Afraid of missing important security news during the week? We're here to help! Every week we put together a curated list of all important security news in one place, for your reading pleasure. Enjoy!
For the less technical
- [PL] E-vaccination card sparks controversy. Is it "coercion infrastructure"?
- [PL] Pegasus report before summer break. Services block declassification of data
- [PL] [VIDEO] ABW report: Are we safe?
- [PL] Who uses AI, for what, and how in public institutions?
- [PL] Military bets on artificial intelligence. Creates its own language model
- [PL] Warsaw will host NASK cybersecurity center
- [PL] Scams are most often run by cybercriminal corporations
- [PL] Estonian financial inspectorate suspends Zondacrypto license
- [PL] Cinkciarz.pl site CEO arrested. Lived a comfortable life in the USA
- Grafana says stolen GitHub token let hackers steal codebase
- GitHub confirms breach of 3,800 repos via malicious VSCode extension
- Google publishes exploit code threatening millions of Chromium users
- Mozilla ’ s response to the UK Department of Science, Innovation and Technology’s consultation “Growing up in the online world”
- Independent review confirms critical Telegram vulnerability
- Every voice and video call on Discord is now end-to-end encrypted
For the more technical
- [PL] CERT Poland releases April 2026 monthly threat report
- [PL] FlyHack ad offers cheap flights but delivers malicious Android app
- [PL] New vulnerabilities Fragnesia (CVE-2026-46300) and DirtyDecrypt (CVE-2026-31635) disclosed
- Open WebUI - stored XSS via file upload that leads to RCE with 1-click
- New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released
- DirtyCBC — Linux RxGK chosen-plaintext page-cache poisoning to root shell
- Claw Chain: Cyera research unveil four chainable vulnerabilities in OpenClaw
- Second time, same sandbox: Another Anthropic Claude Code network sandbox bypass enables data exfiltration
- Exposing Fox Tempest: A malware-signing service operation
- Hunting down the Google-sent phishing wave compromising 30,000+ Facebook accounts
- Tracking TamperedChef clusters via certificate and code reuse
- SEO poisoning campaign leverages Gemini and Claude Code impersonation to deliver infostealer
- Premium Deception: Uncovering a global Android carrier billing fraud campaign
- Mini Shai-Hulud hits @antv ecosystem, 639 compromised npm package versions
- Gremlin Stealer's evolved tactics: Hiding in plain sight with resource files
- Fake Microsoft Teams campaign delivers ValleyRAT via NSIS installer and DLL sideloading
- Inside SHADOW-WATER-063’s Banana RAT: From build server to banking fraud
- WantToCry ransomware remotely encrypts files
- CypherLoc, an advanced browser-locking scareware targeting millions
- Webworm: New burrowing techniques
- From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat
- Operation Dragon Whistle: UNG0002 targets Chinese academia via weaponized institutional lure
- Analyzing TAX#TRIDENT: Fake Indian tax lures pivot across ZIP, VBS, stego and PHP-wrapped VBS delivery
- How Storm-2949 turned a compromised identity into a cloud-wide breach
- UAC-0184: From HTA to a signed network stack
Did you enjoy this list? You can subscribe to one of our feeds on Twitter, Facebook or RSS.
Comments