Vulnerabilities and CVEs Authlib CVE-2026-96760: when a missing signature passes verification
CERT/CC warns of a JWS verification bypass in Authlib. We explain the advisory's scope, exposure assessment and controls at the trust boundary.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Vulnerabilities and CVEs CERT/CC warns of a JWS verification bypass in Authlib. We explain the advisory's scope, exposure assessment and controls at the trust boundary.
Human Security CERT Orange warns about criminals obtaining top-up codes from drivers and couriers. Learn how to recognise the request and set clear rules for extra purchases.
AI Security The new Digital Defense Report connects AI risk with identity, data and tools. Here are the decisions organisations should make before deploying an agent.
Vulnerabilities and CVEs CVE-2026-88771 and CVE-2026-88772 allow unauthenticated remote code execution. Here are the fixed versions and a practical compromise-assessment plan.
Threats and Incidents ENISA Threat Landscape 2026 examines ransomware, DDoS, vulnerabilities and supplier dependencies. We translate its findings into board-level decisions.
Human Security Microsoft described campaigns in which fake invitations and documents installed legitimate remote access tools. Here is what employees and organisations should do.
Governance and Compliance The ministry proposes supplier certification, minimum safeguards, patient alerts and new duties for large-scale health-data processors.
Identity and Access The free sandbox provides a demo mObywatel Europa app and identity verifier. We explain useful test cases, privacy choices and failure modes.
Cloud, Infrastructure and DevSecOps A new government recommendation calls for segmentation, MFA, configuration backups and monitoring. We translate it into service resilience.
Human Security The eighth Cybersecurity Forum and European Cybersecurity Month begin on 30 September. Here is a practical plan for staff and management.
Governance and Compliance Essential and important entities have until 3 October to apply for Poland's KSC register. Here is what to verify and what comes next.
Identity and Access S46 supports European eID through login.gov.pl. We explain what this means for foreign representatives and how to govern their access.
Human Security CERT Polska linked 852 Meta ads to 17 Google Play apps in a toll-fraud operation. We explain the risk and actions for users and employers.
Governance and Compliance Reporting duties for actively exploited vulnerabilities and severe product incidents are already in force through ENISA's new platform.
Threats and Incidents Poland's data protection authority plans to inspect the Medyc software vendor while cybercrime police investigate. Here is what is known and what to do next.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.
We turn current threats into role-based training, safe exercises and a clear reporting path. The free Academy remains available for self-paced learning.