Vulnerabilities and CVEs New critical vulnerabilities — how not to drown in CVEs
Dozens of new vulnerabilities are published every day. We show how to tell the ones that actually affect you from the noise.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Vulnerabilities and CVEs Dozens of new vulnerabilities are published every day. We show how to tell the ones that actually affect you from the noise.
Human Security Criminals impersonate KSeF, e-government and gov.pl domains to target company finance teams. What this phishing looks like and how to secure it.
AI Security AI agents run code and tools on untrusted data. Build a sandbox with process, network, filesystem and secret isolation plus hard resource limits.
AI Security Browser agents read untrusted pages and act inside user sessions. Constrain cookies, origins, forms, downloads and the impact of prompt injection.
Cybersecurity History In 2003, the fastest worm in history doubled in size every few seconds, packed into a single package, and infected almost all vulnerable servers in 10 minutes - despite an existing patch.
AI Security A malicious API, MCP or CLI result can redirect an agent. Secure tool output with schemas, provenance, isolation and independent action policy.
AI Security Poisoned memory affects future agent sessions and users. Enforce provenance, tenant isolation, write validation, expiry and reliable deletion.
AI Security An LLM gateway centralises keys, model routing and logs but becomes a critical trust point. Secure auth, tenants, retention, cache and fallback.
Cloud, Infrastructure and DevSecOps Microsoft 365 is the heart of most companies — and the top target of account attacks. Ten configurations that close common takeover paths.
Cybersecurity History In 2010 the world discovered a landmark cyberweapon: code that damaged Iranian centrifuges while showing operators normal readings. The Stuxnet story and its lessons for OT security.
AI Security An agent test harness measures prompt injection, tool abuse, memory poisoning, exfiltration and cost loops. Build scenarios, oracles and CI gates.
AI Security Coding agents install packages, run scripts and publish changes. Secure dependencies, CI identities, provenance, reviews, tests and secrets.
Human Security A campaign impersonating mObywatel uses sender spoofing and a fake 200 PLN fine. We explain why it looks so convincing and how not to fall for it.
AI Security Trace models, workflows and tool calls with OpenTelemetry. Design spans, metrics, content redaction, retention and security alerts for AI agents.
AI Security Model routers optimise cost and quality but can change region, retention and safety. Enforce data-class policy and test downgrade and fallback paths.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.