Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- [PL] Polish government approves National Digitalization Strategy
- [PL] Is transparency a threat to national security?
- [PL][VIDEO] Secret Department No. 4: What Russian intelligence agents study?
- [PL] Expert warns there’s no such thing as a risk-free investment. A “safe” profit offer online could be a scam
- [PL] The World Cup “guaranteed win” that drains your account: An analysis of a deepfake campaign ahead of the FIFA World Cup
- [PL] Mandatory age checks for porn sites
- [PL][AUDIO] Meta and Google in court. Will the verdicts change the internet?
- [PL] Americans united in opposition to AI data centers
- [PL] AI enables coordinated disinformation campaigns
- [PL] Poland’s data protection chief appeals the closure of an investigation into AI-generated nude images of a student
- Aviva detects record £230m in bogus insurance claims as use of AI rises
- Pokémon Go data trained AI that could assist military drones in war zones
- [VIDEO] Something is jamming GPS over Europe. Here's what we found
- French govt messaging service breached in account hijacking attack
- Spyware firm targeted WhatsApp users in defiance of US court order, Meta says
For the more technical
- [PL][VIDEO] MCP – the hot topic in the world of app security
- [PL] Signal rolls out new anti-phishing features
- UNC1151/Ghostwriter phishing campaign targeting Gmail accounts
- Active exploitation of Check Point VPN authentication bypass (CVE-2026-50751)
- Inside the cross-platform propagation of a new Gafgyt variant C0XMO
- June 2026 Patch Tuesday: Microsoft patches 206 vulnerabilities including three publicly disclosed zero-days
- When "moderate" means "sometimes"
- Google patches new Chrome zero-day flaw exploited in the wild
- [VIDEO] The only Open Redirect that scares me
- Oracle mitigates PeopleSoft zero-day exploited in data theft attacks
- Off by !: Exploiting a use-after-free in the Linux kernel
- FSB’s matryoshka – Gamaredon’s gifts that keeps unpacking – GammaPhish and GammaWorm
- FSB’s matryoshka #2/3 – Gamaredon’s gifts that keeps unpacking – GammaLoad
- FSB’s matryoshka #3/3 – Gamaredon’s gifts that keeps unpacking – GammaSteel
- Threat actors weaponize AI hype to deliver AsyncRAT
- IronWorm: Shai-Hulud's rustier cousin
- Miasma npm supply chain attack: Self-spreading worm via Phantom Gyp
- Inside the Miasma software supply chain attack toolkit
- The blight reaches Microsoft: 73 repos disabled in 105 seconds
- You do surprise me.exe: An unexpected executable in Hola Browser
- AI brands as bait: How threat actors are using the AI hype in social engineering
- Don't fear the repo: UNK_DeadDrop phishing campaign targets developers to steal cryptocurrency
- GoFlateLoader: A widespread Golang loader delivering multiple infostealers
- Blinding the watchmen: Abusing cloud logging services for defense evasion and visibility
- Technical analysis of MLTBackdoor
- From fiscal lures to remote access, a previously undocumented NinjaOne RMM abuse chain
- OceanLotus: From external espionage to domestic targeting
- VerdantBamboo: Just another BRICKSTORM in the firewall
- APT28, an evolution of tradecraft
- Old WinRAR flaw fuels attacks on Ukraine: How unmanaged software keeps the door open
- Seeking counsel: Ongoing targeted campaign against US law firms
- Behind Khmer Shadow: Targeted espionage against Cambodian government entities
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments