Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- [PL] [VIDEO] Everyday cybersecurity
- [PL] Why posting photos of children with their certificates is a bad idea?
- [PL] Are website login credentials personal data?
- [PL] Members of a criminal group arrested by Poland’s CBZC with help from the FBI and HSI
- [PL] Selling a phone on Vinted? Watch out for more than phishing and BLIK scams
- [PL] How a popular charity campaign became fuel for scammers
- [PL] Poland’s data protection chief advises law enforcement on how to interpret deepfakes
- [PL] NIS2: Oversight and supervision of essential and important entities
- [PL] Whose digital sovereignty is the European Union trying to protect?
- [PL] Blocking children’s access to pornography vs freedom to provide services
- [PL] Could disappearing messages become a way to avoid transparency?
- EU says Amazon, Microsoft cloud services should fall under digital dominance rules
- Russia breaks into human rights activist’s phone with Cellebrite
- Scammers have killed the physical Steam Gift cards
- Nintendo confirms data stolen in WebMD subsidiary cyberattack
- JaredFromSubway MEV bot hacked in $15 million crypto theft
For the more technical
- [PL] How an unauthorized account gained access to FIFA systems
- Introducing usbliter8: An A12/A13 SecureROM exploit
- Squidbleed (CVE-2026-47729). Heartbleed's ancient cousin, hiding in Squid since 1997
- When defenses become attack surface: CVE-2026-20971, a Samsung kernel UAF
- Following user outcry, AMD reinstates memory encryption in consumer CPUs
- PixelSmash – critical FFmpeg vulnerability turns media files into weapons
- More than 4,000 legacy routers compromised by AryStinger, turned into global attack proxies for hackers
- Inside the FortiBleed open directory: A technical analysis of what the attacker left behind
- Attackers actively exploiting sensitive information exposure vulnerability in Gravity SMTP plugin
- BadBlocker: 11 million users, one server call away from compromise
- macOS.Gaslight: Rust backdoor turns prompt injection on the analyst, not the sandbox
- Lost in relocation: analysis of a new loader distributing CastleStealer
- Inside OnyxC2: The new stealer targeting 210 apps
- Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances
- SolarisLoader - a new malware loader
- Crypto Clipper uses Tor and worm-like propagation for persistence and control
- A multi-stage steganographic loader campaign deploying diverse payloads globally
- Inside Vidar’s ABE bypass: From memory scanning to APC injections
- EvilTokens: How “ghost” code threatens US and European businesses
- Payouts King ransomware initial access broker deploys new Edgecution malware
- Threat actors weaponizing RAR archives to target Thailand’s healthcare sector
- Threat intelligence report: Nation-state targeting of water systems 2024–2026
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments