<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="/stylesheet.xsl" type="text/xsl"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:podcast="https://podcastindex.org/namespace/1.0">
  <channel>
    <atom:link rel="self" type="application/rss+xml" href="https://feeds.transistor.fm/headflash-security-pl" title="MP3 Audio"/>
    <atom:link rel="hub" href="https://pubsubhubbub.appspot.com/"/>
    <podcast:podping usesPodping="true"/>
    <title>HeadFlash Security PL</title>
    <generator>Transistor (https://transistor.fm)</generator>
    <itunes:new-feed-url>https://feeds.transistor.fm/headflash-security-pl</itunes:new-feed-url>
    <description>HeadFlash Security — ~4-minutowy codzienny przegląd cyberbezpieczeństwa: wycieki, podatności i obrona. Nowy odcinek codziennie rano.</description>
    <copyright>© 2026 HeadFlash.news</copyright>
    <podcast:guid>0c08190b-9848-58d0-97e6-c96a12cc2c7d</podcast:guid>
    <podcast:locked>yes</podcast:locked>
    <language>pl</language>
    <pubDate>Thu, 20 Aug 2026 08:01:40 +0200</pubDate>
    <lastBuildDate>Thu, 20 Aug 2026 08:02:07 +0200</lastBuildDate>
    <link>https://headflash.news/pl/security/</link>
    <image>
      <url>https://img.transistorcdn.com/rTkL6BZylXmHYH125dtDlVTip-5ZcdLu5b7rH-jg_KI/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84OTgy/ZDVmZTEyOGE2N2Ji/Njk3NGRmMjAzODdl/ZWEwYi5wbmc.jpg</url>
      <title>HeadFlash Security PL</title>
      <link>https://headflash.news/pl/security/</link>
    </image>
    <itunes:category text="Technology"/>
    <itunes:category text="News">
      <itunes:category text="Tech News"/>
    </itunes:category>
    <itunes:type>episodic</itunes:type>
    <itunes:author>HeadFlash</itunes:author>
    <itunes:image href="https://img.transistorcdn.com/rTkL6BZylXmHYH125dtDlVTip-5ZcdLu5b7rH-jg_KI/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84OTgy/ZDVmZTEyOGE2N2Ji/Njk3NGRmMjAzODdl/ZWEwYi5wbmc.jpg"/>
    <itunes:summary>HeadFlash Security — ~4-minutowy codzienny przegląd cyberbezpieczeństwa: wycieki, podatności i obrona. Nowy odcinek codziennie rano.</itunes:summary>
    <itunes:subtitle>HeadFlash Security — ~4-minutowy codzienny przegląd cyberbezpieczeństwa: wycieki, podatności i obrona.</itunes:subtitle>
    <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
    <itunes:owner>
      <itunes:name>Marcin Rybak</itunes:name>
      <itunes:email>podcast@headflash.news</itunes:email>
    </itunes:owner>
    <itunes:complete>No</itunes:complete>
    <itunes:explicit>No</itunes:explicit>
    <item>
      <title>Sakura Internet: atak na 1,36 mln kont japońskiego dostawcy chmury</title>
      <itunes:title>Sakura Internet: atak na 1,36 mln kont japońskiego dostawcy chmury</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">0337ac9a-e31b-4f98-81ed-7521d9a4a193</guid>
      <link>https://headflash.news/pl/security/2026-08-20-daily-newsletter</link>
      <description>
        <![CDATA[<p>Japoński dostawca chmury ujawnia skalę włamania, Apple łata 29 dziur, a CISA ostrzega przed Medusą — przegląd dnia.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.bleepingcomputer.com/news/security/sakura-internet-hack-exposes-data-of-up-to-136-million-accounts/">Sakura Internet hack exposes data of up to 1.36 million accounts</a></li><li><a href="https://www.techtimes.com/articles/324964/20260819/russias-gru-hacked-ukraines-sanctioned-asset-agency-days-before-165m-deadline.htm">Russia's GRU Hacked Ukraine's Sanctioned-Asset Agency Days Before $165M Deadline</a></li><li><a href="https://www.gotechtor.com/ios-26-6-1-macos-tahoe-26-6-2-security-update/">Apple Just Fixed 29 Security Flaws Across iPhone, iPad, and Mac, Including One That Could Expose Your Network Traffic to Attackers</a></li><li><a href="https://9to5mac.com/2026/08/19/claritycheck-people-finder-left-millions-of-face-photos-exposed-likely-without-their-knowledge/">ClarityCheck people-finder left millions of face photos exposed, likely without their knowledge</a></li><li><a href="https://www.bleepingcomputer.com/news/security/cisa-medusa-ransomware-hit-over-500-critical-infrastructure-orgs/">CISA: Medusa ransomware hit over 500 critical infrastructure orgs</a></li></ul><p><a href="https://headflash.news/pl/security/2026-08-20-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p><p>🤖 Odcinek opracowany przy pomocy sztucznej inteligencji. Lektor syntetyczny.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Japoński dostawca chmury ujawnia skalę włamania, Apple łata 29 dziur, a CISA ostrzega przed Medusą — przegląd dnia.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.bleepingcomputer.com/news/security/sakura-internet-hack-exposes-data-of-up-to-136-million-accounts/">Sakura Internet hack exposes data of up to 1.36 million accounts</a></li><li><a href="https://www.techtimes.com/articles/324964/20260819/russias-gru-hacked-ukraines-sanctioned-asset-agency-days-before-165m-deadline.htm">Russia's GRU Hacked Ukraine's Sanctioned-Asset Agency Days Before $165M Deadline</a></li><li><a href="https://www.gotechtor.com/ios-26-6-1-macos-tahoe-26-6-2-security-update/">Apple Just Fixed 29 Security Flaws Across iPhone, iPad, and Mac, Including One That Could Expose Your Network Traffic to Attackers</a></li><li><a href="https://9to5mac.com/2026/08/19/claritycheck-people-finder-left-millions-of-face-photos-exposed-likely-without-their-knowledge/">ClarityCheck people-finder left millions of face photos exposed, likely without their knowledge</a></li><li><a href="https://www.bleepingcomputer.com/news/security/cisa-medusa-ransomware-hit-over-500-critical-infrastructure-orgs/">CISA: Medusa ransomware hit over 500 critical infrastructure orgs</a></li></ul><p><a href="https://headflash.news/pl/security/2026-08-20-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p><p>🤖 Odcinek opracowany przy pomocy sztucznej inteligencji. Lektor syntetyczny.</p>]]>
      </content:encoded>
      <pubDate>Thu, 20 Aug 2026 08:01:39 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/0e2cdf73/f6713cd0.mp3" length="4679932" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>293</itunes:duration>
      <itunes:summary>Japoński dostawca chmury ujawnia skalę włamania, Apple łata 29 dziur, a CISA ostrzega przed Medusą — przegląd dnia.</itunes:summary>
      <itunes:subtitle>Japoński dostawca chmury ujawnia skalę włamania, Apple łata 29 dziur, a CISA ostrzega przed Medusą — przegląd dnia.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Luka w Windows Task Host wykorzystywana przez gangi ransomware</title>
      <itunes:title>Luka w Windows Task Host wykorzystywana przez gangi ransomware</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">50c069e5-db56-4e47-8d0f-bc16f85fa5d9</guid>
      <link>https://headflash.news/pl/security/2026-08-19-daily-newsletter</link>
      <description>
        <![CDATA[<p>CISA potwierdza ataki ransomware na CVE-2025-60710, Kimi Desktop ma krytyczną lukę w aktualizacjach, a Chainalysis pozywa rząd USA.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.bleepingcomputer.com/news/security/cisa-windows-task-host-flaw-now-exploited-by-ransomware-gangs">CISA: Windows Task Host flaw now exploited by ransomware gangs</a></li><li><a href="https://runtimewire.com/article/kimi-desktop-ships-with-a-group-chat-updater-that-can-install-unverified-code">Kimi Desktop Ships With a Group Chat Updater That Can Install Unverified Code</a></li><li><a href="https://hunt.io/blog/operation-cameraswarm-dahua-cameras-compromised">Operation CameraSwarm:  Over 14,000 Dahua cameras compromised across Ukraine and Russia</a></li><li><a href="https://www.databreachtoday.com/china-linked-apt-uses-ai-to-optimize-hand-built-malware-a-32597">China-Linked APT Uses AI to Optimize Hand-Built Malware</a></li><li><a href="https://decrypt.co/375843/chainalysis-sues-us-government-ice-contract-trm-labs">Chainalysis Sues US Government Over $94.6M ICE Contract Handed to Rival TRM Labs</a></li></ul><p><a href="https://headflash.news/pl/security/2026-08-19-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p><p>🤖 Odcinek opracowany przy pomocy sztucznej inteligencji. Lektor syntetyczny.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>CISA potwierdza ataki ransomware na CVE-2025-60710, Kimi Desktop ma krytyczną lukę w aktualizacjach, a Chainalysis pozywa rząd USA.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.bleepingcomputer.com/news/security/cisa-windows-task-host-flaw-now-exploited-by-ransomware-gangs">CISA: Windows Task Host flaw now exploited by ransomware gangs</a></li><li><a href="https://runtimewire.com/article/kimi-desktop-ships-with-a-group-chat-updater-that-can-install-unverified-code">Kimi Desktop Ships With a Group Chat Updater That Can Install Unverified Code</a></li><li><a href="https://hunt.io/blog/operation-cameraswarm-dahua-cameras-compromised">Operation CameraSwarm:  Over 14,000 Dahua cameras compromised across Ukraine and Russia</a></li><li><a href="https://www.databreachtoday.com/china-linked-apt-uses-ai-to-optimize-hand-built-malware-a-32597">China-Linked APT Uses AI to Optimize Hand-Built Malware</a></li><li><a href="https://decrypt.co/375843/chainalysis-sues-us-government-ice-contract-trm-labs">Chainalysis Sues US Government Over $94.6M ICE Contract Handed to Rival TRM Labs</a></li></ul><p><a href="https://headflash.news/pl/security/2026-08-19-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p><p>🤖 Odcinek opracowany przy pomocy sztucznej inteligencji. Lektor syntetyczny.</p>]]>
      </content:encoded>
      <pubDate>Wed, 19 Aug 2026 07:30:48 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/0a8d42fd/47a8c879.mp3" length="3125959" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>196</itunes:duration>
      <itunes:summary>CISA potwierdza ataki ransomware na CVE-2025-60710, Kimi Desktop ma krytyczną lukę w aktualizacjach, a Chainalysis pozywa rząd USA.</itunes:summary>
      <itunes:subtitle>CISA potwierdza ataki ransomware na CVE-2025-60710, Kimi Desktop ma krytyczną lukę w aktualizacjach, a Chainalysis pozywa rząd USA.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Luka w serwerze MCP CircleCI z oceną CVSS 10.0</title>
      <itunes:title>Luka w serwerze MCP CircleCI z oceną CVSS 10.0</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">bc0a5674-62a2-44b0-ba5f-25cf3dbfe92e</guid>
      <link>https://headflash.news/pl/security/2026-08-18-daily-newsletter</link>
      <description>
        <![CDATA[<p>Krytyczna podatność RCE w CircleCI MCP Server, wyciek danych 678 tys. osób z francuskiego urzędu skarbowego i inne ważne historie.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://remedio.io/blog/the-critical-unauthenticated-rce-vulnerability-in-circlecis-mcp-server">Unauthenticated RCE in CircleCI MCP Server Explained</a></li><li><a href="https://michaelcummin.gs/blog/hacking-nyc-building-permit-portal">Hacking the New York City Building Permit Portal | Michael Cummings</a></li><li><a href="https://deafnews.it/en/news/cybersecurity/passkey-bypass-three-attacks-demolish-phishing-resistant-authentication">Passkey Bypass: Three Attacks Demolish Phishing-Resistant… | DeafNews</a></li><li><a href="https://www.computerweekly.com/news/366649396/Revealed-Cyber-spies-used-malware-from-GitHub-to-hack-EncroChat-cryptophone-network">Revealed: Cyber spies used malware from GitHub to hack EncroChat cryptophone network | Computer Weekly</a></li><li><a href="https://thenextweb.com/news/french-tax-agency-breach-678000-dgfip-anssi-audit">France’s tax agency lost data on 678,000 people to a stolen login</a></li></ul><p><a href="https://headflash.news/pl/security/2026-08-18-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p><p>🤖 Odcinek opracowany przy pomocy sztucznej inteligencji. Lektor syntetyczny.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Krytyczna podatność RCE w CircleCI MCP Server, wyciek danych 678 tys. osób z francuskiego urzędu skarbowego i inne ważne historie.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://remedio.io/blog/the-critical-unauthenticated-rce-vulnerability-in-circlecis-mcp-server">Unauthenticated RCE in CircleCI MCP Server Explained</a></li><li><a href="https://michaelcummin.gs/blog/hacking-nyc-building-permit-portal">Hacking the New York City Building Permit Portal | Michael Cummings</a></li><li><a href="https://deafnews.it/en/news/cybersecurity/passkey-bypass-three-attacks-demolish-phishing-resistant-authentication">Passkey Bypass: Three Attacks Demolish Phishing-Resistant… | DeafNews</a></li><li><a href="https://www.computerweekly.com/news/366649396/Revealed-Cyber-spies-used-malware-from-GitHub-to-hack-EncroChat-cryptophone-network">Revealed: Cyber spies used malware from GitHub to hack EncroChat cryptophone network | Computer Weekly</a></li><li><a href="https://thenextweb.com/news/french-tax-agency-breach-678000-dgfip-anssi-audit">France’s tax agency lost data on 678,000 people to a stolen login</a></li></ul><p><a href="https://headflash.news/pl/security/2026-08-18-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p><p>🤖 Odcinek opracowany przy pomocy sztucznej inteligencji. Lektor syntetyczny.</p>]]>
      </content:encoded>
      <pubDate>Tue, 18 Aug 2026 09:02:14 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/5e9b0803/17e26f80.mp3" length="3636287" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>228</itunes:duration>
      <itunes:summary>Krytyczna podatność RCE w CircleCI MCP Server, wyciek danych 678 tys. osób z francuskiego urzędu skarbowego i inne ważne historie.</itunes:summary>
      <itunes:subtitle>Krytyczna podatność RCE w CircleCI MCP Server, wyciek danych 678 tys. osób z francuskiego urzędu skarbowego i inne ważne historie.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Ruby 4.0.6 z uniwersalnym łańcuchem RCE; Coldcard traci 130 mln USD</title>
      <itunes:title>Ruby 4.0.6 z uniwersalnym łańcuchem RCE; Coldcard traci 130 mln USD</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">24ac263b-8032-493f-a487-766913bd524e</guid>
      <link>https://headflash.news/pl/security/2026-08-17-daily-newsletter</link>
      <description>
        <![CDATA[<p>Nowy łańcuch gadgetów omija zabezpieczenia Ruby, atak na Coldcard opróżnia portfele, a Clop uderza w Shell i GE.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.elttam.com/blog/ruby-4-0-universal-rce-deserialization-gadget-chain">Ruby 4.0 Universal RCE Deserialization Gadget Chain - elttam</a></li><li><a href="https://www.thecooldown.com/green-tech/hackers-drain-bitcoin-cold-wallets-security/">Hackers drained $130 million in Bitcoin from 7,300 'cold' wallets once billed as secure</a></li><li><a href="https://www.digitaltrends.com/computing/u-s-courts-will-now-make-government-use-of-spyware-tools-public/">U.S. courts will now make government use of spyware tools public</a></li><li><a href="https://www.bbc.co.uk/news/articles/clyj92j210do">NHS Blood and Transplant investigate data breach due to pager use</a></li><li><a href="https://www.itpro.com/security/cyber-crime/expired-domains-are-a-goldmine-for-hackers-and-some-cyber-crime-groups-are-investing-millions-in-dropcatch-scams-to-deliver-malware">Expired domains are a goldmine for hackers – and some cyber crime groups are investing millions in 'dropcatch' scams to deliver malware</a></li><li><a href="https://deafnews.it/en/news/cybersecurity/metabase-zero-day-cve-2026-72898-active-exploitation-cvss-100-wide-blast-radius">Metabase Zero-Day CVE-2026-72898: Active Exploitation, CVSS… | DeafNews</a></li><li><a href="https://www.techtimes.com/articles/324578/20260815/clop-hacks-shell-ge-philips-43-victim-ptc-windchill-zero-day-campaign.htm">Clop Hacks Shell, GE, Philips in 43-Victim PTC Windchill Zero-Day Campaign</a></li><li><a href="https://thenextweb.com/news/shinyhunters-ringcentral-leak-voice-phishing-ey">A phone company just lost 1.6 million records to a phone call</a></li><li><a href="https://www.techtimes.com/articles/324574/20260815/macos-screen-sharing-flaw-actively-exploited-mine-monero-patch-now.htm">macOS Screen Sharing Flaw Actively Exploited to Mine Monero: Patch Now</a></li><li><a href="https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/">New Evooo1Bot Linux botnet turns routers into traffic relay nodes</a></li><li><a href="https://ransomnews.com/mcdonalds-employee-data-leak-2026">McDonald’s employee data listed for sale in wider Entra campaign | Ransomnews</a></li><li><a href="https://simonkoeck.com/writeups/n8n-gsuiteadmin-prototype-pollution-rce">CVE-2026-33696: From a Schema Name to RCE in n8n | Simon Koeck</a></li><li><a href="https://www.lightstalking.com/removing-exif-data-is-no-longer-enough-ai-can-now-tell-where-your-photos-are-taken-without-it/">Removing Exif Data Is No Longer Enough. AI Can Now Tell Where Your Photos Are Taken Without It</a></li></ul><p><a href="https://headflash.news/pl/security/2026-08-17-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p><p>🤖 Odcinek opracowany przy pomocy sztucznej inteligencji. Lektor syntetyczny.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Nowy łańcuch gadgetów omija zabezpieczenia Ruby, atak na Coldcard opróżnia portfele, a Clop uderza w Shell i GE.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.elttam.com/blog/ruby-4-0-universal-rce-deserialization-gadget-chain">Ruby 4.0 Universal RCE Deserialization Gadget Chain - elttam</a></li><li><a href="https://www.thecooldown.com/green-tech/hackers-drain-bitcoin-cold-wallets-security/">Hackers drained $130 million in Bitcoin from 7,300 'cold' wallets once billed as secure</a></li><li><a href="https://www.digitaltrends.com/computing/u-s-courts-will-now-make-government-use-of-spyware-tools-public/">U.S. courts will now make government use of spyware tools public</a></li><li><a href="https://www.bbc.co.uk/news/articles/clyj92j210do">NHS Blood and Transplant investigate data breach due to pager use</a></li><li><a href="https://www.itpro.com/security/cyber-crime/expired-domains-are-a-goldmine-for-hackers-and-some-cyber-crime-groups-are-investing-millions-in-dropcatch-scams-to-deliver-malware">Expired domains are a goldmine for hackers – and some cyber crime groups are investing millions in 'dropcatch' scams to deliver malware</a></li><li><a href="https://deafnews.it/en/news/cybersecurity/metabase-zero-day-cve-2026-72898-active-exploitation-cvss-100-wide-blast-radius">Metabase Zero-Day CVE-2026-72898: Active Exploitation, CVSS… | DeafNews</a></li><li><a href="https://www.techtimes.com/articles/324578/20260815/clop-hacks-shell-ge-philips-43-victim-ptc-windchill-zero-day-campaign.htm">Clop Hacks Shell, GE, Philips in 43-Victim PTC Windchill Zero-Day Campaign</a></li><li><a href="https://thenextweb.com/news/shinyhunters-ringcentral-leak-voice-phishing-ey">A phone company just lost 1.6 million records to a phone call</a></li><li><a href="https://www.techtimes.com/articles/324574/20260815/macos-screen-sharing-flaw-actively-exploited-mine-monero-patch-now.htm">macOS Screen Sharing Flaw Actively Exploited to Mine Monero: Patch Now</a></li><li><a href="https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/">New Evooo1Bot Linux botnet turns routers into traffic relay nodes</a></li><li><a href="https://ransomnews.com/mcdonalds-employee-data-leak-2026">McDonald’s employee data listed for sale in wider Entra campaign | Ransomnews</a></li><li><a href="https://simonkoeck.com/writeups/n8n-gsuiteadmin-prototype-pollution-rce">CVE-2026-33696: From a Schema Name to RCE in n8n | Simon Koeck</a></li><li><a href="https://www.lightstalking.com/removing-exif-data-is-no-longer-enough-ai-can-now-tell-where-your-photos-are-taken-without-it/">Removing Exif Data Is No Longer Enough. AI Can Now Tell Where Your Photos Are Taken Without It</a></li></ul><p><a href="https://headflash.news/pl/security/2026-08-17-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p><p>🤖 Odcinek opracowany przy pomocy sztucznej inteligencji. Lektor syntetyczny.</p>]]>
      </content:encoded>
      <pubDate>Mon, 17 Aug 2026 07:30:42 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/dcd45629/4055149f.mp3" length="5879056" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>368</itunes:duration>
      <itunes:summary>Nowy łańcuch gadgetów omija zabezpieczenia Ruby, atak na Coldcard opróżnia portfele, a Clop uderza w Shell i GE.</itunes:summary>
      <itunes:subtitle>Nowy łańcuch gadgetów omija zabezpieczenia Ruby, atak na Coldcard opróżnia portfele, a Clop uderza w Shell i GE.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Lazarus atakuje przez Windows zero-day; AI szturmem na Tajwan</title>
      <itunes:title>Lazarus atakuje przez Windows zero-day; AI szturmem na Tajwan</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">d0d51c5b-14da-49ed-9f8c-af673d27dd14</guid>
      <link>https://headflash.news/pl/security/2026-08-14-daily-newsletter</link>
      <description>
        <![CDATA[<p>Microsoft łata exploit wykorzystywany przez Lazarus, AI agenci zaatakowali Tajwan, a rozszerzenia IDE to nowa furtka dla atakujących.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.uniladtech.com/news/tech-news/microsoft-emergency-patch-north-korean-hackers-find-exploit-556700-20260813">Microsoft issues emergency patch as North Korean hackers caught exploiting dangerous flaw</a></li><li><a href="https://www.techtimes.com/articles/324237/20260813/open-source-ai-agents-breach-taiwan-nuclear-agency-four-day-autonomous-strike.htm">Open-Source AI Agents Breach Taiwan Nuclear Agency in Four-Day Autonomous Strike</a></li><li><a href="https://www.darkreading.com/threat-intelligence/jewelbug-apt-state-espionage-cryptocurrency-theft">'Jewelbug' APT Balances State Espionage &amp; Cryptocurrency Theft</a></li><li><a href="https://thenextweb.com/news/bloom-security-extension-resurrection-vscode-supply-chain">Bloom Security’s Extension Resurrection research exposes a blind spot in developer security</a></li><li><a href="https://www.androidauthority.com/chrome-update-pop-ups-extension-malware-3698053/">PSA: Don't trust that Chrome update popup — it could be malware</a></li></ul><p><a href="https://headflash.news/pl/security/2026-08-14-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p><p>🤖 Odcinek opracowany przy pomocy sztucznej inteligencji. Lektor syntetyczny.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Microsoft łata exploit wykorzystywany przez Lazarus, AI agenci zaatakowali Tajwan, a rozszerzenia IDE to nowa furtka dla atakujących.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.uniladtech.com/news/tech-news/microsoft-emergency-patch-north-korean-hackers-find-exploit-556700-20260813">Microsoft issues emergency patch as North Korean hackers caught exploiting dangerous flaw</a></li><li><a href="https://www.techtimes.com/articles/324237/20260813/open-source-ai-agents-breach-taiwan-nuclear-agency-four-day-autonomous-strike.htm">Open-Source AI Agents Breach Taiwan Nuclear Agency in Four-Day Autonomous Strike</a></li><li><a href="https://www.darkreading.com/threat-intelligence/jewelbug-apt-state-espionage-cryptocurrency-theft">'Jewelbug' APT Balances State Espionage &amp; Cryptocurrency Theft</a></li><li><a href="https://thenextweb.com/news/bloom-security-extension-resurrection-vscode-supply-chain">Bloom Security’s Extension Resurrection research exposes a blind spot in developer security</a></li><li><a href="https://www.androidauthority.com/chrome-update-pop-ups-extension-malware-3698053/">PSA: Don't trust that Chrome update popup — it could be malware</a></li></ul><p><a href="https://headflash.news/pl/security/2026-08-14-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p><p>🤖 Odcinek opracowany przy pomocy sztucznej inteligencji. Lektor syntetyczny.</p>]]>
      </content:encoded>
      <pubDate>Fri, 14 Aug 2026 09:02:19 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/22e023bc/6762b661.mp3" length="2492751" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>156</itunes:duration>
      <itunes:summary>Microsoft łata exploit wykorzystywany przez Lazarus, AI agenci zaatakowali Tajwan, a rozszerzenia IDE to nowa furtka dla atakujących.</itunes:summary>
      <itunes:subtitle>Microsoft łata exploit wykorzystywany przez Lazarus, AI agenci zaatakowali Tajwan, a rozszerzenia IDE to nowa furtka dla atakujących.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>LiteLLM supply chain breach exposes secrets of 2,488 firms</title>
      <itunes:title>LiteLLM supply chain breach exposes secrets of 2,488 firms</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">81003171-cf44-4994-b886-0329a8e73d16</guid>
      <link>https://headflash.news/pl/security/2026-08-13-daily-newsletter</link>
      <description>
        <![CDATA[<p>Atak na LiteLLM wyciekł 153 GB sekretów tysięcy firm. Windows kernel zero-day uderzał w obronność. Android malware łączy NFC relay z RAT.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.infostealers.com/article/largest-ai-supply-chain-breach-of-2026-litellm-hack-impacts-thousands-of-global-enterprises-claim-your-ethical-disclosure">Largest AI Supply Chain Breach of 2026: LiteLLM Hack Impacts Thousands of Global Enterprises - Claim Your Ethical Disclosure | InfoStealers</a></li><li><a href="https://www.techtimes.com/articles/324157/20260812/lazarus-group-hacked-defense-workers-windows-kernel-zero-day-five-weeks.htm">Lazarus Group Hacked Defense Workers With Windows Kernel Zero-Day for Five Weeks</a></li><li><a href="https://www.bleepingcomputer.com/news/security/android-malware-combo-takes-out-loans-and-relays-victims-credit-cards/">Android malware combo takes out loans and relays victims' credit cards</a></li><li><a href="https://www.bleepingcomputer.com/news/security/signal-adds-new-security-feature-to-thwart-man-in-the-middle-attacks/">Signal adds new security feature to thwart man-in-the-middle attacks</a></li><li><a href="https://www.wired.com/story/this-coin-sized-device-can-hack-a-boeing-737">This Coin-Sized Device Can Hack a Boeing 737 | WIRED</a></li></ul><p><a href="https://headflash.news/pl/security/2026-08-13-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p><p>🤖 Odcinek opracowany przy pomocy sztucznej inteligencji. Lektor syntetyczny.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Atak na LiteLLM wyciekł 153 GB sekretów tysięcy firm. Windows kernel zero-day uderzał w obronność. Android malware łączy NFC relay z RAT.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.infostealers.com/article/largest-ai-supply-chain-breach-of-2026-litellm-hack-impacts-thousands-of-global-enterprises-claim-your-ethical-disclosure">Largest AI Supply Chain Breach of 2026: LiteLLM Hack Impacts Thousands of Global Enterprises - Claim Your Ethical Disclosure | InfoStealers</a></li><li><a href="https://www.techtimes.com/articles/324157/20260812/lazarus-group-hacked-defense-workers-windows-kernel-zero-day-five-weeks.htm">Lazarus Group Hacked Defense Workers With Windows Kernel Zero-Day for Five Weeks</a></li><li><a href="https://www.bleepingcomputer.com/news/security/android-malware-combo-takes-out-loans-and-relays-victims-credit-cards/">Android malware combo takes out loans and relays victims' credit cards</a></li><li><a href="https://www.bleepingcomputer.com/news/security/signal-adds-new-security-feature-to-thwart-man-in-the-middle-attacks/">Signal adds new security feature to thwart man-in-the-middle attacks</a></li><li><a href="https://www.wired.com/story/this-coin-sized-device-can-hack-a-boeing-737">This Coin-Sized Device Can Hack a Boeing 737 | WIRED</a></li></ul><p><a href="https://headflash.news/pl/security/2026-08-13-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p><p>🤖 Odcinek opracowany przy pomocy sztucznej inteligencji. Lektor syntetyczny.</p>]]>
      </content:encoded>
      <pubDate>Thu, 13 Aug 2026 08:31:54 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/bfcd93ff/7e96f43e.mp3" length="3082910" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>193</itunes:duration>
      <itunes:summary>Atak na LiteLLM wyciekł 153 GB sekretów tysięcy firm. Windows kernel zero-day uderzał w obronność. Android malware łączy NFC relay z RAT.</itunes:summary>
      <itunes:subtitle>Atak na LiteLLM wyciekł 153 GB sekretów tysięcy firm. Windows kernel zero-day uderzał w obronność. Android malware łączy NFC relay z RAT.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Polska wini Rosjan za ataki na wodociągi; BTCPay wyznacza nagrodę</title>
      <itunes:title>Polska wini Rosjan za ataki na wodociągi; BTCPay wyznacza nagrodę</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">7421471b-5e79-4a04-b2fe-425557674d86</guid>
      <link>https://headflash.news/pl/security/2026-08-12-daily-newsletter</link>
      <description>
        <![CDATA[<p>Polska stawia zarzuty dwóm Rosjanom za 17 ataków na infrastrukturę, w tym na wodociągi. BTCPay oferuje 190 tys. dol. za odzyskanie skradzionych bitcoinów.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.techtimes.com/articles/323888/20260811/polands-water-hack-prosecution-names-russians-cant-reach-them-default-passwords-opened-plants.htm">Poland's Water Hack Prosecution Names Russians But Can't Reach Them: Default Passwords Opened Plants</a></li><li><a href="https://www.coindesk.com/markets/2026/08/11/btcpay-offers-usd190-000-bounty-after-bitcoin-payment-servers-drained-in-exploit">BTCPay offers $190,000 bounty after bitcoin payment servers drained in exploit</a></li><li><a href="https://inews.co.uk/news/media/bbc-emergency-putin-cyber-attack-4689896">Inside the BBC’s emergency plans for a Putin cyber attack</a></li><li><a href="https://thecyberexpress.com/new-zealand-sanctions-against-russia/">New Zealand Targets Russian Cyber Actors With Fresh Sanctions</a></li><li><a href="https://www.imperva.com/blog/copyescape-taking-over-docker-hosts-with-docker-cp">CopyEscape: Taking Over Docker Hosts with docker cp | Imperva</a></li><li><a href="https://thehackernews.com/2026/08/hackers-breach-polish-power-plant.html">Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine</a></li><li><a href="https://a.security/blog/asecurity-zoomsday">Ⓐ Cyber Security | Blog | ZOOMSDAY</a></li><li><a href="https://www.techtimes.com/articles/323949/20260811/deadlock-ransomware-hides-c2-polygon-blockchain-80-plus-victims-hit.htm">DeadLock Ransomware Hides C2 on Polygon Blockchain, 80-Plus Victims Hit</a></li></ul><p><a href="https://headflash.news/pl/security/2026-08-12-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p><p>🤖 Odcinek opracowany przy pomocy sztucznej inteligencji. Lektor syntetyczny.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Polska stawia zarzuty dwóm Rosjanom za 17 ataków na infrastrukturę, w tym na wodociągi. BTCPay oferuje 190 tys. dol. za odzyskanie skradzionych bitcoinów.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.techtimes.com/articles/323888/20260811/polands-water-hack-prosecution-names-russians-cant-reach-them-default-passwords-opened-plants.htm">Poland's Water Hack Prosecution Names Russians But Can't Reach Them: Default Passwords Opened Plants</a></li><li><a href="https://www.coindesk.com/markets/2026/08/11/btcpay-offers-usd190-000-bounty-after-bitcoin-payment-servers-drained-in-exploit">BTCPay offers $190,000 bounty after bitcoin payment servers drained in exploit</a></li><li><a href="https://inews.co.uk/news/media/bbc-emergency-putin-cyber-attack-4689896">Inside the BBC’s emergency plans for a Putin cyber attack</a></li><li><a href="https://thecyberexpress.com/new-zealand-sanctions-against-russia/">New Zealand Targets Russian Cyber Actors With Fresh Sanctions</a></li><li><a href="https://www.imperva.com/blog/copyescape-taking-over-docker-hosts-with-docker-cp">CopyEscape: Taking Over Docker Hosts with docker cp | Imperva</a></li><li><a href="https://thehackernews.com/2026/08/hackers-breach-polish-power-plant.html">Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine</a></li><li><a href="https://a.security/blog/asecurity-zoomsday">Ⓐ Cyber Security | Blog | ZOOMSDAY</a></li><li><a href="https://www.techtimes.com/articles/323949/20260811/deadlock-ransomware-hides-c2-polygon-blockchain-80-plus-victims-hit.htm">DeadLock Ransomware Hides C2 on Polygon Blockchain, 80-Plus Victims Hit</a></li></ul><p><a href="https://headflash.news/pl/security/2026-08-12-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p><p>🤖 Odcinek opracowany przy pomocy sztucznej inteligencji. Lektor syntetyczny.</p>]]>
      </content:encoded>
      <pubDate>Wed, 12 Aug 2026 09:01:11 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/32ea93b0/71e811f2.mp3" length="5079918" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>318</itunes:duration>
      <itunes:summary>Polska stawia zarzuty dwóm Rosjanom za 17 ataków na infrastrukturę, w tym na wodociągi. BTCPay oferuje 190 tys. dol. za odzyskanie skradzionych bitcoinów.</itunes:summary>
      <itunes:subtitle>Polska stawia zarzuty dwóm Rosjanom za 17 ataków na infrastrukturę, w tym na wodociągi. BTCPay oferuje 190 tys. dol. za odzyskanie skradzionych bitcoinów.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>OpenAI udostępnia GPT-5.6-Cyber: model znalazł luki w Chrome</title>
      <itunes:title>OpenAI udostępnia GPT-5.6-Cyber: model znalazł luki w Chrome</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">8e5dc776-2654-48f8-a14b-cfcad30b1278</guid>
      <link>https://headflash.news/pl/security/2026-08-11-daily-newsletter</link>
      <description>
        <![CDATA[<p>Nowy model OpenAI ma pomagać obrońcom, ale w testach odpowiada na 95 proc. scenariuszy ataków. Znalazł już luki w V8 i mobilnym systemie.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://the-decoder.com/openai-launches-gpt-5-6-cyber-to-help-defenders-find-vulnerabilities-before-attackers-do/">OpenAI launches GPT-5.6-Cyber to help defenders find vulnerabilities before attackers do</a></li></ul><p><a href="https://headflash.news/pl/security/2026-08-11-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p><p>🤖 Odcinek opracowany przy pomocy sztucznej inteligencji. Lektor syntetyczny.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Nowy model OpenAI ma pomagać obrońcom, ale w testach odpowiada na 95 proc. scenariuszy ataków. Znalazł już luki w V8 i mobilnym systemie.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://the-decoder.com/openai-launches-gpt-5-6-cyber-to-help-defenders-find-vulnerabilities-before-attackers-do/">OpenAI launches GPT-5.6-Cyber to help defenders find vulnerabilities before attackers do</a></li></ul><p><a href="https://headflash.news/pl/security/2026-08-11-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p><p>🤖 Odcinek opracowany przy pomocy sztucznej inteligencji. Lektor syntetyczny.</p>]]>
      </content:encoded>
      <pubDate>Tue, 11 Aug 2026 09:02:03 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/9bde7c4b/03b0774a.mp3" length="2189313" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>137</itunes:duration>
      <itunes:summary>Nowy model OpenAI ma pomagać obrońcom, ale w testach odpowiada na 95 proc. scenariuszy ataków. Znalazł już luki w V8 i mobilnym systemie.</itunes:summary>
      <itunes:subtitle>Nowy model OpenAI ma pomagać obrońcom, ale w testach odpowiada na 95 proc. scenariuszy ataków. Znalazł już luki w V8 i mobilnym systemie.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Backdoor w 100 tys. routerów Zbtlink, RCE w eID Belgii</title>
      <itunes:title>Backdoor w 100 tys. routerów Zbtlink, RCE w eID Belgii</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">9e306a50-400a-4b8c-b430-a00fbed5adc6</guid>
      <link>https://headflash.news/pl/security/2026-08-10-daily-newsletter</link>
      <description>
        <![CDATA[<p>Ukryte konto root w routerach Zbtlink, krytyczne dziury w belgijskim eID i OP-TEE, wyciek 181 tys. spotkań z tl;dv.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.sofx.com/chinese-router-backdoor-opens-root-access-on-100000-devices-worldwide">Chinese Router Backdoor Opens Root Access on 100,000 Devices Worldwide &amp;#8211; SOFX</a></li><li><a href="https://blog.byteray.co.uk/blog/optee-rsa-nopad-heap-underwrite.html">Trustfall: An RSA Heap Underwrite Into OP-TEE's Secure World &amp;middot; ByteRay Blog</a></li><li><a href="https://bobdahacker.com/blog/tldv-hack">tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open | bobdahacker</a></li><li><a href="https://thenewstack.io/npm-supply-chain-worm-attack/">The npm attack that turned provenance attestations into camouflage</a></li><li><a href="https://decrypt.co/375133/hackers-use-bnb-chain-spread-malware-fake-captchas">Hackers Use BNB Chain to Spread Malware Through Fake CAPTCHAs</a></li><li><a href="https://amibeingpwned.com/blog/8-in-10-banks-in-belgium">8 out of 10 Banks in Belgium HATE This One Weird eID RCE - Am I Being Pwned?</a></li><li><a href="https://www.varonis.com/blog/rovoblast">RovoBlast: How One Click Triggered Atlassian’s AI Assistant to Leak Data</a></li><li><a href="https://www.bleepingcomputer.com/news/security/hackers-breach-trueconf-to-trojanize-client-installers-with-backdoors/">Hackers breach TrueConf to trojanize client installers with backdoors</a></li><li><a href="https://www.coindesk.com/tech/2026/08/08/another-bitcoin-infrastructure-exploit-hits-this-time-draining-merchant-lightning-nodes">Another Bitcoin infrastructure exploit hits, this time draining Lightning payment servers</a></li><li><a href="https://pwnhackers.substack.com/p/researchers-wiretapped-a-whole-neighborhoods">Researchers wiretapped a whole neighborhood&amp;#x27;s fiber internet from home</a></li><li><a href="https://www.digitaltrends.com/computing/mit-tontou-spectre-attack-intel-amd-cpus/">MIT researchers found a new Spectre attack that can slip past Intel and AMD defenses</a></li><li><a href="https://www.techradar.com/pro/security/experts-warn-this-fake-claude-install-guide-can-be-used-to-empty-crypto-wallets">Experts warn this fake Claude install guide can be used to empty crypto wallets</a></li><li><a href="https://www.foxnews.com/tech/self-destructing-phone-code-sparks-federal-case">Self-destructing phone code sparks federal case</a></li><li><a href="https://www.dotsec.com/insecure-deserialisation-app-control-bypass">Bypassing Windows application whitelisting | dotSec</a></li></ul><p><a href="https://headflash.news/pl/security/2026-08-10-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p><p>🤖 Odcinek opracowany przy pomocy sztucznej inteligencji. Lektor syntetyczny.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Ukryte konto root w routerach Zbtlink, krytyczne dziury w belgijskim eID i OP-TEE, wyciek 181 tys. spotkań z tl;dv.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.sofx.com/chinese-router-backdoor-opens-root-access-on-100000-devices-worldwide">Chinese Router Backdoor Opens Root Access on 100,000 Devices Worldwide &amp;#8211; SOFX</a></li><li><a href="https://blog.byteray.co.uk/blog/optee-rsa-nopad-heap-underwrite.html">Trustfall: An RSA Heap Underwrite Into OP-TEE's Secure World &amp;middot; ByteRay Blog</a></li><li><a href="https://bobdahacker.com/blog/tldv-hack">tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open | bobdahacker</a></li><li><a href="https://thenewstack.io/npm-supply-chain-worm-attack/">The npm attack that turned provenance attestations into camouflage</a></li><li><a href="https://decrypt.co/375133/hackers-use-bnb-chain-spread-malware-fake-captchas">Hackers Use BNB Chain to Spread Malware Through Fake CAPTCHAs</a></li><li><a href="https://amibeingpwned.com/blog/8-in-10-banks-in-belgium">8 out of 10 Banks in Belgium HATE This One Weird eID RCE - Am I Being Pwned?</a></li><li><a href="https://www.varonis.com/blog/rovoblast">RovoBlast: How One Click Triggered Atlassian’s AI Assistant to Leak Data</a></li><li><a href="https://www.bleepingcomputer.com/news/security/hackers-breach-trueconf-to-trojanize-client-installers-with-backdoors/">Hackers breach TrueConf to trojanize client installers with backdoors</a></li><li><a href="https://www.coindesk.com/tech/2026/08/08/another-bitcoin-infrastructure-exploit-hits-this-time-draining-merchant-lightning-nodes">Another Bitcoin infrastructure exploit hits, this time draining Lightning payment servers</a></li><li><a href="https://pwnhackers.substack.com/p/researchers-wiretapped-a-whole-neighborhoods">Researchers wiretapped a whole neighborhood&amp;#x27;s fiber internet from home</a></li><li><a href="https://www.digitaltrends.com/computing/mit-tontou-spectre-attack-intel-amd-cpus/">MIT researchers found a new Spectre attack that can slip past Intel and AMD defenses</a></li><li><a href="https://www.techradar.com/pro/security/experts-warn-this-fake-claude-install-guide-can-be-used-to-empty-crypto-wallets">Experts warn this fake Claude install guide can be used to empty crypto wallets</a></li><li><a href="https://www.foxnews.com/tech/self-destructing-phone-code-sparks-federal-case">Self-destructing phone code sparks federal case</a></li><li><a href="https://www.dotsec.com/insecure-deserialisation-app-control-bypass">Bypassing Windows application whitelisting | dotSec</a></li></ul><p><a href="https://headflash.news/pl/security/2026-08-10-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p><p>🤖 Odcinek opracowany przy pomocy sztucznej inteligencji. Lektor syntetyczny.</p>]]>
      </content:encoded>
      <pubDate>Mon, 10 Aug 2026 09:00:28 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/cf91aa8d/73bbfe46.mp3" length="5795047" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>363</itunes:duration>
      <itunes:summary>Ukryte konto root w routerach Zbtlink, krytyczne dziury w belgijskim eID i OP-TEE, wyciek 181 tys. spotkań z tl;dv.</itunes:summary>
      <itunes:subtitle>Ukryte konto root w routerach Zbtlink, krytyczne dziury w belgijskim eID i OP-TEE, wyciek 181 tys. spotkań z tl;dv.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Claude Code podatny na atak przez złośliwy pull request</title>
      <itunes:title>Claude Code podatny na atak przez złośliwy pull request</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">f9790967-d0c4-4fd5-9c25-c1ad4ad96536</guid>
      <link>https://headflash.news/pl/security/2026-08-07-daily-newsletter</link>
      <description>
        <![CDATA[<p>Backdoor w routerach Zbtlink, wyciek Snowflake z wyrokiem, atak Midnight Blizzard i luka w portfelach kryptowalut.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.immersivelabs.com/resources/blog/claude-code-rce-vulnerability-how-a-malicious-pull-request-executes-code">Claude Code RCE: How a Malicious PR Triggers Code Execution</a></li><li><a href="https://9to5mac.com/2026/08/06/biggest-backdoor-yet-found-in-chinese-routers-sold-under-multiple-brand-names/">Biggest backdoor yet found in Chinese routers sold under multiple brand names</a></li><li><a href="https://hoodline.com/2026/08/canadian-hacker-admits-to-snowflake-breach-that-hit-at-t-ticketmaster/">Canadian Hacker Admits to Snowflake Breach That Hit AT&amp;T, Ticketmaster</a></li><li><a href="https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft">CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft | Microsoft Security Blog</a></li><li><a href="https://www.coinspect.com/blog/ill-bloom-investigation">Ill Bloom: Investigating a Wallet Generation Vulnerability During Active Exploitation</a></li></ul><p><a href="https://headflash.news/pl/security/2026-08-07-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Backdoor w routerach Zbtlink, wyciek Snowflake z wyrokiem, atak Midnight Blizzard i luka w portfelach kryptowalut.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.immersivelabs.com/resources/blog/claude-code-rce-vulnerability-how-a-malicious-pull-request-executes-code">Claude Code RCE: How a Malicious PR Triggers Code Execution</a></li><li><a href="https://9to5mac.com/2026/08/06/biggest-backdoor-yet-found-in-chinese-routers-sold-under-multiple-brand-names/">Biggest backdoor yet found in Chinese routers sold under multiple brand names</a></li><li><a href="https://hoodline.com/2026/08/canadian-hacker-admits-to-snowflake-breach-that-hit-at-t-ticketmaster/">Canadian Hacker Admits to Snowflake Breach That Hit AT&amp;T, Ticketmaster</a></li><li><a href="https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft">CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft | Microsoft Security Blog</a></li><li><a href="https://www.coinspect.com/blog/ill-bloom-investigation">Ill Bloom: Investigating a Wallet Generation Vulnerability During Active Exploitation</a></li></ul><p><a href="https://headflash.news/pl/security/2026-08-07-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Fri, 07 Aug 2026 08:32:26 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/757ee577/09f4fd61.mp3" length="3028993" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>190</itunes:duration>
      <itunes:summary>Backdoor w routerach Zbtlink, wyciek Snowflake z wyrokiem, atak Midnight Blizzard i luka w portfelach kryptowalut.</itunes:summary>
      <itunes:subtitle>Backdoor w routerach Zbtlink, wyciek Snowflake z wyrokiem, atak Midnight Blizzard i luka w portfelach kryptowalut.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>AISI: agent AI sam zaatakował realne cele w testach bezpieczeństwa</title>
      <itunes:title>AISI: agent AI sam zaatakował realne cele w testach bezpieczeństwa</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">5ec53d2a-415c-4f6a-b165-c3a7fa5df056</guid>
      <link>https://headflash.news/pl/security/2026-08-06-daily-newsletter</link>
      <description>
        <![CDATA[<p>Agent AI podczas testów AISI samodzielnie zaatakował realne podmioty. Nowe podatności w przeglądarkach AI i backdoor w routerach Zbtlink.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing">Incident Report: unsanctioned agent behaviour during cyber testing  | AISI Work</a></li><li><a href="https://www.darkreading.com/cyber-risk/ai-browsers-zero-click-agent-hijacking">AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking</a></li><li><a href="https://www.wired.com/story/a-security-pro-hacked-north-korean-hackers-he-found-theyd-breached-hundreds-of-networks-worldwide">A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide | WIRED</a></li><li><a href="https://decipher.sc/2026/08/05/researchers-find-persistent-backdoor-in-zbtlink-routers">Researchers Find Persistent Backdoor in Zbtlink Routers - Decipher</a></li><li><a href="https://www.kyivpost.com/post/81791">Russian State Hackers Target Hotel Wi-fi to Spy on Travelers, Microsoft Reports</a></li></ul><p><a href="https://headflash.news/pl/security/2026-08-06-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Agent AI podczas testów AISI samodzielnie zaatakował realne podmioty. Nowe podatności w przeglądarkach AI i backdoor w routerach Zbtlink.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing">Incident Report: unsanctioned agent behaviour during cyber testing  | AISI Work</a></li><li><a href="https://www.darkreading.com/cyber-risk/ai-browsers-zero-click-agent-hijacking">AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking</a></li><li><a href="https://www.wired.com/story/a-security-pro-hacked-north-korean-hackers-he-found-theyd-breached-hundreds-of-networks-worldwide">A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide | WIRED</a></li><li><a href="https://decipher.sc/2026/08/05/researchers-find-persistent-backdoor-in-zbtlink-routers">Researchers Find Persistent Backdoor in Zbtlink Routers - Decipher</a></li><li><a href="https://www.kyivpost.com/post/81791">Russian State Hackers Target Hotel Wi-fi to Spy on Travelers, Microsoft Reports</a></li></ul><p><a href="https://headflash.news/pl/security/2026-08-06-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Thu, 06 Aug 2026 08:31:19 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/b75b8e14/43bf1603.mp3" length="4033349" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>253</itunes:duration>
      <itunes:summary>Agent AI podczas testów AISI samodzielnie zaatakował realne podmioty. Nowe podatności w przeglądarkach AI i backdoor w routerach Zbtlink.</itunes:summary>
      <itunes:subtitle>Agent AI podczas testów AISI samodzielnie zaatakował realne podmioty. Nowe podatności w przeglądarkach AI i backdoor w routerach Zbtlink.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Google Passkeys mają luki, a atak na npm obejmuje 1300 pakietów</title>
      <itunes:title>Google Passkeys mają luki, a atak na npm obejmuje 1300 pakietów</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">e80ee630-6153-4dfe-9274-8bd52b1cbb13</guid>
      <link>https://headflash.news/pl/security/2026-08-05-daily-newsletter</link>
      <description>
        <![CDATA[<p>Google Passkeys z poważnymi lukami, ChainDrop infekuje 1300 pakietów npm, kradzież 130 mln USD z Coldcard i krytyczna podatność N-central.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.privacyguides.org/news/2026/08/03/multiple-flaws-in-googles-synced-passkey-implementation-allow-attackers-to-take-over-your-accounts">Multiple Flaws in Google's Synced Passkey Implementation Allow Attackers to Take Over Your Accounts</a></li><li><a href="https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/">Hackers steal over $130 million by exploiting bug in offline hardware wallets</a></li><li><a href="https://www.bleepingcomputer.com/news/security/massive-chaindrop-npm-supply-chain-attack-infects-hundreds-of-packages/">Massive ChainDrop npm supply-chain attack infects hundreds of packages</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/msps-urged-to-patch-immediately-after-n-able-issues-hotfix-for-n-central-god-mode-flaw">MSPs urged to patch immediately after N-able issues hotfix for N-central 'god mode' flaw</a></li><li><a href="https://decrypt.co/374933/bitcoin-bridge-shuts-down-ai-finding-bugs-too-fast">This Bitcoin Bridge Shut Itself Down Because AI Was Finding Bugs Too Fast</a></li></ul><p><a href="https://headflash.news/pl/security/2026-08-05-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Google Passkeys z poważnymi lukami, ChainDrop infekuje 1300 pakietów npm, kradzież 130 mln USD z Coldcard i krytyczna podatność N-central.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.privacyguides.org/news/2026/08/03/multiple-flaws-in-googles-synced-passkey-implementation-allow-attackers-to-take-over-your-accounts">Multiple Flaws in Google's Synced Passkey Implementation Allow Attackers to Take Over Your Accounts</a></li><li><a href="https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/">Hackers steal over $130 million by exploiting bug in offline hardware wallets</a></li><li><a href="https://www.bleepingcomputer.com/news/security/massive-chaindrop-npm-supply-chain-attack-infects-hundreds-of-packages/">Massive ChainDrop npm supply-chain attack infects hundreds of packages</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/msps-urged-to-patch-immediately-after-n-able-issues-hotfix-for-n-central-god-mode-flaw">MSPs urged to patch immediately after N-able issues hotfix for N-central 'god mode' flaw</a></li><li><a href="https://decrypt.co/374933/bitcoin-bridge-shuts-down-ai-finding-bugs-too-fast">This Bitcoin Bridge Shut Itself Down Because AI Was Finding Bugs Too Fast</a></li></ul><p><a href="https://headflash.news/pl/security/2026-08-05-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Wed, 05 Aug 2026 09:01:57 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/cd5c2814/ae53abfb.mp3" length="3912976" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>245</itunes:duration>
      <itunes:summary>Google Passkeys z poważnymi lukami, ChainDrop infekuje 1300 pakietów npm, kradzież 130 mln USD z Coldcard i krytyczna podatność N-central.</itunes:summary>
      <itunes:subtitle>Google Passkeys z poważnymi lukami, ChainDrop infekuje 1300 pakietów npm, kradzież 130 mln USD z Coldcard i krytyczna podatność N-central.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Microsoft wiąże ataki na Wi-Fi w hotelach z rosyjską grupą Storm-2945</title>
      <itunes:title>Microsoft wiąże ataki na Wi-Fi w hotelach z rosyjską grupą Storm-2945</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">9522d329-aeb7-4b52-8fa2-db47252bda85</guid>
      <link>https://headflash.news/pl/security/2026-08-04-daily-newsletter</link>
      <description>
        <![CDATA[<p>Grupa powiązana z Midnight Blizzard atakuje gości hotelowych przez fałszywe logowania Microsoft 365. Nowe malware CornFlake i ChocoShell w akcji.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.bleepingcomputer.com/news/security/hotel-wi-fi-attacks-use-custom-malware-to-breach-microsoft-365-accounts/">Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts</a></li><li><a href="https://www.bleepingcomputer.com/news/security/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys/">New Pass-ta-key attacks let malware hijack Google-synced passkeys</a></li><li><a href="https://research.jfrog.com/post/sqlite-critical-cves-or-llm-slops/">SQLite Critical CVEs or LLM Slop? - JFrog Security Research</a></li><li><a href="https://www.tomshardware.com/laptops/ai-enthusiast-mods-bios-with-claude-code-ai-defeats-rsa-2048-signature-checks-and-unlocks-55-hidden-settings/">AI enthusiast unlocks and mods BIOS with Claude Code — AI defeats RSA-2048 signature checks and unlocks 55 hidden settings | Tom's Hardware</a></li><li><a href="https://www.bleepingcomputer.com/news/security/new-doublecup-clickfix-service-hides-malware-in-browser-cache-images/">New DOUBLECUP ClickFix service hides malware in browser cache images</a></li><li><a href="https://research.jfrog.com/post/sqlite-critical-cves-or-llm-slops">SQLite Critical CVEs or LLM Slop? - JFrog Security Research</a></li><li><a href="https://www.tomshardware.com/laptops/ai-enthusiast-mods-bios-with-claude-code-ai-defeats-rsa-2048-signature-checks-and-unlocks-55-hidden-settings">AI enthusiast unlocks and mods BIOS with Claude Code &amp;mdash; AI defeats RSA-2048 signature checks and unlocks 55 hidden settings | Tom's Hardware</a></li></ul><p><a href="https://headflash.news/pl/security/2026-08-04-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Grupa powiązana z Midnight Blizzard atakuje gości hotelowych przez fałszywe logowania Microsoft 365. Nowe malware CornFlake i ChocoShell w akcji.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.bleepingcomputer.com/news/security/hotel-wi-fi-attacks-use-custom-malware-to-breach-microsoft-365-accounts/">Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts</a></li><li><a href="https://www.bleepingcomputer.com/news/security/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys/">New Pass-ta-key attacks let malware hijack Google-synced passkeys</a></li><li><a href="https://research.jfrog.com/post/sqlite-critical-cves-or-llm-slops/">SQLite Critical CVEs or LLM Slop? - JFrog Security Research</a></li><li><a href="https://www.tomshardware.com/laptops/ai-enthusiast-mods-bios-with-claude-code-ai-defeats-rsa-2048-signature-checks-and-unlocks-55-hidden-settings/">AI enthusiast unlocks and mods BIOS with Claude Code — AI defeats RSA-2048 signature checks and unlocks 55 hidden settings | Tom's Hardware</a></li><li><a href="https://www.bleepingcomputer.com/news/security/new-doublecup-clickfix-service-hides-malware-in-browser-cache-images/">New DOUBLECUP ClickFix service hides malware in browser cache images</a></li><li><a href="https://research.jfrog.com/post/sqlite-critical-cves-or-llm-slops">SQLite Critical CVEs or LLM Slop? - JFrog Security Research</a></li><li><a href="https://www.tomshardware.com/laptops/ai-enthusiast-mods-bios-with-claude-code-ai-defeats-rsa-2048-signature-checks-and-unlocks-55-hidden-settings">AI enthusiast unlocks and mods BIOS with Claude Code &amp;mdash; AI defeats RSA-2048 signature checks and unlocks 55 hidden settings | Tom's Hardware</a></li></ul><p><a href="https://headflash.news/pl/security/2026-08-04-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Tue, 04 Aug 2026 09:01:52 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/c162c6b2/1b061443.mp3" length="3677665" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>230</itunes:duration>
      <itunes:summary>Grupa powiązana z Midnight Blizzard atakuje gości hotelowych przez fałszywe logowania Microsoft 365. Nowe malware CornFlake i ChocoShell w akcji.</itunes:summary>
      <itunes:subtitle>Grupa powiązana z Midnight Blizzard atakuje gości hotelowych przez fałszywe logowania Microsoft 365. Nowe malware CornFlake i ChocoShell w akcji.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>AI atakuje, łańcuchy dostaw krwawią, a Ty czytasz to z opóźnieniem</title>
      <itunes:title>AI atakuje, łańcuchy dostaw krwawią, a Ty czytasz to z opóźnieniem</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">9a778469-ee1e-4624-9c62-6449fcebd269</guid>
      <link>https://headflash.news/pl/security/2026-08-03-daily-newsletter</link>
      <description>
        <![CDATA[<p>Claude włamało się do firm, DeepSeek prowadziło cyberataki, Arch Linux zamraża AUR, a Coldcard stracił 70 mln USD. Oto przegląd.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.bleepingcomputer.com/news/security/anthropics-claude-breached-3-orgs-uploaded-pypi-malware-during-tests">Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests</a></li><li><a href="https://aws.amazon.com/blogs/security/amazon-identifies-north-korean-hacker-group-behind-open-source-supply-chain-attacks">Amazon identifies North Korean hacker group behind open-source supply chain attacks | AWS Security Blog</a></li><li><a href="https://www.techtimes.com/articles/322510/20260731/ftx-begins-900m-payout-kroll-breach-left-creditors-exposed-scammers.htm">FTX Begins $900M Payout: Kroll Breach Left Creditors Exposed to Scammers</a></li><li><a href="https://the-decoder.com/a-security-researcher-built-a-self-spreading-worm-that-hides-inside-word-docs-and-hijacks-microsoft-copilot">A security researcher built a self-spreading worm that hides inside Word docs and hijacks Microsoft Copilot</a></li><li><a href="https://www.techtimes.com/articles/322582/20260801/deepseek-ran-autonomous-cyberattacks-that-claude-openai-safety-controls-blocked.htm">DeepSeek Ran Autonomous Cyberattacks That Claude and OpenAI Safety Controls Blocked</a></li><li><a href="https://247wallst.com/investing/cryptocurrency/2026/08/01/coldcard-hacked-for-70m-how-do-you-keep-bitcoin-safe-if-cold-wallets-can-be-hacked">Coldcard Hacked for $70M: How Do You Keep Bitcoin Safe if Cold Wallets Can Be Hacked?</a></li><li><a href="https://www.techtimes.com/articles/322619/20260801/arch-linux-freezes-aur-adoption-tor-backed-rust-infostealer-bypasses-june-defenses-third-wave.htm">Arch Linux Freezes AUR Adoption: Tor-Backed Rust Infostealer Bypasses June Defenses in Third Wave</a></li><li><a href="https://www.privacyguides.org/news/2026/07/29/over-100-vulnerabilities-found-in-irs-contractor-handling-americans-tax-information">Over 100 Vulnerabilities Found in IRS Contractor Handling Americans' Tax Information</a></li><li><a href="https://www.msecops.de/blog/posts/backdoored-llms">The Risk of Fine-Tuned Open-Weight Models · MSec Operations Blog</a></li><li><a href="https://www.digitaltrends.com/computing/ai-is-finding-apple-security-flaws-faster-than-apple-can-sort-through-them">AI is finding Apple security flaws faster than Apple can sort through them</a></li><li><a href="https://www.tomshardware.com/tech-industry/cyber-security/iran-suspected-of-conducting-cyberattacks-on-us-water-suppliers-in-45-municipalities-small-towns-mostly-targeted-with-utilities-switching-to-manual-control">Iran suspected of conducting cyberattacks on US water suppliers in 45 municipalities — small towns mostly targeted, with utilities switching to manual control</a></li><li><a href="https://the-decoder.com/a-security-researcher-built-a-self-spreading-worm-that-hides-inside-word-docs-and-hijacks-microsoft-copilot/">A security researcher built a self-spreading worm that hides inside Word docs and hijacks Microsoft Copilot</a></li><li><a href="https://247wallst.com/investing/cryptocurrency/2026/08/01/coldcard-hacked-for-70m-how-do-you-keep-bitcoin-safe-if-cold-wallets-can-be-hacked/">Coldcard Hacked for $70M: How Do You Keep Bitcoin Safe if Cold Wallets Can Be Hacked?</a></li><li><a href="https://www.digitaltrends.com/computing/ai-is-finding-apple-security-flaws-faster-than-apple-can-sort-through-them/">AI is finding Apple security flaws faster than Apple can sort through them</a></li></ul><p><a href="https://headflash.news/pl/security/2026-08-03-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Claude włamało się do firm, DeepSeek prowadziło cyberataki, Arch Linux zamraża AUR, a Coldcard stracił 70 mln USD. Oto przegląd.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.bleepingcomputer.com/news/security/anthropics-claude-breached-3-orgs-uploaded-pypi-malware-during-tests">Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests</a></li><li><a href="https://aws.amazon.com/blogs/security/amazon-identifies-north-korean-hacker-group-behind-open-source-supply-chain-attacks">Amazon identifies North Korean hacker group behind open-source supply chain attacks | AWS Security Blog</a></li><li><a href="https://www.techtimes.com/articles/322510/20260731/ftx-begins-900m-payout-kroll-breach-left-creditors-exposed-scammers.htm">FTX Begins $900M Payout: Kroll Breach Left Creditors Exposed to Scammers</a></li><li><a href="https://the-decoder.com/a-security-researcher-built-a-self-spreading-worm-that-hides-inside-word-docs-and-hijacks-microsoft-copilot">A security researcher built a self-spreading worm that hides inside Word docs and hijacks Microsoft Copilot</a></li><li><a href="https://www.techtimes.com/articles/322582/20260801/deepseek-ran-autonomous-cyberattacks-that-claude-openai-safety-controls-blocked.htm">DeepSeek Ran Autonomous Cyberattacks That Claude and OpenAI Safety Controls Blocked</a></li><li><a href="https://247wallst.com/investing/cryptocurrency/2026/08/01/coldcard-hacked-for-70m-how-do-you-keep-bitcoin-safe-if-cold-wallets-can-be-hacked">Coldcard Hacked for $70M: How Do You Keep Bitcoin Safe if Cold Wallets Can Be Hacked?</a></li><li><a href="https://www.techtimes.com/articles/322619/20260801/arch-linux-freezes-aur-adoption-tor-backed-rust-infostealer-bypasses-june-defenses-third-wave.htm">Arch Linux Freezes AUR Adoption: Tor-Backed Rust Infostealer Bypasses June Defenses in Third Wave</a></li><li><a href="https://www.privacyguides.org/news/2026/07/29/over-100-vulnerabilities-found-in-irs-contractor-handling-americans-tax-information">Over 100 Vulnerabilities Found in IRS Contractor Handling Americans' Tax Information</a></li><li><a href="https://www.msecops.de/blog/posts/backdoored-llms">The Risk of Fine-Tuned Open-Weight Models · MSec Operations Blog</a></li><li><a href="https://www.digitaltrends.com/computing/ai-is-finding-apple-security-flaws-faster-than-apple-can-sort-through-them">AI is finding Apple security flaws faster than Apple can sort through them</a></li><li><a href="https://www.tomshardware.com/tech-industry/cyber-security/iran-suspected-of-conducting-cyberattacks-on-us-water-suppliers-in-45-municipalities-small-towns-mostly-targeted-with-utilities-switching-to-manual-control">Iran suspected of conducting cyberattacks on US water suppliers in 45 municipalities — small towns mostly targeted, with utilities switching to manual control</a></li><li><a href="https://the-decoder.com/a-security-researcher-built-a-self-spreading-worm-that-hides-inside-word-docs-and-hijacks-microsoft-copilot/">A security researcher built a self-spreading worm that hides inside Word docs and hijacks Microsoft Copilot</a></li><li><a href="https://247wallst.com/investing/cryptocurrency/2026/08/01/coldcard-hacked-for-70m-how-do-you-keep-bitcoin-safe-if-cold-wallets-can-be-hacked/">Coldcard Hacked for $70M: How Do You Keep Bitcoin Safe if Cold Wallets Can Be Hacked?</a></li><li><a href="https://www.digitaltrends.com/computing/ai-is-finding-apple-security-flaws-faster-than-apple-can-sort-through-them/">AI is finding Apple security flaws faster than Apple can sort through them</a></li></ul><p><a href="https://headflash.news/pl/security/2026-08-03-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Mon, 03 Aug 2026 09:01:34 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/24ab7ff2/b5d120ad.mp3" length="7805848" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>488</itunes:duration>
      <itunes:summary>Claude włamało się do firm, DeepSeek prowadziło cyberataki, Arch Linux zamraża AUR, a Coldcard stracił 70 mln USD. Oto przegląd.</itunes:summary>
      <itunes:subtitle>Claude włamało się do firm, DeepSeek prowadziło cyberataki, Arch Linux zamraża AUR, a Coldcard stracił 70 mln USD. Oto przegląd.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>CosmosEscape, Claude atakuje, OWAReaper i inne — przegląd security</title>
      <itunes:title>CosmosEscape, Claude atakuje, OWAReaper i inne — przegląd security</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">b9a0f790-ccec-4639-a3e6-e9fb119a2274</guid>
      <link>https://headflash.news/pl/security/2026-07-31-daily-newsletter</link>
      <description>
        <![CDATA[<p>Krytyczna luka w Azure Cosmos DB, ucieczki modeli AI na produkcję, backdoor przetrwający reinstalację i kampanie APT — oto najważniejsze historie.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.wiz.io/blog/cosmosescape-taking-over-every-database-in-azure-cosmos-db">CosmosEscape: Taking Over Every Azure Cosmos DB | Wiz Blog</a></li><li><a href="https://www.bleepingcomputer.com/news/security/claude-uploaded-malware-to-pypi-in-anthropics-botched-test/">Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests</a></li><li><a href="https://www.bleepingcomputer.com/news/security/amazon-links-debug-chalk-npm-supply-chain-attacks-to-north-korean-hackers/">Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers</a></li><li><a href="https://www.techtimes.com/articles/322178/20260730/russian-hackers-breached-exchange-servers-owareaper-implant-survives-re-imaging.htm">Russian Hackers Breached Exchange Servers With OWAReaper: Implant Survives Re-Imaging</a></li><li><a href="https://www.techtimes.com/articles/322157/20260730/state-hackers-made-south-koreas-mandatory-banking-software-zero-day-weapon.htm">State Hackers Made South Korea's Mandatory Banking Software Into Zero-Day Weapon</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-31-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Krytyczna luka w Azure Cosmos DB, ucieczki modeli AI na produkcję, backdoor przetrwający reinstalację i kampanie APT — oto najważniejsze historie.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.wiz.io/blog/cosmosescape-taking-over-every-database-in-azure-cosmos-db">CosmosEscape: Taking Over Every Azure Cosmos DB | Wiz Blog</a></li><li><a href="https://www.bleepingcomputer.com/news/security/claude-uploaded-malware-to-pypi-in-anthropics-botched-test/">Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests</a></li><li><a href="https://www.bleepingcomputer.com/news/security/amazon-links-debug-chalk-npm-supply-chain-attacks-to-north-korean-hackers/">Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers</a></li><li><a href="https://www.techtimes.com/articles/322178/20260730/russian-hackers-breached-exchange-servers-owareaper-implant-survives-re-imaging.htm">Russian Hackers Breached Exchange Servers With OWAReaper: Implant Survives Re-Imaging</a></li><li><a href="https://www.techtimes.com/articles/322157/20260730/state-hackers-made-south-koreas-mandatory-banking-software-zero-day-weapon.htm">State Hackers Made South Korea's Mandatory Banking Software Into Zero-Day Weapon</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-31-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Fri, 31 Jul 2026 08:32:03 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/4cd104cf/bacd3bb6.mp3" length="3597417" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>225</itunes:duration>
      <itunes:summary>Krytyczna luka w Azure Cosmos DB, ucieczki modeli AI na produkcję, backdoor przetrwający reinstalację i kampanie APT — oto najważniejsze historie.</itunes:summary>
      <itunes:subtitle>Krytyczna luka w Azure Cosmos DB, ucieczki modeli AI na produkcję, backdoor przetrwający reinstalację i kampanie APT — oto najważniejsze historie.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>AI zalewa Microsoft; Iran atakuje wodociągi; rekord kryptohakerów</title>
      <itunes:title>AI zalewa Microsoft; Iran atakuje wodociągi; rekord kryptohakerów</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">733c9b9a-df8e-4b87-bbe2-d8d6f1c2650d</guid>
      <link>https://headflash.news/pl/security/2026-07-30-daily-newsletter</link>
      <description>
        <![CDATA[<p>Mythos AI znajduje setki krytycznych błędów Microsoftu. Iran atakuje 30 wodociągów w Minnesocie. Kryptohakerzy kradną miliard dolarów w pół roku.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.propublica.org/article/anthropic-mythos-microsoft-software-vulnerabilities">Microsoft Struggling With Hundreds of AI-Discovered Security Bugs — ProPublica</a></li><li><a href="https://www.techtimes.com/articles/322059/20260729/iranian-hackers-exploited-unpatchable-plc-flaw-breach-30-minnesota-water-systems.htm">Iranian Hackers Exploited Unpatchable PLC Flaw to Breach 30 Minnesota Water Systems</a></li><li><a href="https://www.techtimes.com/articles/321943/20260729/iran-deploys-nightledger-backdoor-websocket-relays-across-six-nations.htm">Iran Deploys NightLedger Backdoor and WebSocket Relays Across Six Nations</a></li><li><a href="https://www.techtimes.com/articles/321926/20260729/rebuilt-six-days-dysphoria-iot-botnet-hides-blockchain-defy-seizure.htm">Rebuilt in Six Days: Dysphoria IoT Botnet Hides on Blockchain to Defy Seizure</a></li><li><a href="https://www.techtimes.com/articles/321940/20260729/crypto-hacks-hit-all-time-high-north-korea-drains-over-600m-ai-agents-become-new-target.htm">Crypto Hacks Hit All-Time High as North Korea Drains Over $600M and AI Agents Become New Target</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-30-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Mythos AI znajduje setki krytycznych błędów Microsoftu. Iran atakuje 30 wodociągów w Minnesocie. Kryptohakerzy kradną miliard dolarów w pół roku.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.propublica.org/article/anthropic-mythos-microsoft-software-vulnerabilities">Microsoft Struggling With Hundreds of AI-Discovered Security Bugs — ProPublica</a></li><li><a href="https://www.techtimes.com/articles/322059/20260729/iranian-hackers-exploited-unpatchable-plc-flaw-breach-30-minnesota-water-systems.htm">Iranian Hackers Exploited Unpatchable PLC Flaw to Breach 30 Minnesota Water Systems</a></li><li><a href="https://www.techtimes.com/articles/321943/20260729/iran-deploys-nightledger-backdoor-websocket-relays-across-six-nations.htm">Iran Deploys NightLedger Backdoor and WebSocket Relays Across Six Nations</a></li><li><a href="https://www.techtimes.com/articles/321926/20260729/rebuilt-six-days-dysphoria-iot-botnet-hides-blockchain-defy-seizure.htm">Rebuilt in Six Days: Dysphoria IoT Botnet Hides on Blockchain to Defy Seizure</a></li><li><a href="https://www.techtimes.com/articles/321940/20260729/crypto-hacks-hit-all-time-high-north-korea-drains-over-600m-ai-agents-become-new-target.htm">Crypto Hacks Hit All-Time High as North Korea Drains Over $600M and AI Agents Become New Target</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-30-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Thu, 30 Jul 2026 10:01:13 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/61b8597a/772dcc3e.mp3" length="3184056" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>199</itunes:duration>
      <itunes:summary>Mythos AI znajduje setki krytycznych błędów Microsoftu. Iran atakuje 30 wodociągów w Minnesocie. Kryptohakerzy kradną miliard dolarów w pół roku.</itunes:summary>
      <itunes:subtitle>Mythos AI znajduje setki krytycznych błędów Microsoftu. Iran atakuje 30 wodociągów w Minnesocie. Kryptohakerzy kradną miliard dolarów w pół roku.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Skynet Day, Botnet Watchdog i federalny VPN do kasacji</title>
      <itunes:title>Skynet Day, Botnet Watchdog i federalny VPN do kasacji</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">5a3a8107-2c95-4bd8-8a93-74743cf75fe3</guid>
      <link>https://headflash.news/pl/security/2026-07-29-daily-newsletter</link>
      <description>
        <![CDATA[<p>OpenAI model uciekł z piaskownicy, Tengu używa watchdog do zacierania śladów, a Sen. Wyden chce wyeliminować legacy VPN w rządzie USA.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.thecooldown.com/green-tech/openai-model-cybersecurity-hugging-face-incident/">Internet decides 'Skynet Day' has arrived after OpenAI says model escaped its sandbox to hack test</a></li><li><a href="https://lavahq.io/research/bmc-exposure-alert">How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability | Lava</a></li><li><a href="https://deafnews.it/en/news/malware/brickstorm-chinese-backdoor-targets-us-and-canadian-critical-infrastructure">BRICKSTORM: Chinese Backdoor Targets US and Canadian Critical… | DeafNews</a></li><li><a href="https://www.techtimes.com/articles/321800/20260728/tengu-botnet-uses-hardware-watchdog-erase-forensic-evidence-reboot.htm">Tengu Botnet Uses Hardware Watchdog to Erase Forensic Evidence on Reboot</a></li><li><a href="https://www.techtimes.com/articles/321768/20260728/wyden-demands-two-year-federal-vpn-purge-zero-trust-procurement-rule-would-reshape-vendor-market.htm">Wyden Demands Two-Year Federal VPN Purge: Zero-Trust Procurement Rule Would Reshape Vendor Market</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-29-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>OpenAI model uciekł z piaskownicy, Tengu używa watchdog do zacierania śladów, a Sen. Wyden chce wyeliminować legacy VPN w rządzie USA.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.thecooldown.com/green-tech/openai-model-cybersecurity-hugging-face-incident/">Internet decides 'Skynet Day' has arrived after OpenAI says model escaped its sandbox to hack test</a></li><li><a href="https://lavahq.io/research/bmc-exposure-alert">How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability | Lava</a></li><li><a href="https://deafnews.it/en/news/malware/brickstorm-chinese-backdoor-targets-us-and-canadian-critical-infrastructure">BRICKSTORM: Chinese Backdoor Targets US and Canadian Critical… | DeafNews</a></li><li><a href="https://www.techtimes.com/articles/321800/20260728/tengu-botnet-uses-hardware-watchdog-erase-forensic-evidence-reboot.htm">Tengu Botnet Uses Hardware Watchdog to Erase Forensic Evidence on Reboot</a></li><li><a href="https://www.techtimes.com/articles/321768/20260728/wyden-demands-two-year-federal-vpn-purge-zero-trust-procurement-rule-would-reshape-vendor-market.htm">Wyden Demands Two-Year Federal VPN Purge: Zero-Trust Procurement Rule Would Reshape Vendor Market</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-29-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Wed, 29 Jul 2026 09:02:34 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/98c8289c/36cefada.mp3" length="4752656" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>298</itunes:duration>
      <itunes:summary>OpenAI model uciekł z piaskownicy, Tengu używa watchdog do zacierania śladów, a Sen. Wyden chce wyeliminować legacy VPN w rządzie USA.</itunes:summary>
      <itunes:subtitle>OpenAI model uciekł z piaskownicy, Tengu używa watchdog do zacierania śladów, a Sen. Wyden chce wyeliminować legacy VPN w rządzie USA.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Botnety, sabotaż i wycieki – security w ogniu</title>
      <itunes:title>Botnety, sabotaż i wycieki – security w ogniu</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">2ec08d82-8200-4780-b9c8-6d18465b6d55</guid>
      <link>https://headflash.news/pl/security/2026-07-28-daily-newsletter</link>
      <description>
        <![CDATA[<p>Iran atakuje PLC w USA, botnet Dysphoria rośnie do 200 tys. urządzeń, a Coca-Cola potwierdza kradzież danych po ransomware.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://deafnews.it/en/news/cybersecurity/iran-apt-sabotages-us-plcs-cisa-warns-of-physical-risk">Iran APT Sabotages US PLCs: CISA Warns of Physical Risk | DeafNews</a></li><li><a href="https://www.bleepingcomputer.com/news/security/new-dysphoria-ddos-botnet-spreads-to-200k-devices-worldwide/">New Dysphoria DDoS botnet spreads to 200k devices worldwide</a></li><li><a href="https://variety.com/2026/film/news/tribeca-festival-data-leak-jennifer-lawrence-robert-de-niro-1236822023/">Massive Tribeca Fest Data Leak Exposes Jennifer Lawrence, Robert De Niro and More Celebs’ Contact Info; Meet the Man Who Discovered the Files</a></li><li><a href="https://www.bleepingcomputer.com/news/security/coca-cola-confirms-data-theft-in-fairlife-ransomware-attack/">Coca-Cola confirms data theft in Fairlife ransomware attack</a></li><li><a href="https://www.darkreading.com/cyberattacks-data-breaches/ai-agent-espionage-attack-thai-ministry-finance">AI Agent Drives Espionage Attack on Thai Ministry of Finance</a></li><li><a href="https://variety.com/2026/film/news/tribeca-festival-data-leak-jennifer-lawrence-robert-de-niro-1236822023/#utm_campaign=syndication&amp;utm_source=flipboard&amp;utm_medium=referral">Massive Tribeca Fest Data Leak Exposes Jennifer Lawrence, Robert De Niro and More Celebs’ Contact Info; Meet the Man Who Discovered the Files</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-28-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Iran atakuje PLC w USA, botnet Dysphoria rośnie do 200 tys. urządzeń, a Coca-Cola potwierdza kradzież danych po ransomware.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://deafnews.it/en/news/cybersecurity/iran-apt-sabotages-us-plcs-cisa-warns-of-physical-risk">Iran APT Sabotages US PLCs: CISA Warns of Physical Risk | DeafNews</a></li><li><a href="https://www.bleepingcomputer.com/news/security/new-dysphoria-ddos-botnet-spreads-to-200k-devices-worldwide/">New Dysphoria DDoS botnet spreads to 200k devices worldwide</a></li><li><a href="https://variety.com/2026/film/news/tribeca-festival-data-leak-jennifer-lawrence-robert-de-niro-1236822023/">Massive Tribeca Fest Data Leak Exposes Jennifer Lawrence, Robert De Niro and More Celebs’ Contact Info; Meet the Man Who Discovered the Files</a></li><li><a href="https://www.bleepingcomputer.com/news/security/coca-cola-confirms-data-theft-in-fairlife-ransomware-attack/">Coca-Cola confirms data theft in Fairlife ransomware attack</a></li><li><a href="https://www.darkreading.com/cyberattacks-data-breaches/ai-agent-espionage-attack-thai-ministry-finance">AI Agent Drives Espionage Attack on Thai Ministry of Finance</a></li><li><a href="https://variety.com/2026/film/news/tribeca-festival-data-leak-jennifer-lawrence-robert-de-niro-1236822023/#utm_campaign=syndication&amp;utm_source=flipboard&amp;utm_medium=referral">Massive Tribeca Fest Data Leak Exposes Jennifer Lawrence, Robert De Niro and More Celebs’ Contact Info; Meet the Man Who Discovered the Files</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-28-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Tue, 28 Jul 2026 09:02:44 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/c31250be/8effd574.mp3" length="2951670" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>185</itunes:duration>
      <itunes:summary>Iran atakuje PLC w USA, botnet Dysphoria rośnie do 200 tys. urządzeń, a Coca-Cola potwierdza kradzież danych po ransomware.</itunes:summary>
      <itunes:subtitle>Iran atakuje PLC w USA, botnet Dysphoria rośnie do 200 tys. urządzeń, a Coca-Cola potwierdza kradzież danych po ransomware.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>AI agent hula się, Rosjanie testują na Ukrainie, a fałszywy plugin Notepad++ kradnie dane</title>
      <itunes:title>AI agent hula się, Rosjanie testują na Ukrainie, a fałszywy plugin Notepad++ kradnie dane</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">275a3d43-0264-40fe-bca6-2da55325cec1</guid>
      <link>https://headflash.news/pl/security/2026-07-27-daily-newsletter</link>
      <description>
        <![CDATA[<p>Rogue AI atakuje Hugging Face, rosyjscy hakerzy testują metody na Ukrainie, a fałszywy plugin Notepad++ infekuje obrońców.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.kyivpost.com/post/81027">Russian Hackers Used Ukraine as Test Ground Before Targeting US Nuclear Scientists</a></li><li><a href="https://9to5mac.com/2026/07/24/new-lawsuit-alleges-unpatchable-apple-chip-exploit-was-developed-using-stolen-trade-secrets/">New lawsuit alleges unpatchable Apple chip exploit was developed using stolen trade secrets</a></li><li><a href="https://www.bleepingcomputer.com/news/security/hackers-hijack-hotel-wi-fi-dns-to-steal-microsoft-365-accounts">Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts</a></li><li><a href="https://www.group-ib.com/blog/jadeprox-china-nexus-triback-loader">JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake | Group-IB Blog</a></li><li><a href="https://www.accomplish.ai/blog/sharedroot-escaping-claude-cowork-sandbox">SharedRoot; Escaping the Claude Cowork sandbox — Accomplish Blog</a></li><li><a href="https://www.tomshardware.com/tech-industry/artificial-intelligence/openai-agent-goes-rogue-and-hacks-popular-ai-community-left-escape-plans-for-future-models-inside-the-companys-infrastructure">OpenAI agent goes rogue and hacks popular AI community — left escape plans for future models inside the company's infrastructure</a></li><li><a href="https://www.techtimes.com/articles/321549/20260725/claude-opus-5-hacked-enterprise-networks-8-10-government-tests-safety-card-shows.htm">Claude Opus 5 Hacked Enterprise Networks in 8 of 10 Government Tests, Safety Card Shows</a></li><li><a href="https://www.techtimes.com/articles/321558/20260725/fake-notepad-plugin-hides-russian-malware-targeting-ukrainian-defense-teams.htm">Fake Notepad++ Plugin Hides Russian Malware Targeting Ukrainian Defense Teams</a></li><li><a href="https://www.foxnews.com/tech/clicklock-mac-malware-locks-apps-until-you-give-in">ClickLock Mac malware locks apps until you give in</a></li><li><a href="https://news.bitcoin.com/8000-devices-infected-80-crypto-wallets-accessed-by-video-game-malware/">8,000 Devices Infected, 80 Crypto Wallets Accessed by Video Game Malware</a></li><li><a href="https://hackernoon.com/stop-writing-incident-reports-start-writing-case-law-gaps-from-openai-and-hugging-face-disclosure">Stop Writing Incident Reports, Start Writing Case Law: Gaps from OpenAI and Hugging Face Disclosure | HackerNoon</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-27-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Rogue AI atakuje Hugging Face, rosyjscy hakerzy testują metody na Ukrainie, a fałszywy plugin Notepad++ infekuje obrońców.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.kyivpost.com/post/81027">Russian Hackers Used Ukraine as Test Ground Before Targeting US Nuclear Scientists</a></li><li><a href="https://9to5mac.com/2026/07/24/new-lawsuit-alleges-unpatchable-apple-chip-exploit-was-developed-using-stolen-trade-secrets/">New lawsuit alleges unpatchable Apple chip exploit was developed using stolen trade secrets</a></li><li><a href="https://www.bleepingcomputer.com/news/security/hackers-hijack-hotel-wi-fi-dns-to-steal-microsoft-365-accounts">Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts</a></li><li><a href="https://www.group-ib.com/blog/jadeprox-china-nexus-triback-loader">JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake | Group-IB Blog</a></li><li><a href="https://www.accomplish.ai/blog/sharedroot-escaping-claude-cowork-sandbox">SharedRoot; Escaping the Claude Cowork sandbox — Accomplish Blog</a></li><li><a href="https://www.tomshardware.com/tech-industry/artificial-intelligence/openai-agent-goes-rogue-and-hacks-popular-ai-community-left-escape-plans-for-future-models-inside-the-companys-infrastructure">OpenAI agent goes rogue and hacks popular AI community — left escape plans for future models inside the company's infrastructure</a></li><li><a href="https://www.techtimes.com/articles/321549/20260725/claude-opus-5-hacked-enterprise-networks-8-10-government-tests-safety-card-shows.htm">Claude Opus 5 Hacked Enterprise Networks in 8 of 10 Government Tests, Safety Card Shows</a></li><li><a href="https://www.techtimes.com/articles/321558/20260725/fake-notepad-plugin-hides-russian-malware-targeting-ukrainian-defense-teams.htm">Fake Notepad++ Plugin Hides Russian Malware Targeting Ukrainian Defense Teams</a></li><li><a href="https://www.foxnews.com/tech/clicklock-mac-malware-locks-apps-until-you-give-in">ClickLock Mac malware locks apps until you give in</a></li><li><a href="https://news.bitcoin.com/8000-devices-infected-80-crypto-wallets-accessed-by-video-game-malware/">8,000 Devices Infected, 80 Crypto Wallets Accessed by Video Game Malware</a></li><li><a href="https://hackernoon.com/stop-writing-incident-reports-start-writing-case-law-gaps-from-openai-and-hugging-face-disclosure">Stop Writing Incident Reports, Start Writing Case Law: Gaps from OpenAI and Hugging Face Disclosure | HackerNoon</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-27-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Mon, 27 Jul 2026 09:01:40 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/fba15c4b/471f1a43.mp3" length="11325483" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>708</itunes:duration>
      <itunes:summary>Rogue AI atakuje Hugging Face, rosyjscy hakerzy testują metody na Ukrainie, a fałszywy plugin Notepad++ infekuje obrońców.</itunes:summary>
      <itunes:subtitle>Rogue AI atakuje Hugging Face, rosyjscy hakerzy testują metody na Ukrainie, a fałszywy plugin Notepad++ infekuje obrońców.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>AI w natarciu, Linux podatny, dane w rękach hakerów</title>
      <itunes:title>AI w natarciu, Linux podatny, dane w rękach hakerów</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">49b7b2f8-a7aa-42d7-911f-e5e42ca9360f</guid>
      <link>https://headflash.news/pl/security/2026-07-24-daily-newsletter</link>
      <description>
        <![CDATA[<p>Wyciek danych, AI w ataku, podatności Linux i ChatGPT – najważniejsze historie dnia.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.sbs.com.au/news/article/not-just-phishing-the-scams-to-watch-for-if-youre-an-origin-energy-customer/3jauqz344">„Not just phishing: The scams to watch for if you're an Origin Energy customer”</a></li><li><a href="https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent">„Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged”</a></li><li><a href="https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-zimbra-zero-click-flaw-for-email-theft/">„Russian hackers exploit Zimbra zero-click flaw for email theft”</a></li><li><a href="https://www.techtimes.com/articles/321359/20260723/linux-kernel-flaw-exposes-16-million-rhel-systems-silent-root-takeover.htm">„Linux Kernel Flaw Exposes 16 Million RHEL Systems to Silent Root Takeover”</a></li><li><a href="https://the-decoder.com/one-tampered-chatgpt-link-could-spawn-a-rogue-ai-agent-that-took-orders-from-an-attacker-every-five-minutes/">„One tampered ChatGPT link could spawn a rogue AI agent that took orders from an attacker every five minutes”</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-24-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Wyciek danych, AI w ataku, podatności Linux i ChatGPT – najważniejsze historie dnia.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.sbs.com.au/news/article/not-just-phishing-the-scams-to-watch-for-if-youre-an-origin-energy-customer/3jauqz344">„Not just phishing: The scams to watch for if you're an Origin Energy customer”</a></li><li><a href="https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent">„Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged”</a></li><li><a href="https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-zimbra-zero-click-flaw-for-email-theft/">„Russian hackers exploit Zimbra zero-click flaw for email theft”</a></li><li><a href="https://www.techtimes.com/articles/321359/20260723/linux-kernel-flaw-exposes-16-million-rhel-systems-silent-root-takeover.htm">„Linux Kernel Flaw Exposes 16 Million RHEL Systems to Silent Root Takeover”</a></li><li><a href="https://the-decoder.com/one-tampered-chatgpt-link-could-spawn-a-rogue-ai-agent-that-took-orders-from-an-attacker-every-five-minutes/">„One tampered ChatGPT link could spawn a rogue AI agent that took orders from an attacker every five minutes”</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-24-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Fri, 24 Jul 2026 09:31:46 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/55c28f1a/4abea708.mp3" length="3809741" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>239</itunes:duration>
      <itunes:summary>Wyciek danych, AI w ataku, podatności Linux i ChatGPT – najważniejsze historie dnia.</itunes:summary>
      <itunes:subtitle>Wyciek danych, AI w ataku, podatności Linux i ChatGPT – najważniejsze historie dnia.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Microsoft zabija SMS MFA, AI oszukuje testy, a nowe backdoory celują w rodziny</title>
      <itunes:title>Microsoft zabija SMS MFA, AI oszukuje testy, a nowe backdoory celują w rodziny</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">a63bcbbd-f3a0-46eb-a332-3c146c1f286a</guid>
      <link>https://headflash.news/pl/security/2026-07-23-daily-newsletter</link>
      <description>
        <![CDATA[<p>Microsoft wymusza passkeys do 2027, AI modele oszukują testy bezpieczeństwa, a nowy backdoor APT42 przetrwa zmianę hasła.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.windowslatest.com/2026/07/22/microsoft-admits-sms-and-voice-mfa-cant-stop-ai-attacks-mandates-passkeys-in-entra-by-february-2027">Microsoft admits SMS and voice MFA can’t stop AI attacks, mandates passkeys in Entra by February 2027</a></li><li><a href="https://www.404media.co/license-plate-reader-company-flock-is-building-a-massive-people-lookup-tool-leak-shows">License Plate Reader Company Flock Is Building a Massive People Lookup Tool, Leak Shows</a></li><li><a href="https://www.techtimes.com/articles/321272/20260722/iranian-spies-now-use-ai-lures-telegram-c2-backdoor-that-survives-password-resets.htm">Iranian Spies Now Use AI Lures, Telegram C2, and a Backdoor That Survives Password Resets</a></li><li><a href="https://www.varonis.com/blog/dolphin-x-stealer">Dolphin X Stealer Targets 300+ Apps and Profiles Users with AI</a></li><li><a href="https://the-decoder.com/every-frontier-ai-model-tested-by-britains-safety-institute-tried-to-cheat-on-cybersecurity-evaluations/">Every frontier AI model tested by Britain's safety institute tried to cheat on cybersecurity evaluations</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-23-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Microsoft wymusza passkeys do 2027, AI modele oszukują testy bezpieczeństwa, a nowy backdoor APT42 przetrwa zmianę hasła.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.windowslatest.com/2026/07/22/microsoft-admits-sms-and-voice-mfa-cant-stop-ai-attacks-mandates-passkeys-in-entra-by-february-2027">Microsoft admits SMS and voice MFA can’t stop AI attacks, mandates passkeys in Entra by February 2027</a></li><li><a href="https://www.404media.co/license-plate-reader-company-flock-is-building-a-massive-people-lookup-tool-leak-shows">License Plate Reader Company Flock Is Building a Massive People Lookup Tool, Leak Shows</a></li><li><a href="https://www.techtimes.com/articles/321272/20260722/iranian-spies-now-use-ai-lures-telegram-c2-backdoor-that-survives-password-resets.htm">Iranian Spies Now Use AI Lures, Telegram C2, and a Backdoor That Survives Password Resets</a></li><li><a href="https://www.varonis.com/blog/dolphin-x-stealer">Dolphin X Stealer Targets 300+ Apps and Profiles Users with AI</a></li><li><a href="https://the-decoder.com/every-frontier-ai-model-tested-by-britains-safety-institute-tried-to-cheat-on-cybersecurity-evaluations/">Every frontier AI model tested by Britain's safety institute tried to cheat on cybersecurity evaluations</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-23-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Thu, 23 Jul 2026 09:08:19 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/8e269195/d125c462.mp3" length="4659034" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>292</itunes:duration>
      <itunes:summary>Microsoft wymusza passkeys do 2027, AI modele oszukują testy bezpieczeństwa, a nowy backdoor APT42 przetrwa zmianę hasła.</itunes:summary>
      <itunes:subtitle>Microsoft wymusza passkeys do 2027, AI modele oszukują testy bezpieczeństwa, a nowy backdoor APT42 przetrwa zmianę hasła.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Szybki przegląd: AI ucieka, dane wyciekają, piraci tracą domeny</title>
      <itunes:title>Szybki przegląd: AI ucieka, dane wyciekają, piraci tracą domeny</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">22b19bfc-5762-46db-a0fc-909500de7d1e</guid>
      <link>https://headflash.news/pl/security/2026-07-22-daily-newsletter</link>
      <description>
        <![CDATA[<p>Codzienna dawka najważniejszych wiadomości ze świata bezpieczeństwa: od uciekających modeli AI po największą w historii akcję antypiracką.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.wired.com/story/openai-models-escaped-containment-and-hacked-huggingface">OpenAI Models Escaped Containment and Hacked Hugging Face | WIRED</a></li><li><a href="https://www.techtimes.com/articles/321142/20260721/free-world-cup-streams-infected-devices-doj-seizes-1000-domains-historic-crackdown.htm">Free World Cup Streams Infected Devices: DOJ Seizes 1,000 Domains in Historic Crackdown</a></li><li><a href="https://www.bleepingcomputer.com/news/security/fakegit-campaign-uses-7-600-github-repos-to-push-smartloader-malware/">FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware</a></li><li><a href="https://www.zdnet.com/article/ernst-young-breach-exposed-client-tax-data/">Ernst &amp; Young breach exposes client tax data - find out if you're at risk and what to do next</a></li><li><a href="https://www.wired.com/story/a-device-hidden-in-cars-across-the-us-leaves-them-vulnerable-to-hacking-and-paralysis-patch-it-now">A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now | WIRED</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-22-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Codzienna dawka najważniejszych wiadomości ze świata bezpieczeństwa: od uciekających modeli AI po największą w historii akcję antypiracką.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.wired.com/story/openai-models-escaped-containment-and-hacked-huggingface">OpenAI Models Escaped Containment and Hacked Hugging Face | WIRED</a></li><li><a href="https://www.techtimes.com/articles/321142/20260721/free-world-cup-streams-infected-devices-doj-seizes-1000-domains-historic-crackdown.htm">Free World Cup Streams Infected Devices: DOJ Seizes 1,000 Domains in Historic Crackdown</a></li><li><a href="https://www.bleepingcomputer.com/news/security/fakegit-campaign-uses-7-600-github-repos-to-push-smartloader-malware/">FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware</a></li><li><a href="https://www.zdnet.com/article/ernst-young-breach-exposed-client-tax-data/">Ernst &amp; Young breach exposes client tax data - find out if you're at risk and what to do next</a></li><li><a href="https://www.wired.com/story/a-device-hidden-in-cars-across-the-us-leaves-them-vulnerable-to-hacking-and-paralysis-patch-it-now">A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now | WIRED</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-22-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Wed, 22 Jul 2026 09:32:41 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/30c74fff/4596567a.mp3" length="2919487" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>183</itunes:duration>
      <itunes:summary>Codzienna dawka najważniejszych wiadomości ze świata bezpieczeństwa: od uciekających modeli AI po największą w historii akcję antypiracką.</itunes:summary>
      <itunes:subtitle>Codzienna dawka najważniejszych wiadomości ze świata bezpieczeństwa: od uciekających modeli AI po największą w historii akcję antypiracką.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>AI kontra AI, dziura w WordPressie i agentowy chaos</title>
      <itunes:title>AI kontra AI, dziura w WordPressie i agentowy chaos</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">06e97ff7-681e-4b69-b538-5e28e8155167</guid>
      <link>https://headflash.news/pl/security/2026-07-21-daily-newsletter</link>
      <description>
        <![CDATA[<p>Hugging Face odparło autonomiczny atak AI. GPT znalazło RCE w WordPressie. Agenci AI mają ten sam problem.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://gizmodo.com/hugging-face-we-used-ai-to-catch-the-first-confirmed-ai-agent-breach-of-a-major-ai-platform-2000787778">Hugging Face: We Used AI to Catch the First Confirmed AI Agent Breach of a Major AI Platform</a></li><li><a href="https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6">Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25 › Searchlight Cyber</a></li><li><a href="https://www.group-ib.com/blog/hollowgraph-microsoft-365">HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels | Group-IB Blog</a></li><li><a href="https://www.foxnews.com/tech/redhook-android-malware-quietly-hijack-phone">RedHook Android malware can quietly hijack your phone</a></li><li><a href="https://thenextweb.com/news/ai-agent-security-four-attacks-one-flaw">Four teams just broke AI agents four ways in ten days. The flaw is the same one.</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-21-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Hugging Face odparło autonomiczny atak AI. GPT znalazło RCE w WordPressie. Agenci AI mają ten sam problem.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://gizmodo.com/hugging-face-we-used-ai-to-catch-the-first-confirmed-ai-agent-breach-of-a-major-ai-platform-2000787778">Hugging Face: We Used AI to Catch the First Confirmed AI Agent Breach of a Major AI Platform</a></li><li><a href="https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6">Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25 › Searchlight Cyber</a></li><li><a href="https://www.group-ib.com/blog/hollowgraph-microsoft-365">HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels | Group-IB Blog</a></li><li><a href="https://www.foxnews.com/tech/redhook-android-malware-quietly-hijack-phone">RedHook Android malware can quietly hijack your phone</a></li><li><a href="https://thenextweb.com/news/ai-agent-security-four-attacks-one-flaw">Four teams just broke AI agents four ways in ten days. The flaw is the same one.</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-21-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Tue, 21 Jul 2026 08:01:41 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/ab9d7bab/e1506c31.mp3" length="4524869" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>283</itunes:duration>
      <itunes:summary>Hugging Face odparło autonomiczny atak AI. GPT znalazło RCE w WordPressie. Agenci AI mają ten sam problem.</itunes:summary>
      <itunes:subtitle>Hugging Face odparło autonomiczny atak AI. GPT znalazło RCE w WordPressie. Agenci AI mają ten sam problem.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>FortiSandbox w ogniu, WordPress na celowniku – przegląd bezpieczeństwa</title>
      <itunes:title>FortiSandbox w ogniu, WordPress na celowniku – przegląd bezpieczeństwa</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">c09b15d7-72b8-40f8-9ad4-e7624db29a19</guid>
      <link>https://headflash.news/pl/security/2026-07-20-daily-newsletter</link>
      <description>
        <![CDATA[<p>CISA potwierdza exploitację krytycznych luk w FortiSandbox, WordPress łata RCE bez uwierzytelnienia, a hakerzy kradną dane EY i 10 mln pasażerów londyńskiego metra.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.techtimes.com/articles/320892/20260718/fortisandbox-exploited-wild-patch-sunday-trust-chain-collapses.htm">FortiSandbox Exploited in Wild: Patch by Sunday or Trust Chain Collapses</a></li><li><a href="https://ransomnews.com/wp2shell-wordpress-core-rce-2026">wp2shell: pre-auth RCE in WordPress core (CVE-2026-63030) | Ransomnews</a></li><li><a href="https://www.techtimes.com/articles/320969/20260719/ey-tax-data-stolen-through-third-party-help-desk-platform-four-states-notified.htm">EY Tax Data Stolen Through Third-Party Help-Desk Platform, Four States Notified</a></li><li><a href="https://www.techtimes.com/articles/320871/20260717/vishing-call-brought-down-tfl-scattered-spider-duo-jailed-record-uk-prosecution.htm">Vishing Call Brought Down TfL: Scattered Spider Duo Jailed in Record UK Prosecution</a></li><li><a href="https://www.techtimes.com/articles/320796/20260717/goserpent-backdoor-looted-police-biometric-data-across-southeast-asia-five-years.htm">GoSerpent Backdoor Looted Police and Biometric Data Across Southeast Asia for Five Years</a></li><li><a href="https://www.rferl.org/a/russia-hacker-fsb-thailand-dutch-us-cyber-fraud/33805051.html">An Alleged Russian FSB Hacker Traveled To Thailand. Now He's Facing 10 Years In A US Prison.</a></li><li><a href="https://www.itpro.com/security/cyber-crime/cisco-sounds-alarm-over-new-russian-malware-campaign-hitting-firms-in-us-and-europe">Cisco sounds alarm over new Russian malware campaign hitting firms in US and Europe</a></li><li><a href="https://www.techtimes.com/articles/320927/20260718/north-korea-buried-four-stage-malware-flag-images-zero-antivirus-detections.htm">North Korea Buried Four-Stage Malware in Flag Images: Zero Antivirus Detections</a></li><li><a href="https://www.techtimes.com/articles/320804/20260717/unauthenticated-debug-port-rockwell-adapter-gives-attackers-plant-floor-control.htm">Unauthenticated Debug Port in Rockwell Adapter Gives Attackers Plant-Floor Control</a></li><li><a href="https://zenger.news/s-bcnd-qs30/">Trump says China stole 220 million U.S. voter files in largest election-data breach</a></li><li><a href="https://thenextweb.com/news/world-cup-stolen-streaming-accounts-dark-web-220-million">Cybercriminals released 802,000 stolen accounts in one day during the World Cup group stage</a></li><li><a href="https://www.techtimes.com/articles/320970/20260719/firefox-exploit-code-goes-public-chrome-adobe-vmware-ship-emergency-patches.htm">Firefox Exploit Code Goes Public as Chrome, Adobe, VMware Ship Emergency Patches</a></li><li><a href="https://www.techspot.com/news/113163-fbi-arrests-21-year-old-accused-infecting-8000.html">FBI arrests 21-year-old accused of infecting 8,000 PCs with malware through fake Steam games</a></li><li><a href="https://futurism.com/future-society/easy-poison-open-weight-ai">It's Laughably Easy to Poison Open-Weight AI Models, Researcher Finds</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-20-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>CISA potwierdza exploitację krytycznych luk w FortiSandbox, WordPress łata RCE bez uwierzytelnienia, a hakerzy kradną dane EY i 10 mln pasażerów londyńskiego metra.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.techtimes.com/articles/320892/20260718/fortisandbox-exploited-wild-patch-sunday-trust-chain-collapses.htm">FortiSandbox Exploited in Wild: Patch by Sunday or Trust Chain Collapses</a></li><li><a href="https://ransomnews.com/wp2shell-wordpress-core-rce-2026">wp2shell: pre-auth RCE in WordPress core (CVE-2026-63030) | Ransomnews</a></li><li><a href="https://www.techtimes.com/articles/320969/20260719/ey-tax-data-stolen-through-third-party-help-desk-platform-four-states-notified.htm">EY Tax Data Stolen Through Third-Party Help-Desk Platform, Four States Notified</a></li><li><a href="https://www.techtimes.com/articles/320871/20260717/vishing-call-brought-down-tfl-scattered-spider-duo-jailed-record-uk-prosecution.htm">Vishing Call Brought Down TfL: Scattered Spider Duo Jailed in Record UK Prosecution</a></li><li><a href="https://www.techtimes.com/articles/320796/20260717/goserpent-backdoor-looted-police-biometric-data-across-southeast-asia-five-years.htm">GoSerpent Backdoor Looted Police and Biometric Data Across Southeast Asia for Five Years</a></li><li><a href="https://www.rferl.org/a/russia-hacker-fsb-thailand-dutch-us-cyber-fraud/33805051.html">An Alleged Russian FSB Hacker Traveled To Thailand. Now He's Facing 10 Years In A US Prison.</a></li><li><a href="https://www.itpro.com/security/cyber-crime/cisco-sounds-alarm-over-new-russian-malware-campaign-hitting-firms-in-us-and-europe">Cisco sounds alarm over new Russian malware campaign hitting firms in US and Europe</a></li><li><a href="https://www.techtimes.com/articles/320927/20260718/north-korea-buried-four-stage-malware-flag-images-zero-antivirus-detections.htm">North Korea Buried Four-Stage Malware in Flag Images: Zero Antivirus Detections</a></li><li><a href="https://www.techtimes.com/articles/320804/20260717/unauthenticated-debug-port-rockwell-adapter-gives-attackers-plant-floor-control.htm">Unauthenticated Debug Port in Rockwell Adapter Gives Attackers Plant-Floor Control</a></li><li><a href="https://zenger.news/s-bcnd-qs30/">Trump says China stole 220 million U.S. voter files in largest election-data breach</a></li><li><a href="https://thenextweb.com/news/world-cup-stolen-streaming-accounts-dark-web-220-million">Cybercriminals released 802,000 stolen accounts in one day during the World Cup group stage</a></li><li><a href="https://www.techtimes.com/articles/320970/20260719/firefox-exploit-code-goes-public-chrome-adobe-vmware-ship-emergency-patches.htm">Firefox Exploit Code Goes Public as Chrome, Adobe, VMware Ship Emergency Patches</a></li><li><a href="https://www.techspot.com/news/113163-fbi-arrests-21-year-old-accused-infecting-8000.html">FBI arrests 21-year-old accused of infecting 8,000 PCs with malware through fake Steam games</a></li><li><a href="https://futurism.com/future-society/easy-poison-open-weight-ai">It's Laughably Easy to Poison Open-Weight AI Models, Researcher Finds</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-20-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Mon, 20 Jul 2026 08:01:46 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/051bf5dc/860fe9a4.mp3" length="8085881" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>506</itunes:duration>
      <itunes:summary>CISA potwierdza exploitację krytycznych luk w FortiSandbox, WordPress łata RCE bez uwierzytelnienia, a hakerzy kradną dane EY i 10 mln pasażerów londyńskiego metra.</itunes:summary>
      <itunes:subtitle>CISA potwierdza exploitację krytycznych luk w FortiSandbox, WordPress łata RCE bez uwierzytelnienia, a hakerzy kradną dane EY i 10 mln pasażerów londyńskiego metra.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Krytyczne luki, RCE w odkurzaczach i atak na Fairlife – przegląd bezpieczeństwa</title>
      <itunes:title>Krytyczne luki, RCE w odkurzaczach i atak na Fairlife – przegląd bezpieczeństwa</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">cc0a64c6-46e0-4817-9b6b-ae2e3430e35e</guid>
      <link>https://headflash.news/pl/security/2026-07-17-daily-newsletter</link>
      <description>
        <![CDATA[<p>Zoom łatuje podatność 9.8, 7-Zip bez fixa na RCE, Google naprawia przejęcie konta, a SharkNinja ignoruje dziurę w milionach robotów.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.bleepingcomputer.com/news/security/zoom-warns-of-critical-account-takeover-vulnerability">Zoom warns of critical account takeover vulnerability</a></li><li><a href="https://deafnews.it/en/news/vulnerabilities/7-zip-xz-parser-rce-vulnerability-opening-an-archive-is-enough">7-Zip XZ Parser RCE Vulnerability: Opening an Archive Is Enough | DeafNews</a></li><li><a href="https://weirdmachine64.github.io/research/google-oauth-device-code-hijacking.html">Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking // weirdmachine64</a></li><li><a href="https://tokay0.com/posts/millions-of-shark-vacuums-vulnerable-to-rce.html">Just a moment...</a></li><li><a href="https://www.bleepingcomputer.com/news/security/coca-cola-says-fairlife-ransomware-attack-halts-us-dairy-production/">Coca-Cola says Fairlife ransomware attack halts US dairy production</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-17-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Zoom łatuje podatność 9.8, 7-Zip bez fixa na RCE, Google naprawia przejęcie konta, a SharkNinja ignoruje dziurę w milionach robotów.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.bleepingcomputer.com/news/security/zoom-warns-of-critical-account-takeover-vulnerability">Zoom warns of critical account takeover vulnerability</a></li><li><a href="https://deafnews.it/en/news/vulnerabilities/7-zip-xz-parser-rce-vulnerability-opening-an-archive-is-enough">7-Zip XZ Parser RCE Vulnerability: Opening an Archive Is Enough | DeafNews</a></li><li><a href="https://weirdmachine64.github.io/research/google-oauth-device-code-hijacking.html">Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking // weirdmachine64</a></li><li><a href="https://tokay0.com/posts/millions-of-shark-vacuums-vulnerable-to-rce.html">Just a moment...</a></li><li><a href="https://www.bleepingcomputer.com/news/security/coca-cola-says-fairlife-ransomware-attack-halts-us-dairy-production/">Coca-Cola says Fairlife ransomware attack halts US dairy production</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-17-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Fri, 17 Jul 2026 09:01:50 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/8d7b4c11/9bdc1c70.mp3" length="2658681" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>167</itunes:duration>
      <itunes:summary>Zoom łatuje podatność 9.8, 7-Zip bez fixa na RCE, Google naprawia przejęcie konta, a SharkNinja ignoruje dziurę w milionach robotów.</itunes:summary>
      <itunes:subtitle>Zoom łatuje podatność 9.8, 7-Zip bez fixa na RCE, Google naprawia przejęcie konta, a SharkNinja ignoruje dziurę w milionach robotów.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>BitLocker, 570 łat, rosyjski hosting i malware na Maca</title>
      <itunes:title>BitLocker, 570 łat, rosyjski hosting i malware na Maca</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">8ee51928-0cf5-4b1a-87f8-907f8960e878</guid>
      <link>https://headflash.news/pl/security/2026-07-16-daily-newsletter</link>
      <description>
        <![CDATA[<p>Microsoft łata BitLocker, rekord 570 błędów, oskarżenia o rosyjskie hostingi i nowe macOS malware.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://thecybersecguru.com/news/bitlocker-zero-day-cve-2026-50661">Windows BitLocker Zero-Day (CVE-2026-50661) Lets Attackers Bypass Encryption | The CyberSec Guru</a></li><li><a href="https://www.zdnet.com/article/microsoft-patches-570-vulnerabilities-exploited-zero-days/">Microsoft patches record 570 Windows security bugs with two exploited zero days - update now</a></li><li><a href="https://timesofindia.indiatimes.com/india/kudankulam-nuclear-plant-data-breached-npcil-says-core-systems-untouched/articleshow/132425150.cms">Kudankulam nuclear plant data breached, NPCIL says core systems untouched</a></li><li><a href="https://techcrunch.com/2026/07/15/us-charges-russian-bulletproof-web-hosts-over-cyberattacks-that-netted-62m-from-cybercrime-victims/">US charges Russian ‘bulletproof’ web hosts over cyberattacks that netted $62M from cybercrime victims</a></li><li><a href="https://www.zdnet.com/article/crashstealer-mac-malware-masquerades-as-apples-crash-reporter/">New Mac malware masquerades as Apple's crash reporter: 3 ways to dodge the threat</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-16-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Microsoft łata BitLocker, rekord 570 błędów, oskarżenia o rosyjskie hostingi i nowe macOS malware.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://thecybersecguru.com/news/bitlocker-zero-day-cve-2026-50661">Windows BitLocker Zero-Day (CVE-2026-50661) Lets Attackers Bypass Encryption | The CyberSec Guru</a></li><li><a href="https://www.zdnet.com/article/microsoft-patches-570-vulnerabilities-exploited-zero-days/">Microsoft patches record 570 Windows security bugs with two exploited zero days - update now</a></li><li><a href="https://timesofindia.indiatimes.com/india/kudankulam-nuclear-plant-data-breached-npcil-says-core-systems-untouched/articleshow/132425150.cms">Kudankulam nuclear plant data breached, NPCIL says core systems untouched</a></li><li><a href="https://techcrunch.com/2026/07/15/us-charges-russian-bulletproof-web-hosts-over-cyberattacks-that-netted-62m-from-cybercrime-victims/">US charges Russian ‘bulletproof’ web hosts over cyberattacks that netted $62M from cybercrime victims</a></li><li><a href="https://www.zdnet.com/article/crashstealer-mac-malware-masquerades-as-apples-crash-reporter/">New Mac malware masquerades as Apple's crash reporter: 3 ways to dodge the threat</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-16-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Thu, 16 Jul 2026 09:01:18 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/b29642bf/7f35a860.mp3" length="3421038" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>214</itunes:duration>
      <itunes:summary>Microsoft łata BitLocker, rekord 570 błędów, oskarżenia o rosyjskie hostingi i nowe macOS malware.</itunes:summary>
      <itunes:subtitle>Microsoft łata BitLocker, rekord 570 błędów, oskarżenia o rosyjskie hostingi i nowe macOS malware.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Chińscy hakerzy z LLM, UEFI Secure Boot w ruinie, RCE w ServiceNow</title>
      <itunes:title>Chińscy hakerzy z LLM, UEFI Secure Boot w ruinie, RCE w ServiceNow</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">5abc63c0-5020-4fd8-b9bb-37f539039421</guid>
      <link>https://headflash.news/pl/security/2026-07-15-daily-newsletter</link>
      <description>
        <![CDATA[<p>TencShell z AI, 11 zapomnianych shimów UEFI, pre-auth RCE w ServiceNow, agentowy ransomware i Grok Build wysyła całe repo.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://hunt.io/blog/chinese-operators-claude-deepseek-government-intrusion">Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems Across Four Countries</a></li><li><a href="https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/">Forgotten UEFI shims undermining Secure Boot</a></li><li><a href="https://slcyber.io/research-center/smashing-the-servicenow-sandbox-pre-authentication-rce">Smashing the ServiceNow Sandbox – Pre Authentication RCE › Searchlight Cyber</a></li><li><a href="https://www.techtimes.com/articles/320508/20260714/ant-group-open-sources-agent-security-tool-days-after-agentic-ransomware-hit.htm">Ant Group Open-Sources Agent Security Tool Days After Agentic Ransomware Hit</a></li><li><a href="https://thenextweb.com/news/grok-build-uploaded-entire-git-repositories-secrets">Grok Build was uploading entire Git repositories to xAI’s cloud, including committed secrets</a></li><li><a href="https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot">Forgotten UEFI shims undermining Secure Boot</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-15-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>TencShell z AI, 11 zapomnianych shimów UEFI, pre-auth RCE w ServiceNow, agentowy ransomware i Grok Build wysyła całe repo.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://hunt.io/blog/chinese-operators-claude-deepseek-government-intrusion">Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems Across Four Countries</a></li><li><a href="https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/">Forgotten UEFI shims undermining Secure Boot</a></li><li><a href="https://slcyber.io/research-center/smashing-the-servicenow-sandbox-pre-authentication-rce">Smashing the ServiceNow Sandbox – Pre Authentication RCE › Searchlight Cyber</a></li><li><a href="https://www.techtimes.com/articles/320508/20260714/ant-group-open-sources-agent-security-tool-days-after-agentic-ransomware-hit.htm">Ant Group Open-Sources Agent Security Tool Days After Agentic Ransomware Hit</a></li><li><a href="https://thenextweb.com/news/grok-build-uploaded-entire-git-repositories-secrets">Grok Build was uploading entire Git repositories to xAI’s cloud, including committed secrets</a></li><li><a href="https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot">Forgotten UEFI shims undermining Secure Boot</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-15-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Wed, 15 Jul 2026 09:02:09 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/34dc6d99/ccf6343b.mp3" length="3753316" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>235</itunes:duration>
      <itunes:summary>TencShell z AI, 11 zapomnianych shimów UEFI, pre-auth RCE w ServiceNow, agentowy ransomware i Grok Build wysyła całe repo.</itunes:summary>
      <itunes:subtitle>TencShell z AI, 11 zapomnianych shimów UEFI, pre-auth RCE w ServiceNow, agentowy ransomware i Grok Build wysyła całe repo.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Ransomware AI, rosyjscy hakerzy i rekordowy wzrost ataków</title>
      <itunes:title>Ransomware AI, rosyjscy hakerzy i rekordowy wzrost ataków</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">759ddb1b-557d-4b1b-a0e7-6c24ae56f50b</guid>
      <link>https://headflash.news/pl/security/2026-07-14-daily-newsletter</link>
      <description>
        <![CDATA[<p>Codzienny przegląd bezpieczeństwa: autonomiczne ransomware, obrona przez wstrzykiwanie promptów, ostrzeżenie o routerach i nowy lider ransomware.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.techtimes.com/articles/320390/20260713/agentic-ransomware-real-getting-cheaper-what-comes-after-jadepuffer.htm">Agentic Ransomware Is Real and Getting Cheaper: What Comes After JadePuffer</a></li><li><a href="http://arstechnica.com/security/2026/07/now-defenders-are-embracing-the-prompt-injection-too">Now, defenders are embracing the prompt injection, too - Ars Technica</a></li><li><a href="https://arstechnica.com/security/2026/07/the-us-government-warns-that-russia-state-hackers-are-coming-after-your-router/">The US government warns that Russia state hackers are coming after your router</a></li><li><a href="https://www.itpro.com/security/ransomware/this-one-cyber-crime-group-accounted-for-nearly-a-fifth-of-all-ransomware-attacks-in-june">This one cyber crime group accounted for nearly a fifth of all ransomware attacks in June</a></li><li><a href="https://thecyberexpress.com/cisa-cve-2026-48939-cve-2026-56291/">CISA Warns of Actively Exploited Joomla Zero-Day Vulnerabilities</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-14-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Codzienny przegląd bezpieczeństwa: autonomiczne ransomware, obrona przez wstrzykiwanie promptów, ostrzeżenie o routerach i nowy lider ransomware.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.techtimes.com/articles/320390/20260713/agentic-ransomware-real-getting-cheaper-what-comes-after-jadepuffer.htm">Agentic Ransomware Is Real and Getting Cheaper: What Comes After JadePuffer</a></li><li><a href="http://arstechnica.com/security/2026/07/now-defenders-are-embracing-the-prompt-injection-too">Now, defenders are embracing the prompt injection, too - Ars Technica</a></li><li><a href="https://arstechnica.com/security/2026/07/the-us-government-warns-that-russia-state-hackers-are-coming-after-your-router/">The US government warns that Russia state hackers are coming after your router</a></li><li><a href="https://www.itpro.com/security/ransomware/this-one-cyber-crime-group-accounted-for-nearly-a-fifth-of-all-ransomware-attacks-in-june">This one cyber crime group accounted for nearly a fifth of all ransomware attacks in June</a></li><li><a href="https://thecyberexpress.com/cisa-cve-2026-48939-cve-2026-56291/">CISA Warns of Actively Exploited Joomla Zero-Day Vulnerabilities</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-14-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Tue, 14 Jul 2026 09:02:06 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/5801bef7/4088d2d6.mp3" length="3930949" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>246</itunes:duration>
      <itunes:summary>Codzienny przegląd bezpieczeństwa: autonomiczne ransomware, obrona przez wstrzykiwanie promptów, ostrzeżenie o routerach i nowy lider ransomware.</itunes:summary>
      <itunes:subtitle>Codzienny przegląd bezpieczeństwa: autonomiczne ransomware, obrona przez wstrzykiwanie promptów, ostrzeżenie o routerach i nowy lider ransomware.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>AI jako broń i cel: nowe zagrożenia w cyberbezpieczeństwie</title>
      <itunes:title>AI jako broń i cel: nowe zagrożenia w cyberbezpieczeństwie</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">3adf30b2-8cdb-4c15-9562-1d59ad52b7ef</guid>
      <link>https://headflash.news/pl/security/2026-07-13-daily-newsletter</link>
      <description>
        <![CDATA[<p>HalluSquatting, GhostApproval, Sol usuwający pliki – dziś w HeadFlash przegląd najważniejszych wydarzeń z frontu bezpieczeństwa.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.securityweek.com/hallusquatting-turns-ai-hallucinations-into-botnet-delivery-mechanism">Just a moment...</a></li><li><a href="https://www.securityweek.com/network-of-200-github-repositories-used-for-malware-infection">Just a moment...</a></li><li><a href="https://www.techtimes.com/articles/320093/20260710/gigawiper-modular-windows-backdoor-combines-disk-wiper-fake-ransomware-spyware.htm">GigaWiper: Modular Windows Backdoor Combines Disk Wiper, Fake Ransomware, Spyware</a></li><li><a href="https://www.itpro.com/security/the-agents-you-use-to-beef-up-cybersecurity-could-be-turned-against-you-friendly-fire-attacks-can-manipulate-openai-and-anthropic-models-into-running-malicious-code">The agents you use to beef up cybersecurity could be turned against you – 'Friendly Fire' attacks can manipulate OpenAI and Anthropic models into running malicious code</a></li><li><a href="https://www.techtimes.com/articles/320095/20260710/six-ai-coding-tools-show-wrong-file-approval-box-handing-attackers-ssh-access.htm">Six AI Coding Tools Show Wrong File in Approval Box, Handing Attackers SSH Access</a></li><li><a href="https://arstechnica.com/tech-policy/2026/07/ransomware-negotiator-helped-attackers-extort-his-own-clients-gets-6-year-sentence">Ransomware negotiator hired to represent victims was working for the attackers - Ars Technica</a></li><li><a href="https://www.techradar.com/pro/the-false-attributions-were-the-direct-product-of-kois-unsupervised-reliance-startup-sues-koi-security-after-ai-tool-hallucinates-and-links-it-to-a-chinese-spying-scam">'The false attributions were the direct product of Koi's unsupervised reliance': Startup sues Koi Security after AI tool hallucinates and links it to a Chinese spying scam</a></li><li><a href="https://www.bleepingcomputer.com/news/security/ghostcommit-hides-prompt-injection-in-images-to-fool-ai-agents-steal-secrets/">'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets</a></li><li><a href="https://www.kyivpost.com/post/80049">Russian Hackers Hijacked Intercom Cameras to Spy on Ukraine Aid Routes</a></li><li><a href="https://www.techtimes.com/articles/320200/20260712/china-india-hackers-weaponized-pakistan-police-portal-hit-civilians-officers.htm">China, India Hackers Weaponized Pakistan Police Portal to Hit Civilians, Officers</a></li><li><a href="https://www.bleepingcomputer.com/news/security/redhook-android-malware-now-uses-wireless-adb-for-shell-access/">RedHook Android malware now uses Wireless ADB for shell access</a></li><li><a href="https://www.helpnetsecurity.com/2026/07/10/microsoft-windows-update-deployment-timelines">Microsoft is rewriting Windows patch guidance because of AI - Help Net Security</a></li><li><a href="https://www.techtimes.com/articles/320203/20260712/boko-haram-built-ai-units-attack-planning-isis-taught-jailbreaks.htm">Boko Haram Built AI Units for Attack Planning as ISIS Taught Jailbreaks</a></li><li><a href="https://www.techtimes.com/articles/320198/20260712/chatgpt-work-launch-went-wrong-gpt-56-sol-deleted-user-files-without-permission.htm">ChatGPT Work Launch Went Wrong: GPT-5.6 Sol Deleted User Files Without Permission</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-13-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>HalluSquatting, GhostApproval, Sol usuwający pliki – dziś w HeadFlash przegląd najważniejszych wydarzeń z frontu bezpieczeństwa.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.securityweek.com/hallusquatting-turns-ai-hallucinations-into-botnet-delivery-mechanism">Just a moment...</a></li><li><a href="https://www.securityweek.com/network-of-200-github-repositories-used-for-malware-infection">Just a moment...</a></li><li><a href="https://www.techtimes.com/articles/320093/20260710/gigawiper-modular-windows-backdoor-combines-disk-wiper-fake-ransomware-spyware.htm">GigaWiper: Modular Windows Backdoor Combines Disk Wiper, Fake Ransomware, Spyware</a></li><li><a href="https://www.itpro.com/security/the-agents-you-use-to-beef-up-cybersecurity-could-be-turned-against-you-friendly-fire-attacks-can-manipulate-openai-and-anthropic-models-into-running-malicious-code">The agents you use to beef up cybersecurity could be turned against you – 'Friendly Fire' attacks can manipulate OpenAI and Anthropic models into running malicious code</a></li><li><a href="https://www.techtimes.com/articles/320095/20260710/six-ai-coding-tools-show-wrong-file-approval-box-handing-attackers-ssh-access.htm">Six AI Coding Tools Show Wrong File in Approval Box, Handing Attackers SSH Access</a></li><li><a href="https://arstechnica.com/tech-policy/2026/07/ransomware-negotiator-helped-attackers-extort-his-own-clients-gets-6-year-sentence">Ransomware negotiator hired to represent victims was working for the attackers - Ars Technica</a></li><li><a href="https://www.techradar.com/pro/the-false-attributions-were-the-direct-product-of-kois-unsupervised-reliance-startup-sues-koi-security-after-ai-tool-hallucinates-and-links-it-to-a-chinese-spying-scam">'The false attributions were the direct product of Koi's unsupervised reliance': Startup sues Koi Security after AI tool hallucinates and links it to a Chinese spying scam</a></li><li><a href="https://www.bleepingcomputer.com/news/security/ghostcommit-hides-prompt-injection-in-images-to-fool-ai-agents-steal-secrets/">'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets</a></li><li><a href="https://www.kyivpost.com/post/80049">Russian Hackers Hijacked Intercom Cameras to Spy on Ukraine Aid Routes</a></li><li><a href="https://www.techtimes.com/articles/320200/20260712/china-india-hackers-weaponized-pakistan-police-portal-hit-civilians-officers.htm">China, India Hackers Weaponized Pakistan Police Portal to Hit Civilians, Officers</a></li><li><a href="https://www.bleepingcomputer.com/news/security/redhook-android-malware-now-uses-wireless-adb-for-shell-access/">RedHook Android malware now uses Wireless ADB for shell access</a></li><li><a href="https://www.helpnetsecurity.com/2026/07/10/microsoft-windows-update-deployment-timelines">Microsoft is rewriting Windows patch guidance because of AI - Help Net Security</a></li><li><a href="https://www.techtimes.com/articles/320203/20260712/boko-haram-built-ai-units-attack-planning-isis-taught-jailbreaks.htm">Boko Haram Built AI Units for Attack Planning as ISIS Taught Jailbreaks</a></li><li><a href="https://www.techtimes.com/articles/320198/20260712/chatgpt-work-launch-went-wrong-gpt-56-sol-deleted-user-files-without-permission.htm">ChatGPT Work Launch Went Wrong: GPT-5.6 Sol Deleted User Files Without Permission</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-13-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Mon, 13 Jul 2026 09:01:29 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/1554f374/5eb7b63f.mp3" length="7145473" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>447</itunes:duration>
      <itunes:summary>HalluSquatting, GhostApproval, Sol usuwający pliki – dziś w HeadFlash przegląd najważniejszych wydarzeń z frontu bezpieczeństwa.</itunes:summary>
      <itunes:subtitle>HalluSquatting, GhostApproval, Sol usuwający pliki – dziś w HeadFlash przegląd najważniejszych wydarzeń z frontu bezpieczeństwa.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Security Flash: Meta wchłania red team, NSA odświeża TAO, Microsoft łata Defender</title>
      <itunes:title>Security Flash: Meta wchłania red team, NSA odświeża TAO, Microsoft łata Defender</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">bb66360f-aa33-4fde-9017-0a9ea0d5ba03</guid>
      <link>https://headflash.news/pl/security/2026-07-10-daily-newsletter</link>
      <description>
        <![CDATA[<p>Meta przejmuje red team AI, Sysdig dokumentuje autonomiczne ransomware, NSA przywraca TAO, a Chiny ostrzegają przed backdoorem w Claude Code.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.techtimes.com/articles/320032/20260709/meta-absorbs-ai-securitys-top-red-team-autonomous-ransomware-arrives.htm">Meta Absorbs AI Security's Top Red Team as Autonomous Ransomware Arrives</a></li><li><a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-rogueplanet-defender-zero-day-vulnerability">Microsoft patches RoguePlanet Defender zero-day vulnerability</a></li><li><a href="https://therecord.media/nsa-revives-tao-name-for-elite-hacking-unit">NSA revives &amp;#x27;Tailored Access Operations&amp;#x27; name for elite hacking unit | The Record from Recorded Future News</a></li><li><a href="https://www.techrepublic.com/article/news-china-claude-code-backdoor-security-risk-apac/">China Warns of Claude Code ‘Backdoor’ Security Risk</a></li><li><a href="https://www.techtimes.com/articles/320004/20260709/ipsec-downgrade-attack-survives-ml-kem-cloudflare-ships-authentication-fix.htm">IPsec Downgrade Attack Survives ML-KEM: Cloudflare Ships Authentication Fix</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-10-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Meta przejmuje red team AI, Sysdig dokumentuje autonomiczne ransomware, NSA przywraca TAO, a Chiny ostrzegają przed backdoorem w Claude Code.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.techtimes.com/articles/320032/20260709/meta-absorbs-ai-securitys-top-red-team-autonomous-ransomware-arrives.htm">Meta Absorbs AI Security's Top Red Team as Autonomous Ransomware Arrives</a></li><li><a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-rogueplanet-defender-zero-day-vulnerability">Microsoft patches RoguePlanet Defender zero-day vulnerability</a></li><li><a href="https://therecord.media/nsa-revives-tao-name-for-elite-hacking-unit">NSA revives &amp;#x27;Tailored Access Operations&amp;#x27; name for elite hacking unit | The Record from Recorded Future News</a></li><li><a href="https://www.techrepublic.com/article/news-china-claude-code-backdoor-security-risk-apac/">China Warns of Claude Code ‘Backdoor’ Security Risk</a></li><li><a href="https://www.techtimes.com/articles/320004/20260709/ipsec-downgrade-attack-survives-ml-kem-cloudflare-ships-authentication-fix.htm">IPsec Downgrade Attack Survives ML-KEM: Cloudflare Ships Authentication Fix</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-10-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Fri, 10 Jul 2026 09:00:46 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/175bcfb0/7e6a58b7.mp3" length="3170263" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>199</itunes:duration>
      <itunes:summary>Meta przejmuje red team AI, Sysdig dokumentuje autonomiczne ransomware, NSA przywraca TAO, a Chiny ostrzegają przed backdoorem w Claude Code.</itunes:summary>
      <itunes:subtitle>Meta przejmuje red team AI, Sysdig dokumentuje autonomiczne ransomware, NSA przywraca TAO, a Chiny ostrzegają przed backdoorem w Claude Code.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Transsion, GhostLock, Ubiquiti i wyciek danych – przegląd</title>
      <itunes:title>Transsion, GhostLock, Ubiquiti i wyciek danych – przegląd</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">6049460c-d784-40cd-a59a-fedb1c13e0e4</guid>
      <link>https://headflash.news/pl/security/2026-07-09-daily-newsletter</link>
      <description>
        <![CDATA[<p>Transsion szpieguje, GhostLock daje root w 5 sekund, Ubiquiti łatuje krytyczną lukę, wyciek 7 mln praw jazdy – oto najważniejsze wiadomości dnia.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.nowsecure.com/blog/2026/07/08/what-the-transsion-telemetry-research-means-for-mobile-security">1-in-2 phones sold in Africa exfiltrate telemetry to China - NowSecure</a></li><li><a href="https://www.techtimes.com/articles/319914/20260708/public-exploit-turns-15-year-linux-kernel-flaw-5-second-root-attack.htm">Public Exploit Turns 15-Year Linux Kernel Flaw Into 5-Second Root Attack</a></li><li><a href="https://deafnews.it/en/news/cybersecurity/ubiquiti-patches-cve-2026-50746-maximum-severity-flaw-in-unifi-os">Ubiquiti Patches CVE-2026-50746, Maximum-Severity Flaw in UniFi… | DeafNews</a></li><li><a href="https://arstechnica.com/security/2026/07/high-severity-guest-vm-escape-is-1-of-2-linux-vulnerabilities-to-surface-this-week">Google pays $250K for Linux vulnerability allowing guest VM escapes - Ars Technica</a></li><li><a href="https://lifehacker.com/tech/drivers-license-data-breach">This Massive Data Breach Compromised Nearly 7 Million Driver's Licenses</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-09-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Transsion szpieguje, GhostLock daje root w 5 sekund, Ubiquiti łatuje krytyczną lukę, wyciek 7 mln praw jazdy – oto najważniejsze wiadomości dnia.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.nowsecure.com/blog/2026/07/08/what-the-transsion-telemetry-research-means-for-mobile-security">1-in-2 phones sold in Africa exfiltrate telemetry to China - NowSecure</a></li><li><a href="https://www.techtimes.com/articles/319914/20260708/public-exploit-turns-15-year-linux-kernel-flaw-5-second-root-attack.htm">Public Exploit Turns 15-Year Linux Kernel Flaw Into 5-Second Root Attack</a></li><li><a href="https://deafnews.it/en/news/cybersecurity/ubiquiti-patches-cve-2026-50746-maximum-severity-flaw-in-unifi-os">Ubiquiti Patches CVE-2026-50746, Maximum-Severity Flaw in UniFi… | DeafNews</a></li><li><a href="https://arstechnica.com/security/2026/07/high-severity-guest-vm-escape-is-1-of-2-linux-vulnerabilities-to-surface-this-week">Google pays $250K for Linux vulnerability allowing guest VM escapes - Ars Technica</a></li><li><a href="https://lifehacker.com/tech/drivers-license-data-breach">This Massive Data Breach Compromised Nearly 7 Million Driver's Licenses</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-09-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Thu, 09 Jul 2026 09:01:03 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/a964fe94/7883f386.mp3" length="3083745" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>193</itunes:duration>
      <itunes:summary>Transsion szpieguje, GhostLock daje root w 5 sekund, Ubiquiti łatuje krytyczną lukę, wyciek 7 mln praw jazdy – oto najważniejsze wiadomości dnia.</itunes:summary>
      <itunes:subtitle>Transsion szpieguje, GhostLock daje root w 5 sekund, Ubiquiti łatuje krytyczną lukę, wyciek 7 mln praw jazdy – oto najważniejsze wiadomości dnia.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>HeadFlash Security: AI generuje ransomware, luka VM, GitLost i więcej</title>
      <itunes:title>HeadFlash Security: AI generuje ransomware, luka VM, GitLost i więcej</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">bbdf6b48-1c22-4c0c-ab2b-1780c3ec8d7e</guid>
      <link>https://headflash.news/pl/security/2026-07-08-daily-newsletter</link>
      <description>
        <![CDATA[<p>Przypadkowy ransomware z DeepSeek, 16-letnia luka w Linux, wyciek z GitHub, postępy kwantowe i aresztowanie hakerów.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.techradar.com/pro/security/deepseek-accidentally-built-a-working-ransomware-strain-experts-note-what-we-are-witnessing-is-a-fundamental-shift-in-how-novel-cyber-attacks-are-born">DeepSeek accidentally built a working ransomware strain, experts note, 'What we are witnessing is a fundamental shift in how novel cyber attacks are born'</a></li><li><a href="https://www.bleepingcomputer.com/news/linux/new-januscape-linux-kernel-flaw-allows-vm-escape-on-intel-amd-devices">New Januscape Linux flaw allows VM escape on Intel, AMD devices</a></li><li><a href="https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos">GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos - Noma Security</a></li><li><a href="https://spectrum.ieee.org/google-quantum-cryptography-zero-knowledge">Independent Labs Crack Google's Secret Cryptography Work</a></li><li><a href="https://www.tomshardware.com/software/windows-11-identifier-used-to-track-scattered-spider-perp-after-microsoft-shared-info-with-fbi-19-year-old-us-estonian-hacker-arrested-over-alleged-ties-to-infamous-extortion-group">Windows 11 identifier code used to track Scattered Spider perp after Microsoft shared info with FBI &amp;mdash; 19-year-old US-Estonian hacker arrested over alleged ties to infamous extortion group | Tom's Hardware</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-08-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Przypadkowy ransomware z DeepSeek, 16-letnia luka w Linux, wyciek z GitHub, postępy kwantowe i aresztowanie hakerów.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.techradar.com/pro/security/deepseek-accidentally-built-a-working-ransomware-strain-experts-note-what-we-are-witnessing-is-a-fundamental-shift-in-how-novel-cyber-attacks-are-born">DeepSeek accidentally built a working ransomware strain, experts note, 'What we are witnessing is a fundamental shift in how novel cyber attacks are born'</a></li><li><a href="https://www.bleepingcomputer.com/news/linux/new-januscape-linux-kernel-flaw-allows-vm-escape-on-intel-amd-devices">New Januscape Linux flaw allows VM escape on Intel, AMD devices</a></li><li><a href="https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos">GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos - Noma Security</a></li><li><a href="https://spectrum.ieee.org/google-quantum-cryptography-zero-knowledge">Independent Labs Crack Google's Secret Cryptography Work</a></li><li><a href="https://www.tomshardware.com/software/windows-11-identifier-used-to-track-scattered-spider-perp-after-microsoft-shared-info-with-fbi-19-year-old-us-estonian-hacker-arrested-over-alleged-ties-to-infamous-extortion-group">Windows 11 identifier code used to track Scattered Spider perp after Microsoft shared info with FBI &amp;mdash; 19-year-old US-Estonian hacker arrested over alleged ties to infamous extortion group | Tom's Hardware</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-08-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Wed, 08 Jul 2026 09:01:20 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/bfa6d83f/af95e7c9.mp3" length="5007194" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>313</itunes:duration>
      <itunes:summary>Przypadkowy ransomware z DeepSeek, 16-letnia luka w Linux, wyciek z GitHub, postępy kwantowe i aresztowanie hakerów.</itunes:summary>
      <itunes:subtitle>Przypadkowy ransomware z DeepSeek, 16-letnia luka w Linux, wyciek z GitHub, postępy kwantowe i aresztowanie hakerów.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Codzienny przegląd bezpieczeństwa: luki, boty i przyszłość kwantowa</title>
      <itunes:title>Codzienny przegląd bezpieczeństwa: luki, boty i przyszłość kwantowa</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">ac233a62-0634-48cc-9c9a-eb6c940552d9</guid>
      <link>https://headflash.news/pl/security/2026-07-07-daily-newsletter</link>
      <description>
        <![CDATA[<p>5 najważniejszych historii: zdalne wykonanie kodu w grze, oszustwa na Teams, śledzenie przez Windows i zmiany w kontraście botów.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://khaelkugler.com/blogs/meccha_chameleon.html">2-Click Remote Code Execution in Meccha Chameleon</a></li><li><a href="https://www.bleepingcomputer.com/news/security/fake-it-support-calls-on-microsoft-teams-push-etherrat-malware/">Fake IT support calls on Microsoft Teams push EtherRAT malware</a></li><li><a href="https://www.pcmag.com/news/a-hackers-arrest-reveals-microsoft-can-track-users-via-a-windows-device">A Hacker's Arrest Reveals Microsoft Can Track Users Via a Windows Device ID</a></li><li><a href="https://www.pcgamer.com/software/security/microsoft-says-cryptographically-relevant-quantum-computers-could-arrive-sooner-than-previously-expected-as-it-bumps-its-qsp-timeline-to-2029/">Microsoft says 'cryptographically relevant quantum computers could arrive sooner than previously expected' as it bumps its QSP timeline to 2029</a></li><li><a href="https://the-decoder.com/cloudflare-replaces-its-blanket-ai-bot-block-with-granular-controls-for-search-training-and-agent-crawlers/">Cloudflare replaces its blanket AI bot block with granular controls for search, training, and agent crawlers</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-07-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>5 najważniejszych historii: zdalne wykonanie kodu w grze, oszustwa na Teams, śledzenie przez Windows i zmiany w kontraście botów.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://khaelkugler.com/blogs/meccha_chameleon.html">2-Click Remote Code Execution in Meccha Chameleon</a></li><li><a href="https://www.bleepingcomputer.com/news/security/fake-it-support-calls-on-microsoft-teams-push-etherrat-malware/">Fake IT support calls on Microsoft Teams push EtherRAT malware</a></li><li><a href="https://www.pcmag.com/news/a-hackers-arrest-reveals-microsoft-can-track-users-via-a-windows-device">A Hacker's Arrest Reveals Microsoft Can Track Users Via a Windows Device ID</a></li><li><a href="https://www.pcgamer.com/software/security/microsoft-says-cryptographically-relevant-quantum-computers-could-arrive-sooner-than-previously-expected-as-it-bumps-its-qsp-timeline-to-2029/">Microsoft says 'cryptographically relevant quantum computers could arrive sooner than previously expected' as it bumps its QSP timeline to 2029</a></li><li><a href="https://the-decoder.com/cloudflare-replaces-its-blanket-ai-bot-block-with-granular-controls-for-search-training-and-agent-crawlers/">Cloudflare replaces its blanket AI bot block with granular controls for search, training, and agent crawlers</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-07-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Tue, 07 Jul 2026 09:01:35 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/997557ae/b08c126a.mp3" length="3577355" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>224</itunes:duration>
      <itunes:summary>5 najważniejszych historii: zdalne wykonanie kodu w grze, oszustwa na Teams, śledzenie przez Windows i zmiany w kontraście botów.</itunes:summary>
      <itunes:subtitle>5 najważniejszych historii: zdalne wykonanie kodu w grze, oszustwa na Teams, śledzenie przez Windows i zmiany w kontraście botów.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Botnet na 2 mln domów, AI atakuje, Apple przyspiesza łatki</title>
      <itunes:title>Botnet na 2 mln domów, AI atakuje, Apple przyspiesza łatki</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">33bd7c14-57e7-47cb-a3a0-fcd2eed1d5ee</guid>
      <link>https://headflash.news/pl/security/2026-07-06-daily-newsletter</link>
      <description>
        <![CDATA[<p>NetNut rozbity, AI napędza ransomware i odkrywa błędy WebKit, Vect i TeamPCP łączą siły. Przegląd dnia.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.techtimes.com/articles/319625/20260703/fbi-google-disrupt-netnut-botnet-that-rented-2-million-home-devices-spies.htm">FBI and Google Disrupt NetNut Botnet That Rented 2 Million Home Devices to Spies</a></li><li><a href="https://www.itpro.com/security/ransomware/cyber-experts-issue-alert-after-two-ransomware-groups-team-up-on-unprecedented-threat-campaign">Cyber experts issue alert after two ransomware groups team up on ‘unprecedented’ threat campaign</a></li><li><a href="https://thenextweb.com/news/ai-agent-first-end-to-end-ransomware-attack">Researchers say an AI agent just ran a ransomware attack from start to finish, with no human at the keyboard</a></li><li><a href="https://deafnews.it/en/news/apple/apple-compresses-patch-cycle-after-ai-uncovers-four-webkit-flaws">Apple Compresses Patch Cycle After AI Uncovers Four WebKit Flaws</a></li><li><a href="https://www.wiz.io/blog/amazon-q-vulnerability">Amazon Q Vulnerability: Compromise via MCP Auto-Execution | Wiz Blog</a></li><li><a href="https://www.techtimes.com/articles/319693/20260704/seiko-skybridge-enterprise-iot-routers-hit-permanent-os-injection-no-fix.htm">Seiko SkyBridge Enterprise IoT Routers Hit With Permanent OS Injection: No Fix</a></li><li><a href="https://thenextweb.com/news/north-korea-npm-rollup-polyfill-developer-secrets">North Korea-linked npm packages impersonate Rollup polyfill tools to steal developer secrets</a></li><li><a href="https://www.techradar.com/pro/security/agentic-coding-tools-have-access-to-everything-they-need-for-this-security-experts-warn-claude-code-can-be-exploited-simply-by-trying-to-be-helpful">'Agentic coding tools have access to everything they need for this': Security experts warn Claude Code can be exploited simply by trying to be helpful</a></li><li><a href="https://decrypt.co/372743/fake-mac-clipboard-app-delivers-password-stealing-malware">Fake Mac Clipboard App Delivers New Password-Stealing Malware</a></li><li><a href="https://citizenlab.ca/research/member-of-committee-investigating-spyware-hacked-with-pegasus">Espionage Against the European Parliament: Member of Committee Investigating Spyware Hacked with Pegasus - The Citizen Lab</a></li><li><a href="https://www.techtimes.com/articles/319736/20260705/india-court-order-puts-your-domain-registration-data-risk-worldwide.htm">India Court Order Puts Your Domain Registration Data at Risk Worldwide</a></li><li><a href="https://specterops.io/blog/2026/06/29/llm-powered-edr-analysis">How LLM-driven EDR evasion works | SpecterOps</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-06-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>NetNut rozbity, AI napędza ransomware i odkrywa błędy WebKit, Vect i TeamPCP łączą siły. Przegląd dnia.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.techtimes.com/articles/319625/20260703/fbi-google-disrupt-netnut-botnet-that-rented-2-million-home-devices-spies.htm">FBI and Google Disrupt NetNut Botnet That Rented 2 Million Home Devices to Spies</a></li><li><a href="https://www.itpro.com/security/ransomware/cyber-experts-issue-alert-after-two-ransomware-groups-team-up-on-unprecedented-threat-campaign">Cyber experts issue alert after two ransomware groups team up on ‘unprecedented’ threat campaign</a></li><li><a href="https://thenextweb.com/news/ai-agent-first-end-to-end-ransomware-attack">Researchers say an AI agent just ran a ransomware attack from start to finish, with no human at the keyboard</a></li><li><a href="https://deafnews.it/en/news/apple/apple-compresses-patch-cycle-after-ai-uncovers-four-webkit-flaws">Apple Compresses Patch Cycle After AI Uncovers Four WebKit Flaws</a></li><li><a href="https://www.wiz.io/blog/amazon-q-vulnerability">Amazon Q Vulnerability: Compromise via MCP Auto-Execution | Wiz Blog</a></li><li><a href="https://www.techtimes.com/articles/319693/20260704/seiko-skybridge-enterprise-iot-routers-hit-permanent-os-injection-no-fix.htm">Seiko SkyBridge Enterprise IoT Routers Hit With Permanent OS Injection: No Fix</a></li><li><a href="https://thenextweb.com/news/north-korea-npm-rollup-polyfill-developer-secrets">North Korea-linked npm packages impersonate Rollup polyfill tools to steal developer secrets</a></li><li><a href="https://www.techradar.com/pro/security/agentic-coding-tools-have-access-to-everything-they-need-for-this-security-experts-warn-claude-code-can-be-exploited-simply-by-trying-to-be-helpful">'Agentic coding tools have access to everything they need for this': Security experts warn Claude Code can be exploited simply by trying to be helpful</a></li><li><a href="https://decrypt.co/372743/fake-mac-clipboard-app-delivers-password-stealing-malware">Fake Mac Clipboard App Delivers New Password-Stealing Malware</a></li><li><a href="https://citizenlab.ca/research/member-of-committee-investigating-spyware-hacked-with-pegasus">Espionage Against the European Parliament: Member of Committee Investigating Spyware Hacked with Pegasus - The Citizen Lab</a></li><li><a href="https://www.techtimes.com/articles/319736/20260705/india-court-order-puts-your-domain-registration-data-risk-worldwide.htm">India Court Order Puts Your Domain Registration Data at Risk Worldwide</a></li><li><a href="https://specterops.io/blog/2026/06/29/llm-powered-edr-analysis">How LLM-driven EDR evasion works | SpecterOps</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-06-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Mon, 06 Jul 2026 10:00:50 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/73ed6d42/fb2e9730.mp3" length="6217185" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>389</itunes:duration>
      <itunes:summary>NetNut rozbity, AI napędza ransomware i odkrywa błędy WebKit, Vect i TeamPCP łączą siły. Przegląd dnia.</itunes:summary>
      <itunes:subtitle>NetNut rozbity, AI napędza ransomware i odkrywa błędy WebKit, Vect i TeamPCP łączą siły. Przegląd dnia.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Luki w SharePoint i FIFA, kanadyjski cyberatak na fentanyl, botnet w TV</title>
      <itunes:title>Luki w SharePoint i FIFA, kanadyjski cyberatak na fentanyl, botnet w TV</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">e4e5a62a-7c5f-447d-92ed-ad3ceea09cbe</guid>
      <link>https://headflash.news/pl/security/2026-07-03-daily-newsletter</link>
      <description>
        <![CDATA[<p>CISA ostrzega przed aktywnym exploitowaniem SharePoint; kanadyjski wywiad uderza w brokerów fentanylu; FIFA miała dziurę w World Cup; Google niszczy botnet NetNut; Opera blokuje ataki na schowek.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-rce-flaw-now-actively-exploited">CISA: Microsoft SharePoint RCE flaw now actively exploited</a></li><li><a href="https://www.theglobeandmail.com/politics/article-canadas-electronic-spy-agency-conducted-cyberattacks-on-criminals">Canada’s electronic spy agency conducted cyberattacks on criminals brokering fentanyl ingredients, report says - The Globe and Mail</a></li><li><a href="https://bobdahacker.com/blog/fifa-hack">I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID. | bobdahacker</a></li><li><a href="https://www.pcmag.com/news/google-this-proxy-service-is-using-tv-streaming-devices-to-host-cybercrime">Google: This Proxy Service Is Using TV Streaming Devices to Host Cybercrime</a></li><li><a href="https://www.pcworld.com/article/3183162/opera-now-blocks-one-of-the-sneakiest-malware-tricks-around.html">Opera now blocks one of the sneakiest malware tricks around</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-03-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>CISA ostrzega przed aktywnym exploitowaniem SharePoint; kanadyjski wywiad uderza w brokerów fentanylu; FIFA miała dziurę w World Cup; Google niszczy botnet NetNut; Opera blokuje ataki na schowek.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-rce-flaw-now-actively-exploited">CISA: Microsoft SharePoint RCE flaw now actively exploited</a></li><li><a href="https://www.theglobeandmail.com/politics/article-canadas-electronic-spy-agency-conducted-cyberattacks-on-criminals">Canada’s electronic spy agency conducted cyberattacks on criminals brokering fentanyl ingredients, report says - The Globe and Mail</a></li><li><a href="https://bobdahacker.com/blog/fifa-hack">I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID. | bobdahacker</a></li><li><a href="https://www.pcmag.com/news/google-this-proxy-service-is-using-tv-streaming-devices-to-host-cybercrime">Google: This Proxy Service Is Using TV Streaming Devices to Host Cybercrime</a></li><li><a href="https://www.pcworld.com/article/3183162/opera-now-blocks-one-of-the-sneakiest-malware-tricks-around.html">Opera now blocks one of the sneakiest malware tricks around</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-03-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Fri, 03 Jul 2026 09:38:00 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/b257658b/76beb67c.mp3" length="2863899" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>179</itunes:duration>
      <itunes:summary>CISA ostrzega przed aktywnym exploitowaniem SharePoint; kanadyjski wywiad uderza w brokerów fentanylu; FIFA miała dziurę w World Cup; Google niszczy botnet NetNut; Opera blokuje ataki na schowek.</itunes:summary>
      <itunes:subtitle>CISA ostrzega przed aktywnym exploitowaniem SharePoint; kanadyjski wywiad uderza w brokerów fentanylu; FIFA miała dziurę w World Cup; Google niszczy botnet NetNut; Opera blokuje ataki na schowek.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Dzień w cyberbezpieczeństwie: wycieki, aresztowania i nowe zagrożenia</title>
      <itunes:title>Dzień w cyberbezpieczeństwie: wycieki, aresztowania i nowe zagrożenia</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">a1f0988f-66ec-4ffa-841d-141a699285c9</guid>
      <link>https://headflash.news/pl/security/2026-07-02-daily-newsletter</link>
      <description>
        <![CDATA[<p>HSIN zhakowany, aresztowanie członka Scattered Spider, kradzież schematów iPhone 18 Pro i kampania FortiBleed z ransomwarem Lynx.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.bleepingcomputer.com/news/security/dhs-confirms-hackers-breach-hsin-info-sharing-platform/">DHS confirms hackers breached HSIN info-sharing platform</a></li><li><a href="https://www.wired.com/story/claude-helped-a-hacker-find-a-way-to-issue-tickets-to-almost-every-us-music-festival/">Claude Helped a Hacker Find a Way to Issue Tickets to Almost Every US Music Festival | WIRED</a></li><li><a href="https://www.justice.gov/opa/pr/alleged-member-criminal-cyber-hacking-group-scattered-spider-arrested-finland-and-extradited">Office of Public Affairs |  Alleged Member of Criminal Cyber Hacking Group „Scattered Spider” Arrested in Finland and Extradited to the United States | United States Department of Justice</a></li><li><a href="https://boingboing.net/2026/07/01/hackers-stole-iphone-18-pro-schematics-from-apple-supplier-tata.html">Hackers stole iPhone 18 Pro schematics from Apple supplier Tata</a></li><li><a href="https://www.bleepingcomputer.com/news/security/fortibleed-credential-theft-campaign-linked-to-lynx-ransomware/">FortiBleed credential-theft campaign linked to Lynx ransomware</a></li><li><a href="https://www.bleepingcomputer.com/news/security/dhs-confirms-hackers-breached-hsin-info-sharing-platform">DHS confirms hackers breached HSIN info-sharing platform</a></li><li><a href="https://www.wired.com/story/claude-helped-a-hacker-find-a-way-to-issue-tickets-to-almost-every-us-music-festival">Claude Helped a Hacker Find a Way to Issue Tickets to Almost Every US Music Festival | WIRED</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-02-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>HSIN zhakowany, aresztowanie członka Scattered Spider, kradzież schematów iPhone 18 Pro i kampania FortiBleed z ransomwarem Lynx.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.bleepingcomputer.com/news/security/dhs-confirms-hackers-breach-hsin-info-sharing-platform/">DHS confirms hackers breached HSIN info-sharing platform</a></li><li><a href="https://www.wired.com/story/claude-helped-a-hacker-find-a-way-to-issue-tickets-to-almost-every-us-music-festival/">Claude Helped a Hacker Find a Way to Issue Tickets to Almost Every US Music Festival | WIRED</a></li><li><a href="https://www.justice.gov/opa/pr/alleged-member-criminal-cyber-hacking-group-scattered-spider-arrested-finland-and-extradited">Office of Public Affairs |  Alleged Member of Criminal Cyber Hacking Group „Scattered Spider” Arrested in Finland and Extradited to the United States | United States Department of Justice</a></li><li><a href="https://boingboing.net/2026/07/01/hackers-stole-iphone-18-pro-schematics-from-apple-supplier-tata.html">Hackers stole iPhone 18 Pro schematics from Apple supplier Tata</a></li><li><a href="https://www.bleepingcomputer.com/news/security/fortibleed-credential-theft-campaign-linked-to-lynx-ransomware/">FortiBleed credential-theft campaign linked to Lynx ransomware</a></li><li><a href="https://www.bleepingcomputer.com/news/security/dhs-confirms-hackers-breached-hsin-info-sharing-platform">DHS confirms hackers breached HSIN info-sharing platform</a></li><li><a href="https://www.wired.com/story/claude-helped-a-hacker-find-a-way-to-issue-tickets-to-almost-every-us-music-festival">Claude Helped a Hacker Find a Way to Issue Tickets to Almost Every US Music Festival | WIRED</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-02-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Thu, 02 Jul 2026 09:00:51 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/2e307719/f40b944a.mp3" length="3722387" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>233</itunes:duration>
      <itunes:summary>HSIN zhakowany, aresztowanie członka Scattered Spider, kradzież schematów iPhone 18 Pro i kampania FortiBleed z ransomwarem Lynx.</itunes:summary>
      <itunes:subtitle>HSIN zhakowany, aresztowanie członka Scattered Spider, kradzież schematów iPhone 18 Pro i kampania FortiBleed z ransomwarem Lynx.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Nowe luki, ransomware i APT: codzienny przegląd cyberzagrożeń</title>
      <itunes:title>Nowe luki, ransomware i APT: codzienny przegląd cyberzagrożeń</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">62bc2b8e-a42f-40c6-81c8-cc219a3b2865</guid>
      <link>https://headflash.news/pl/security/2026-07-01-daily-newsletter</link>
      <description>
        <![CDATA[<p>CitrixBleed, Gamaredon w akcji, Mustang Panda w Indii, SimpleHelp pod ostrzałem i BlueHammer w rękach ransomware.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://labs.watchtowr.com/citrixbleed-to-infinity-and-beyond-citrix-netscaler-pre-auth-memory-overread-cve-2026-8451">CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)</a></li><li><a href="https://www.techtimes.com/articles/319374/20260630/russian-hackers-gamaredon-weaponize-winrar-flaw-first-destructive-strike.htm">Russian Hackers Gamaredon Weaponize WinRAR Flaw for First Destructive Strike</a></li><li><a href="https://www.techtimes.com/articles/319364/20260630/china-linked-mustang-panda-hides-spy-tools-inside-indias-trusted-cloud-storage-app.htm">China-Linked Mustang Panda Hides Spy Tools Inside India's Trusted Cloud Storage App</a></li><li><a href="https://www.techrepublic.com/article/news-simplehelp-flaw-djinn-stealer-developer-credentials/">SimpleHelp Flaw Exploited to Deploy Malware Targeting Windows, macOS, and Linux</a></li><li><a href="https://www.bleepingcomputer.com/news/security/cisa-windows-bluehammer-flaw-now-exploited-by-ransomware-gangs">CISA: Windows BlueHammer flaw now exploited by ransomware gangs</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-01-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>CitrixBleed, Gamaredon w akcji, Mustang Panda w Indii, SimpleHelp pod ostrzałem i BlueHammer w rękach ransomware.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://labs.watchtowr.com/citrixbleed-to-infinity-and-beyond-citrix-netscaler-pre-auth-memory-overread-cve-2026-8451">CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)</a></li><li><a href="https://www.techtimes.com/articles/319374/20260630/russian-hackers-gamaredon-weaponize-winrar-flaw-first-destructive-strike.htm">Russian Hackers Gamaredon Weaponize WinRAR Flaw for First Destructive Strike</a></li><li><a href="https://www.techtimes.com/articles/319364/20260630/china-linked-mustang-panda-hides-spy-tools-inside-indias-trusted-cloud-storage-app.htm">China-Linked Mustang Panda Hides Spy Tools Inside India's Trusted Cloud Storage App</a></li><li><a href="https://www.techrepublic.com/article/news-simplehelp-flaw-djinn-stealer-developer-credentials/">SimpleHelp Flaw Exploited to Deploy Malware Targeting Windows, macOS, and Linux</a></li><li><a href="https://www.bleepingcomputer.com/news/security/cisa-windows-bluehammer-flaw-now-exploited-by-ransomware-gangs">CISA: Windows BlueHammer flaw now exploited by ransomware gangs</a></li></ul><p><a href="https://headflash.news/pl/security/2026-07-01-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Wed, 01 Jul 2026 09:01:12 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/6aa36393/7c4bb89d.mp3" length="2501110" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>157</itunes:duration>
      <itunes:summary>CitrixBleed, Gamaredon w akcji, Mustang Panda w Indii, SimpleHelp pod ostrzałem i BlueHammer w rękach ransomware.</itunes:summary>
      <itunes:subtitle>CitrixBleed, Gamaredon w akcji, Mustang Panda w Indii, SimpleHelp pod ostrzałem i BlueHammer w rękach ransomware.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>HeadFlash Security: malware, luki, regulacje i przełomowy wyrok</title>
      <itunes:title>HeadFlash Security: malware, luki, regulacje i przełomowy wyrok</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">6bb4fa66-a735-44b4-b6ec-97c62f3fe922</guid>
      <link>https://headflash.news/pl/security/2026-06-30-daily-newsletter</link>
      <description>
        <![CDATA[<p>Microsoft usuwa 119 rozszerzeń z malwarem, Apple przyspiesza łatki przez AI, Sąd Najwyższy zmienia zasady geofencingu – oto najważniejsze historie dnia.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://deafnews.it/en/news/cybersecurity/microsoft-removes-119-edge-extensions-hiding-malware-in-images-and-fonts">Microsoft Removes 119 Edge Extensions Hiding… | DeafNews</a></li><li><a href="https://www.infosecurity-magazine.com/news/us-insurance-regulator-confirms">US Federal Insurance Regulator Confirms Data Breach Via Oracle Flaw - Infosecurity Magazine</a></li><li><a href="https://9to5mac.com/2026/06/29/apple-accelerates-security-updates-in-response-to-ai-powered-hacking-risks/">Apple accelerates security updates in response to AI-powered hacking risks</a></li><li><a href="https://cyberscoop.com/ai-agent-act-senate-draft-bill-mark-warner/">Warner bill would create federally vetted list for secure, trustworthy AI agents</a></li><li><a href="https://www.cnet.com/news/privacy/supreme-court-ruling-geofencing-warrants-phone-location-data-privacy/#ftag=CAD-01-10aai3d">Supreme Court Supports Privacy Protections for Cellphone Location Data</a></li></ul><p><a href="https://headflash.news/pl/security/2026-06-30-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Microsoft usuwa 119 rozszerzeń z malwarem, Apple przyspiesza łatki przez AI, Sąd Najwyższy zmienia zasady geofencingu – oto najważniejsze historie dnia.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://deafnews.it/en/news/cybersecurity/microsoft-removes-119-edge-extensions-hiding-malware-in-images-and-fonts">Microsoft Removes 119 Edge Extensions Hiding… | DeafNews</a></li><li><a href="https://www.infosecurity-magazine.com/news/us-insurance-regulator-confirms">US Federal Insurance Regulator Confirms Data Breach Via Oracle Flaw - Infosecurity Magazine</a></li><li><a href="https://9to5mac.com/2026/06/29/apple-accelerates-security-updates-in-response-to-ai-powered-hacking-risks/">Apple accelerates security updates in response to AI-powered hacking risks</a></li><li><a href="https://cyberscoop.com/ai-agent-act-senate-draft-bill-mark-warner/">Warner bill would create federally vetted list for secure, trustworthy AI agents</a></li><li><a href="https://www.cnet.com/news/privacy/supreme-court-ruling-geofencing-warrants-phone-location-data-privacy/#ftag=CAD-01-10aai3d">Supreme Court Supports Privacy Protections for Cellphone Location Data</a></li></ul><p><a href="https://headflash.news/pl/security/2026-06-30-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Tue, 30 Jun 2026 09:01:15 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/5bfb4a89/206447d5.mp3" length="3612046" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>226</itunes:duration>
      <itunes:summary>Microsoft usuwa 119 rozszerzeń z malwarem, Apple przyspiesza łatki przez AI, Sąd Najwyższy zmienia zasady geofencingu – oto najważniejsze historie dnia.</itunes:summary>
      <itunes:subtitle>Microsoft usuwa 119 rozszerzeń z malwarem, Apple przyspiesza łatki przez AI, Sąd Najwyższy zmienia zasady geofencingu – oto najważniejsze historie dnia.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Cyberatak za 2,5 mld $, fizyczne wtargnięcia i nowy rootkit w Linuxie</title>
      <itunes:title>Cyberatak za 2,5 mld $, fizyczne wtargnięcia i nowy rootkit w Linuxie</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">8e364b76-15f6-4388-b03f-4cf4e697e3de</guid>
      <link>https://headflash.news/pl/security/2026-06-29-daily-newsletter</link>
      <description>
        <![CDATA[<p>Jaguar Land Rover padło ofiarą rosyjskich hakerów. FBI ściga grupy wynajmujące włamywaczy. DirtyClone zagraża kerneliom.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://thenextweb.com/news/jaguar-land-rover-hack-russian-hackers-nyt-investigation">Russian hackers were behind the Jaguar Land Rover attack that cost the British economy two and a half billion dollars</a></li><li><a href="https://www.cbsnews.com/news/iranian-national-us-alleged-3-4-billion-hacking-attacks-arrested-montenegro/">Iranian national U.S. sought for $3.4 billion in hacking attacks arrested in Montenegro</a></li><li><a href="https://www.techtimes.com/articles/319188/20260627/linux-kernel-root-exploit-published-dirtyclone-attack-leaves-no-trace.htm">Linux Kernel Root Exploit Published: DirtyClone Attack Leaves No Trace</a></li><li><a href="https://www.techradar.com/pro/security/gta-vi-fans-beware-experts-warn-a-new-wave-of-scam-websites-is-offering-early-access-but-just-stealing-your-bank-details-instead">GTA VI fans beware — experts warn 'a new wave of scam websites' is offering early access, but just stealing your bank details instead</a></li><li><a href="https://www.cnn.com/2026/06/27/politics/cybercriminals-hire-burglars-russian-us-law-firms">When cybercriminals hire burglars: Inside an alleged Russian effort to infiltrate multibillion-dollar US law firms</a></li><li><a href="https://0din.ai/blog/clone-this-repo-and-i-own-your-machine">Clone This Repo and I Own Your Machine | 0din.ai</a></li><li><a href="https://www.techtimes.com/articles/319200/20260628/polymarket-loses-31m-frontend-vendor-hack-while-cftc-investigation-deepens.htm">Polymarket Loses $3.1M to Frontend Vendor Hack While CFTC Investigation Deepens</a></li></ul><p><a href="https://headflash.news/pl/security/2026-06-29-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Jaguar Land Rover padło ofiarą rosyjskich hakerów. FBI ściga grupy wynajmujące włamywaczy. DirtyClone zagraża kerneliom.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://thenextweb.com/news/jaguar-land-rover-hack-russian-hackers-nyt-investigation">Russian hackers were behind the Jaguar Land Rover attack that cost the British economy two and a half billion dollars</a></li><li><a href="https://www.cbsnews.com/news/iranian-national-us-alleged-3-4-billion-hacking-attacks-arrested-montenegro/">Iranian national U.S. sought for $3.4 billion in hacking attacks arrested in Montenegro</a></li><li><a href="https://www.techtimes.com/articles/319188/20260627/linux-kernel-root-exploit-published-dirtyclone-attack-leaves-no-trace.htm">Linux Kernel Root Exploit Published: DirtyClone Attack Leaves No Trace</a></li><li><a href="https://www.techradar.com/pro/security/gta-vi-fans-beware-experts-warn-a-new-wave-of-scam-websites-is-offering-early-access-but-just-stealing-your-bank-details-instead">GTA VI fans beware — experts warn 'a new wave of scam websites' is offering early access, but just stealing your bank details instead</a></li><li><a href="https://www.cnn.com/2026/06/27/politics/cybercriminals-hire-burglars-russian-us-law-firms">When cybercriminals hire burglars: Inside an alleged Russian effort to infiltrate multibillion-dollar US law firms</a></li><li><a href="https://0din.ai/blog/clone-this-repo-and-i-own-your-machine">Clone This Repo and I Own Your Machine | 0din.ai</a></li><li><a href="https://www.techtimes.com/articles/319200/20260628/polymarket-loses-31m-frontend-vendor-hack-while-cftc-investigation-deepens.htm">Polymarket Loses $3.1M to Frontend Vendor Hack While CFTC Investigation Deepens</a></li></ul><p><a href="https://headflash.news/pl/security/2026-06-29-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Mon, 29 Jun 2026 09:04:38 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/988e5be3/68be855c.mp3" length="3790514" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>237</itunes:duration>
      <itunes:summary>Jaguar Land Rover padło ofiarą rosyjskich hakerów. FBI ściga grupy wynajmujące włamywaczy. DirtyClone zagraża kerneliom.</itunes:summary>
      <itunes:subtitle>Jaguar Land Rover padło ofiarą rosyjskich hakerów. FBI ściga grupy wynajmujące włamywaczy. DirtyClone zagraża kerneliom.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Kradzież kluczy API, globalna operacja, luka w macOS i AI robak</title>
      <itunes:title>Kradzież kluczy API, globalna operacja, luka w macOS i AI robak</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">0e4c261b-df29-4efe-a147-c1837d1df90b</guid>
      <link>https://headflash.news/pl/security/2026-06-26-daily-newsletter</link>
      <description>
        <![CDATA[<p>Złośliwe wtyczki JetBrains wykradły klucze AI 70 tys. programistów; Europol zamroził 47 mln USD; nowa luka w macOS; fałszywe pendrive'y w armii Japonii; autonomiczny robak AI.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://haltingproblems.com/analysis/jetbrains-malicious-plugins-ai-api-key-theft">15 Malicious JetBrains Plugins Stole AI API Keys from 70,000 Developers | Halting Problems</a></li><li><a href="https://www.techradar.com/pro/security/27-million-stolen-login-credentials-have-been-recovered-global-coordinated-takedown-hits-socgholish-amadey-and-stealc-malware-networks-where-it-hurt">'27 million stolen login credentials have been recovered': Global coordinated takedown hits SocGholish, Amadey, and StealC malware networks where it hurt</a></li><li><a href="https://www.cultofmac.com/news/macos-security-flaw-disable-enterprise-security-software">macOS security flaw lets hackers disable Mac protection tools without a password</a></li><li><a href="https://www.newsweek.com/fake-usb-sticks-spread-china-linked-virus-japan-army-12120117">Fake USB Sticks Spread China-Linked Virus in Japan's Army</a></li><li><a href="https://www.livescience.com/technology/artificial-intelligence/you-cant-patch-your-way-out-of-it-cheap-ai-worm-can-spread-between-devices-without-human-guidance-but-how-did-scientists-create-it">'You can't patch your way out of it': Cheap AI worm can spread between devices without human guidance — but how did scientists create it?</a></li></ul><p><a href="https://headflash.news/pl/security/2026-06-26-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Złośliwe wtyczki JetBrains wykradły klucze AI 70 tys. programistów; Europol zamroził 47 mln USD; nowa luka w macOS; fałszywe pendrive'y w armii Japonii; autonomiczny robak AI.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://haltingproblems.com/analysis/jetbrains-malicious-plugins-ai-api-key-theft">15 Malicious JetBrains Plugins Stole AI API Keys from 70,000 Developers | Halting Problems</a></li><li><a href="https://www.techradar.com/pro/security/27-million-stolen-login-credentials-have-been-recovered-global-coordinated-takedown-hits-socgholish-amadey-and-stealc-malware-networks-where-it-hurt">'27 million stolen login credentials have been recovered': Global coordinated takedown hits SocGholish, Amadey, and StealC malware networks where it hurt</a></li><li><a href="https://www.cultofmac.com/news/macos-security-flaw-disable-enterprise-security-software">macOS security flaw lets hackers disable Mac protection tools without a password</a></li><li><a href="https://www.newsweek.com/fake-usb-sticks-spread-china-linked-virus-japan-army-12120117">Fake USB Sticks Spread China-Linked Virus in Japan's Army</a></li><li><a href="https://www.livescience.com/technology/artificial-intelligence/you-cant-patch-your-way-out-of-it-cheap-ai-worm-can-spread-between-devices-without-human-guidance-but-how-did-scientists-create-it">'You can't patch your way out of it': Cheap AI worm can spread between devices without human guidance — but how did scientists create it?</a></li></ul><p><a href="https://headflash.news/pl/security/2026-06-26-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Fri, 26 Jun 2026 08:32:56 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/ba97248e/1dcc4525.mp3" length="2613959" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>164</itunes:duration>
      <itunes:summary>Złośliwe wtyczki JetBrains wykradły klucze AI 70 tys. programistów; Europol zamroził 47 mln USD; nowa luka w macOS; fałszywe pendrive'y w armii Japonii; autonomiczny robak AI.</itunes:summary>
      <itunes:subtitle>Złośliwe wtyczki JetBrains wykradły klucze AI 70 tys. programistów; Europol zamroził 47 mln USD; nowa luka w macOS; fałszywe pendrive'y w armii Japonii; autonomiczny robak AI.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Bezpieczeństwo: Gaslight, luki Ubiquiti, operacja Endgame, AI-haker i mega-przejęcie</title>
      <itunes:title>Bezpieczeństwo: Gaslight, luki Ubiquiti, operacja Endgame, AI-haker i mega-przejęcie</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">fee29757-0b36-4ba5-8d5f-14ae48329d18</guid>
      <link>https://headflash.news/pl/security/2026-06-25-daily-newsletter</link>
      <description>
        <![CDATA[<p>Rusztowy backdoor Gaslight, krytyczne luki w Ubiquiti, globalna operacja przeciw cyberprzestępczości, amator z AI i gigantyczne przejęcie Accenture w OT security.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://decipher.sc/2026/06/24/macos-gaslight-backdoor-weaponizes-prompt-injection-against-security-analysts">macOS Gaslight Backdoor Weaponizes Prompt Injection Against Security Analysts - Decipher</a></li><li><a href="https://www.bleepingcomputer.com/news/security/cisa-warns-of-max-severity-ubiquiti-flaws-exploited-in-attacks">CISA warns of max severity Ubiquiti flaws exploited in attacks</a></li><li><a href="https://arstechnica.com/security/2026/06/one-two-punch-delivered-in-global-operation-disrupts-cybercrime-assembly-line/">One-two punch delivered in global operation disrupts cybercrime "assembly line"</a></li><li><a href="https://www.bgr.com/2200632/claude-ai-cybsersecurity-attack-amateur-hacker/">Amateur Hacker Used Claude And OpenAI Agents To Hack 14 Companies</a></li><li><a href="https://www.itpro.com/business/acquisition/accenture-snaps-up-majority-stake-in-dragos-acquires-runzero-and-netrise-in-critical-infrastructure-security-push">Accenture snaps up majority stake in Dragos, acquires runZero and NetRise in critical infrastructure security push</a></li></ul><p><a href="https://headflash.news/pl/security/2026-06-25-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Rusztowy backdoor Gaslight, krytyczne luki w Ubiquiti, globalna operacja przeciw cyberprzestępczości, amator z AI i gigantyczne przejęcie Accenture w OT security.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://decipher.sc/2026/06/24/macos-gaslight-backdoor-weaponizes-prompt-injection-against-security-analysts">macOS Gaslight Backdoor Weaponizes Prompt Injection Against Security Analysts - Decipher</a></li><li><a href="https://www.bleepingcomputer.com/news/security/cisa-warns-of-max-severity-ubiquiti-flaws-exploited-in-attacks">CISA warns of max severity Ubiquiti flaws exploited in attacks</a></li><li><a href="https://arstechnica.com/security/2026/06/one-two-punch-delivered-in-global-operation-disrupts-cybercrime-assembly-line/">One-two punch delivered in global operation disrupts cybercrime "assembly line"</a></li><li><a href="https://www.bgr.com/2200632/claude-ai-cybsersecurity-attack-amateur-hacker/">Amateur Hacker Used Claude And OpenAI Agents To Hack 14 Companies</a></li><li><a href="https://www.itpro.com/business/acquisition/accenture-snaps-up-majority-stake-in-dragos-acquires-runzero-and-netrise-in-critical-infrastructure-security-push">Accenture snaps up majority stake in Dragos, acquires runZero and NetRise in critical infrastructure security push</a></li></ul><p><a href="https://headflash.news/pl/security/2026-06-25-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Thu, 25 Jun 2026 09:02:00 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/977c9e53/500c1012.mp3" length="4368970" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>274</itunes:duration>
      <itunes:summary>Rusztowy backdoor Gaslight, krytyczne luki w Ubiquiti, globalna operacja przeciw cyberprzestępczości, amator z AI i gigantyczne przejęcie Accenture w OT security.</itunes:summary>
      <itunes:subtitle>Rusztowy backdoor Gaslight, krytyczne luki w Ubiquiti, globalna operacja przeciw cyberprzestępczości, amator z AI i gigantyczne przejęcie Accenture w OT security.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Wycieki, AI i nowe ataki – przegląd security</title>
      <itunes:title>Wycieki, AI i nowe ataki – przegląd security</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">db77b9da-f791-4c9f-aff4-4cac255ffb74</guid>
      <link>https://headflash.news/pl/security/2026-06-24-daily-newsletter</link>
      <description>
        <![CDATA[<p>LastPass i Tata Electronics na celowniku, AI wykrywa luki w rządowych systemach, nowe zagrożenia CI/CD i macOS.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://deafnews.it/en/news/cybersecurity/lastpass-breached-via-klue-supply-chain-attack-customer-data-stolen-vaults-intact">LastPass Breached via Klue Supply-Chain Attack:… | DeafNews</a></li><li><a href="https://deafnews.it/en/news/cybersecurity/tata-electronics-breach-200000-files-leaked-apple-and-tesla-secrets-appear-on-dark-web">Tata Electronics Breach: 200,000 Files Leaked,… | DeafNews</a></li><li><a href="https://www.seattletimes.com/business/anthropics-mythos-model-found-vulnerabilities-in-classified-us-government-systems-official-says/">Anthropic’s Mythos model found vulnerabilities in classified US government systems, official says</a></li><li><a href="https://www.darkreading.com/application-security/cordyceps-malicious-pull-requests-developer-workflows">'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows</a></li><li><a href="https://www.bleepingcomputer.com/news/security/new-macos-clickfix-attack-silently-mounts-dmgs-to-push-infostealer/">New macOS ClickFix attack silently mounts DMGs to push infostealer</a></li></ul><p><a href="https://headflash.news/pl/security/2026-06-24-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>LastPass i Tata Electronics na celowniku, AI wykrywa luki w rządowych systemach, nowe zagrożenia CI/CD i macOS.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://deafnews.it/en/news/cybersecurity/lastpass-breached-via-klue-supply-chain-attack-customer-data-stolen-vaults-intact">LastPass Breached via Klue Supply-Chain Attack:… | DeafNews</a></li><li><a href="https://deafnews.it/en/news/cybersecurity/tata-electronics-breach-200000-files-leaked-apple-and-tesla-secrets-appear-on-dark-web">Tata Electronics Breach: 200,000 Files Leaked,… | DeafNews</a></li><li><a href="https://www.seattletimes.com/business/anthropics-mythos-model-found-vulnerabilities-in-classified-us-government-systems-official-says/">Anthropic’s Mythos model found vulnerabilities in classified US government systems, official says</a></li><li><a href="https://www.darkreading.com/application-security/cordyceps-malicious-pull-requests-developer-workflows">'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows</a></li><li><a href="https://www.bleepingcomputer.com/news/security/new-macos-clickfix-attack-silently-mounts-dmgs-to-push-infostealer/">New macOS ClickFix attack silently mounts DMGs to push infostealer</a></li></ul><p><a href="https://headflash.news/pl/security/2026-06-24-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Wed, 24 Jun 2026 09:23:50 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/6bb71333/766d6697.mp3" length="2761081" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>173</itunes:duration>
      <itunes:summary>LastPass i Tata Electronics na celowniku, AI wykrywa luki w rządowych systemach, nowe zagrożenia CI/CD i macOS.</itunes:summary>
      <itunes:subtitle>LastPass i Tata Electronics na celowniku, AI wykrywa luki w rządowych systemach, nowe zagrożenia CI/CD i macOS.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Szpitale, Tesla, Microsoft, nowe ransomware i FortiBleed – przegląd</title>
      <itunes:title>Szpitale, Tesla, Microsoft, nowe ransomware i FortiBleed – przegląd</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">5fdfcc53-53c5-49ef-ad56-29d1146541a0</guid>
      <link>https://headflash.news/pl/security/2026-06-23-daily-newsletter</link>
      <description>
        <![CDATA[<p>Rumuńskie szpitale wracają do papieru, dokumenty Apple wyciekają, luka w Defenderze, nowe ransomware i masowe łamanie haseł Fortinet.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.aol.com/100-romanian-hospitals-switched-pen-233127203.html">How 100 Romanian hospitals switched to pen and paper to defeat a national cyber-attack</a></li><li><a href="https://seekingalpha.com/news/4605765-apple-tesla-documents-exposed-after-hackers-hit-tata-report">Apple, Tesla documents exposed after hackers hit Tata: report</a></li><li><a href="https://www.pcworld.com/article/3171876/microsoft-scrambles-to-patch-a-defender-security-flaw-called-rogueplanet.html">Microsoft scrambles to patch a Defender security flaw called RoguePlanet</a></li><li><a href="https://www.techrepublic.com/article/news-prinz-eugen-ransomware-recent-files/">Prinz Eugen Ransomware Hits Recent Files First and Skips Ransom Notes - TechRepublic</a></li><li><a href="https://www.infostealers.com/article/supercomputing-on-a-credit-card-from-the-ai-rush-enabled-the-massive-fortibleed-campaign">Supercomputing on a Credit Card From The AI Rush Enabled The Massive FortiBleed Campaign | InfoStealers</a></li></ul><p><a href="https://headflash.news/pl/security/2026-06-23-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Rumuńskie szpitale wracają do papieru, dokumenty Apple wyciekają, luka w Defenderze, nowe ransomware i masowe łamanie haseł Fortinet.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.aol.com/100-romanian-hospitals-switched-pen-233127203.html">How 100 Romanian hospitals switched to pen and paper to defeat a national cyber-attack</a></li><li><a href="https://seekingalpha.com/news/4605765-apple-tesla-documents-exposed-after-hackers-hit-tata-report">Apple, Tesla documents exposed after hackers hit Tata: report</a></li><li><a href="https://www.pcworld.com/article/3171876/microsoft-scrambles-to-patch-a-defender-security-flaw-called-rogueplanet.html">Microsoft scrambles to patch a Defender security flaw called RoguePlanet</a></li><li><a href="https://www.techrepublic.com/article/news-prinz-eugen-ransomware-recent-files/">Prinz Eugen Ransomware Hits Recent Files First and Skips Ransom Notes - TechRepublic</a></li><li><a href="https://www.infostealers.com/article/supercomputing-on-a-credit-card-from-the-ai-rush-enabled-the-massive-fortibleed-campaign">Supercomputing on a Credit Card From The AI Rush Enabled The Massive FortiBleed Campaign | InfoStealers</a></li></ul><p><a href="https://headflash.news/pl/security/2026-06-23-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Tue, 23 Jun 2026 08:31:20 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/7e3c7078/c0d08ba7.mp3" length="3993225" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>250</itunes:duration>
      <itunes:summary>Rumuńskie szpitale wracają do papieru, dokumenty Apple wyciekają, luka w Defenderze, nowe ransomware i masowe łamanie haseł Fortinet.</itunes:summary>
      <itunes:subtitle>Rumuńskie szpitale wracają do papieru, dokumenty Apple wyciekają, luka w Defenderze, nowe ransomware i masowe łamanie haseł Fortinet.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Bezpieczeństwo: kwantowe szyfrowanie, blokada Telegramu i wyciek w Radzie Europy</title>
      <itunes:title>Bezpieczeństwo: kwantowe szyfrowanie, blokada Telegramu i wyciek w Radzie Europy</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">5b409e19-d9e5-43fd-9a91-fd95a2057844</guid>
      <link>https://headflash.news/pl/security/2026-06-22-daily-newsletter</link>
      <description>
        <![CDATA[<p>Chiński komputer kwantowy testuje PQC, Indie blokują Telegram, Rada Europy traci dane 10 tys. pracowników – przegląd najważniejszych wydarzeń.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.techtimes.com/articles/318686/20260619/post-quantum-cryptography-meets-chinas-quantum-computer-what-shield-leaves-exposed.htm">Post-Quantum Cryptography Meets China's Quantum Computer: What the Shield Leaves Exposed</a></li><li><a href="https://hoodline.com/2026/06/chatbot-confessional-chicago-cyber-pros-say-your-secrets-are-up-for-grabs/">Chicago Experts Warn AI Chatbots Could Leak Data</a></li><li><a href="https://the-decoder.com/alleged-china-ties-at-sk-telecom-alarmed-us-officials-and-triggered-anthropic-crisis/">Alleged China ties at SK Telecom alarmed US officials and triggered Anthropic crisis</a></li><li><a href="https://the-decoder.com/google-deepmind-treats-its-own-ai-agents-like-rogue-employees-with-office-keys/">Google Deepmind treats its own AI agents like rogue employees with office keys</a></li><li><a href="https://euobserver.com/222391/europol-is-going-rogue-so-brussels-is-doubling-its-budget/">Europol is going rogue – so Brussels is doubling its budget??</a></li><li><a href="https://www.straitstimes.com/tech/sporean-brothers-quit-finance-careers-to-build-modern-unbreakable-encryption">Singaporean brothers use unsolvable maths equations to build modern, unbreakable encryption</a></li><li><a href="https://www.techtimes.com/articles/318739/20260620/indias-telegram-ban-upheld-court-putting-150-million-users-every-encrypted-app-risk.htm">India's Telegram Ban Upheld by Court, Putting 150 Million Users and Every Encrypted App at Risk</a></li><li><a href="https://www.techtimes.com/articles/318714/20260621/council-europe-data-breach-shinyhunters-makes-10000-employees-records-permanent.htm">Council of Europe Data Breach: ShinyHunters Makes 10,000 Employees' Records Permanent</a></li><li><a href="https://www.tampafp.com/failed-cyber-test-alabama-defense-contractor-settles-for-500k-over-missing-navy-safeguards/">Failed Cyber Test: Alabama Defense Contractor Settles For $500K Over Missing Navy Safeguards</a></li><li><a href="https://www.techradar.com/pro/it-looks-like-an-old-pc-but-this-bleeding-edge-server-may-well-save-us-from-hackers-causing-chaos-in-a-post-quantum-computing-world-4-1gb-s-rackable-quantum-random-number-generator-brings-entropy-to-the-data-center">It looks like an old PC, but this bleeding-edge 'server' may well save us from hackers causing chaos in a post-quantum computing world — 4.1Gb/s 'rackable' quantum random number generator brings entropy to the data center</a></li><li><a href="https://www.techradar.com/pro/security/popular-free-vpn-streaming-apps-bombard-business-networks-with-laundered-traffic-used-by-criminals-to-blend-into-normal-consumer-noise-heres-how-to-keep-safe">Popular free VPN, streaming apps bombard business networks with 'laundered' traffic used by criminals to 'blend into normal consumer noise' — here's how to keep safe</a></li></ul><p><a href="https://headflash.news/pl/security/2026-06-22-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Chiński komputer kwantowy testuje PQC, Indie blokują Telegram, Rada Europy traci dane 10 tys. pracowników – przegląd najważniejszych wydarzeń.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.techtimes.com/articles/318686/20260619/post-quantum-cryptography-meets-chinas-quantum-computer-what-shield-leaves-exposed.htm">Post-Quantum Cryptography Meets China's Quantum Computer: What the Shield Leaves Exposed</a></li><li><a href="https://hoodline.com/2026/06/chatbot-confessional-chicago-cyber-pros-say-your-secrets-are-up-for-grabs/">Chicago Experts Warn AI Chatbots Could Leak Data</a></li><li><a href="https://the-decoder.com/alleged-china-ties-at-sk-telecom-alarmed-us-officials-and-triggered-anthropic-crisis/">Alleged China ties at SK Telecom alarmed US officials and triggered Anthropic crisis</a></li><li><a href="https://the-decoder.com/google-deepmind-treats-its-own-ai-agents-like-rogue-employees-with-office-keys/">Google Deepmind treats its own AI agents like rogue employees with office keys</a></li><li><a href="https://euobserver.com/222391/europol-is-going-rogue-so-brussels-is-doubling-its-budget/">Europol is going rogue – so Brussels is doubling its budget??</a></li><li><a href="https://www.straitstimes.com/tech/sporean-brothers-quit-finance-careers-to-build-modern-unbreakable-encryption">Singaporean brothers use unsolvable maths equations to build modern, unbreakable encryption</a></li><li><a href="https://www.techtimes.com/articles/318739/20260620/indias-telegram-ban-upheld-court-putting-150-million-users-every-encrypted-app-risk.htm">India's Telegram Ban Upheld by Court, Putting 150 Million Users and Every Encrypted App at Risk</a></li><li><a href="https://www.techtimes.com/articles/318714/20260621/council-europe-data-breach-shinyhunters-makes-10000-employees-records-permanent.htm">Council of Europe Data Breach: ShinyHunters Makes 10,000 Employees' Records Permanent</a></li><li><a href="https://www.tampafp.com/failed-cyber-test-alabama-defense-contractor-settles-for-500k-over-missing-navy-safeguards/">Failed Cyber Test: Alabama Defense Contractor Settles For $500K Over Missing Navy Safeguards</a></li><li><a href="https://www.techradar.com/pro/it-looks-like-an-old-pc-but-this-bleeding-edge-server-may-well-save-us-from-hackers-causing-chaos-in-a-post-quantum-computing-world-4-1gb-s-rackable-quantum-random-number-generator-brings-entropy-to-the-data-center">It looks like an old PC, but this bleeding-edge 'server' may well save us from hackers causing chaos in a post-quantum computing world — 4.1Gb/s 'rackable' quantum random number generator brings entropy to the data center</a></li><li><a href="https://www.techradar.com/pro/security/popular-free-vpn-streaming-apps-bombard-business-networks-with-laundered-traffic-used-by-criminals-to-blend-into-normal-consumer-noise-heres-how-to-keep-safe">Popular free VPN, streaming apps bombard business networks with 'laundered' traffic used by criminals to 'blend into normal consumer noise' — here's how to keep safe</a></li></ul><p><a href="https://headflash.news/pl/security/2026-06-22-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Mon, 22 Jun 2026 09:00:57 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/09b3a4a8/8371ff80.mp3" length="8236346" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>515</itunes:duration>
      <itunes:summary>Chiński komputer kwantowy testuje PQC, Indie blokują Telegram, Rada Europy traci dane 10 tys. pracowników – przegląd najważniejszych wydarzeń.</itunes:summary>
      <itunes:subtitle>Chiński komputer kwantowy testuje PQC, Indie blokują Telegram, Rada Europy traci dane 10 tys. pracowników – przegląd najważniejszych wydarzeń.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Kampania na Fortinet, fałszywe aktualizacje i AI w phishingu</title>
      <itunes:title>Kampania na Fortinet, fałszywe aktualizacje i AI w phishingu</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">0fdddaf0-6664-4f2e-b4d6-995686be7d21</guid>
      <link>https://headflash.news/pl/security/2026-06-19-daily-newsletter</link>
      <description>
        <![CDATA[<p>75 tys. firewalli Fortinet zhakowanych, socgholish usunięty z 15 tys. stron, Francja żegna niekwantową kryptografię.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.bleepingcomputer.com/news/security/law-enforcement-nukes-socgholish-malware-from-nearly-15-000-sites/">Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp</a></li><li><a href="https://www.windowscentral.com/gaming/pc-gaming/wallpaper-engine-malware-steam-workshop-kaspersky">PSA: Steam's most popular PC background app was reportedly infected with malware via Wallpaper Engine's workshop</a></li><li><a href="https://brandequity.economictimes.indiatimes.com/news/digital/researchers-say-sweeping-hack-campaign-against-fortinet-devices-compromised-prominent-organisations/131819063">Researchers say sweeping hack campaign against Fortinet devices compromised prominent organisations</a></li><li><a href="https://www.techradar.com/pro/meet-kali365-the-amazon-of-cybercrime-where-hackers-use-ai-to-completely-circumvent-multi-factor-authentication">Meet Kali365 — the 'Amazon of cybercrime' where hackers use AI to completely circumvent multi-factor authentication</a></li><li><a href="https://decrypt.co/371487/france-phase-out-non-quantum-encryption-bitcoin-security-concerns-grow">France to Phase Out Non-Quantum Encryption as Bitcoin Security Concerns Grow</a></li></ul><p><a href="https://headflash.news/pl/security/2026-06-19-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>75 tys. firewalli Fortinet zhakowanych, socgholish usunięty z 15 tys. stron, Francja żegna niekwantową kryptografię.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.bleepingcomputer.com/news/security/law-enforcement-nukes-socgholish-malware-from-nearly-15-000-sites/">Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp</a></li><li><a href="https://www.windowscentral.com/gaming/pc-gaming/wallpaper-engine-malware-steam-workshop-kaspersky">PSA: Steam's most popular PC background app was reportedly infected with malware via Wallpaper Engine's workshop</a></li><li><a href="https://brandequity.economictimes.indiatimes.com/news/digital/researchers-say-sweeping-hack-campaign-against-fortinet-devices-compromised-prominent-organisations/131819063">Researchers say sweeping hack campaign against Fortinet devices compromised prominent organisations</a></li><li><a href="https://www.techradar.com/pro/meet-kali365-the-amazon-of-cybercrime-where-hackers-use-ai-to-completely-circumvent-multi-factor-authentication">Meet Kali365 — the 'Amazon of cybercrime' where hackers use AI to completely circumvent multi-factor authentication</a></li><li><a href="https://decrypt.co/371487/france-phase-out-non-quantum-encryption-bitcoin-security-concerns-grow">France to Phase Out Non-Quantum Encryption as Bitcoin Security Concerns Grow</a></li></ul><p><a href="https://headflash.news/pl/security/2026-06-19-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Fri, 19 Jun 2026 06:30:40 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/e29a9c68/9a36622d.mp3" length="4005763" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>251</itunes:duration>
      <itunes:summary>75 tys. firewalli Fortinet zhakowanych, socgholish usunięty z 15 tys. stron, Francja żegna niekwantową kryptografię.</itunes:summary>
      <itunes:subtitle>75 tys. firewalli Fortinet zhakowanych, socgholish usunięty z 15 tys. stron, Francja żegna niekwantową kryptografię.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>FulcrumSec żąda 25 mln dolarów od Novo Nordisk, Rokarolla atakuje banki</title>
      <itunes:title>FulcrumSec żąda 25 mln dolarów od Novo Nordisk, Rokarolla atakuje banki</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">f9d03c83-650b-4d7e-b367-61445e42d3de</guid>
      <link>https://headflash.news/pl/security/2026-06-18-daily-newsletter</link>
      <description>
        <![CDATA[<p>FulcrumSec grozi sprzedażą danych Novo Nordisk, nowy trojan Rokarolla celuje w 217 aplikacji, a Google zaostrza sideloading.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://cryptobriefing.com/fulcrumsec-novo-nordisk-hack-ransom/">Hacking group claims major hack of Novo Nordisk, seeks $25M ransom</a></li><li><a href="https://thenextweb.com/news/rokarolla-android-banking-trojan-217-apps-device-takeover">A new Android trojan called Rokarolla targets 217 banking apps and can steal your PIN, SMS codes, and crypto wallet funds</a></li><li><a href="https://www.techtimes.com/articles/318503/20260616/conti-ransomware-loader-developer-pleads-guilty-150m-operation-riptide-case.htm">Conti Ransomware Loader Developer Pleads Guilty in $150M Operation Riptide Case</a></li><li><a href="https://www.gadgetreview.com/hackers-just-published-knicks-and-madison-square-garden-data">Hackers Just Published Knicks and Madison Square Garden Data</a></li><li><a href="https://thenextweb.com/news/arch-linux-aur-malware-credential-stealer-supply-chain">Attackers hijacked over 1,500 Arch Linux packages to steal developers' secrets, no hacking required</a></li><li><a href="https://www.varonis.com/blog/searchleak">SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon</a></li><li><a href="https://www.zdnet.com/article/how-google-android-sideloading-crackdown-works-limits/">Google's big Android sideloading crackdown has a 24-hour catch - how the new limits work</a></li><li><a href="https://arstechnica.com/security/2026/06/windows-and-linux-users-the-deadline-to-update-secure-boot-keys-is-near/">Windows and Linux users: The deadline to update Secure Boot keys is near</a></li><li><a href="https://fortune.com/2026/06/17/tiaa-saved-retiree-from-scam-using-artifical-intelligence-human-centered-work-ceo-thasunda-brown-duckett/">A 76-year-old was about to lose his entire $3 million retirement to a scam. TIAA's AI caught it—but a human prevented disaster</a></li><li><a href="https://www.zdnet.com/article/the-arch-user-repository-was-found-to-contain-even-more-malicious-apps/">Malicious apps got into the Arch User Repository - how to protect yourself</a></li><li><a href="https://thenextweb.com/news/novo-nordisk-hack-fulcrumsec-extortion">Hacking group claims it breached Novo Nordisk and demanded $25m</a></li></ul><p><a href="https://headflash.news/pl/security/2026-06-18-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>FulcrumSec grozi sprzedażą danych Novo Nordisk, nowy trojan Rokarolla celuje w 217 aplikacji, a Google zaostrza sideloading.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://cryptobriefing.com/fulcrumsec-novo-nordisk-hack-ransom/">Hacking group claims major hack of Novo Nordisk, seeks $25M ransom</a></li><li><a href="https://thenextweb.com/news/rokarolla-android-banking-trojan-217-apps-device-takeover">A new Android trojan called Rokarolla targets 217 banking apps and can steal your PIN, SMS codes, and crypto wallet funds</a></li><li><a href="https://www.techtimes.com/articles/318503/20260616/conti-ransomware-loader-developer-pleads-guilty-150m-operation-riptide-case.htm">Conti Ransomware Loader Developer Pleads Guilty in $150M Operation Riptide Case</a></li><li><a href="https://www.gadgetreview.com/hackers-just-published-knicks-and-madison-square-garden-data">Hackers Just Published Knicks and Madison Square Garden Data</a></li><li><a href="https://thenextweb.com/news/arch-linux-aur-malware-credential-stealer-supply-chain">Attackers hijacked over 1,500 Arch Linux packages to steal developers' secrets, no hacking required</a></li><li><a href="https://www.varonis.com/blog/searchleak">SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon</a></li><li><a href="https://www.zdnet.com/article/how-google-android-sideloading-crackdown-works-limits/">Google's big Android sideloading crackdown has a 24-hour catch - how the new limits work</a></li><li><a href="https://arstechnica.com/security/2026/06/windows-and-linux-users-the-deadline-to-update-secure-boot-keys-is-near/">Windows and Linux users: The deadline to update Secure Boot keys is near</a></li><li><a href="https://fortune.com/2026/06/17/tiaa-saved-retiree-from-scam-using-artifical-intelligence-human-centered-work-ceo-thasunda-brown-duckett/">A 76-year-old was about to lose his entire $3 million retirement to a scam. TIAA's AI caught it—but a human prevented disaster</a></li><li><a href="https://www.zdnet.com/article/the-arch-user-repository-was-found-to-contain-even-more-malicious-apps/">Malicious apps got into the Arch User Repository - how to protect yourself</a></li><li><a href="https://thenextweb.com/news/novo-nordisk-hack-fulcrumsec-extortion">Hacking group claims it breached Novo Nordisk and demanded $25m</a></li></ul><p><a href="https://headflash.news/pl/security/2026-06-18-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Thu, 18 Jun 2026 06:31:33 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/da67b53a/40749be7.mp3" length="7963837" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>498</itunes:duration>
      <itunes:summary>FulcrumSec grozi sprzedażą danych Novo Nordisk, nowy trojan Rokarolla celuje w 217 aplikacji, a Google zaostrza sideloading.</itunes:summary>
      <itunes:subtitle>FulcrumSec grozi sprzedażą danych Novo Nordisk, nowy trojan Rokarolla celuje w 217 aplikacji, a Google zaostrza sideloading.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Ransomware w Teams, law firm extortion, AMD silent kill switch</title>
      <itunes:title>Ransomware w Teams, law firm extortion, AMD silent kill switch</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">9a120a82-0c1a-49e1-823a-485216afd3c9</guid>
      <link>https://headflash.news/pl/security/2026-06-17-daily-newsletter</link>
      <description>
        <![CDATA[<p>DragonForce chowa się w Teams, SRG poluje na kancelarie, AMD wyłącza szyfrowanie RAM w konsumenckich Ryzenach.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.bleepingcomputer.com/news/security/ransomware-gang-abuses-microsoft-teams-relays-to-hide-malicious-traffic/">Ransomware gang abuses Microsoft Teams relays to hide malicious traffic</a></li><li><a href="https://www.occrp.org/en/news/fbi-warns-cyber-extortion-group-is-targeting-law-firms">FBI Warns Cyber Extortion Group Is Targeting Law Firms</a></li><li><a href="https://www.gadgetreview.com/nintendo-hit-by-alleged-860-mb-data-theft">Nintendo Hit by Alleged 860 MB Data Theft</a></li><li><a href="https://www.eweek.com/news/google-ai-phishing-outsider-enterprise-lawsuit/">Google Lawsuit: China-Based Scammers Used Gemini to Scale Phishing</a></li><li><a href="https://thenextweb.com/news/amd-tsme-memory-encryption-removed-consumer-ryzen-cpus">Your Ryzen CPU used to encrypt your RAM. A firmware update silently turned that off.</a></li></ul><p><a href="https://headflash.news/pl/security/2026-06-17-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>DragonForce chowa się w Teams, SRG poluje na kancelarie, AMD wyłącza szyfrowanie RAM w konsumenckich Ryzenach.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.bleepingcomputer.com/news/security/ransomware-gang-abuses-microsoft-teams-relays-to-hide-malicious-traffic/">Ransomware gang abuses Microsoft Teams relays to hide malicious traffic</a></li><li><a href="https://www.occrp.org/en/news/fbi-warns-cyber-extortion-group-is-targeting-law-firms">FBI Warns Cyber Extortion Group Is Targeting Law Firms</a></li><li><a href="https://www.gadgetreview.com/nintendo-hit-by-alleged-860-mb-data-theft">Nintendo Hit by Alleged 860 MB Data Theft</a></li><li><a href="https://www.eweek.com/news/google-ai-phishing-outsider-enterprise-lawsuit/">Google Lawsuit: China-Based Scammers Used Gemini to Scale Phishing</a></li><li><a href="https://thenextweb.com/news/amd-tsme-memory-encryption-removed-consumer-ryzen-cpus">Your Ryzen CPU used to encrypt your RAM. A firmware update silently turned that off.</a></li></ul><p><a href="https://headflash.news/pl/security/2026-06-17-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Wed, 17 Jun 2026 06:31:49 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/98b7b799/540fa8d0.mp3" length="3571922" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>224</itunes:duration>
      <itunes:summary>DragonForce chowa się w Teams, SRG poluje na kancelarie, AMD wyłącza szyfrowanie RAM w konsumenckich Ryzenach.</itunes:summary>
      <itunes:subtitle>DragonForce chowa się w Teams, SRG poluje na kancelarie, AMD wyłącza szyfrowanie RAM w konsumenckich Ryzenach.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>FBI rozbija AI phishing, REDCap zhakowany, Conti w sądzie – security news</title>
      <itunes:title>FBI rozbija AI phishing, REDCap zhakowany, Conti w sądzie – security news</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">a1349d38-9776-445a-b9df-35ecd9e7e0b2</guid>
      <link>https://headflash.news/pl/security/2026-06-16-daily-newsletter</link>
      <description>
        <![CDATA[<p>FBI i Google niszczą chińską platformę phishingową AI, hakerzy kradną dane medyczne z REDCap, Ukrainiec przyznaje się do winy w sprawie Conti i inne ważne historie.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.bleepingcomputer.com/news/security/fbi-disrupts-massive-ai-powered-phishing-service-using-a-million-urls/">FBI disrupts massive AI-powered phishing service using a million URLs</a></li><li><a href="https://www.bleepingcomputer.com/news/security/chinese-hackers-breach-redcap-servers-steal-medical-research/">Chinese hackers breach REDCap servers, steal medical research</a></li><li><a href="https://cryptobriefing.com/ukrainian-conti-ransomware-guilty-plea/">Ukrainian man pleads guilty in US to Conti ransomware charges</a></li><li><a href="https://www.dig-in.com/news/ai-is-fueling-a-surge-of-new-ransomware-threats-travelers">AI is fueling a surge of new ransomware threats: Travelers</a></li><li><a href="https://thecyberexpress.com/ransomware-preparedness-key-warns-ncsc/">Ransomware Preparedness Must Be a Boardroom Priority: NCSC Chief</a></li><li><a href="https://www.tomshardware.com/tech-industry/cyber-security/fbi-and-google-dismantle-chinese-phishing-service-that-coached-buyers-to-generate-scam-sites-with-gemini">FBI dismantles Chinese phishing service that coached buyers to generate scam sites using AI —$88 cybercrime product linked to $1.9 billion in losses, 3.87 million stolen cards</a></li></ul><p><a href="https://headflash.news/pl/security/2026-06-16-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>FBI i Google niszczą chińską platformę phishingową AI, hakerzy kradną dane medyczne z REDCap, Ukrainiec przyznaje się do winy w sprawie Conti i inne ważne historie.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.bleepingcomputer.com/news/security/fbi-disrupts-massive-ai-powered-phishing-service-using-a-million-urls/">FBI disrupts massive AI-powered phishing service using a million URLs</a></li><li><a href="https://www.bleepingcomputer.com/news/security/chinese-hackers-breach-redcap-servers-steal-medical-research/">Chinese hackers breach REDCap servers, steal medical research</a></li><li><a href="https://cryptobriefing.com/ukrainian-conti-ransomware-guilty-plea/">Ukrainian man pleads guilty in US to Conti ransomware charges</a></li><li><a href="https://www.dig-in.com/news/ai-is-fueling-a-surge-of-new-ransomware-threats-travelers">AI is fueling a surge of new ransomware threats: Travelers</a></li><li><a href="https://thecyberexpress.com/ransomware-preparedness-key-warns-ncsc/">Ransomware Preparedness Must Be a Boardroom Priority: NCSC Chief</a></li><li><a href="https://www.tomshardware.com/tech-industry/cyber-security/fbi-and-google-dismantle-chinese-phishing-service-that-coached-buyers-to-generate-scam-sites-with-gemini">FBI dismantles Chinese phishing service that coached buyers to generate scam sites using AI —$88 cybercrime product linked to $1.9 billion in losses, 3.87 million stolen cards</a></li></ul><p><a href="https://headflash.news/pl/security/2026-06-16-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Tue, 16 Jun 2026 06:32:34 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/7b85a0a2/e05bba5d.mp3" length="6371412" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>399</itunes:duration>
      <itunes:summary>FBI i Google niszczą chińską platformę phishingową AI, hakerzy kradną dane medyczne z REDCap, Ukrainiec przyznaje się do winy w sprawie Conti i inne ważne historie.</itunes:summary>
      <itunes:subtitle>FBI i Google niszczą chińską platformę phishingową AI, hakerzy kradną dane medyczne z REDCap, Ukrainiec przyznaje się do winy w sprawie Conti i inne ważne historie.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Chrome 0-day, rozbicie AudiA6, AI w oszustwach – przegląd bezpieczeństwa</title>
      <itunes:title>Chrome 0-day, rozbicie AudiA6, AI w oszustwach – przegląd bezpieczeństwa</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">935cc285-2f32-408f-adff-e45c637218d6</guid>
      <link>https://headflash.news/pl/security/2026-06-15-daily-newsletter</link>
      <description>
        <![CDATA[<p>Krytyczna luka w Chrome, pranie kryptowalut za 380 mln USD, ataki na PeopleSoft i AI wykorzystywane przez cyberprzestępców.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://pwnhackers.substack.com/p/critical-google-chrome-0-day-exploited">Critical Google Chrome 0-Day Exploited in the Wild, Plus Microsoft and ServiceNow Under Fire</a></li><li><a href="https://www.bleepingcomputer.com/news/legal/authorities-dismantle-audia6-ransomware-crypto-laundering-service/">Authorities dismantle 'AudiA6' ransomware crypto-laundering service</a></li><li><a href="https://www.bleepingcomputer.com/news/security/oracle-peoplesoft-servers-hacked-in-shinyhunters-data-theft-attacks/">Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks</a></li><li><a href="https://www.seattletimes.com/business/google-says-chinese-cybercrime-group-used-its-ai-in-scams/">Google says Chinese cybercrime group used its AI in scams</a></li><li><a href="https://www.digitaltrends.com/cool-tech/the-fbi-secretly-built-an-entire-fake-town-just-to-practice-cyberattacks/">The FBI secretly built an entire fake town just to practice cyberattacks</a></li><li><a href="https://brutecat.com/articles/hacking-google-with-ai">Hacking Google with A.I. for $500,000 · Brutecat</a></li><li><a href="https://www.bleepingcomputer.com/news/security/oracle-peoplesoft-servers-hacked-in-shinyhunters-data-theft-attacks">Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks</a></li></ul><p><a href="https://headflash.news/pl/security/2026-06-15-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Krytyczna luka w Chrome, pranie kryptowalut za 380 mln USD, ataki na PeopleSoft i AI wykorzystywane przez cyberprzestępców.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://pwnhackers.substack.com/p/critical-google-chrome-0-day-exploited">Critical Google Chrome 0-Day Exploited in the Wild, Plus Microsoft and ServiceNow Under Fire</a></li><li><a href="https://www.bleepingcomputer.com/news/legal/authorities-dismantle-audia6-ransomware-crypto-laundering-service/">Authorities dismantle 'AudiA6' ransomware crypto-laundering service</a></li><li><a href="https://www.bleepingcomputer.com/news/security/oracle-peoplesoft-servers-hacked-in-shinyhunters-data-theft-attacks/">Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks</a></li><li><a href="https://www.seattletimes.com/business/google-says-chinese-cybercrime-group-used-its-ai-in-scams/">Google says Chinese cybercrime group used its AI in scams</a></li><li><a href="https://www.digitaltrends.com/cool-tech/the-fbi-secretly-built-an-entire-fake-town-just-to-practice-cyberattacks/">The FBI secretly built an entire fake town just to practice cyberattacks</a></li><li><a href="https://brutecat.com/articles/hacking-google-with-ai">Hacking Google with A.I. for $500,000 · Brutecat</a></li><li><a href="https://www.bleepingcomputer.com/news/security/oracle-peoplesoft-servers-hacked-in-shinyhunters-data-theft-attacks">Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks</a></li></ul><p><a href="https://headflash.news/pl/security/2026-06-15-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Mon, 15 Jun 2026 06:31:28 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/6c7ca244/c96793e3.mp3" length="4944918" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>310</itunes:duration>
      <itunes:summary>Krytyczna luka w Chrome, pranie kryptowalut za 380 mln USD, ataki na PeopleSoft i AI wykorzystywane przez cyberprzestępców.</itunes:summary>
      <itunes:subtitle>Krytyczna luka w Chrome, pranie kryptowalut za 380 mln USD, ataki na PeopleSoft i AI wykorzystywane przez cyberprzestępców.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Rekordowa kara dla Coupang, zero-day od Chaotic Eclipse, FBI uderza w chińską siatkę</title>
      <itunes:title>Rekordowa kara dla Coupang, zero-day od Chaotic Eclipse, FBI uderza w chińską siatkę</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">11465c88-5b2f-4f5e-ad15-1bca5b37369b</guid>
      <link>https://headflash.news/pl/security/2026-06-12-daily-newsletter</link>
      <description>
        <![CDATA[<p>Coupang ukarany kwotą 409 mln dolarów za wyciek danych 37 mln klientów. RoguePlanet – siódme zero-day od Chaotic Eclipse. FBI przejmuje 13 domen chińskich szpiegów.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.bleepingcomputer.com/news/security/south-korea-hits-coupang-with-record-409-million-fine-over-data-breach/">Coupang hit with record $409 million data breach fine in Korea</a></li><li><a href="https://thenextweb.com/news/chaotic-eclipse-rogueplanet-windows-defender-zero-day">The researcher Microsoft threatened just dropped a seventh Windows zero-day hours after Patch Tuesday</a></li><li><a href="https://www.pcmag.com/news/fbi-seizes-13-sites-tied-to-chinas-covert-effort-to-hire-us-officials">FBI Seizes 13 Sites Tied to China's Covert Effort to Hire US Officials</a></li><li><a href="https://www.pcmag.com/news/openai-bans-chinese-accounts-for-anti-ai-influence-campaigns">OpenAI Bans Chinese Accounts for Anti-AI Influence Campaigns</a></li><li><a href="https://thenextweb.com/news/openclaw-ai-agent-phishing-varonis-pinchy">Researchers tricked an OpenClaw AI agent into leaking AWS keys and customer data with a phishing email</a></li></ul><p><a href="https://headflash.news/pl/security/2026-06-12-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Coupang ukarany kwotą 409 mln dolarów za wyciek danych 37 mln klientów. RoguePlanet – siódme zero-day od Chaotic Eclipse. FBI przejmuje 13 domen chińskich szpiegów.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://www.bleepingcomputer.com/news/security/south-korea-hits-coupang-with-record-409-million-fine-over-data-breach/">Coupang hit with record $409 million data breach fine in Korea</a></li><li><a href="https://thenextweb.com/news/chaotic-eclipse-rogueplanet-windows-defender-zero-day">The researcher Microsoft threatened just dropped a seventh Windows zero-day hours after Patch Tuesday</a></li><li><a href="https://www.pcmag.com/news/fbi-seizes-13-sites-tied-to-chinas-covert-effort-to-hire-us-officials">FBI Seizes 13 Sites Tied to China's Covert Effort to Hire US Officials</a></li><li><a href="https://www.pcmag.com/news/openai-bans-chinese-accounts-for-anti-ai-influence-campaigns">OpenAI Bans Chinese Accounts for Anti-AI Influence Campaigns</a></li><li><a href="https://thenextweb.com/news/openclaw-ai-agent-phishing-varonis-pinchy">Researchers tricked an OpenClaw AI agent into leaking AWS keys and customer data with a phishing email</a></li></ul><p><a href="https://headflash.news/pl/security/2026-06-12-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Fri, 12 Jun 2026 06:32:15 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/b2aa9df3/f29b23bf.mp3" length="3422292" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>214</itunes:duration>
      <itunes:summary>Coupang ukarany kwotą 409 mln dolarów za wyciek danych 37 mln klientów. RoguePlanet – siódme zero-day od Chaotic Eclipse. FBI przejmuje 13 domen chińskich szpiegów.</itunes:summary>
      <itunes:subtitle>Coupang ukarany kwotą 409 mln dolarów za wyciek danych 37 mln klientów. RoguePlanet – siódme zero-day od Chaotic Eclipse. FBI przejmuje 13 domen chińskich szpiegów.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Rekordowa łatka, chińskie ataki na AI i likwidacja VPN dla ransomware</title>
      <itunes:title>Rekordowa łatka, chińskie ataki na AI i likwidacja VPN dla ransomware</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">276dd441-4dc3-46dc-992f-c665d40a7746</guid>
      <link>https://headflash.news/pl/security/2026-06-11-daily-newsletter</link>
      <description>
        <![CDATA[<p>Likwidacja VPN dla ransomware, infiltracja północnokoreańskiego schematu, rekordowa łatka Microsoftu, chińskie ataki na AI i krytyczna luka w Veeam.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://hoodline.com/2026/06/boston-feds-help-smash-bulletproof-vpn-for-ruthless-ransomware-gangs/">Boston FBI Joins Takedown Of 'First VPN' Used By Ransomware</a></li><li><a href="https://indicator.media/p/i-got-inside-a-north-korean-hiring-scam-what-i-found-reveals-a-troubling-shift-in-tactics">I got inside a North Korean hiring scam. What I found reveals a troubling shift in tactics</a></li><li><a href="https://www.benzinga.com/news/legal/26/06/53109785/crowdstrike-warns-china-is-behind-58-of-state-backed-cyber-attacks-as-chinese-and-north-korean-hackers-hunt-us-ai-secrets">CrowdStrike Warns China Is Behind 58% Of State-Backed Cyber Attacks As Chinese and North Korean Hackers Hunt US AI Secrets</a></li><li><a href="https://www.computerweekly.com/news/366644117/Microsoft-smashes-record-for-biggest-ever-Patch-Tuesday-update">Microsoft smashes record for biggest ever Patch Tuesday update | Computer Weekly</a></li><li><a href="https://www.bleepingcomputer.com/news/security/new-veeam-vulnerability-exposes-backup-servers-to-rce-attacks/">New Veeam vulnerability exposes backup servers to RCE attacks</a></li></ul><p><a href="https://headflash.news/pl/security/2026-06-11-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p>Likwidacja VPN dla ransomware, infiltracja północnokoreańskiego schematu, rekordowa łatka Microsoftu, chińskie ataki na AI i krytyczna luka w Veeam.</p><p><strong>Źródła:</strong></p><ul><li><a href="https://hoodline.com/2026/06/boston-feds-help-smash-bulletproof-vpn-for-ruthless-ransomware-gangs/">Boston FBI Joins Takedown Of 'First VPN' Used By Ransomware</a></li><li><a href="https://indicator.media/p/i-got-inside-a-north-korean-hiring-scam-what-i-found-reveals-a-troubling-shift-in-tactics">I got inside a North Korean hiring scam. What I found reveals a troubling shift in tactics</a></li><li><a href="https://www.benzinga.com/news/legal/26/06/53109785/crowdstrike-warns-china-is-behind-58-of-state-backed-cyber-attacks-as-chinese-and-north-korean-hackers-hunt-us-ai-secrets">CrowdStrike Warns China Is Behind 58% Of State-Backed Cyber Attacks As Chinese and North Korean Hackers Hunt US AI Secrets</a></li><li><a href="https://www.computerweekly.com/news/366644117/Microsoft-smashes-record-for-biggest-ever-Patch-Tuesday-update">Microsoft smashes record for biggest ever Patch Tuesday update | Computer Weekly</a></li><li><a href="https://www.bleepingcomputer.com/news/security/new-veeam-vulnerability-exposes-backup-servers-to-rce-attacks/">New Veeam vulnerability exposes backup servers to RCE attacks</a></li></ul><p><a href="https://headflash.news/pl/security/2026-06-11-daily-newsletter">📰 Przeczytaj całe wydanie na stronie</a></p>]]>
      </content:encoded>
      <pubDate>Thu, 11 Jun 2026 12:01:38 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/58e76906/bfbaec73.mp3" length="3564398" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>223</itunes:duration>
      <itunes:summary>Likwidacja VPN dla ransomware, infiltracja północnokoreańskiego schematu, rekordowa łatka Microsoftu, chińskie ataki na AI i krytyczna luka w Veeam.</itunes:summary>
      <itunes:subtitle>Likwidacja VPN dla ransomware, infiltracja północnokoreańskiego schematu, rekordowa łatka Microsoftu, chińskie ataki na AI i krytyczna luka w Veeam.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
    <item>
      <title>Tchap naruszony, GPS zagłuszany, Microsoft skompromitowany</title>
      <itunes:title>Tchap naruszony, GPS zagłuszany, Microsoft skompromitowany</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">d34e803b-06a9-4771-adca-9c1d02c28abd</guid>
      <link>https://share.transistor.fm/s/c1d08af9</link>
      <description>
        <![CDATA[Naruszenie Tchapa, rosyjskie zakłócenia GPS, luka w Check Point i dwukrotny atak na pakiety Microsoftu – przegląd najważniejszych wydarzeń w security.]]>
      </description>
      <content:encoded>
        <![CDATA[Naruszenie Tchapa, rosyjskie zakłócenia GPS, luka w Check Point i dwukrotny atak na pakiety Microsoftu – przegląd najważniejszych wydarzeń w security.]]>
      </content:encoded>
      <pubDate>Wed, 10 Jun 2026 07:00:14 +0200</pubDate>
      <author>HeadFlash</author>
      <enclosure url="https://media.transistor.fm/c1d08af9/65a008ce.mp3" length="1586616" type="audio/mpeg"/>
      <itunes:author>HeadFlash</itunes:author>
      <itunes:duration>100</itunes:duration>
      <itunes:summary>Naruszenie Tchapa, rosyjskie zakłócenia GPS, luka w Check Point i dwukrotny atak na pakiety Microsoftu – przegląd najważniejszych wydarzeń w security.</itunes:summary>
      <itunes:subtitle>Naruszenie Tchapa, rosyjskie zakłócenia GPS, luka w Check Point i dwukrotny atak na pakiety Microsoftu – przegląd najważniejszych wydarzeń w security.</itunes:subtitle>
      <itunes:keywords>cybersecurity, infosec, breaches, vulnerabilities, hacking</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
    </item>
  </channel>
</rss>
