equipment, and much more. We explain what this vulnerability is and what device owners should do.
We Live Security…
- A shift in operational pattern of the infamous Vietnam-aligned APT group
- A company that's expecting a cyberattack but hasn’t actively prepared for it risks making the hardest decisions at the worst possible moment
- Every organisation gets audited. The question is who does the auditing.
- Your child’s first data breach may happen before they’ve even opened a bank account. Here’s how to keep their digital life safe.
- In this roundup, Tony looks at attacks against Polish water treatment facilities, how AI-directed attacks failed in Mexico, and what Google believes is the first AI-generated zero-day exploit
- An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2025 and Q1 2026
- Using chatbots for medical advice could elicit hallucinations and even expose you to security and privacy risks. Here’s what’s at stake and how to stay safe.
- The malware pairs remote access capabilities with ready-made campaign tools, lowering the barrier for full device compromise
- Watch out for bogus World Cup websites that mimic official ticket and merchandise flows to steal money and personal data
- ESET researchers describe new tools and techniques that the Webworm APT group recently added to its arsenal
- A complete decoupling from US technology is neither realistic nor necessary, but the changing environment does require nations and companies to reassess their relationships and dependencies
- Conflict is a boon for opportunistic fraudsters. Look out for their ploys.
- ESET researchers uncovered new activities attributed to FrostyNeighbor, updating its compromise chain to support the group’s continual cyberespionage operations
- Smart glasses allow anyone to track and record the world around them. That could put your data and the privacy of those nearby at risk.
- ESET researchers uncovered fraudulent apps on Google Play that claim to provide the call history “for any number” and had been downloaded more than seven million times before being taken down
- How come it’s still possible to ‘secure’ an online account with a six-digit string?
- ESET researchers have investigated an ongoing attack by the ScarCruft APT group that targets the Yanbian region via backdoor-laced Windows and Android games
- Warnings about helpdesk impersonation scams and Iran-linked hackers targeting critical sectors in the US, plus the most damaging scams of 2025 – here's some of what made the headlines this month
- A breach claims the systems as well as the confidence that was, in retrospect, a major vulnerability
- ESET Research has discovered a new China-aligned APT group that we’ve named GopherWhisper, which targets Mongolian governmental institutions